<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=devops+learner+seeks+realworld%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Sun, 02 Aug 2026 09:46:43 +0200</lastBuildDate>
<pubDate>Sun, 02 Aug 2026 09:46:43 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=devops+learner+seeks+realworld%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=devops+learner+seeks+realworld%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Tech layoffs: A 2026 timeline]]></title>
<description><![CDATA[Among a range of factors leading to a wave of tech sector layoffs in 2026 is the rapid rise of artificial intelligence and automation. Companies are reconfiguring their workforces to leverage AI for increased efficiency and reduced operating costs. This realignment and reduction is implemented ev...]]></description>
<link>https://tsecurity.de/de/3694770/ai-nachrichten/tech-layoffs-a-2026-timeline/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694770/ai-nachrichten/tech-layoffs-a-2026-timeline/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:08 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Among a range of factors leading to a wave of tech sector layoffs in 2026 is the rapid rise of artificial intelligence and automation. Companies are reconfiguring their workforces to leverage AI for increased efficiency and reduced operating costs. This realignment and reduction is implemented even by companies reporting strong financial performance.</p>



<p class="wp-block-paragraph">But it’s not just AI leading to workforce cuts. Complementing this technological shift are ongoing economic uncertainty, inflation, and higher interest rates, compounded by a chip shortage and rising energy costs. This mix is driving companies to cut costs and streamline operations for increased efficiency.</p>



<p class="wp-block-paragraph">According to data compiled by <a href="https://layoffs.fyi/" target="_blank" rel="noreferrer noopener">Layoffs.fyi</a>, an online tracker that keep tabs on job losses in the technology sector, 123,941 tech employees were laid off at 269 companies in 2025. The site also reports that 71,981 government employees were laid off by DOGE alone, with 182,528 total federal workers laid off.</p>



<p class="wp-block-paragraph">Here is a list — to be updated regularly — of some of the most prominent technology layoffs the industry has experienced recently.</p>



<h2 class="wp-block-heading">Notable tech layoffs in 2026</h2>



<ul class="wp-block-list">
<li>Monday.com</li>



<li>Microsoft</li>



<li>Meta</li>



<li>Cisco</li>



<li>Cloudflare</li>



<li>Oracle</li>



<li>Atlassian </li>



<li>Salesforce</li>



<li>Amazon</li>



<li>Ericsson</li>
</ul>



<h3 class="wp-block-heading">July 22, 2026: Monday.com cuts 20% of its workforce to restructure for the AI era</h3>



<p class="wp-block-paragraph">The company says the decision to <a href="https://www.computerworld.com/article/4200349/monday-com-cuts-20-of-its-workforce-to-restructure-for-the-ai-era-2.html">cut 620 jobs</a> isn’t about margins, but about creating a flatter organization built around AI agents, autonomous teams, and deeper customer engagement.</p>



<h3 class="wp-block-heading">July 6, 2026: Microsoft cuts 4,800 jobs, primarily in sales and Xbox teams</h3>



<p class="wp-block-paragraph">As the company <a href="https://www.computerworld.com/article/4193532/microsoft-bets-that-enterprise-ai-needs-engineers-not-bigger-sales-teams-2.html" target="_blank">trims thousands of jobs</a>, it’s also investing in embedded engineering teams and AI infrastructure. The layoffs come several weeks after the company offered 8,750 US employees <a href="https://www.computerworld.com/article/4163188/microsoft-to-offer-voluntary-retirement-buyouts-to-about-7-of-the-us-workforce.html">voluntary retirement buyouts</a>.</p>



<h3 class="wp-block-heading">June 5, 2026: Tech industry cut 38,242 jobs in May, worst since 2024</h3>



<p class="wp-block-paragraph">AI was blamed for 40% of <a href="https://www.computerworld.com/article/4181822/tech-industry-cut-38242-jobs-in-may-worst-since-2024.html">the job cuts in May</a>, up from 7% in January, according to research by employment placement company Challenger, Gray &amp; Christmas.</p>



<h3 class="wp-block-heading">May 20, 2026: Meta cuts 8,000 jobs, around 10% of workforce</h3>



<p class="wp-block-paragraph">The cuts are expected to expected to hit Meta’s engineering and product teams the hardest, arriving as Meta pivots toward AI to boost efficiency across its organization, <a href="https://tech.yahoo.com/general/article/meta-starts-cutting-8000-jobs-as-part-of-previously-announced-layoffs-145220586.html" target="_blank" rel="noreferrer noopener">according to Yahoo Tech</a>.</p>



<h3 class="wp-block-heading">May 13, 2026: Cisco to cut nearly 4,000 jobs despite strong growth in AI, enterprise networking</h3>



<p class="wp-block-paragraph">Despite reporting positive financial news — including record third-quarter revenue of $15.8 billion, a 12% year-over-year increase — Cisco said it will <a href="https://www.networkworld.com/article/4171043/cisco-to-cut-nearly-4000-jobs-despite-strong-growth-in-ai-enterprise-networking.html" target="_blank">eliminate almost 4,000 jobs</a>.</p>



<h3 class="wp-block-heading">May 7, 2026: Cloudflare to cut 1,100 jobs in AI-focused restructuring</h3>



<p class="wp-block-paragraph">About <a href="https://finance.yahoo.com/markets/stocks/articles/cloudflare-cut-over-1-100-204726989.html" target="_blank" rel="noreferrer noopener">20% of Cloudflare’s global workforce will be culled</a> as the company pivots for the agentic AI era, Reuters reported.</p>



<h3 class="wp-block-heading">April 1, 2026: Oracle to cut up to 30,000 jobs globally, putting enterprise support and roadmaps at risk</h3>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4153113/oracle-cuts-up-to-30000-jobs-globally-putting-enterprise-support-and-roadmaps-at-risk.html">Oracle began laying off employees</a> on March 31 in what could be the largest workforce reduction in the company’s history. Employees received termination emails at 6 a.m. local time with immediate system lockouts and no prior warning. <em>(Note: in June, CNBC put the <a href="https://www.cnbc.com/2026/06/23/oracle-ai-job-cuts-layoffs-21000.html" target="_blank" rel="noreferrer noopener">final layoff tally at 21,000</a>.)</em></p>



<h3 class="wp-block-heading">March 12, 2026: Atlassian cuts 1,600 jobs to fund AI and enterprise expansion</h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4144218/atlassian-cuts-1600-jobs-to-fund-ai-and-enterprise-expansion.html">Atlassian will reduce its global workforce</a> by approximately 10%, eliminating around 1,600 roles, as the collaboration software maker redirects capital toward artificial intelligence development and enterprise sales.</p>



<h3 class="wp-block-heading">March 11, 2026: Tech layoffs surpass 45,000 in early 2026</h3>



<p class="wp-block-paragraph">A recent analysis by RationalFX found 45,363 job cuts globally so far this year—with roughly 68% or more than 30,000 occurring in the U.S. — highlighting ongoing <a href="https://www.networkworld.com/article/4143749/tech-layoffs-surpass-45000-in-early-2026.html" target="_blank">workforce cuts even as many tech companies report strong revenue growth</a>.</p>



<h3 class="wp-block-heading">February 10, 2026: Salesforce lays off staffers as executive leadership churn continues</h3>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4130028/salesforce-lays-off-staffers-as-executive-leadership-churn-continues.html" target="_blank">Salesforce has reduced close to 1,000 roles</a> earlier this month across teams, including marketing, product management, data analytics, and its <a href="https://www.cio.com/article/4011936/salesforce-agentforce-3-promises-new-ways-to-monitor-and-manage-ai-agents.html">Agentforce</a> AI unit, <a href="https://www.businessinsider.com/salesforce-cuts-jobs-executive-changes-2026-2">Business Insider</a> reported, quoting employees familiar with the matter.</p>



<h3 class="wp-block-heading">January 23, 2026: Amazon layoffs expected to disproportionately hit AWS and tech talent</h3>



<p class="wp-block-paragraph">As the market slows down, <a href="https://www.computerworld.com/article/4121653/amazon-layoffs-expected-to-disproportionately-hit-aws-and-tech-talent.html">AWS and other Amazon units are preparing for another round of layoffs</a>, which is expected to overwhelmingly impact tech talent. An email from HR leader Beth Galetti on Jan. 28 <a href="https://www.computerworld.com/article/4123477/amazon-confirms-16000-job-cuts-including-to-aws.html">confirmed 16,000 job cuts</a>.</p>



<h3 class="wp-block-heading">January 15, 2026: Ericsson plans to shed 1,600 jobs in Sweden</h3>



<p class="wp-block-paragraph"> Ericsson lans to cut some 1,600 jobs in Sweden, the telecommunications equipment maker said doubling down on recent cost-saving measures that have helped it weather a prolonged downturn in telecoms spending, <a href="https://www.reuters.com/business/world-at-work/ericsson-shed-1600-jobs-sweden-2026-01-15/" target="_blank" rel="noreferrer noopener">Reuters reports</a>.</p>



<h3 class="wp-block-heading">January 13, 2026: Meta plans to cut around 10% of employees in Reality Labs business</h3>



<p class="wp-block-paragraph">Meta plans to cut around 10% of the employees in its Reality Labs division who work on products including the metaverse, according to three people with knowledge of the discussions, <a href="http://meta%20plans%20to%20cut%20around%2010%25%20of%20employees%20in%20reality%20labs%20business/" target="_blank" rel="noreferrer noopener">according to The New York Times</a>.</p>



<h2 class="wp-block-heading">Layoffs in 2025</h2>



<ul class="wp-block-list">
<li>Cisco</li>



<li>Oracle</li>



<li>Windsurf</li>



<li>Intel</li>



<li>Microsoft</li>



<li>Crowdstrike</li>



<li>HPE</li>



<li>Autodesk</li>



<li>HPE</li>



<li>CISA</li>



<li>Workday</li>



<li>Salesforce</li>



<li>Meta</li>
</ul>



<h3 class="wp-block-heading">Global tech-sector layoffs surpass 244,000 in 2025</h3>



<p class="wp-block-paragraph">Economic uncertainty, elevated interest rates, and AI adoption have <a href="https://www.networkworld.com/article/4114572/global-tech-sector-layoffs-surpass-244000-in-2025.html" target="_blank">driven workforce reductions across tech companies worldwide</a>, according to a RationalFX report.</p>



<h3 class="wp-block-heading">October 28, 2025: Amazon to cut 14,000 jobs across company</h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4080142/amazon-to-cut-14000-jobs-across-company.html">Amazon will reduce its overall workforce</a> by 14,000, cutting layers of management across the company and hiring in some areas to support its “biggest bets”.</p>



<h3 class="wp-block-heading">August 18, 2025: Cisco and Oracle to cut hundreds of Bay Area jobs</h3>



<p class="wp-block-paragraph">Tech companies Cisco and Oracle are <a href="https://www.sfchronicle.com/tech/article/cisco-oracle-layoffs-bay-area-20824135.php" target="_blank" rel="noreferrer noopener">cutting hundreds of jobs across the Bay Area</a>. Cisco will eliminate 221 positions at its Milpitas and San Francisco offices, effective Oct. 13. Oracle is reducing 101 positions in Santa Clara on the same date </p>



<h3 class="wp-block-heading">August 5, 2025: 3 weeks after acquiring Windsurf, Cognition offers staff the exit door</h3>



<p class="wp-block-paragraph">Cognition, the AI coding startup that acquired rival company Windsurf three weeks ago, laid off 30 employees last week and is offering buyouts to the roughly 200 remaining employees on the team, <a href="https://www.theinformation.com/articles/cognition-offers-buyouts-newly-acquired-windsurf-staff" target="_blank" rel="noreferrer noopener">reports The Information</a>.</p>



<h3 class="wp-block-heading">July 25, 2025, Intel to lay off 22% of workforce, CEO Tan signals ‘no more blank checks’</h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4028896/intel-to-lay-off-22-of-workforce-as-ceo-tan-signals-no-more-blank-checks.html">Intel will reduce its workforce to 75,000 employees</a> by the end of 2025 as new CEO Lip-Bu Tan implements sweeping changes designed to transform the struggling chipmaker</p>



<h3 class="wp-block-heading">July 8, 2025, Intel layoffs begin: Chipmaker is cutting many thousands of jobs</h3>



<p class="wp-block-paragraph">Intel has begun laying off employees across the company. CEO Lip-Bu Tan told workers back in April to expect <a href="https://www.oregonlive.com/silicon-forest/2025/07/intel-layoffs-begin-chipmaker-is-cutting-many-thousands-of-jobs.html">major layoffs at Intel </a>in the coming months as the chipmaker slashes costs and overhauls its organization after years of technical setbacks and falling sales. </p>



<h3 class="wp-block-heading">July 2, 2025: Microsoft will cut 9,000 workers</h3>



<p class="wp-block-paragraph">Microsoft will lay off about 9,000 employees, a source familiar with the workforce cut <a href="https://www.nbcnews.com/business/business-news/microsoft-laying-9000-employees-latest-cuts-rcna216553">told CNBC</a>.  The cuts will reportedly affect less than 4% of Microsoft’s global workforce and will impact different teams, geographies and levels of experience. This is the latest in a string of cuts the tech giant has made this year.</p>



<h3 class="wp-block-heading">June 17, 2025: Intel looks to factory layoffs to return to profitability</h3>



<p class="wp-block-paragraph"><a href="https://www.networkworld.com/article/4008670/can-intel-cut-its-way-to-profit-with-factory-layoffs.html">Intel will lay off up to 20% of its manufacturing sector employees</a> starting in July,  according to media reports, as the company looks for options as it seeks a return to profitability. The cuts reportedly will be made around the world, but some of the layoffs will be closer to home, according to a report in The Oregonian citing an internal company memo from Intel manufacturing Vice President Naga Chandrasekaran.</p>



<h3 class="wp-block-heading">May 7, 2025: CrowdStrike to lay off 5% of staff</h3>



<p class="wp-block-paragraph"><a href="https://www.reuters.com/sustainability/crowdstrike-lay-off-5-staff-reaffirms-forecasts-2025-05-07/">CrowdStrike announced a plan to cut about 500 roles</a>, roughly 5% of its workforce, to streamline operations and reduce costs. The cybersecurity company will incur about $36 million to $53 million in charges related to the layoffs</p>



<h3 class="wp-block-heading">March 6, 2025: HPE cuts 2,500 jobs, remains committed to Juniper buy</h3>



<p class="wp-block-paragraph">CEO Antonio Neri told Wall Street analysts that <a href="https://www.networkworld.com/article/3840596/hpe-cuts-2500-workers-expects-juniper-buy-to-close-end-of-25-faces-tariff-issues.html">HPE would begin implementing a cost-cutting program involving layoffs </a>of about 2,500 employees over the next 18 months. HPE employs about 61,000 people worldwide.</p>



<h3 class="wp-block-heading">Feb. 27, 2025: Autodesk to lay off 9% of workforce</h3>



<p class="wp-block-paragraph">Software maker Autodesk is laying off 1,350 staff. With the rise of subscription and multi-year contracts billed annually, and self-service enablement, it finds it needs fewer sales staff, <a href="https://adsknews.autodesk.com/en/news/022725-employee-message/">CEO Andrew Anagnost said in a message to employees</a>. And with its cloud, platform, and AI products proving most profitable, it’s concentrating its staff and investments there. </p>



<h3 class="wp-block-heading">Feb. 27, 2025: HP to lay off 2,000 more</h3>



<p class="wp-block-paragraph">As part of an ongoing restructuring, HP plans to lay off up to another 2,000 workers. In recent weeks, the company has tried — unsuccessfully — to do away with telephone support staff by <a href="https://www.pcworld.com/article/2617767/hp-forced-callers-to-wait-15-minutes-before-connecting-to-support-staff.html">forcing callers to wait for at least 15 minutes</a> if they refuse to use self-service support resources online. The company swiftly backtracked, but wider job cuts are still on. </p>



<h3 class="wp-block-heading">Feb. 21, 2025: <a href="https://www.csoonline.com/article/3829710/firing-of-130-cisa-staff-worries-cybersecurity-industry.html">CISA lays off 130</a></h3>



<p class="wp-block-paragraph">Government employees get laid off too: In this case, 130 workers at the US Cybersecurity and Infrastructure Security Agency are being shown the door as a result of a DOGE decision. Cybersecurity experts are concerned that the cuts will harm the international collaborations that CISA has fostered, quite apart from their concerns about the security of the DOGE layoff process itself.</p>



<h3 class="wp-block-heading">Feb. 5, 2025: <a href="https://www.computerworld.com/article/3817887/workday-to-cut-1750-jobs-shift-focus-to-ai-and-global-expansion.html">Workday lays off 1,750</a></h3>



<p class="wp-block-paragraph">As it moves to invest more in AI and international growth, Workday is laying off 8.5% of its workforce and disposing of unused office space. Some analysts fear the cutbacks will affect the company’s customer service — unless AI can pick up the slack.</p>



<h3 class="wp-block-heading">Feb. 4, 2025: Salesforce lays off over 1,000</h3>



<p class="wp-block-paragraph">At the same time as it’s hiring sales staff for its new artificial intelligence products, Salesforce is laying off over 1,000 workers across the company, according to Bloomberg. As of June, 2024, the company had over 72,000 employees, according to its website. Salesforce did not comment on the report. In 2024 the company reportedly laid off around 1,000 staff too, in two waves: January and July.</p>



<h3 class="wp-block-heading">Jan. 14, 2025: Meta will lay off 5% of workforce</h3>



<p class="wp-block-paragraph">Mark Zuckerberg told Meta employees he intended to “move out the low performers faster” in an internal memo reported by Bloomberg. The memo announced that the company will lay off 5% of its staff, or around 3,600 staff, beginning Feb. 10. The company had already reduced its headcount by 5% in 2024 through natural attrition, the memo said. Among those leaving the company will be staff previously responsible for fact checking of posts on its social media platforms in the US, as the company begins relying on its users to police content.</p>



<h2 class="wp-block-heading">Tech layoffs in 2024</h2>



<ul class="wp-block-list">
<li>Equinix</li>



<li>AMD</li>



<li>Freshworks</li>



<li>Cisco</li>



<li>General Motors</li>



<li>Intel</li>



<li>OpenText</li>



<li>Microsoft</li>



<li>AWS</li>



<li>Dell</li>
</ul>



<h3 class="wp-block-heading">Nov. 26, 2024: <a href="https://www.networkworld.com/article/3613399/equinix-to-cut-3-of-staff-amidst-the-greatest-demand-for-data-center-infrastructure-ever.html">Equinix to cut 3% of staff</a></h3>



<p class="wp-block-paragraph">Despite intense demand for its data center capacity, Equinix is planning to lay off 3% of its workforce, or around 400 employees. The announcement followed the appointment of Adaire Fox-Martin to replace Charles Meyers as CEO and the departures of two other senior executives, CIO Milind Wagle and CISO Michael Montoya.</p>



<h3 class="wp-block-heading">Nov. 13, 2024: <a href="https://www.networkworld.com/article/3605016/amd-to-cut-4-of-workforce-to-prioritize-ai-chip-expansion-to-rival-nvidia.html#:~:text=Workforce%20reduction%20comes%20amid%20strong,shift%20in%20focus%20toward%20AI.&amp;text=Advanced%20Micro%20Devices%20(AMD)%20is,Nvidia's%20lead%20in%20the%20sector.">AMD to cut 4% of workforce</a></h3>



<p class="wp-block-paragraph">AMD will lay off around 1,000 employees as it pivots towards developing AI-focused chips, it said. The move came as a surprise to staff, as the company also reported strong quarterly earnings. </p>



<h3 class="wp-block-heading">Nov. 7, 2024: <a href="https://www.cio.com/article/3601088/freshworks-lays-off-660-about-13-percent-of-its-global-workforce-despite-strong-earnings-profits.html">Freshworks lays off 660</a></h3>



<p class="wp-block-paragraph">Enterprise software vendor Freshworks laid off around 660 staff, or around 13% of its headcount, despite reporting increased revenue and profits in its fourth fiscal quarter. The company described the layoffs as a realignment of its global workforce.</p>



<h3 class="wp-block-heading">Sept. 17, 2024: <a href="https://www.networkworld.com/article/3486901/cisco-to-cut-7-of-workforce-restructure-product-groups.html">Cisco lays off 6,000</a></h3>



<p class="wp-block-paragraph">After laying off around 4,200 staff in February, Cisco is at it again, laying off another 6,000 or around 7% of its workforce. Among the divisions affected were its threat intelligence unit, Talos Security. </p>



<h3 class="wp-block-heading">Aug. 20, 2024: <a href="https://www.cio.com/article/3489323/gm-software-layoffs-could-signal-a-shift-in-digital-transformation-strategy.html">General Motors lays off 1,000 software staff</a></h3>



<p class="wp-block-paragraph">More than 1,000 software and services staff are on the way out at General Motors, signalling that it could be rethinking its digital transformation strategy. In an internal memo, the company said that it was moving resources to its highest-priority work and flattening hierarchies.</p>



<h3 class="wp-block-heading">August 1, 2024: <a href="https://www.computerworld.com/article/3480715/intel-fires-15000-employees-as-it-intensifies-focus-on-ai.html">Intel removes 15,000 roles</a></h3>



<p class="wp-block-paragraph">Intel plans to cut its workforce by around 15% to reduce costs after a disastrous second quarter. Revenue for the three months to June 29 stagnated at around $12.8 billion, but net income fell 85% to $83 million, prompting CEO Pat Gelsinger to bring forward a company-wide meeting in order to announce that 15,000 staff would lose their jobs. “This is an incredibly hard day for Intel as we are making some of the most consequential changes in our company’s history,” Gelsinger wrote in an email to staff, continuing: “Our revenues have not grown as expected — and we’ve yet to fully benefit from powerful trends, like AI. Our costs are too high, our margins are too low. We need bolder actions to address both — particularly given our financial results and outlook for the second half of 2024, which is tougher than previously expected.”</p>



<h3 class="wp-block-heading">July 4, 2024: <a href="https://www.computerworld.es/article/2513686/opentext-despedira-a-cerca-de-1-200-empleados.html">OpenText to lay off 1,200</a></h3>



<p class="wp-block-paragraph">OpenText said it will lay off 1,200 staff, or about 1.7% of its workforce, in a bid to save around $100 million annually. It plans to hire new sales and engineering staff in other areas in 2025, it said.</p>



<h3 class="wp-block-heading">June 4, 2024: <a href="https://www.networkworld.com/article/2138075/microsoft-lays-off-staffers-from-its-azure-division.html">Microsoft lays off staff in Azure division</a></h3>



<p class="wp-block-paragraph">Microsoft laid off staff in several teams supporting its cloud services, including Azure for Operations and Mission Engineering. The company didn’t say exactly how many staff were leaving.</p>



<h3 class="wp-block-heading">April 4, 2024: <a href="https://www.cio.com/article/2081437/amazon-downsizes-aws-in-a-fresh-cost-cutting-round.html">Amazon downsizes AWS</a> in a fresh cost-cutting round</h3>



<p class="wp-block-paragraph">Amazon announced hundreds of layoffs in the sales and marketing teams of its AWS cloud services division — and also in the technology development teams for its physical retail stores, as it stepped back from efforts to generalize the “<a href="https://www.cio.com/article/2079910/amazon-drops-just-walk-out-technology-at-its-us-retail-locations.html">Just Walk Out</a>” technology built for its Amazon Fresh grocery stores. </p>



<h3 class="wp-block-heading">April 1, 2024: <a href="https://investors.delltechnologies.com/static-files/d6e82f58-d417-422f-b2f3-4d08d498abd4" target="_blank" rel="noreferrer noopener">Dell acknowledges 13,000 job cuts</a></h3>



<p class="wp-block-paragraph">Dell Technologies’ <a href="https://investors.delltechnologies.com/static-files/d6e82f58-d417-422f-b2f3-4d08d498abd4" target="_blank" rel="noreferrer noopener">latest 10K filing with the US Securities and Exchange Commission</a> disclosed that the company had laid off 13,000 employees over the course of the 2023 fiscal year; it characterized the layoffs and other reorganizational moves as cost-cutting measures. “These actions resulted in a reduction in our overall headcount,” the company said. A comparison to the previous year’s 10K filing, performed by The Register, found that Dell employed 133,000 people at that point, compared to 120,000 as of February 2024. Dell announced layoffs of 6,650 staffers on Feb. 6, but it is unclear whether those cuts were reflected in the numbers from this year’s 10K statement.</p>



<p class="wp-block-paragraph"><em><a href="https://www.computerworld.com/article/3816662/tech-layoffs-in-2024-a-timeline.html">See news of earlier layoffs.</a></em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sam Altman’s biometric startup World raises $52.5M via crypto sale]]></title>
<description><![CDATA[Sam Altman's side project — which seeks to scan the world's eyeballs and turn them into unique digital identifiers — has raised some fresh cash through a crypto sale.]]></description>
<link>https://tsecurity.de/de/3694738/ai-nachrichten/sam-altmans-biometric-startup-world-raises-525m-via-crypto-sale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694738/ai-nachrichten/sam-altmans-biometric-startup-world-raises-525m-via-crypto-sale/</guid>
<pubDate>Sat, 25 Jul 2026 19:49:49 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sam Altman's side project — which seeks to scan the world's eyeballs and turn them into unique digital identifiers — has raised some fresh cash through a crypto sale.]]></content:encoded>
</item>
<item>
<title><![CDATA[The May 2026 Security Update Review]]></title>
<description><![CDATA[I’m currently in Berlin helping set up for Pwn2Own Berlin, but that doesn’t stop Patch Tuesday from coming, and it’s another big one. At least nothing is listed as being in the wild – for now. Take a break from your regularly scheduled activities and let’s take a look at the latest security patch...]]></description>
<link>https://tsecurity.de/de/3694568/hacking/the-may-2026-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694568/hacking/the-may-2026-security-update-review/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:56 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">I’m currently in Berlin helping set up for Pwn2Own Berlin, but that doesn’t stop Patch Tuesday from coming, and it’s another big one. At least nothing is listed as being in the wild – for now. Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft. Due to technical difficulties, there will not be a video companion for this month.</p><p class=""><strong>Adobe Patches for May 2026</strong></p><p class="">For May, Adobe released 10 bulletins addressing 52 unique CVEs in Adobe Commerce, After Effects, Adobe Connect, Illustrator, Media Encoder, Premiere Pro, Substance 3D Painter, Substance 3D Sampler, Content Authenticity SDK, and the Adobe Substance 3D Designer. Here’s this month’s overview table:</p>





















  
  




  


  
    


<table>
<colgroup>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
</colgroup>
<thead>
  <tr>
    <th>Bulletin ID</th>
    <th>Product</th>
    <th>CVE Count</th>
    <th>Highest Severity</th>
    <th>Highest CVSS</th>
    <th>Exploited</th>
    <th>Deployment Priority</th>
  </tr>
</thead>
<tbody>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/magento/apsb26-49.html" target="_blank">APSB26-49</a></td>
    <td>Adobe Commerce</td>
    <td>15</td>
    <td>Critical</td>
    <td>8.7</td>
    <td>No</td>
    <td>2</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/after_effects/apsb26-48.html" target="_blank">APSB26-48</a></td>
    <td>Adobe After Effects</td>
    <td>4</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/connect/apsb26-50.html" target="_blank">APSB26-50</a></td>
    <td>Adobe Connect</td>
    <td>2</td>
    <td>Critical</td>
    <td>9.6</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/illustrator/apsb26-51.html" target="_blank">APSB26-51</a></td>
    <td>Adobe Illustrator</td>
    <td>4</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/media-encoder/apsb26-47.html" target="_blank">APSB26-47</a></td>
    <td>Adobe Media Encoder</td>
    <td>2</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/premiere_pro/apsb26-46.html" target="_blank">APSB26-46</a></td>
    <td>Adobe Premiere Pro</td>
    <td>3</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/substance3d_painter/apsb26-55.html" target="_blank">APSB26-55</a></td>
    <td>Adobe Substance 3D Painter</td>
    <td>2</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/substance3d-sampler/apsb26-54.html" target="_blank">APSB26-54</a></td>
    <td>Adobe Substance 3D Sampler</td>
    <td>1</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-53.html" target="_blank">APSB26-53</a></td>
    <td>Content Authenticity SDK</td>
    <td>14</td>
    <td>Critical</td>
    <td>7.5</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/substance3d_designer/apsb26-52.html" target="_blank">APSB26-52</a></td>
    <td>Adobe Substance 3D Designer</td>
    <td>5</td>
    <td>Important</td>
    <td>6.3</td>
    <td>No</td>
    <td>3</td>
  </tr>
</tbody>
<tfoot>
  <tr>
    <td>TOTAL</td>
    <td>10 bulletins</td>
    <td>52</td>
    <td></td>
    <td></td>
    <td></td>
    <td></td>
  </tr>
</tfoot>
</table>



  
  









  <p class="">The obvious priority this month is the patch for Commerce, with its 15 bugs and deployment priority of 2. The Connect fix should also rank up there since both of its CVEs are CVSS 9s. Beyond those, it’s a pretty typical month for Adobe, with most of the bugs either being cross-site scripting (XSS) or open-and-own code executions.</p><p class=""><strong>Microsoft Patches for May 2026</strong></p><p class="">This month, Microsoft released a whopping 138 new CVEs in Windows and Windows components, Office and Office Components, Microsoft Edge (Chromium-based), Azure, .NET and Visual Studio, Copilot Chat, Github Copilot, M365 Copilot, SQL Server, TCP/IP, and the Telnet Client – yes, the Telnet client. Two of these bugs were reported through the TrendAI ZDI program. 30 of these bugs are rated Critical, three are rated as Moderate, one is rated Low, and the rest are rated Important in severity.</p><p class="">This large volume of fixes follows the largest monthly release in Microsoft’s history and reflects the trend across the industry of a high number of submissions. While not all of these bugs were found by AI, it’s likely they had an AI-related component – even if it was just AI writing the submission. I should also point out the Pwn2Own Berlin occurs in just a few days, and it’s typical for vendors to patch as much as they can before the event.</p><p class="">None of the bugs patched by Microsoft this month are listed as publicly known or under active attack at the time of release, so we’ve got that going for us. Let’s take a closer look at some of the more interesting updates for this month, starting with a nasty-looking bug in DNS:</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41096"><strong>CVE-2026-41096</strong></a><strong> - Windows DNS Client Remote Code Execution Vulnerability<br></strong>This patch fixes a heap-based buffer overflow in the DNS Client triggered by a malicious DNS response. No authentication or user interaction needed, and since the DNS Client runs on virtually every Windows machine, the attack surface is enormous. An attacker with a position to influence DNS responses (MitM, rogue server) could achieve unauthenticated RCE across your enterprise.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41089"><strong>CVE-2026-41089</strong></a><strong> - Windows Netlogon Remote Code Execution Vulnerability<br></strong>This update covers another CVSS 9.8 bug, which is a stack-based buffer overflow that lets an unauthenticated remote attacker execute code on a domain controller by sending a specially crafted network request — no credentials, no user interaction required. Yup – that makes it wormable. This is the highest-impact bug that requires immediate patching: a compromised domain controller is a compromised domain.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42898"><strong>CVE-2026-42898</strong></a><strong> - Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability<br></strong>This bug rates a CVSS 9.9(!) and represents a code injection in Dynamics 365. It allows any authenticated user to execute code with a scope change, meaning exploitation can break out and affect resources beyond the vulnerable component itself. Scope changes are pretty rare, so if you’re running Dynamics 365 On-Prem, definitely test and deploy this patch quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40415"><strong>CVE-2026-40415</strong></a><strong> - Windows TCP/IP Remote Code Execution Vulnerability<br></strong>This bug in the TCP/IP stack results from a use-after-free (UAF) and could allow a remote, unauthenticated threat actor to execute code without user interaction. That makes this another wormable bug. However, this one is much less likely to be exploited. The target needs to be under sustained low-memory (memory pressure) conditions, which is pretty rare. Still, no need to tempt fate here. Test and deploy this one quickly.</p><p class="">Here’s the full list of CVEs released by Microsoft for May 2026:</p>





















  
  




  


  
    





<link rel="File-List" href="2026-May-cvrf.fld/filelist.xml">













<table border="0" cellpadding="0" cellspacing="0" width="920">
 <col width="144">
 <col width="256">
 <col width="104" span="5">
 <tr height="47">
  <td width="144" class="xl65" height="47">CVE</td>
  <td width="256" class="xl65">Title</td>
  <td width="104" class="xl66">Severity</td>
  <td width="104" class="xl66">CVSS</td>
  <td width="104" class="xl66">Public</td>
  <td width="104" class="xl66">Exploited</td>
  <td width="104" class="xl66">Type</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35435"><span>CVE-2026-35435</span></a></td>
  <td width="256" class="xl73">Azure AI Foundry
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35428"><span>CVE-2026-35428</span></a></td>
  <td width="256" class="xl73">Azure Cloud Shell
  Spoofing Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9.6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42826"><span>CVE-2026-42826</span></a></td>
  <td width="256" class="xl73">Azure DevOps
  Information Disclosure Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">10</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32207"><span>CVE-2026-32207</span></a></td>
  <td width="256" class="xl73">Azure Machine Learning
  Notebook Spoofing Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33109"><span>CVE-2026-33109</span></a></td>
  <td width="256" class="xl73">Azure Managed Instance
  for Apache Cassandra Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9.9</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33844"><span>CVE-2026-33844</span></a></td>
  <td width="256" class="xl73">Azure Managed Instance
  for Apache Cassandra Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41105"><span>CVE-2026-41105</span></a></td>
  <td width="256" class="xl73">Azure Monitor Action
  Group Notification System Elevation of Privilege Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33111"><span>CVE-2026-33111</span></a></td>
  <td width="256" class="xl73">Copilot Chat
  (Microsoft Edge) Information Disclosure Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26129"><span>CVE-2026-26129</span></a></td>
  <td width="256" class="xl73">M365 Copilot
  Information Disclosure Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26164"><span>CVE-2026-26164</span></a></td>
  <td width="256" class="xl73">M365 Copilot
  Information Disclosure Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33821"><span>CVE-2026-33821</span></a></td>
  <td width="256" class="xl73">Microsoft Dynamics 365
  Customer Insights Elevation of Privilege Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">7.7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42898"><span>CVE-2026-42898</span></a></td>
  <td width="256" class="xl73">Microsoft Dynamics 365
  On-Premises Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9.9</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40379"><span>CVE-2026-40379</span></a></td>
  <td width="256" class="xl73">Microsoft Enterprise
  Security Token Service (ESTS) Spoofing Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40363"><span>CVE-2026-40363</span></a></td>
  <td width="256" class="xl73">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40358"><span>CVE-2026-40358</span></a></td>
  <td width="256" class="xl73">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34327"><span>CVE-2026-34327</span></a></td>
  <td width="256" class="xl73">Microsoft Partner
  Center Spoofing Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40365"><span>CVE-2026-40365</span></a></td>
  <td width="256" class="xl73">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="72">
  <td class="xl67" height="72"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41103"><span>CVE-2026-41103</span></a></td>
  <td width="256" class="xl73">Microsoft SSO Plugin
  for Jira &amp; Confluence Elevation of Privilege Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl67" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33823"><span>CVE-2026-33823</span></a></td>
  <td width="256" class="xl73">Microsoft Team Events
  Portal Information Disclosure Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9.6</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40364"><span>CVE-2026-40364</span></a></td>
  <td width="256" class="xl73">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40366"><span>CVE-2026-40366</span></a></td>
  <td width="256" class="xl73">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40361"><span>CVE-2026-40361</span></a></td>
  <td width="256" class="xl73">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40367"><span>CVE-2026-40367</span></a></td>
  <td width="256" class="xl73">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42831"><span>CVE-2026-42831</span></a></td>
  <td width="256" class="xl73">Office for Android
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41096"><span>CVE-2026-41096</span></a></td>
  <td width="256" class="xl73">Windows DNS Client
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35421"><span>CVE-2026-35421</span></a></td>
  <td width="256" class="xl73">Windows GDI Remote
  Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="71">
  <td class="xl67" height="71"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40403"><span>CVE-2026-40403</span></a></td>
  <td width="256" class="xl73">Windows Graphics
  Component Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40402"><span>CVE-2026-40402</span></a></td>
  <td width="256" class="xl73">Windows Hyper-V
  Elevation of Privilege Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32161"><span>CVE-2026-32161</span></a></td>
  <td width="256" class="xl73">Windows Native WiFi
  Miniport Driver Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41089"><span>CVE-2026-41089</span></a></td>
  <td width="256" class="xl73">Windows Netlogon
  Remote Code Execution Vulnerability</td>
  <td class="xl68">Critical</td>
  <td class="xl69">9.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32175"><span>CVE-2026-32175</span></a></td>
  <td width="256" class="xl73">.NET Core Tampering
  Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">4.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Tampering</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32177"><span>CVE-2026-32177</span></a></td>
  <td width="256" class="xl73">.NET Elevation of
  Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35433"><span>CVE-2026-35433</span></a></td>
  <td width="256" class="xl73">.NET Elevation of
  Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-54518"><span>CVE-2025-54518 *</span></a></td>
  <td width="256" class="xl73">AMD: CVE-2025-54518
  CPU OP Cache Corruption</td>
  <td class="xl70">Important</td>
  <td class="xl69"></td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42899"><span>CVE-2026-42899</span></a></td>
  <td width="256" class="xl73">ASP.NET Core Denial of
  Service Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40381"><span>CVE-2026-40381</span></a></td>
  <td width="256" class="xl73">Azure Connected
  Machine Agent Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42823"><span>CVE-2026-42823 †</span></a></td>
  <td width="256" class="xl73">Azure Logic Apps
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">9.9</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33833"><span>CVE-2026-33833</span></a></td>
  <td width="256" class="xl73">Azure Machine Learning
  Notebook Spoofing Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32204"><span>CVE-2026-32204</span></a></td>
  <td width="256" class="xl73">Azure Monitor Agent
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42830"><span>CVE-2026-42830</span></a></td>
  <td width="256" class="xl73">Azure Monitor Agent
  Metrics Extension Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33117"><span>CVE-2026-33117</span></a></td>
  <td width="256" class="xl73">Azure SDK for Java
  Security Feature Bypass Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">9.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41109"><span>CVE-2026-41109</span></a></td>
  <td width="256" class="xl73">GitHub Copilot and
  Visual Studio Code Security Feature Bypass Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35424"><span>CVE-2026-35424</span></a></td>
  <td width="256" class="xl73">Internet Key Exchange
  (IKE) Protocol Denial of Service Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41614"><span>CVE-2026-41614</span></a></td>
  <td width="256" class="xl73">M365 Copilot for
  Desktop Spoofing Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41100"><span>CVE-2026-41100</span></a></td>
  <td width="256" class="xl73">Microsoft 365 Copilot
  for Android Spoofing Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">4.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40377"><span>CVE-2026-40377</span></a></td>
  <td width="256" class="xl73">Microsoft
  Cryptographic Services Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41094"><span>CVE-2026-41094</span></a></td>
  <td width="256" class="xl73">Microsoft Data
  Formulator Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40417"><span>CVE-2026-40417</span></a></td>
  <td width="256" class="xl73">Microsoft Dynamics 365
  Business Central Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42833"><span>CVE-2026-42833</span></a></td>
  <td width="256" class="xl73">Microsoft Dynamics 365
  On-Premises Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">9.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42838"><span>CVE-2026-42838</span></a></td>
  <td width="256" class="xl73">Microsoft Edge
  (Chromium-based) Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">5.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40360"><span>CVE-2026-40360</span></a></td>
  <td width="256" class="xl73">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40359"><span>CVE-2026-40359</span></a></td>
  <td width="256" class="xl73">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40362"><span>CVE-2026-40362</span></a></td>
  <td width="256" class="xl73">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42832"><span>CVE-2026-42832</span></a></td>
  <td width="256" class="xl73">Microsoft Excel
  Spoofing Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34329"><span>CVE-2026-34329</span></a></td>
  <td width="256" class="xl73">Microsoft Message
  Queuing (MSMQ) Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40419"><span>CVE-2026-40419</span></a></td>
  <td width="256" class="xl73">Microsoft Office
  Click-To-Run Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40418"><span>CVE-2026-40418</span></a></td>
  <td width="256" class="xl73">Microsoft Office
  Click-To-Run Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35436"><span>CVE-2026-35436</span></a></td>
  <td width="256" class="xl73">Microsoft Office
  Click-To-Run Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40420"><span>CVE-2026-40420</span></a></td>
  <td width="256" class="xl73">Microsoft Office
  Click-To-Run Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42893"><span>CVE-2026-42893</span></a></td>
  <td width="256" class="xl73">Microsoft Outlook for
  iOS Tampering Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Tampering</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40374"><span>CVE-2026-40374</span></a></td>
  <td width="256" class="xl73">Microsoft Power
  Automate Desktop Information Disclosure Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41102"><span>CVE-2026-41102</span></a></td>
  <td width="256" class="xl73">Microsoft PowerPoint
  for Android Spoofing Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35439"><span>CVE-2026-35439</span></a></td>
  <td width="256" class="xl73">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40368"><span>CVE-2026-40368</span></a></td>
  <td width="256" class="xl73">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33110"><span>CVE-2026-33110</span></a></td>
  <td width="256" class="xl73">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33112"><span>CVE-2026-33112</span></a></td>
  <td width="256" class="xl73">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40357"><span>CVE-2026-40357</span></a></td>
  <td width="256" class="xl73">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32185"><span>CVE-2026-32185</span></a></td>
  <td width="256" class="xl73">Microsoft Teams
  Spoofing Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41101"><span>CVE-2026-41101</span></a></td>
  <td width="256" class="xl73">Microsoft Word for
  Android Spoofing Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35440"><span>CVE-2026-35440</span></a></td>
  <td width="256" class="xl73">Microsoft Word
  Information Disclosure Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40421"><span>CVE-2026-40421</span></a></td>
  <td width="256" class="xl73">Microsoft Word
  Information Disclosure Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">4.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41097"><span>CVE-2026-41097</span></a></td>
  <td width="256" class="xl73">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40370"><span>CVE-2026-40370 †</span></a></td>
  <td width="256" class="xl73">SQL Server Remote Code
  Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41613"><span>CVE-2026-41613</span></a></td>
  <td width="256" class="xl73">Visual Studio Code
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41612"><span>CVE-2026-41612</span></a></td>
  <td width="256" class="xl73">Visual Studio Code
  Information Disclosure Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41611"><span>CVE-2026-41611</span></a></td>
  <td width="256" class="xl73">Visual Studio Code
  Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41610"><span>CVE-2026-41610</span></a></td>
  <td width="256" class="xl73">Visual Studio Code
  Security Feature Bypass Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33839"><span>CVE-2026-33839</span></a></td>
  <td width="256" class="xl73">Win32k Elevation of
  Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33840"><span>CVE-2026-33840</span></a></td>
  <td width="256" class="xl73">Win32k Elevation of
  Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34330"><span>CVE-2026-34330</span></a></td>
  <td width="256" class="xl73">Win32k Elevation of
  Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34331"><span>CVE-2026-34331</span></a></td>
  <td width="256" class="xl73">Win32k Elevation of
  Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35423"><span>CVE-2026-35423</span></a></td>
  <td width="256" class="xl73">Windows 11 Telnet
  Client Information Disclosure Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">5.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35438"><span>CVE-2026-35438</span></a></td>
  <td width="256" class="xl73">Windows Admin Center
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41086"><span>CVE-2026-41086</span></a></td>
  <td width="256" class="xl73">Windows Admin Center
  in Azure Portal Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34344"><span>CVE-2026-34344</span></a></td>
  <td width="256" class="xl73">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34345"><span>CVE-2026-34345</span></a></td>
  <td width="256" class="xl73">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35416"><span>CVE-2026-35416</span></a></td>
  <td width="256" class="xl73">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41088"><span>CVE-2026-41088</span></a></td>
  <td width="256" class="xl73">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34343"><span>CVE-2026-34343</span></a></td>
  <td width="256" class="xl73">Windows Application
  Identity (AppID) Subsystem Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35418"><span>CVE-2026-35418</span></a></td>
  <td width="256" class="xl73">Windows Cloud Files
  Mini Filter Driver Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33835"><span>CVE-2026-33835</span></a></td>
  <td width="256" class="xl73">Windows Cloud Files
  Mini Filter Driver Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34337"><span>CVE-2026-34337</span></a></td>
  <td width="256" class="xl73">Windows Cloud Files
  Mini Filter Driver Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40407"><span>CVE-2026-40407</span></a></td>
  <td width="256" class="xl73">Windows Common Log
  File System Driver Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40397"><span>CVE-2026-40397</span></a></td>
  <td width="256" class="xl73">Windows Common Log
  File System Driver Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42896"><span>CVE-2026-42896</span></a></td>
  <td width="256" class="xl73">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35419"><span>CVE-2026-35419</span></a></td>
  <td width="256" class="xl73">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34336"><span>CVE-2026-34336</span></a></td>
  <td width="256" class="xl73">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33834"><span>CVE-2026-33834</span></a></td>
  <td width="256" class="xl73">Windows Event Logging
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32209"><span>CVE-2026-32209</span></a></td>
  <td width="256" class="xl73">Windows Filtering
  Platform (WFP) Security Feature Bypass Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">4.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33841"><span>CVE-2026-33841</span></a></td>
  <td width="256" class="xl73">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35420"><span>CVE-2026-35420</span></a></td>
  <td width="256" class="xl73">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40369"><span>CVE-2026-40369</span></a></td>
  <td width="256" class="xl73">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="71">
  <td class="xl67" height="71"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34332"><span>CVE-2026-34332</span></a></td>
  <td width="256" class="xl73">Windows Kernel-Mode
  Driver Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34339"><span>CVE-2026-34339</span></a></td>
  <td width="256" class="xl73">Windows Lightweight
  Directory Access Protocol (LDAP) Denial of Service Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">5.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34341"><span>CVE-2026-34341</span></a></td>
  <td width="256" class="xl73">Windows Link-Layer
  Discovery Protocol (LLDP) Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33838"><span>CVE-2026-33838</span></a></td>
  <td width="256" class="xl73">Windows Message
  Queuing (MSMQ) Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34342"><span>CVE-2026-34342</span></a></td>
  <td width="256" class="xl73">Windows Print Spooler
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41095"><span>CVE-2026-41095</span></a></td>
  <td width="256" class="xl73">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34340"><span>CVE-2026-34340</span></a></td>
  <td width="256" class="xl73">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40398"><span>CVE-2026-40398</span></a></td>
  <td width="256" class="xl73">Windows Remote Desktop
  Services Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21530"><span>CVE-2026-21530</span></a></td>
  <td width="256" class="xl73">Windows Rich Text Edit
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32170"><span>CVE-2026-32170</span></a></td>
  <td width="256" class="xl73">Windows Rich Text Edit
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40410"><span>CVE-2026-40410</span></a></td>
  <td width="256" class="xl73">Windows SMB Client
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35415"><span>CVE-2026-35415</span></a></td>
  <td width="256" class="xl73">Windows Storage Spaces
  Controller Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34350"><span>CVE-2026-34350</span></a></td>
  <td width="256" class="xl73">Windows Storport
  Miniport Driver Denial of Service Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40405"><span>CVE-2026-40405</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP Denial
  of Service Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40414"><span>CVE-2026-40414</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP Denial
  of Service Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40401"><span>CVE-2026-40401</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP Denial
  of Service Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40413"><span>CVE-2026-40413</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP Denial
  of Service Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35422"><span>CVE-2026-35422</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP Driver
  Security Feature Bypass Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34351"><span>CVE-2026-34351</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40399"><span>CVE-2026-40399</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34334"><span>CVE-2026-34334</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40406"><span>CVE-2026-40406</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP
  Information Disclosure Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33837"><span>CVE-2026-33837</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP Local
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40415"><span>CVE-2026-40415</span></a></td>
  <td width="256" class="xl73">Windows TCP/IP Remote
  Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">8.1</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42825"><span>CVE-2026-42825</span></a></td>
  <td width="256" class="xl73">Windows Telephony
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34338"><span>CVE-2026-34338</span></a></td>
  <td width="256" class="xl73">Windows Telephony
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40382"><span>CVE-2026-40382</span></a></td>
  <td width="256" class="xl73">Windows Telephony
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40380"><span>CVE-2026-40380</span></a></td>
  <td width="256" class="xl73">Windows Volume Manager
  Extension Driver Remote Code Execution Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">6.2</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40408"><span>CVE-2026-40408</span></a></td>
  <td width="256" class="xl73">Windows WAN ARP Driver
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34333"><span>CVE-2026-34333</span></a></td>
  <td width="256" class="xl73">Windows Win32k
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34347"><span>CVE-2026-34347</span></a></td>
  <td width="256" class="xl73">Windows Win32k
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35417"><span>CVE-2026-35417</span></a></td>
  <td width="256" class="xl73">Windows Win32k
  Elevation of Privilege Vulnerability</td>
  <td class="xl70">Important</td>
  <td class="xl69">7.8</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42891"><span>CVE-2026-42891</span></a></td>
  <td width="256" class="xl73">Microsoft Edge
  (Chromium-based) for Android Spoofing Vulnerability</td>
  <td class="xl71">Moderate</td>
  <td class="xl69">6.5</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35429"><span>CVE-2026-35429</span></a></td>
  <td width="256" class="xl73">Microsoft Edge
  (Chromium-based) for Android Spoofing Vulnerability</td>
  <td class="xl71">Moderate</td>
  <td class="xl69">4.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41107"><span>CVE-2026-41107</span></a></td>
  <td width="256" class="xl73">Microsoft Edge
  (Chromium-based) Information Disclosure Vulnerability</td>
  <td class="xl71">Moderate</td>
  <td class="xl69">7.4</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40416"><span>CVE-2026-40416</span></a></td>
  <td width="256" class="xl73">Microsoft
  Edge (Chromium-based) for Android Spoofing Vulnerability</td>
  <td class="xl72">Low</td>
  <td class="xl69">4.3</td>
  <td class="xl69">No</td>
  <td class="xl69">No</td>
  <td class="xl69">Spoofing</td>
 </tr>
 &lt;![if supportMisalignedColumns]&gt;
 <tr height="0">
  <td width="144"></td>
  <td width="256"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
 </tr>
 &lt;![endif]&gt;
</table>











  
  









  <p class=""><em>* Indicates this CVE had been released by a third party and is now being included in Microsoft releases</em>.</p><p class=""><em>† Indicates further administrative actions are required to fully address the vulnerability.</em></p><p class=""><em> </em></p><p class="">Looking at the other Critical-rated bugs in this month’s release, there are quite a few scary-looking bugs (including a CVSS 10!), but there’s no action for the end user as Microsoft has already mitigated these bugs and is just now documenting them. There’s also this month’s crop of Office bugs where the Preview Pane is an attack vector. However, the bug in Office for Android does not have the Preview Pane vector; it’s simple open and own. The bug in the WiFi driver needs a network adjacent attacker. The SharePoint bug requires authentication, but anyone with site privileges has the authentication needed. The bug in SSO Plugin for Jira &amp; Confluence should really be called an authentication bypass, since it allows an unauthenticated attacker to gain access to a system.</p><p class="">Looking at the other code execution bugs, most are of the open and own variety as expected. The bug in Dynamic 365 (On Prem) requires high privileges. The Message Queueing bug requires an adjacent attacker. The bug in SQL Server requires authentication, but as usual, patching won’t be straightforward. Finally, there’s a bug in the kernel that leads to code execution. Most kernel bugs are privilege escalations, but this one could allow code execution if an attacker sends specially crafted NVMe over Fabrics (NVMe‑oF) response messages during the connection handshake process that contains an invalid header length value. Neat.</p><p class="">As usual, the vast majority of the Microsoft release fixes Elevation of Privilege (EoP) bugs. Also as usual, most simply lead to local attackers executing their code at SYSTEM-level privileges or administrative privileges, so there’s not much to add without further technical details about the bugs themselves. There are also a few bugs that just state the attacker could “gain ELEVATED privileges.” How obtuse. The bugs in Azure allow an attacker to access data otherwise hidden from them. The Edge bug allows threat actors to elevate to the privileges of the running application. The bug in Visual Studio allows attackers to get permissions associated with the MCP Server’s managed identity. Finally, there are a couple of sandbox escapes, too, which are always useful.</p><p class="">This month's update includes six Security Feature Bypass vulnerabilities. The most severe is in the Azure SDK for Java (CVSS 9.1). An attacker over the network can bypass the integrity protection provided by authentication tags on encrypted data, effectively manipulating encrypted input in a way that slips past integrity checks during decryption.  Close behind is the bypass affecting the GitHub Copilot integration in Visual Studio Code (CWE-74). This one requires a user interaction, but it allows an attacker to circumvent the path validation safeguards that normally control which files Copilot is permitted to modify. The other Visual Studio Code bypass involves cross-site scripting, improper link resolution, and information exposure triggered when a user opens or views a maliciously crafted notebook.  On the Windows networking side there are two bypasses. The first hits the Windows TCP/IP driver via an authentication bypass using an alternate channel. The other impacts the Windows Filtering Platform through improper access control, allowing a local, low-privileged attacker to bypass FQDN-based network security rules. Finally, there’s a Secure Boot bypass that, you guessed it, bypasses secure boot features.</p><p class="">Moving on to the Information Disclosure bugs fixed this month, we have 15 different CVEs. As usual, the majority of these simply result in info leaks consisting of unspecified memory contents or memory addresses. The bug in Power Automate could expose data marked “Sensitive” within Power Automate Desktop flows. One of the Word bugs could disclose NLTM hashes. The bug in Edge could disclose your cookies, which seems rude. The bug in Visual Studio could expose file path information. Finally, there’s a bug in Telnet for Windows 11 that leaks information being used by Telnet at the time. I didn’t even realize Windows 11 still had a telnet client.</p><p class="">The May release contains 10 spoofing bugs (plus the ones already addressed by Microsoft). The bug in Azure Machine Learning Notebooks vulnerability requires user interaction, but it could expose info through the Azure ML web interface to the attacker. There’s a cluster of fixes for Microsoft's mobile Office suite on Android. Excel, Word, and PowerPoint for Android all carry spoofing flaws rooted in improper access control. Two Copilot products are also affected by spoofing vulns. The M365 Copilot for Desktop has no details provided. The M365 Copilot for Android variant requires low privileges and producing only limited impact on confidentiality and integrity. Microsoft Teams for Android rounds out the mobile app spoofing bugs. Three Edge bugs close things out, all involving misrepresentation of information in the browser UI. </p><p class="">There are two Tampering bugs in this month’s release. The one in .NET Core allows threat actors to write files to an affected system. The other is in Outlook for iOS and manifests as a command injection bug.</p><p class="">There are eight DoS bugs in the May release, but as always, Microsoft provides little to no actionable information about the vulnerabilities. The most interesting from a practical standpoint are two TCP/IP bugs that allow a low-privilege Hyper-V guest to crash the host. Both are triggered from the adjacent network. On the broader network-exposure side, the ASP.NET Core bug is a straightforward infinite loop condition — an unauthenticated attacker sends a crafted request over the network and the server stops responding.</p><p class="">No new advisories are being released this month.</p><p class=""><strong>Looking Ahead</strong></p><p class="">Assuming I survive Pwn2Own Berlin (which is looking iffy at the moment), I’ll return on June 9th on what will hopefully be a smaller release than this one. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The February 2026 Security Update Review]]></title>
<description><![CDATA[I have survived the biggest Pwn2Own ever, but I’m back in Tokyo for the second Patch Tuesday of 2026. My location never stops Patch Tuesday from coming, so let’s take a look at the latest security patches from Adobe and Microsoft.  If you’d rather watch the full video recap covering the entire re...]]></description>
<link>https://tsecurity.de/de/3694474/it-security-nachrichten/the-february-2026-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694474/it-security-nachrichten/the-february-2026-security-update-review/</guid>
<pubDate>Sat, 25 Jul 2026 19:00:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">I have survived the biggest Pwn2Own ever, but I’m back in Tokyo for the second Patch Tuesday of 2026. My location never stops Patch Tuesday from coming, so let’s take a look at the latest security patches from Adobe and Microsoft.  If you’d rather watch the full video recap covering the entire release, you can check it out here:</p>





















  
  




  
















  
    
      
    
    
      
        
      
    
    
    



  






  <p class=""><strong>Adobe Patches for February 2026</strong></p><p class="">For February, Adobe released nine bulletins addressing 44 unique CVEs in Adobe Audition, After Effects, InDesign, Substance 3D Designer, Substance 3D Stager, Adobe Bridge, Substance 3D Modeler, Lightroom Classic, and the Adobe DNG Software Development Kit (SDK). The largest update here is for <a href="https://helpx.adobe.com/security/products/after_effects/apsb26-15.html">After Effects</a>, which fixes 13 Critical and two Important rated bugs. The patch for <a href="https://helpx.adobe.com/security/products/substance3d_designer/apsb26-19.html">Substance 3D Designer</a> is on the larger side with seven fixes, but only two of those are Critical. On the other hand, the fix for <a href="https://helpx.adobe.com/security/products/substance3d_stager/apsb26-20.html">Substance 3D Stager</a> corrects five Critical-rated bugs that could lead to code execution. The <a href="https://helpx.adobe.com/security/products/audition/apsb26-14.html">Audition</a> patch fixes six bugs, but only one is Critical.</p><p class="">The other patches are smaller in size. The fix for the <a href="https://helpx.adobe.com/security/products/dng-sdk/apsb26-23.html">Adobe DNG Software Development Kit (SDK)</a> corrects two Critical and two Important-rated bugs. The <a href="https://helpx.adobe.com/security/products/indesign/apsb26-17.html">InDesign</a> patch fixes three bugs, but only one is Critical. The update for <a href="https://helpx.adobe.com/security/products/bridge/apsb26-21.html">Adobe Bridge</a> fixes two Critical bug that could lead to code execution. The patch for <a href="https://helpx.adobe.com/security/products/lightroom/apsb26-06.html">Lightroom Classic</a> addresses a single Critical bug, and the release is wrapped up with a patch for <a href="https://helpx.adobe.com/security/products/substance3d-modeler/apsb26-22.html">Substance 3D Modeler</a> that fixes a single, Important-rated memory link.</p><p class="">None of the bugs fixed by Adobe this month are listed as publicly known or under active attack at the time of release, and all of the updates released by Adobe this month are listed as deployment priority 3.</p><p class=""><strong>Microsoft Patches for February 2026</strong></p><p class="">This month, Microsoft drops 58 new CVEs in Windows and Windows components, Office and Office Components, Azure, Microsoft Edge (Chromium-based), .NET and Visual Studio, GitHub Copilot, Mailslot FS, Exchange Server, Internet Explorer (!), Power BI, Hyper-V Server, and the Windows Subsystem for Linux. Counting the third-party and Chromium updates listed in the release, it brings the total number of CVEs to 62. One of the bugs in the Windows Graphics component was submitted through the ZDI program. Five of these bugs are rated Critical, two are rated Moderate, and the rest are rated Important in severity.</p><p class="">It’s typical to see this number of CVEs released in February, but the number of bugs under active attack is extraordinarily high. Microsoft lists six bugs being exploited at the time of release, with three of these listed as publicly known. Last month only had a single bug being exploited, although there were twice as many CVEs patched. We’ll see if we’re on our way to another “hot exploit summer” as we saw a few years ago or if this is just an aberration. </p><p class="">Let’s take a closer look at some of the more interesting updates for this month, starting with the bugs under active attack: </p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510"><strong>CVE-2026-21510</strong></a><strong> - Windows Shell Security Feature Bypass Vulnerability<br></strong>This bug is listed as a security feature bypass, but it could also be classified as code execution. An attacker can bypass Windows SmartScreen and Windows Shell security prompts to execute code on a target system. This bug is also listed as publicly known, but Microsoft doesn’t say where. There is user interaction here, as the client needs to click a link or a shortcut file. Still, a one-click bug to gain code execution is a rarity. Definitely test and deploy this fix quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514"><strong>CVE-2026-21514</strong></a><strong> - Microsoft Word Security Feature Bypass Vulnerability<br></strong>This bug also requires user interaction in the form of opening a Word document, but that’s all that’s required to bypass protections to dangerous COM/OLE controls. Thankfully, the Preview Pane is <em>not</em> an attack vector here. However, users are well known to open lots of documents they receive in e-mail. This bypass could also result in code execution if the right COM/OLE control is hit. This is also listed as publicly known, so add this to the list to test and deploy quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21519"><strong>CVE-2026-21519</strong></a><strong> - Desktop Window Manager Elevation of Privilege Vulnerability<br></strong>This is the second month in a row that a DWM was listed as being exploited in the wild. That leads me to believe the first patch didn’t completely resolve the vulnerability. Same as last month, this bug allows attackers to run code with SYSTEM privileges. Bugs of this type are typically paired with a code execution bug to take over a system. As always, Microsoft offers no indication of how widespread these exploits may be.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21533"><strong>CVE-2026-21533</strong></a><strong> - Windows Remote Desktop Services Elevation of Privilege Vulnerability<br></strong>Don’t let the word “Remote” in the title fool you – this is a local bug that allows attackers to run code with SYSTEM privileges. It’s interesting that Microsoft lists “Improper privilege management” as the root cause for this issue. If the system is running Remote Desktop Services, it’s probably a juicy target for attackers to move laterally after an initial breach. Add this one to the list of patches to test and deploy immediately.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21513"><strong>CVE-2026-21513</strong></a><strong> - Internet Explorer Security Feature Bypass Vulnerability<br></strong>Although long gone by many measurements, IE does still exist on Windows systems, and calling it always results in a vulnerability somehow. This bug manifests similarly to the Shell bug above, as it requires user interaction but could result in code execution. The bypass here is simply the ability to reach IE, which shouldn’t be possible. Again, test and deploy this fix quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21525"><strong>CVE-2026-21525</strong></a><strong> - Windows Remote Access Connection Manager Denial of Service Vulnerability<br></strong>It’s unusual to see DoS bugs being used in active attacks, but that’s what we have here. A null pointer deref in the Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. Most null pointer derefs cause the application or service to crash, but it’s not clear if it will automatically restart. I would exercise caution and patch quickly either way.</p><p class="">Here’s the full list of CVEs released by Microsoft for February 2026:</p>





















  
  




  


  
    





<link rel="File-List" href="2026_PatchTable-Feb.fld/filelist.xml">













<table border="0" cellpadding="0" cellspacing="0" width="953">
 <col width="151" class="xl69">
 <col width="263" class="xl72">
 <col width="111" class="xl71" span="4">
 <col width="95" class="xl71">
 <tr height="48">
  <td width="151" class="xl69" height="48"><span> </span>CVE<span> </span></td>
  <td width="263" class="xl72"><span> </span>Title<span> </span></td>
  <td width="111" class="xl71"><span> </span>Severity<span> </span></td>
  <td width="111" class="xl71"><span> </span>CVSS<span> </span></td>
  <td width="111" class="xl71"><span> </span>Public</td>
  <td width="111" class="xl71"><span> </span>Exploited<span> </span></td>
  <td width="95" class="xl71"><span> </span>TYPE<span> </span></td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514"><span><span> </span>CVE-2026-21514<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Word Security Feature Bypass
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl65">SFB</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510"><span><span> </span>CVE-2026-21510<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Shell Security Feature Bypass
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl65">SFB</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21513"><span><span> </span>CVE-2026-21513<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Internet Explorer Security Feature Bypass
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl65">SFB</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21519"><span><span> </span>CVE-2026-21519<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Desktop Window Manager Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="72">
  <td class="xl74" height="72"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21533"><span><span> </span>CVE-2026-21533<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Remote Desktop Services Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21525"><span><span> </span>CVE-2026-21525<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Remote Access Connection Manager
  Denial of Service Vulnerability<span> </span></td>
  <td class="xl68"><span> </span>Moderate<span> </span></td>
  <td class="xl65">6.2</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl66"><span> </span>Yes<span> </span></td>
  <td class="xl65">DoS</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21511"><span><span> </span>CVE-2026-21511<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Outlook Spoofing
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-2804"><span><span> </span>CVE-2023-2804 *</span></a></td>
  <td width="263" class="xl75"><span> </span>Red Hat, Inc. CVE-2023-2804: Heap Based
  Overflow libjpeg-turbo<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>Yes<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24302"><span><span> </span>CVE-2026-24302<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure Arc Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl73"><span> </span>Critical<span> </span></td>
  <td class="xl65">8.6</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24300"><span><span> </span>CVE-2026-24300<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure Front Door Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl73"><span> </span>Critical<span> </span></td>
  <td class="xl65">9.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21532"><span><span> </span>CVE-2026-21532<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure Function Information Disclosure
  Vulnerability<span> </span></td>
  <td class="xl73"><span> </span>Critical<span> </span></td>
  <td class="xl65">8.2</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Info</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21522"><span><span> </span>CVE-2026-21522<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft ACI Confidential Containers
  Elevation of Privilege Vulnerability<span> </span></td>
  <td class="xl73"><span> </span>Critical<span> </span></td>
  <td class="xl65">6.7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23655"><span><span> </span>CVE-2026-23655<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft ACI Confidential Containers
  Information Disclosure Vulnerability<span> </span></td>
  <td class="xl73"><span> </span>Critical<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Info</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21218"><span><span> </span>CVE-2026-21218<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>.NET and Visual Studio Spoofing
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21512"><span><span> </span>CVE-2026-21512<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure DevOps Server Cross-Site Scripting
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">XSS</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21529"><span><span> </span>CVE-2026-21529 †</span></a></td>
  <td width="263" class="xl75"><span> </span>Azure HDInsight Spoofing Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">5.7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21528"><span><span> </span>CVE-2026-21528<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure IoT Explorer Information Disclosure
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Info</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21228"><span><span> </span>CVE-2026-21228<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure Local Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.1</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21531"><span><span> </span>CVE-2026-21531<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Azure SDK for Python Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">9.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21251"><span><span> </span>CVE-2026-21251<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Cluster Client Failover (CCF) Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20846"><span><span> </span>CVE-2026-20846<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>GDI+ Denial of Service Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">DoS</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21523"><span><span> </span>CVE-2026-21523<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>GitHub Copilot and Visual Studio Code Remote
  Code Execution Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21518"><span><span> </span>CVE-2026-21518<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>GitHub Copilot and Visual Studio Code
  Security Feature Bypass Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">SFB</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21257"><span><span> </span>CVE-2026-21257<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>GitHub Copilot and Visual Studio Elevation
  of Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21256"><span><span> </span>CVE-2026-21256<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>GitHub Copilot and Visual Studio Remote Code
  Execution Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21516"><span><span> </span>CVE-2026-21516<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>GitHub Copilot for Jetbrains Remote Code
  Execution Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21253"><span><span> </span>CVE-2026-21253<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Mailslot File System Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21537"><span><span> </span>CVE-2026-21537 †</span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Defender for Endpoint Linux
  Extension Remote Code Execution Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21259"><span><span> </span>CVE-2026-21259<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Excel Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.3</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21258"><span><span> </span>CVE-2026-21258<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Excel Information Disclosure
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">5.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Info</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21261"><span><span> </span>CVE-2026-21261<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Excel Information Disclosure
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">5.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Info</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21527"><span><span> </span>CVE-2026-21527<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Exchange Server Spoofing
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21260"><span><span> </span>CVE-2026-21260<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Outlook Spoofing
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21229"><span><span> </span>CVE-2026-21229<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Power BI Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21236"><span><span> </span>CVE-2026-21236<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Ancillary Function Driver for
  WinSock Elevation of Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21238"><span><span> </span>CVE-2026-21238<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Ancillary Function Driver for
  WinSock Elevation of Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21241"><span><span> </span>CVE-2026-21241<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Ancillary Function Driver for
  WinSock Elevation of Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21517"><span><span> </span>CVE-2026-21517<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows App for Mac Installer Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21234"><span><span> </span>CVE-2026-21234<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Connected Devices Platform Service
  Elevation of Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21235"><span><span> </span>CVE-2026-21235<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Graphics Component Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.3</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21246"><span><span> </span>CVE-2026-21246<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Graphics Component Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21232"><span><span> </span>CVE-2026-21232<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows HTTP.sys Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21240"><span><span> </span>CVE-2026-21240<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows HTTP.sys Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21250"><span><span> </span>CVE-2026-21250<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows HTTP.sys Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21244"><span><span> </span>CVE-2026-21244<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Hyper-V Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.3</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21247"><span><span> </span>CVE-2026-21247<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Hyper-V Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.3</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21248"><span><span> </span>CVE-2026-21248<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Hyper-V Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.3</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21255"><span><span> </span>CVE-2026-21255<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Hyper-V Security Feature Bypass
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">SFB</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21231"><span><span> </span>CVE-2026-21231<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Kernel Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21239"><span><span> </span>CVE-2026-21239<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Kernel Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21245"><span><span> </span>CVE-2026-21245<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Kernel Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21222"><span><span> </span>CVE-2026-21222<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Kernel Information Disclosure
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">5.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Info</td>
 </tr>
 <tr height="73">
  <td class="xl74" height="73"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21243"><span><span> </span>CVE-2026-21243<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Lightweight Directory Access
  Protocol (LDAP) Denial of Service Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">DoS</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841"><span><span> </span>CVE-2026-20841<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Notepad App Remote Code Execution
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">8.8</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21249"><span><span> </span>CVE-2026-21249<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows NTLM Spoofing Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">3.3</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21508"><span><span> </span>CVE-2026-21508<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Storage Elevation of Privilege
  Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21237"><span><span> </span>CVE-2026-21237<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Subsystem for Linux Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21242"><span><span> </span>CVE-2026-21242<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Windows Subsystem for Linux Elevation of
  Privilege Vulnerability<span> </span></td>
  <td class="xl70"><span> </span>Important<span> </span></td>
  <td class="xl65">7</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">EoP</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-1861"><span><span> </span>CVE-2026-1861 *</span></a></td>
  <td width="263" class="xl75"><span> </span>Chromium: CVE-2026-1861 Heap buffer overflow
  in libvpx<span> </span></td>
  <td class="xl67"><span> </span>High</td>
  <td class="xl65">N/A</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-1862"><span><span> </span>CVE-2026-1862 *</span></a></td>
  <td width="263" class="xl75"><span> </span>Chromium: CVE-2026-1862 Type Confusion in
  V8<span> </span></td>
  <td class="xl67"><span> </span>High</td>
  <td class="xl65">N/A</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">RCE</td>
 </tr>
 <tr height="48">
  <td class="xl74" height="48"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0391"><span><span> </span>CVE-2026-0391<span> </span></span></a></td>
  <td width="263" class="xl75"><span> </span>Microsoft Edge (Chromium-based) for Android
  Spoofing Vulnerability<span> </span></td>
  <td class="xl68"><span> </span>Moderate<span> </span></td>
  <td class="xl65">6.5</td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65"><span> </span>No<span> </span></td>
  <td class="xl65">Spoofing</td>
 </tr>
 &lt;![if supportMisalignedColumns]&gt;
 <tr height="0">
  <td width="151"></td>
  <td width="263"></td>
  <td width="111"></td>
  <td width="111"></td>
  <td width="111"></td>
  <td width="111"></td>
  <td width="95"></td>
 </tr>
 &lt;![endif]&gt;
</table>











  
  









  <p class=""><em>* Indicates this CVE had been released by a third party and is now being included in Microsoft releases</em>.</p><p class=""><em>† Indicates further administrative actions are required to fully address the vulnerability.</em></p><p class=""><em> </em></p><p class="">Moving on to the Critical-rated bugs, the patch for Azure Front Door sounds frightening, but Microsoft has already fixed the bug and is just now documenting it. That’s also true for the bugs in Azure Arc and Azure Function. There are two Critical-rated bugs in the ACI Confidential Containers. The first allows a container escape while the second discloses secret tokens and keys. Either way, you’ll want to handle those quickly.</p><p class="">Taking a look at the other code execution vulnerabilities in this month’s release, we start with a frightening looking bug in Azure SDK for Python that has the highest CVSS this month of 9.8. A remote, unauthenticated attacker code gain code execution on an affected system via a maliciously crafted continuation token. It’s not clear why this isn’t rated Critical, but I would treat it as such. The three bugs in Hyper-V are actually local open-and-own bugs that require a user to open a malicious file on an affected system. That’s also true for the bug in Notepad. The bug in Power BI is confusing, because Microsoft says it requires authentication and could lead to an attacker running code as an authenticated user. There’s the poorly named “Azure Local Remote Code Execution Vulnerability”, but it requires a machine-in-the-middle (MitM) to exploit. The bug in Defender for Endpoint Linux is restricted to local subnets, but you’ll need to enable auto provisioning to get the patch. The final code execution bugs addressed this month are in GitHub Copilot. Two are command injections and the other is a Time-of-check time-of-use (toctou) race condition, but both could end up in code execution on affected systems.</p><p class="">Patches for Elevation of Privilege (EoP) bugs make up nearly 50% of this release, but most simply lead to local attackers executing their code at SYSTEM-level privileges or administrative privileges. There are only two of note. The first is a command injection bug in GitHub Copilot that leads to executing code at the level of the targeted application. The second is a bug in a kernel that leads to SYSTEM but could also be used for a sandbox escape.</p><p class="">There’s a unusually high number of spoofing bugs in this month’s release, and the ones for Outlook are the most troubling. First, the Preview Pane is an attack vector. Secondly, the bugs could be used to relay NTLM credentials via just an email, which could result in credential disclosure. And you’ll need multiple patches to fully address these bugs. At least they can be applied in any order.  There’s a UI misrepresentation bug in Exchange Server that could allow an attacker to either view some sensitive information or “make changes to disclosed information”. At what point does data become disclosed? That odd phrasing makes me think they are using AI to right some of their descriptions. The phrasing also appears in the patch for NTLM. That bug is triggered by opening a specially crafted Office doc, and while they explicitly say it could be used to relay NTLM creds, it sure seems that way. The patch for .NET and Visual Studio fixes a bug that allows attackers to bypass header validation, resulting in the service accepting a message it should reject. Finally, the bug in Azure HDInsight is really just a cross-site scripting (XSS) bug. The caveat here is that you need to restart Ambari server in both of the head nodes to have this fix updated. There is also an XSS in Azure Devops Server, but at least it is labelled as such.</p><p class="">There are a couple of additional security feature bypass bugs to discuss. The first is in Hyper-V and bypasses the Virtualization-based Security feature. The other is in GitHub Copilot and Visual Studio Code. It’s another command injection, but this one can be used to bypass authentication. Neat.</p><p class="">Looking at the remaining info disclosure bugs getting patched this month, most simply result in info leaks consisting of unspecified memory contents or memory addresses. The exception is the bug in Azure IoT Explorer. This bug could be used to view the contents of the target user’s local file system.</p><p class="">We end this month’s release with two DoS bugs: one in LDAP and one in GDI+. Neither descriptions from Microsoft provide any usable information.</p><p class="">No new advisories are being released this month.</p><p class=""><strong>Looking Ahead</strong></p><p class="">I plan on being back home for the March release but wherever I’m at, you can rest assured that March 10, I’ll be here to provide my assessment of the release. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[18 Enterprise-Architecture-Tools]]></title>
<description><![CDATA[Diese Enterprise Architecture Tools unterstützen Sie nicht nur bei der digitalen Transformation Ihres Unternehmens. 
					Foto: I Believe I Can Fly – shutterstock.com




Enterprise Architecture (EA) Tools unterstützen Unternehmen und Organisationen dabei, mit ihren IT-Strategien die Geschäftszie...]]></description>
<link>https://tsecurity.de/de/3694429/it-security-nachrichten/18-enterprise-architecture-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694429/it-security-nachrichten/18-enterprise-architecture-tools/</guid>
<pubDate>Sat, 25 Jul 2026 18:59:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Diese Enterprise Architecture Tools unterstützen Sie nicht nur bei der digitalen Transformation Ihres Unternehmens. " title="Diese Enterprise Architecture Tools unterstützen Sie nicht nur bei der digitalen Transformation Ihres Unternehmens. " src="https://images.computerwoche.de/bdb/3284195/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Diese Enterprise Architecture Tools unterstützen Sie nicht nur bei der digitalen Transformation Ihres Unternehmens. </p></figcaption></figure><p class="imageCredit">
					Foto: I Believe I Can Fly – shutterstock.com</p></div>




<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/2789207/eam-gibt-orientierung-in-der-digitalen-transformation.html" title="Enterprise Architecture" target="_blank">Enterprise Architecture</a> (EA) Tools unterstützen Unternehmen und Organisationen dabei, mit ihren IT-Strategien die Geschäftsziele optimal zu unterstützen. Sie sorgen ebenfalls dafür, dass Unternehmen ihre Roadmaps für die <a href="https://www.computerwoche.de/article/2794425/wie-digitale-transformation-richtig-geht.html" title="digitale Transformation" target="_blank">digitale Transformation</a> geordnet vorantreiben können. EA Tools bieten dafür unter anderem Collaboration-, Reporting-, Testing- und Simulationsfunktionen. Mit deren Hilfe lassen sich Modelle implementieren, die Geschäfts- und IT-Prozesse gezielt verbessern.</p>



<p class="wp-block-paragraph">Um die beste Lösung für Ihr Unternehmen zu finden, sollten Sie zuerst prüfen, ob sich das jeweilige Tool mit Ihrem Technologie-Stack integrieren lässt. Anschließend gilt es abzuwägen, ob die Informationen, Diagramme und Tabellen, die die Software zur Verfügung stellt, für das Unternehmen auch einen echten Nutzwert haben.</p>



<h2 class="wp-block-heading">Empfehlenswerte Enterprise-Architecture-Tools</h2>



<p class="wp-block-paragraph">Nachfolgend finden Sie einen Überblick über die wichtigsten Enterprise-Architecture-Tools – in alphabetischer Reihenfolge. Sie stellen einen Mix aus Visualisierungs-, Collaboration- und Project-Management-Funktionen bereit und unterstützen eine Vielzahl von Enterprise Architecture Frameworks.</p>



<p class="wp-block-paragraph"><strong><a href="https://www.ardoq.com/" title="Ardoq" target="_blank" rel="noopener">Ardoq</a></strong></p>



<p class="wp-block-paragraph">Nachdem zuerst über einfache Formulare Informationen von Usern, Entwicklern und sonstigen Stakeholdern im Unternehmen eingesammelt wurden, lässt sich mithilfe von Ardoq ein digitaler Zwilling der gesamten Organisation erstellen. Der Ansatz setzt also darauf, die Menschen, die in ihren Rollen mit den verschiedensten Systemen arbeiten, realistisch in ihrer Arbeitswelt abzubilden.</p>



<p class="wp-block-paragraph">Jede Mitarbeiterin und jeder Mitarbeiter im Unternehmen kann später von den Netzwerkvisualisierungen und Datenfluss-Diagrammen profitieren, um seine eigene Rolle optimal zu unterstützen und den Arbeitsplatz immer wieder anzupassen und zu modernisieren. Das Tool lässt sich mit den wichtigsten Cloud-Plattformen integrieren. Es bietet eine API, die individuelle Anpassungen in allen wichtigen Programmiersprachen (Python, C#, Java, etc.) ermöglicht.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>“Architektonischen Stress” bei Lastspitzen simulieren, falls größere Veränderungen bevorstehen;</p></li>



<li><p>Verstehen, wie verändertes Nutzerverhalten neue Anforderungen generiert;</p></li>



<li><p>Application Portfolio Management, um besser strategisch zu planen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://atollgroup.eu/samu-enterprise-architecture-tool/" title="Atoll Group SAMU" target="_blank" rel="noopener">Atoll Group SAMU</a></strong></p>



<p class="wp-block-paragraph">Das EA-Tool SAMU macht die Enterprise Architecture sichtbar, indem es tiefe Verknüpfungen zwischen On-Premises-Systemen, dem Cloud-Layer und Tools für das Business Process Management aufzeigt. Das Tool der Atoll Group bietet vielfältige Integrationsmöglichkeiten, zum Beispiel mit Monitoring-Tools (etwa Tivoli, ServiceNow), Configuration-Management-Datenbanken (zum Beispiel CA, BMC) oder Service-Organisations-Tools (BMC, HPE). Alle Informationen fließen in ein zentrales Datenmodell ein, das um den zusätzlichen Input der Stakeholder weiter angereichert wird.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Enterprise-Architektur visualisieren;</p></li>



<li><p>strategische Planungsprozesse und Architektur-Reviews mit Informationen unterfüttern;</p></li>



<li><p>mithilfe einer visuellen Verständnisgrundlage die Kommunikation verbessern.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.avolutionsoftware.com/enterprise-architecture/" title="Avolution Abacus" target="_blank" rel="noopener">Avolution Abacus</a></strong></p>



<p class="wp-block-paragraph">Dieses Tool erfasst die Breite und den Umfang der Unternehmensarchitektur mit Hilfe eines auf Diagrammen basierenden Dashboards. Die Integration mit gängigen Tools wie SharePoint, <a href="https://www.computerwoche.de/k/excel,3461" target="_blank" class="idgGlossaryLink">Excel</a>, Visio, Google Sheets, Technopedia oder ServiceNow vereinfacht die Nutzung. Abacus wurde inzwischen auch um einen Machine-Learning-Layer ergänzt, der es Anwendern ermöglicht, ein Modell zu trainieren, das ihnen beispielsweise hilft zu erkennen, wer im Unternehmen für welches System verantwortlich ist.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>die IT für das gesamte Unternehmen “öffnen”, um ein allgemeines Verständnis der Datenflüsse zu erzeugen;</p></li>



<li><p>umfassendes Enterprise Modeling, um eine Roadmap für künftige Entwicklungen zu erstellen;</p></li>



<li><p>Business-Metriken tracken, die mit der Unternehmens-Performance zusammenhängen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.boc-group.com/de/adoit/" title="BOC Group ADOIT" target="_blank" rel="noopener">BOC Group ADOIT</a></strong></p>



<p class="wp-block-paragraph">ADOIT soll Teams dabei unterstützen, Ressourcen zu verwalten, Bedarfe vorherzusagen und Assets zu tracken. Dazu mappt das Tool jedes System oder Softwarepaket mit einem Objekt. Die Datenflüsse zwischen den Systemen werden in Beziehungen umgewandelt, die von diesen Objekten mithilfe eines anpassbaren Metamodells erfasst werden. Geschäftsprozesse können auf ähnliche Weise über ein gut integriertes Begleitprodukt namens ADONIS modelliert werden. ADOIT ist Web-basiert und lässt sich auch mit Tools wie Atlassian Confluence integrieren, um die Datenerfassung und -entwicklung zu beschleunigen.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>ein unternehmensweites Modell erstellen, das bei sämtlichen Teammitgliedern ein Verständnis über den Stack schafft – und wie man diesen verbessern kann;</p></li>



<li><p>vollständiger Zugriff auf EA-Daten über eine Mobile-Anwendung;</p></li>



<li><p>bei Fusionen und Übernahmen den Tech-Bereich durch genaues Asset-Mapping orchestrieren.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a title="Mega Hopex" href="https://www.mega.com/hopex-platform" target="_blank" rel="noopener">Bizzdesign Hopex</a></strong></p>



<p class="wp-block-paragraph">Nach der Übernahme von Mega International zählt die Hopex-Plattform zum Portfolio von Bizzdesign. Sie soll dabei unterstützen, Unternehmensanwendungen zu modellieren und dabei ein Verständnis der von ihnen unterstützten Geschäfts-Workflows schaffen. Dabei liegt ein Schwerpunkt auf den Bereichen Data Governance und Risikomanagement. Hopex basiert auf Microsoft <a class="idgGlossaryLink" href="https://www.computerwoche.de/article/2732704/microsoft-azure-mit-der-deutschen-cloud-zu-neuen-geldquellen.html" target="_blank">Azure</a> und stützt sich auf eine Reihe offener Standards wie GraphQL und REST Queries, um Informationen aus Komponentensystemen zu sammeln. Das Reporting ist mit den Office-Tools von Microsoft sowie mit grafischen Lösungen wie Tableau und Qlik integriert.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>datengestützte Erkenntnisse herbeiführen, um Cloud- und Anwendungsbereitstellung zu steuern;</p></li>



<li><p>akkurate Nutzungsmodelle erstellen, um Architekturanforderungen zu verstehen;</p></li>



<li><p>eine Bedarfsschätzung mit Umfragen und anderen Tools vornehmen, um für die Zukunft zu planen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://bizzdesign.com/transformation-suite/horizzon" target="_blank" rel="noreferrer noopener">Bizzdesign Horizzon</a></strong></p>



<p class="wp-block-paragraph">Das Tool dient dazu, Business Workflows und den zugrundeliegenden Tech-Stack zu modellieren. Dazu bietet Horizzon ein Graph-basiertes Modell, das Daten von sämtlichen Stakeholdern einsammelt und diese an eine Analytics-Engine weitergibt. Im Ergebnis entstehen Diagramme, die den aktuellen Systemzustand widerspiegeln. Wichtige Schwerpunkte dieses Tools sind <a class="idgGlossaryLink" href="https://www.computerwoche.de/article/2777492/was-sie-ueber-change-management-wissen-muessen.html" target="_blank">Change Management</a> und Zukunftsplanung: Horizzon ist nicht zuletzt dafür konzipiert worden, die Risiken eines Redesigns zu minimieren. Das Toolset unterstützt die wichtigsten Frameworks ArchiMate, TOGAF und BPMN. Neben Mega hat Bizzdesign <a href="https://bizzdesign.com/press-releases/bizzdesign-adds-alfabet-business-following-successful-closing-mega-international" target="_blank" rel="noreferrer noopener">im Januar 2025</a> auch den EA-Geschäftsbereich der Software AG – Alfabet – übernommen.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Vorhersage zukünftiger Anforderungen durch Predictive Modeling;</p></li>



<li><p>Orchestrieren von Workflows auf der Basis der technischen und der Business-Architektur;</p></li>



<li><p>Antizipieren von Risiken sowie Security- und Governance-Problemen durch die Modellierung von Datensicherheitsanforderungen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.capstera.com/" target="_blank" rel="noreferrer noopener">Capstera</a></strong></p>



<p class="wp-block-paragraph">Das Tool von Capstera fokussiert darauf, die Business Architecture selbst abzubilden. Value und Process Maps helfen dabei, die Rollen der verschiedenen Unternehmensbereiche zu definieren und nachzuverfolgen. Dabei können im laufenden Prozess Verknüpfungen mit den zugrundeliegenden Softwarprodukten und Tools hinzugefügt werden.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Reports erstellen, die sich erst einmal mit der Business-Architektur selbst beschäftigen;</p></li>



<li><p>Beziehungen zwischen Menschen, Abteilungen und Rollen analysieren;</p></li>



<li><p>die langfristige strategische Planung vorantreiben.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.bee360.com/de/" title="Clausmark Bee360" target="_blank" rel="noopener">Clausmark Bee360</a></strong></p>



<p class="wp-block-paragraph">Teammitglieder, die Clausmarks Flaggschiffprodukt Bee360 (früher Bee4IT) verwenden, wollen eine einfache “Single Source of Truth” über die Workflows im Unternehmen. Ziel ist es, verschiedenen betrieblichen Rollen intelligentere Entscheidungen zu ermöglichen. Das Modul Bee360 FM (Finanzmanagement) bietet etwa die Möglichkeit, Kosten nachzuvollziehen und zuzuordnen. Die Anwender können verschiedene solcher Module miteinander verknüpfen, um EAM, Finanzmanagement, Portfolio Management und Agile Planning nahtlos zu integrieren – bei maximaler Transparenz. </p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>C-Suite-Ebene befähigen, Projekte zu managen und Assets zuzuweisen;</p></li>



<li><p>präzise digitale Zwillinge entwickeln, um ein Verständnis über Datenflüsse zu schaffen und künftige Erweiterungen zu planen;</p></li>



<li><p>integrierte Wissensdatenbank aufbauen, um alle digitalen Workflows zu tracken.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.enterprise-architecture.com/" title="EAS" target="_blank" rel="noopener">EAS</a></strong></p>



<p class="wp-block-paragraph">Das Essential-Paket von EAS (Enterprise Architecture Solutions) nahm als <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Open-Source</a>-Projekt seinen Anfang und hat sich inzwischen zu einer kommerziell verfügbaren Cloud-Lösung weiterentwickelt. Das Tool erstellt ein Metamodell, das die Interaktionen zwischen Systemen und Geschäftsprozessen beschreibt. Ebenfalls enthalten sind Pakete, um gängige Business Workflows wie Datenmanagement oder DSGVO-Compliance zu tracken.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>den technischen Reifegrad der eigenen Architektur evaluieren;</p></li>



<li><p>Sicherheit und Governance durch besseres Asset Tracking optimieren;</p></li>



<li><p>wachsende Systemkomplexität kontrollieren und managen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a title="Orbus Software iServer" href="https://www.orbussoftware.com/" target="_blank" rel="noopener">OrbusInfinity</a></strong></p>



<p class="wp-block-paragraph">Orbus Software hat Anfang 2025 die Akquisition seines Konkurrenten Capsifi <a href="https://www.orbussoftware.com/landing-pages/events/webinars/unlocking-the-future-orbus-acquires-capsifi-a-new-era-of-innovation-partnership-apac" target="_blank" rel="noreferrer noopener">abgeschlossen</a>. Der Anbieter stellt mit OrbusInfinity eine Enterprise-Transformation-Plattform auf KI-Basis zur Verfügung,  die schnellere, bessere Entscheidungen, Kosteinesparungen und Risikominimierung verspricht. Architecture-Teams sollen mit Hifle von OrbusInfinity mit einer Vielzahl von Stakeholdern interagieren können, um eine “digitale Blaupause” ihres Unternehmens zu generieren, die eine einheitliche Sicht auf das aktuelle und künftige Geschäft realisieren soll. Diverse Drittanbieter-Tools lassen sich außerdem mit der Plattform <a href="https://www.orbussoftware.com/product/integrations" target="_blank" rel="noreferrer noopener">integrieren</a>, darunter etwa von Microsoft, Flexera, ManageEngine oder ServiceNow. </p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Stakeholder-Management;</p></li>



<li><p>Enterprise-Landschaften visualisieren;</p></li>



<li><p>Entscheidungsfindung und Datenanalyse automatisieren.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.planview.com/de/" title="Planview Enterprise One" target="_blank" rel="noopener">Planview Enterprise One</a></strong></p>



<p class="wp-block-paragraph">Planview bietet eine ganze Reihe von Produkten, mit denen Unternehmen Teamwork, Prozesse und die Enterprise Architecture nachvollziehen können. Die Enterprise Tools sind in drei Kategorien unterteilt: strategisches Portfolio-Management, Produktportfolio-Management und Projektportfolio-Management. Im Zusammenspiel entstehen hardware- und Software-übergreifende Layer, die rollenbasierte Perspektiven für Führungskräfte und Teammitglieder eröffnen. Das Toolset integriert mit gängigen Ticket-Tracking-Systemen wie Jira, um Workflow-Analysen und Reports zu erstellen. Inzwischen hat Planview nach einer Übernahme neue Tools in sein Portfolio integriert, die früher unter den Namen Daptiv, Barometer und Projectplace bekannt waren.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>eine langfristige, strategische Vision für die Architekturentwicklung aufbauen;</p></li>



<li><p>Entwicklungsarbeit auf Projektebene tracken und in eine beliebige Strategie integrieren;</p></li>



<li><p>mit Fokus auf die Customer Experience und die Produktstruktur den Change vorantreiben.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.qualiware.com/" title="QualiWare Enterprise Architecture" target="_blank" rel="noopener">QualiWare Enterprise Architecture</a></strong></p>



<p class="wp-block-paragraph">Das Enterprise Architecture Tool von QualiWare ist Teil einer größeren Sammlung von Modellierungswerkzeugen, die darauf abzielt, sämtliche Geschäftsprozesse zu erfassen. Beispielsweise ist es möglich, einen digitalen Zwillinge zu bauen, mit dem sich Customer Journeys nachvollziehen lassen. Qualiware hat diverse KI-Algorithmen integriert, um Dokumentation und Process Discovery zu optimieren.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>ein kollaboratives Ökosystem für Business Manager aufbauen, das ein Verständnis von der Enterprise Architecture vermittelt;</p></li>



<li><p>architektonische Designelemente erfassen, um ein Wissens-Ökosystem rund um den Stack aufzubauen;</p></li>



<li><p>eine breite Beteiligung in Sachen Dokumentationserstellung und -überprüfung fördern.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.erwin.com/de-de/products/erwin-evolve/" title="Quest Erwin Evolve" target="_blank" rel="noopener">Quest Erwin Evolve</a></strong></p>



<p class="wp-block-paragraph">Das Erwin Evolve Tool von Quest hat sich von einem Datenmodellierungs-Tool zu einem System für Enterprise-Architecture- und Geschäftsprozess-Modellierung weiterentwickelt. Um die Komplexität moderner, ineinandergreifender Softwaresysteme und der von ihnen gemanagten Geschäftsprozesse zu durchdringen, können Anwender auf benutzerdefinierte Datenstrukturen zurückgreifen. Das Web-Tool erstellt Modelle, rollenbasierte Diagramme und andere Visualisierungen, die in allgemein zugängliche Dashboards einfließen. Zum Paket gehört ein KI-basiertes Modellierungs-Tool, das Whiteboard-Skizzen integrieren kann.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>einen digitalen Zwilling für die strategische Modellierung der Enterprise Data Architecture erstellen;</p></li>



<li><p>Customer Journeys verstehen;</p></li>



<li><p>Services und Systeme mit Application Portfolio Management tracken.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a title="LeanIX Enterprise Architecture Suite" href="https://www.leanix.net/de/produkte/enterprise-architecture-management" target="_blank" rel="noopener">SAP LeanIX Enterprise Architecture Suite</a></strong></p>



<p class="wp-block-paragraph">Die Tool-Sammlung von LeanIX umfasst unter anderem Enterprise Architecture Management und andere Bereiche, die für Aufgaben wie <a class="idgGlossaryLink" href="https://www.computerwoche.de/k/cloud-computing,3454" target="_blank">SaaS</a>– und Value-Stream-Management wichtig sind – etwa um Cloud-Deployments und darauf laufende Services zu tracken. Die Daten die dabei über die IT-Infrastruktur gesammelt werden, fließen in ein grafisches Dashboard ein. Das Tool ist eng mit wichtigen Cloud-Workflow-Tools wie Confluence, Jira, Signavio und Lucidchart integriert. Das ist für Teams von Vorteil, die diese Tools bereits nutzen, um ihre Entwicklungsstrategien zu planen und umzusetzen. Seit November 2023 <a href="https://www.leanix.net/de/unternehmen/pressemeldungen/leanix-gehoert-jetzt-zu-sap">ist LeanIX Teil von SAP</a>.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Anwendungsmodernisierung und Cloud-Migration managen;</p></li>



<li><p>Obsoleszenz von Software-Services evaluieren;</p></li>



<li><p>Kosten kontrollieren und managen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.servicenow.com/de/" title="ServiceNow" target="_blank" rel="noopener">ServiceNow</a></strong></p>



<p class="wp-block-paragraph">Die Tool-Sammlung von ServiceNow lässt sich auf verschiedene Architekturtypen herunterbrechen, darunter Assets, <a href="https://www.computerwoche.de/article/2785626/wie-devops-die-it-beschleunigen.html" target="_blank" class="idgGlossaryLink">DevOps</a>, Security und Service. Die Tools katalogisieren die unterschiedlichen Hardware- und Softwareplattformen, um Workflows und Datenflüsse im Unternehmen abzubilden und zu verstehen. Ausführliche Reportings und detaillierte Dashboards ermöglichen Analysen, auf deren Grundlage Risiken minimiert und die Ausfallsicherheit der Systeme erhöht werden können.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Tracken von Assets, Services und Systemen, die das Unternehmen ausmachen;</p></li>



<li><p>Governance-Themen, Risikobegrenzung, IT-Management und Security Operations werden in einer Plattform zusammengeführt;</p></li>



<li><p>durch die Integration von CRM-Tools lassen sich auch kundenorientierte Services managen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://sparxsystems.com/products/ea/" title="Sparx Systems" target="_blank" rel="noopener">Sparx Systems</a></strong></p>



<p class="wp-block-paragraph">Um Teams und Projekte verschiedener Größe und Komplexität zu unterstützen, hat Sparx vier Versionen seines EA-Tools entwickelt. Allen gemeinsam ist eine UML-basierte Modellierung, mit der sich die Komponenten komplexer Systeme tracken lassen. Eine Simulations-Engine ermöglicht “War Gaming” und vermittelt ein Verständnis darüber, wie sich Fehler ausbreiten und kaskadieren können. Sparx stellt zudem eine Vielzahl von vorgefertigten Design Patterns bereit, um Teams bei der Modellierung zu unterstützen.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Nachfrage- und Lastveränderungen zur Prognose künftiger Anforderungen simulieren;</p></li>



<li><p>(potenzielle) Probleme durch eine Verbindungs-Matrix im Auge behalten;</p></li>



<li><p>Dokumentation erstellen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.teamblue.unicomsi.com/products/system-architect/" title="Unicom System Architect" target="_blank" rel="noopener">Unicom System Architect</a></strong></p>



<p class="wp-block-paragraph">System Architect ist eines der Angebote aus Unicoms Team Blue. Es handelt sich um ein Tool, das ein Metamodell verwendet, um automatisiert so viele Daten wie möglich über die laufenden Systeme zu sammeln – manchmal auch durch ein Reverse Engineering von Datenflüssen. Dieses systemweite Datenmodell kann über benutzerdefinierte Dashboards Teammitgliedern aller Rollen zugänglich gemacht werden. Ein weiteres erwähnenswertes Feature: Die Ressourcenzuweisung lässt sich mit Hilfe von Simulationen optimieren.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>Was-wäre-wenn-Fragen zum Architekturmodell stellen;</p></li>



<li><p>ein Metamodell von Daten und Systemen aufbauen;</p></li>



<li><p>Migrations- und Transformationspläne erstellen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://www.valueblue.com/bluedolphin" title="ValueBlue BlueDolphin" target="_blank" rel="noopener">ValueBlue BlueDolphin</a></strong></p>



<p class="wp-block-paragraph">Dieses EA-Tool sammelt Daten auf dreierlei Art:</p>



<ol class="wp-block-list">
<li><p>Es importiert Basisdaten auf der Grundlage standardgesteuerter Automatisierung (ITSM, SAM).</p></li>



<li><p>Es arbeitet mit den Dateiformaten von Architekten und Systemdesignern – etwa ArchiMate oder BPMN.</p></li>



<li><p>Es gibt Fragebögen an andere Stakeholder heraus, die auf anpassbaren Vorlagen basieren.</p></li>
</ol>



<p class="wp-block-paragraph">Die aufbereiteten Informationen werden in einer visuellen Umgebung bereitgestellt, die Auskunft über die historische Entwicklung von Systemen gibt.</p>



<p class="wp-block-paragraph"><em>Wichtigste Use Cases:</em></p>



<ul class="wp-block-list">
<li><p>systemweite Daten von internen und externen Stakeholdern automatisiert und formularbasiert erfassen;</p></li>



<li><p>zukunftsorientierte Reportings erzeugen, um den Change zu überwachen und voranzutreiben;</p></li>



<li><p>Kooperation und Zusammenarbeit durch offenes Data Reporting fördern.</p></li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist <a href="https://www.cio.com/article/196069/top-enterprise-architecture-tools.html" target="_blank">im Original</a> bei unserer Schwesterpublikation CIO.com erschienen. </strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Accelerating AWS Network Firewall troubleshooting with AWS DevOps Agent]]></title>
<description><![CDATA[When an administrator introduces a rule change in AWS Network Firewall and network connectivity is disrupted, pinpointing the cause requires inspecting multiple points in the traffic path. The firewall gives you stateless and stateful rule engines, domain rules, and routing…
Read more →
The post ...]]></description>
<link>https://tsecurity.de/de/3692434/it-security-nachrichten/accelerating-aws-network-firewall-troubleshooting-with-aws-devops-agent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692434/it-security-nachrichten/accelerating-aws-network-firewall-troubleshooting-with-aws-devops-agent/</guid>
<pubDate>Fri, 24 Jul 2026 22:11:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When an administrator introduces a rule change in AWS Network Firewall and network connectivity is disrupted, pinpointing the cause requires inspecting multiple points in the traffic path. The firewall gives you stateless and stateful rule engines, domain rules, and routing…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/accelerating-aws-network-firewall-troubleshooting-with-aws-devops-agent/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/accelerating-aws-network-firewall-troubleshooting-with-aws-devops-agent/">Accelerating AWS Network Firewall troubleshooting with AWS DevOps Agent</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sam Altman’s biometric startup World raises $52.5 million via crypto sale]]></title>
<description><![CDATA[Sam Altman's side project — which seeks to scan the world's eyeballs and turn them into unique digital identifiers — has raised some fresh cash through a crypto sale.]]></description>
<link>https://tsecurity.de/de/3692018/it-nachrichten/sam-altmans-biometric-startup-world-raises-525-million-via-crypto-sale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692018/it-nachrichten/sam-altmans-biometric-startup-world-raises-525-million-via-crypto-sale/</guid>
<pubDate>Fri, 24 Jul 2026 18:21:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sam Altman's side project — which seeks to scan the world's eyeballs and turn them into unique digital identifiers — has raised some fresh cash through a crypto sale.]]></content:encoded>
</item>
<item>
<title><![CDATA[LHB Linux Digest #26.09: Docker Compose Override, Claude Skills for DevOps, Solidtime and More]]></title>
<description><![CDATA[Override the compose]]></description>
<link>https://tsecurity.de/de/3691440/linux-tipps/lhb-linux-digest-2609-docker-compose-override-claude-skills-for-devops-solidtime-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691440/linux-tipps/lhb-linux-digest-2609-docker-compose-override-claude-skills-for-devops-solidtime-and-more/</guid>
<pubDate>Fri, 24 Jul 2026 13:44:12 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Override the compose]]></content:encoded>
</item>
<item>
<title><![CDATA[8 Claude Skills I Use Everyday as a DevOps Engineer]]></title>
<description><![CDATA[Sharing the skills I use for troubleshooting and other purposes as a devops engineer. They are primarily for Claude but should work with other AI tools, too.]]></description>
<link>https://tsecurity.de/de/3691391/linux-tipps/8-claude-skills-i-use-everyday-as-a-devops-engineer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691391/linux-tipps/8-claude-skills-i-use-everyday-as-a-devops-engineer/</guid>
<pubDate>Fri, 24 Jul 2026 13:30:07 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sharing the skills I use for troubleshooting and other purposes as a devops engineer. They are primarily for Claude but should work with other AI tools, too.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitOps vs Traditional DevOps]]></title>
<description><![CDATA[This lesson is for paying subscribers only
                                                       
                    
                        This post is for paying subscribers only
                      

        

            
                Subscribe now
            
            
         ...]]></description>
<link>https://tsecurity.de/de/3691332/linux-tipps/gitops-vs-traditional-devops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691332/linux-tipps/gitops-vs-traditional-devops/</guid>
<pubDate>Fri, 24 Jul 2026 13:05:05 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<aside data-sx-content-cta class="relative p-0.5 js-toc-ignore">

    <div class="relative flex flex-col items-center text-center w-full px-4 py-10 lg:px-10 text-base rounded-xl sm:rounded-2xl">
        <div class="dark:hidden absolute -inset-px -z-10 rounded-xl bg-white shadow-pretty-sm transition-shadow duration-200"></div>
        <span class="hidden dark:block absolute -z-10 -inset-px rounded-inherit bg-radial-[50%_100%_at_50%_0%] from-white/10"></span>        
        <div class="hidden dark:block absolute -inset-px -z-10 rounded-xl bg-white/1 transition-colors duration-500 inset-shadow-md inset-shadow-white/2"></div>
        
        <div class="hidden dark:block absolute -z-10 -inset-0.5 mask-to-b mask-position-to-70% mask-opacity-to-50%">
            <div class="hidden dark:block absolute -z-10 inset-px rounded-xl border border-gray-50/10"></div>
        </div>                                                
        <div class="hidden dark:block absolute -z-10 -inset-px rounded-xl border border-gray-50/5 opacity-0"></div>

        <div class="hidden dark:block absolute -top-px start-1/2 -translate-x-1/2 w-1/2 h-px bg-linear-to-r from-white/0 to-white/0 via-gray-400/50"></div>

        <h2 class="text-gray-900 dark:text-gray-100 text-pretty text-xl sm:text-2xl leading-snug tracking-tight">




                                                <span class="hidden first:inline">
                                This lesson is for paying subscribers only
                            </span>                           
                    <span class="hidden first:inline">
                        This post is for paying subscribers only
                    </span>  

        </h2>

            <button data-portal="signup" class="mt-7 px-4 py-2.5 font-semibold text-sm text-center text-accent-contrast bg-primary rounded-full shadow-primary dark:shadow-none dark:drop-shadow-primary-sm hover:opacity-90 transition-opacity duration-200">
                Subscribe now
            </button>
            <p class="mt-5 text-sm">
                Already have an account? <button data-portal="signin" class="block sm:inline mx-auto font-medium underline decoration-primary decoration-2 underline-offset-2 hover:text-primary transition-colors duration-200">Sign in</button>
            </p>
    </div>
</aside>]]></content:encoded>
</item>
<item>
<title><![CDATA[ISC2 seeks input from IT pros for AI security certification]]></title>
<description><![CDATA[ISC2 has begun developing a vendor-neutral AI security certification aimed at cybersecurity professionals working to secure AI systems and manage emerging AI risks.



The nonprofit organization, best known for the CISSP certification, says it is seeking volunteers worldwide to help define the kn...]]></description>
<link>https://tsecurity.de/de/3691227/it-security-nachrichten/isc2-seeks-input-from-it-pros-for-ai-security-certification/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691227/it-security-nachrichten/isc2-seeks-input-from-it-pros-for-ai-security-certification/</guid>
<pubDate>Fri, 24 Jul 2026 12:09:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.isc2.org/" target="_blank" rel="noreferrer noopener">ISC2</a> has begun developing a <a href="https://www.isc2.org/new-ai-certification#AI%20Security%20Certification%20Frequently%20Asked%20Questions" target="_blank" rel="noreferrer noopener">vendor-neutral AI security certification</a> aimed at cybersecurity professionals working to secure AI systems and manage emerging AI risks.</p>



<p class="wp-block-paragraph">The nonprofit organization, best known for the <a href="https://www.isc2.org/certifications/cissp" target="_blank" rel="noreferrer noopener">CISSP certification</a>, says it is seeking volunteers worldwide to help define the knowledge and <a href="https://www.networkworld.com/article/3566827/global-cybersecurity-talent-gap-widens.html" target="_blank">skills</a> that will shape the new credential. While ISC2 has not finalized the certification domains, the <a href="https://www.prnewswire.com/news-releases/isc2-begins-developing-its-ai-security-certification-and-opens-call-for-volunteers-worldwide-302825622.html?tc=eml_cleartime" target="_blank" rel="noreferrer noopener">certification</a> is expected to address both technical AI security and governance topics, with a pilot exam planned before the end of 2026.</p>



<p class="wp-block-paragraph">According to <a href="https://www.linkedin.com/in/caseymarks/">Casey Marks</a>, ISC2 chief operating officer, feedback from cybersecurity practitioners led ISC2 to conclude that AI security had grown beyond expanding AI content within existing certifications.</p>



<p class="wp-block-paragraph">“AI has reached a tipping point,” Marks says. “AI no longer is just another tool; instead, it has fundamentally changed the cybersecurity practice itself.”</p>



<p class="wp-block-paragraph">ISC2 already includes <a href="https://www.networkworld.com/article/4196919/isc2-ai-raises-accountability-demands-for-cybersecurity-teams.html" target="_blank">AI-related content in certifications</a> including CISSP and <a href="https://www.isc2.org/certifications/CCSP" target="_blank" rel="noreferrer noopener">CCSP</a>, but Marks says practitioners have identified new responsibilities and risks that extend beyond those programs. “Enterprise security teams are currently grappling with significant knowledge gaps, particularly around securing model architectures against new vulnerabilities like prompt injection, data poisoning, and model inversion,” Marks adds.</p>



<p class="wp-block-paragraph">Organizations are working to understand emerging governance frameworks, including the NIST AI Risk Management Framework and ISO/IEC 42001, while adapting traditional application security and security operations workflows to AI systems, he says.</p>



<p class="wp-block-paragraph">ISC2 has not finalized the certification domains, but Marks says the organization expects the credential to address both technical controls and governance practices for <a href="https://www.networkworld.com/article/4174188/ai-reshapes-cybersecurity-workforce-priorities-as-it-teams-brace-for-new-risks.html" target="_blank">securing AI systems and managing AI risk</a>. The certification will use ISC2’s established certification development process, which relies on cybersecurity practitioners to define job roles, develop exam content, and validate competencies.</p>



<p class="wp-block-paragraph">Marks says ISC2 will continue to update the certification through ongoing input from cybersecurity professionals, in addition to its regular certification review process.</p>



<p class="wp-block-paragraph">The organization is also determining which professionals the certification will target. Marks says AI security responsibilities are emerging across security architecture, risk management, security operations, software development security, governance and compliance, communication and network security, and security assessment and testing. ISC2 says the certification will reflect how those roles are evolving.</p>



<p class="wp-block-paragraph">For organizations that are building AI security programs now, Marks recommends using existing AI training resources, adopting established governance frameworks, creating cross-functional AI security working groups, and participating in the certification development process.</p>



<p class="wp-block-paragraph">Marks says ISC2 expects AI knowledge to become part of most cybersecurity roles while a more specialized AI security discipline continues to develop. He says organizations will increasingly need professionals with foundational AI security knowledge, as well as specialists in areas such as adversarial machine learning, model architectures, and AI data pipelines.</p>



<p class="wp-block-paragraph">Looking ahead, Marks says he expects AI security expertise to evolve into both a foundational skill for cybersecurity professionals and a specialized discipline of its own.</p>



<p class="wp-block-paragraph">“At this time, we are seeing a hybrid evolution occurring in real time: AI security is simultaneously becoming a baseline expectation for all security roles, while also carving out a dedicated, highly specialized discipline,” Marks says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tech layoffs: A 2026 timeline]]></title>
<description><![CDATA[Among a range of factors leading to a wave of tech sector layoffs in 2026 is the rapid rise of artificial intelligence and automation. Companies are reconfiguring their workforces to leverage AI for increased efficiency and reduced operating costs. This realignment and reduction is implemented ev...]]></description>
<link>https://tsecurity.de/de/3689055/it-nachrichten/tech-layoffs-a-2026-timeline/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689055/it-nachrichten/tech-layoffs-a-2026-timeline/</guid>
<pubDate>Thu, 23 Jul 2026 14:35:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Among a range of factors leading to a wave of tech sector layoffs in 2026 is the rapid rise of artificial intelligence and automation. Companies are reconfiguring their workforces to leverage AI for increased efficiency and reduced operating costs. This realignment and reduction is implemented even by companies reporting strong financial performance.</p>



<p class="wp-block-paragraph">But it’s not just AI leading to workforce cuts. Complementing this technological shift are ongoing economic uncertainty, inflation, and higher interest rates, compounded by a chip shortage and rising energy costs. This mix is driving companies to cut costs and streamline operations for increased efficiency.</p>



<p class="wp-block-paragraph">According to data compiled by <a href="https://layoffs.fyi/" target="_blank" rel="noreferrer noopener">Layoffs.fyi</a>, an online tracker that keep tabs on job losses in the technology sector, 123,941 tech employees were laid off at 269 companies in 2025. The site also reports that 71,981 government employees were laid off by DOGE alone, with 182,528 total federal workers laid off.</p>



<p class="wp-block-paragraph">Here is a list — to be updated regularly — of some of the most prominent technology layoffs the industry has experienced recently.</p>



<h2 class="wp-block-heading">Notable tech layoffs in 2026</h2>



<ul class="wp-block-list">
<li>Monday.com</li>



<li>Microsoft</li>



<li>Meta</li>



<li>Cisco</li>



<li>Cloudflare</li>



<li>Oracle</li>



<li>Atlassian </li>



<li>Salesforce</li>



<li>Amazon</li>



<li>Ericsson</li>
</ul>



<h3 class="wp-block-heading">July 22, 2026: Monday.com cuts 20% of its workforce to restructure for the AI era</h3>



<p class="wp-block-paragraph">The company says the decision to <a href="https://www.computerworld.com/article/4200349/monday-com-cuts-20-of-its-workforce-to-restructure-for-the-ai-era-2.html">cut 620 jobs</a> isn’t about margins, but about creating a flatter organization built around AI agents, autonomous teams, and deeper customer engagement.</p>



<h3 class="wp-block-heading">July 6, 2026: Microsoft cuts 4,800 jobs, primarily in sales and Xbox teams</h3>



<p class="wp-block-paragraph">As the company <a href="https://www.computerworld.com/article/4193532/microsoft-bets-that-enterprise-ai-needs-engineers-not-bigger-sales-teams-2.html" target="_blank">trims thousands of jobs</a>, it’s also investing in embedded engineering teams and AI infrastructure. The layoffs come several weeks after the company offered 8,750 US employees <a href="https://www.computerworld.com/article/4163188/microsoft-to-offer-voluntary-retirement-buyouts-to-about-7-of-the-us-workforce.html">voluntary retirement buyouts</a>.</p>



<h3 class="wp-block-heading">June 5, 2026: Tech industry cut 38,242 jobs in May, worst since 2024</h3>



<p class="wp-block-paragraph">AI was blamed for 40% of <a href="https://www.computerworld.com/article/4181822/tech-industry-cut-38242-jobs-in-may-worst-since-2024.html">the job cuts in May</a>, up from 7% in January, according to research by employment placement company Challenger, Gray &amp; Christmas.</p>



<h3 class="wp-block-heading">May 20, 2026: Meta cuts 8,000 jobs, around 10% of workforce</h3>



<p class="wp-block-paragraph">The cuts are expected to expected to hit Meta’s engineering and product teams the hardest, arriving as Meta pivots toward AI to boost efficiency across its organization, <a href="https://tech.yahoo.com/general/article/meta-starts-cutting-8000-jobs-as-part-of-previously-announced-layoffs-145220586.html" target="_blank" rel="noreferrer noopener">according to Yahoo Tech</a>.</p>



<h3 class="wp-block-heading">May 13, 2026: Cisco to cut nearly 4,000 jobs despite strong growth in AI, enterprise networking</h3>



<p class="wp-block-paragraph">Despite reporting positive financial news — including record third-quarter revenue of $15.8 billion, a 12% year-over-year increase — Cisco said it will <a href="https://www.networkworld.com/article/4171043/cisco-to-cut-nearly-4000-jobs-despite-strong-growth-in-ai-enterprise-networking.html" target="_blank">eliminate almost 4,000 jobs</a>.</p>



<h3 class="wp-block-heading">May 7, 2026: Cloudflare to cut 1,100 jobs in AI-focused restructuring</h3>



<p class="wp-block-paragraph">About <a href="https://finance.yahoo.com/markets/stocks/articles/cloudflare-cut-over-1-100-204726989.html" target="_blank" rel="noreferrer noopener">20% of Cloudflare’s global workforce will be culled</a> as the company pivots for the agentic AI era, Reuters reported.</p>



<h3 class="wp-block-heading">April 1, 2026: Oracle to cut up to 30,000 jobs globally, putting enterprise support and roadmaps at risk</h3>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4153113/oracle-cuts-up-to-30000-jobs-globally-putting-enterprise-support-and-roadmaps-at-risk.html">Oracle began laying off employees</a> on March 31 in what could be the largest workforce reduction in the company’s history. Employees received termination emails at 6 a.m. local time with immediate system lockouts and no prior warning. <em>(Note: in June, CNBC put the <a href="https://www.cnbc.com/2026/06/23/oracle-ai-job-cuts-layoffs-21000.html" target="_blank" rel="noreferrer noopener">final layoff tally at 21,000</a>.)</em></p>



<h3 class="wp-block-heading">March 12, 2026: Atlassian cuts 1,600 jobs to fund AI and enterprise expansion</h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4144218/atlassian-cuts-1600-jobs-to-fund-ai-and-enterprise-expansion.html">Atlassian will reduce its global workforce</a> by approximately 10%, eliminating around 1,600 roles, as the collaboration software maker redirects capital toward artificial intelligence development and enterprise sales.</p>



<h3 class="wp-block-heading">March 11, 2026: Tech layoffs surpass 45,000 in early 2026</h3>



<p class="wp-block-paragraph">A recent analysis by RationalFX found 45,363 job cuts globally so far this year—with roughly 68% or more than 30,000 occurring in the U.S. — highlighting ongoing <a href="https://www.networkworld.com/article/4143749/tech-layoffs-surpass-45000-in-early-2026.html" target="_blank">workforce cuts even as many tech companies report strong revenue growth</a>.</p>



<h3 class="wp-block-heading">February 10, 2026: Salesforce lays off staffers as executive leadership churn continues</h3>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4130028/salesforce-lays-off-staffers-as-executive-leadership-churn-continues.html" target="_blank">Salesforce has reduced close to 1,000 roles</a> earlier this month across teams, including marketing, product management, data analytics, and its <a href="https://www.cio.com/article/4011936/salesforce-agentforce-3-promises-new-ways-to-monitor-and-manage-ai-agents.html">Agentforce</a> AI unit, <a href="https://www.businessinsider.com/salesforce-cuts-jobs-executive-changes-2026-2">Business Insider</a> reported, quoting employees familiar with the matter.</p>



<h3 class="wp-block-heading">January 23, 2026: Amazon layoffs expected to disproportionately hit AWS and tech talent</h3>



<p class="wp-block-paragraph">As the market slows down, <a href="https://www.computerworld.com/article/4121653/amazon-layoffs-expected-to-disproportionately-hit-aws-and-tech-talent.html">AWS and other Amazon units are preparing for another round of layoffs</a>, which is expected to overwhelmingly impact tech talent. An email from HR leader Beth Galetti on Jan. 28 <a href="https://www.computerworld.com/article/4123477/amazon-confirms-16000-job-cuts-including-to-aws.html">confirmed 16,000 job cuts</a>.</p>



<h3 class="wp-block-heading">January 15, 2026: Ericsson plans to shed 1,600 jobs in Sweden</h3>



<p class="wp-block-paragraph"> Ericsson lans to cut some 1,600 jobs in Sweden, the telecommunications equipment maker said doubling down on recent cost-saving measures that have helped it weather a prolonged downturn in telecoms spending, <a href="https://www.reuters.com/business/world-at-work/ericsson-shed-1600-jobs-sweden-2026-01-15/" target="_blank" rel="noreferrer noopener">Reuters reports</a>.</p>



<h3 class="wp-block-heading">January 13, 2026: Meta plans to cut around 10% of employees in Reality Labs business</h3>



<p class="wp-block-paragraph">Meta plans to cut around 10% of the employees in its Reality Labs division who work on products including the metaverse, according to three people with knowledge of the discussions, <a href="http://meta%20plans%20to%20cut%20around%2010%25%20of%20employees%20in%20reality%20labs%20business/" target="_blank" rel="noreferrer noopener">according to The New York Times</a>.</p>



<h2 class="wp-block-heading">Layoffs in 2025</h2>



<ul class="wp-block-list">
<li>Cisco</li>



<li>Oracle</li>



<li>Windsurf</li>



<li>Intel</li>



<li>Microsoft</li>



<li>Crowdstrike</li>



<li>HPE</li>



<li>Autodesk</li>



<li>HPE</li>



<li>CISA</li>



<li>Workday</li>



<li>Salesforce</li>



<li>Meta</li>
</ul>



<h3 class="wp-block-heading">Global tech-sector layoffs surpass 244,000 in 2025</h3>



<p class="wp-block-paragraph">Economic uncertainty, elevated interest rates, and AI adoption have <a href="https://www.networkworld.com/article/4114572/global-tech-sector-layoffs-surpass-244000-in-2025.html" target="_blank">driven workforce reductions across tech companies worldwide</a>, according to a RationalFX report.</p>



<h3 class="wp-block-heading">October 28, 2025: Amazon to cut 14,000 jobs across company</h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4080142/amazon-to-cut-14000-jobs-across-company.html">Amazon will reduce its overall workforce</a> by 14,000, cutting layers of management across the company and hiring in some areas to support its “biggest bets”.</p>



<h3 class="wp-block-heading">August 18, 2025: Cisco and Oracle to cut hundreds of Bay Area jobs</h3>



<p class="wp-block-paragraph">Tech companies Cisco and Oracle are <a href="https://www.sfchronicle.com/tech/article/cisco-oracle-layoffs-bay-area-20824135.php" target="_blank" rel="noreferrer noopener">cutting hundreds of jobs across the Bay Area</a>. Cisco will eliminate 221 positions at its Milpitas and San Francisco offices, effective Oct. 13. Oracle is reducing 101 positions in Santa Clara on the same date </p>



<h3 class="wp-block-heading">August 5, 2025: 3 weeks after acquiring Windsurf, Cognition offers staff the exit door</h3>



<p class="wp-block-paragraph">Cognition, the AI coding startup that acquired rival company Windsurf three weeks ago, laid off 30 employees last week and is offering buyouts to the roughly 200 remaining employees on the team, <a href="https://www.theinformation.com/articles/cognition-offers-buyouts-newly-acquired-windsurf-staff" target="_blank" rel="noreferrer noopener">reports The Information</a>.</p>



<h3 class="wp-block-heading">July 25, 2025, Intel to lay off 22% of workforce, CEO Tan signals ‘no more blank checks’</h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4028896/intel-to-lay-off-22-of-workforce-as-ceo-tan-signals-no-more-blank-checks.html">Intel will reduce its workforce to 75,000 employees</a> by the end of 2025 as new CEO Lip-Bu Tan implements sweeping changes designed to transform the struggling chipmaker</p>



<h3 class="wp-block-heading">July 8, 2025, Intel layoffs begin: Chipmaker is cutting many thousands of jobs</h3>



<p class="wp-block-paragraph">Intel has begun laying off employees across the company. CEO Lip-Bu Tan told workers back in April to expect <a href="https://www.oregonlive.com/silicon-forest/2025/07/intel-layoffs-begin-chipmaker-is-cutting-many-thousands-of-jobs.html">major layoffs at Intel </a>in the coming months as the chipmaker slashes costs and overhauls its organization after years of technical setbacks and falling sales. </p>



<h3 class="wp-block-heading">July 2, 2025: Microsoft will cut 9,000 workers</h3>



<p class="wp-block-paragraph">Microsoft will lay off about 9,000 employees, a source familiar with the workforce cut <a href="https://www.nbcnews.com/business/business-news/microsoft-laying-9000-employees-latest-cuts-rcna216553">told CNBC</a>.  The cuts will reportedly affect less than 4% of Microsoft’s global workforce and will impact different teams, geographies and levels of experience. This is the latest in a string of cuts the tech giant has made this year.</p>



<h3 class="wp-block-heading">June 17, 2025: Intel looks to factory layoffs to return to profitability</h3>



<p class="wp-block-paragraph"><a href="https://www.networkworld.com/article/4008670/can-intel-cut-its-way-to-profit-with-factory-layoffs.html">Intel will lay off up to 20% of its manufacturing sector employees</a> starting in July,  according to media reports, as the company looks for options as it seeks a return to profitability. The cuts reportedly will be made around the world, but some of the layoffs will be closer to home, according to a report in The Oregonian citing an internal company memo from Intel manufacturing Vice President Naga Chandrasekaran.</p>



<h3 class="wp-block-heading">May 7, 2025: CrowdStrike to lay off 5% of staff</h3>



<p class="wp-block-paragraph"><a href="https://www.reuters.com/sustainability/crowdstrike-lay-off-5-staff-reaffirms-forecasts-2025-05-07/">CrowdStrike announced a plan to cut about 500 roles</a>, roughly 5% of its workforce, to streamline operations and reduce costs. The cybersecurity company will incur about $36 million to $53 million in charges related to the layoffs</p>



<h3 class="wp-block-heading">March 6, 2025: HPE cuts 2,500 jobs, remains committed to Juniper buy</h3>



<p class="wp-block-paragraph">CEO Antonio Neri told Wall Street analysts that <a href="https://www.networkworld.com/article/3840596/hpe-cuts-2500-workers-expects-juniper-buy-to-close-end-of-25-faces-tariff-issues.html">HPE would begin implementing a cost-cutting program involving layoffs </a>of about 2,500 employees over the next 18 months. HPE employs about 61,000 people worldwide.</p>



<h3 class="wp-block-heading">Feb. 27, 2025: Autodesk to lay off 9% of workforce</h3>



<p class="wp-block-paragraph">Software maker Autodesk is laying off 1,350 staff. With the rise of subscription and multi-year contracts billed annually, and self-service enablement, it finds it needs fewer sales staff, <a href="https://adsknews.autodesk.com/en/news/022725-employee-message/">CEO Andrew Anagnost said in a message to employees</a>. And with its cloud, platform, and AI products proving most profitable, it’s concentrating its staff and investments there. </p>



<h3 class="wp-block-heading">Feb. 27, 2025: HP to lay off 2,000 more</h3>



<p class="wp-block-paragraph">As part of an ongoing restructuring, HP plans to lay off up to another 2,000 workers. In recent weeks, the company has tried — unsuccessfully — to do away with telephone support staff by <a href="https://www.pcworld.com/article/2617767/hp-forced-callers-to-wait-15-minutes-before-connecting-to-support-staff.html">forcing callers to wait for at least 15 minutes</a> if they refuse to use self-service support resources online. The company swiftly backtracked, but wider job cuts are still on. </p>



<h3 class="wp-block-heading">Feb. 21, 2025: <a href="https://www.csoonline.com/article/3829710/firing-of-130-cisa-staff-worries-cybersecurity-industry.html">CISA lays off 130</a></h3>



<p class="wp-block-paragraph">Government employees get laid off too: In this case, 130 workers at the US Cybersecurity and Infrastructure Security Agency are being shown the door as a result of a DOGE decision. Cybersecurity experts are concerned that the cuts will harm the international collaborations that CISA has fostered, quite apart from their concerns about the security of the DOGE layoff process itself.</p>



<h3 class="wp-block-heading">Feb. 5, 2025: <a href="https://www.computerworld.com/article/3817887/workday-to-cut-1750-jobs-shift-focus-to-ai-and-global-expansion.html">Workday lays off 1,750</a></h3>



<p class="wp-block-paragraph">As it moves to invest more in AI and international growth, Workday is laying off 8.5% of its workforce and disposing of unused office space. Some analysts fear the cutbacks will affect the company’s customer service — unless AI can pick up the slack.</p>



<h3 class="wp-block-heading">Feb. 4, 2025: Salesforce lays off over 1,000</h3>



<p class="wp-block-paragraph">At the same time as it’s hiring sales staff for its new artificial intelligence products, Salesforce is laying off over 1,000 workers across the company, according to Bloomberg. As of June, 2024, the company had over 72,000 employees, according to its website. Salesforce did not comment on the report. In 2024 the company reportedly laid off around 1,000 staff too, in two waves: January and July.</p>



<h3 class="wp-block-heading">Jan. 14, 2025: Meta will lay off 5% of workforce</h3>



<p class="wp-block-paragraph">Mark Zuckerberg told Meta employees he intended to “move out the low performers faster” in an internal memo reported by Bloomberg. The memo announced that the company will lay off 5% of its staff, or around 3,600 staff, beginning Feb. 10. The company had already reduced its headcount by 5% in 2024 through natural attrition, the memo said. Among those leaving the company will be staff previously responsible for fact checking of posts on its social media platforms in the US, as the company begins relying on its users to police content.</p>



<h2 class="wp-block-heading">Tech layoffs in 2024</h2>



<ul class="wp-block-list">
<li>Equinix</li>



<li>AMD</li>



<li>Freshworks</li>



<li>Cisco</li>



<li>General Motors</li>



<li>Intel</li>



<li>OpenText</li>



<li>Microsoft</li>



<li>AWS</li>



<li>Dell</li>
</ul>



<h3 class="wp-block-heading">Nov. 26, 2024: <a href="https://www.networkworld.com/article/3613399/equinix-to-cut-3-of-staff-amidst-the-greatest-demand-for-data-center-infrastructure-ever.html">Equinix to cut 3% of staff</a></h3>



<p class="wp-block-paragraph">Despite intense demand for its data center capacity, Equinix is planning to lay off 3% of its workforce, or around 400 employees. The announcement followed the appointment of Adaire Fox-Martin to replace Charles Meyers as CEO and the departures of two other senior executives, CIO Milind Wagle and CISO Michael Montoya.</p>



<h3 class="wp-block-heading">Nov. 13, 2024: <a href="https://www.networkworld.com/article/3605016/amd-to-cut-4-of-workforce-to-prioritize-ai-chip-expansion-to-rival-nvidia.html#:~:text=Workforce%20reduction%20comes%20amid%20strong,shift%20in%20focus%20toward%20AI.&amp;text=Advanced%20Micro%20Devices%20(AMD)%20is,Nvidia's%20lead%20in%20the%20sector.">AMD to cut 4% of workforce</a></h3>



<p class="wp-block-paragraph">AMD will lay off around 1,000 employees as it pivots towards developing AI-focused chips, it said. The move came as a surprise to staff, as the company also reported strong quarterly earnings. </p>



<h3 class="wp-block-heading">Nov. 7, 2024: <a href="https://www.cio.com/article/3601088/freshworks-lays-off-660-about-13-percent-of-its-global-workforce-despite-strong-earnings-profits.html">Freshworks lays off 660</a></h3>



<p class="wp-block-paragraph">Enterprise software vendor Freshworks laid off around 660 staff, or around 13% of its headcount, despite reporting increased revenue and profits in its fourth fiscal quarter. The company described the layoffs as a realignment of its global workforce.</p>



<h3 class="wp-block-heading">Sept. 17, 2024: <a href="https://www.networkworld.com/article/3486901/cisco-to-cut-7-of-workforce-restructure-product-groups.html">Cisco lays off 6,000</a></h3>



<p class="wp-block-paragraph">After laying off around 4,200 staff in February, Cisco is at it again, laying off another 6,000 or around 7% of its workforce. Among the divisions affected were its threat intelligence unit, Talos Security. </p>



<h3 class="wp-block-heading">Aug. 20, 2024: <a href="https://www.cio.com/article/3489323/gm-software-layoffs-could-signal-a-shift-in-digital-transformation-strategy.html">General Motors lays off 1,000 software staff</a></h3>



<p class="wp-block-paragraph">More than 1,000 software and services staff are on the way out at General Motors, signalling that it could be rethinking its digital transformation strategy. In an internal memo, the company said that it was moving resources to its highest-priority work and flattening hierarchies.</p>



<h3 class="wp-block-heading">August 1, 2024: <a href="https://www.computerworld.com/article/3480715/intel-fires-15000-employees-as-it-intensifies-focus-on-ai.html">Intel removes 15,000 roles</a></h3>



<p class="wp-block-paragraph">Intel plans to cut its workforce by around 15% to reduce costs after a disastrous second quarter. Revenue for the three months to June 29 stagnated at around $12.8 billion, but net income fell 85% to $83 million, prompting CEO Pat Gelsinger to bring forward a company-wide meeting in order to announce that 15,000 staff would lose their jobs. “This is an incredibly hard day for Intel as we are making some of the most consequential changes in our company’s history,” Gelsinger wrote in an email to staff, continuing: “Our revenues have not grown as expected — and we’ve yet to fully benefit from powerful trends, like AI. Our costs are too high, our margins are too low. We need bolder actions to address both — particularly given our financial results and outlook for the second half of 2024, which is tougher than previously expected.”</p>



<h3 class="wp-block-heading">July 4, 2024: <a href="https://www.computerworld.es/article/2513686/opentext-despedira-a-cerca-de-1-200-empleados.html">OpenText to lay off 1,200</a></h3>



<p class="wp-block-paragraph">OpenText said it will lay off 1,200 staff, or about 1.7% of its workforce, in a bid to save around $100 million annually. It plans to hire new sales and engineering staff in other areas in 2025, it said.</p>



<h3 class="wp-block-heading">June 4, 2024: <a href="https://www.networkworld.com/article/2138075/microsoft-lays-off-staffers-from-its-azure-division.html">Microsoft lays off staff in Azure division</a></h3>



<p class="wp-block-paragraph">Microsoft laid off staff in several teams supporting its cloud services, including Azure for Operations and Mission Engineering. The company didn’t say exactly how many staff were leaving.</p>



<h3 class="wp-block-heading">April 4, 2024: <a href="https://www.cio.com/article/2081437/amazon-downsizes-aws-in-a-fresh-cost-cutting-round.html">Amazon downsizes AWS</a> in a fresh cost-cutting round</h3>



<p class="wp-block-paragraph">Amazon announced hundreds of layoffs in the sales and marketing teams of its AWS cloud services division — and also in the technology development teams for its physical retail stores, as it stepped back from efforts to generalize the “<a href="https://www.cio.com/article/2079910/amazon-drops-just-walk-out-technology-at-its-us-retail-locations.html">Just Walk Out</a>” technology built for its Amazon Fresh grocery stores. </p>



<h3 class="wp-block-heading">April 1, 2024: <a href="https://investors.delltechnologies.com/static-files/d6e82f58-d417-422f-b2f3-4d08d498abd4" target="_blank" rel="noreferrer noopener">Dell acknowledges 13,000 job cuts</a></h3>



<p class="wp-block-paragraph">Dell Technologies’ <a href="https://investors.delltechnologies.com/static-files/d6e82f58-d417-422f-b2f3-4d08d498abd4" target="_blank" rel="noreferrer noopener">latest 10K filing with the US Securities and Exchange Commission</a> disclosed that the company had laid off 13,000 employees over the course of the 2023 fiscal year; it characterized the layoffs and other reorganizational moves as cost-cutting measures. “These actions resulted in a reduction in our overall headcount,” the company said. A comparison to the previous year’s 10K filing, performed by The Register, found that Dell employed 133,000 people at that point, compared to 120,000 as of February 2024. Dell announced layoffs of 6,650 staffers on Feb. 6, but it is unclear whether those cuts were reflected in the numbers from this year’s 10K statement.</p>



<p class="wp-block-paragraph"><em><a href="https://www.computerworld.com/article/3816662/tech-layoffs-in-2024-a-timeline.html">See news of earlier layoffs.</a></em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers]]></title>
<description><![CDATA[Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances.

The activity involves malicious Packagist development versions spanning 10 pac...]]></description>
<link>https://tsecurity.de/de/3689000/it-security-nachrichten/attackers-weaponize-github-actions-runners-to-target-cpanel-and-whm-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689000/it-security-nachrichten/attackers-weaponize-github-actions-runners-to-target-cpanel-and-whm-servers/</guid>
<pubDate>Thu, 23 Jul 2026 14:16:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances.

The activity involves malicious Packagist development versions spanning 10 packages associated with a legitimate PHP and DevOps developer, dinushchathurya, between July 12 and 13,]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers]]></title>
<description><![CDATA[Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers, with a primary focus on cPanel and WHM deployments. The campaign first surfaced when malicious development versions were discovered acros...]]></description>
<link>https://tsecurity.de/de/3688856/it-security-nachrichten/hackers-turn-github-actions-into-a-global-botnet-for-attacking-web-hosting-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688856/it-security-nachrichten/hackers-turn-github-actions-into-a-global-botnet-for-attacking-web-hosting-servers/</guid>
<pubDate>Thu, 23 Jul 2026 13:27:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers, with a primary focus on cPanel and WHM deployments. The campaign first surfaced when malicious development versions were discovered across ten Packagist PHP packages tied to a legitimate PHP and DevOps […]</p>
<p>The post <a href="https://gbhackers.com/github-actions-into-a-global-botnet/">Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Azure DevOps MCP: Unsichtbare PR-Kommentare kapern KI-Review-Agenten und leaken Projektinfos]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine einzelne HTML-Notiz in der Beschreibung eines Pull Requests kann eine KI-gestützte Review-Automation missbrauchen und damit Zugriff über Projektgrenzen hinweg verschieben. Der Angriff läuft nicht als „klassisches“ Prompt-Troubleshooting, sondern nutzt eine Lücke in der...]]></description>
<link>https://tsecurity.de/de/3688260/it-security-nachrichten/azure-devops-mcp-unsichtbare-pr-kommentare-kapern-ki-review-agenten-und-leaken-projektinfos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688260/it-security-nachrichten/azure-devops-mcp-unsichtbare-pr-kommentare-kapern-ki-review-agenten-und-leaken-projektinfos/</guid>
<pubDate>Thu, 23 Jul 2026 09:24:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-azure-devops-mcp-hidden-pr-comment.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-azure-devops-mcp-hidden-pr-comment.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-azure-devops-mcp-hidden-pr-comment-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-azure-devops-mcp-hidden-pr-comment-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-azure-devops-mcp-hidden-pr-comment-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-azure-devops-mcp-hidden-pr-comment-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-azure-devops-mcp-hidden-pr-comment-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Eine einzelne HTML-Notiz in der Beschreibung eines Pull Requests kann eine KI-gestützte Review-Automation missbrauchen und damit Zugriff über Projektgrenzen hinweg verschieben. Der Angriff läuft nicht als „klassisches“ Prompt-Troubleshooting, sondern nutzt eine Lücke in der Werkzeugverkettung des offiziellen MCP-Servers. Besonders kritisch wird es, wenn ein Reviewer die KI mit höherer Berechtigung ausführt […]</p>
<div><a href="https://www.it-boltwise.de/azure-devops-mcp-unsichtbare-pr-kommentare-kapern-ki-review-agenten-und-leaken-projektinfos.html">... den vollständigen Artikel <strong>»Azure DevOps MCP: Unsichtbare PR-Kommentare kapern KI-Review-Agenten und leaken Projektinfos«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/azure-devops-mcp-unsichtbare-pr-kommentare-kapern-ki-review-agenten-und-leaken-projektinfos.html">Azure DevOps MCP: Unsichtbare PR-Kommentare kapern KI-Review-Agenten und leaken Projektinfos</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Plans 3.2 GW Data Centre In Georgia]]></title>
<description><![CDATA[AI start-up says massive facility could cost more than $30bn to build, as it seeks to ramp up compute infrastructure This article has been indexed from Silicon UK Read the original article: OpenAI Plans 3.2 GW Data Centre In Georgia
Read more →
The post OpenAI Plans 3.2 GW Data Centre In Georgia ...]]></description>
<link>https://tsecurity.de/de/3688167/it-security-nachrichten/openai-plans-32-gw-data-centre-in-georgia/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688167/it-security-nachrichten/openai-plans-32-gw-data-centre-in-georgia/</guid>
<pubDate>Thu, 23 Jul 2026 08:54:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AI start-up says massive facility could cost more than $30bn to build, as it seeks to ramp up compute infrastructure This article has been indexed from Silicon UK Read the original article: OpenAI Plans 3.2 GW Data Centre In Georgia</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/openai-plans-3-2-gw-data-centre-in-georgia/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/openai-plans-3-2-gw-data-centre-in-georgia/">OpenAI Plans 3.2 GW Data Centre In Georgia</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[2026 DevOps Security Insights: What Matters Most for CISOs]]></title>
<description><![CDATA[Rich threat landscape, agentic AI, vulnerabilities, third-party DevOps platforms… Securing a software supply chain is a multidimensional and complex undertaking, so it is easy to lose track. At GitProtect, we’ve… The post 2026 DevOps Security Insights: What Matters Most for…
Read more →
The post ...]]></description>
<link>https://tsecurity.de/de/3687329/it-security-nachrichten/2026-devops-security-insights-what-matters-most-for-cisos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687329/it-security-nachrichten/2026-devops-security-insights-what-matters-most-for-cisos/</guid>
<pubDate>Wed, 22 Jul 2026 20:38:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Rich threat landscape, agentic AI, vulnerabilities, third-party DevOps platforms… Securing a software supply chain is a multidimensional and complex undertaking, so it is easy to lose track. At GitProtect, we’ve… The post 2026 DevOps Security Insights: What Matters Most for…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/2026-devops-security-insights-what-matters-most-for-cisos/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/2026-devops-security-insights-what-matters-most-for-cisos/">2026 DevOps Security Insights: What Matters Most for CISOs</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[2026 DevOps Security Insights: What Matters Most for CISOs]]></title>
<description><![CDATA[Rich threat landscape, agentic AI, vulnerabilities, third-party DevOps platforms… Securing a software supply chain is a multidimensional and complex undertaking, so it is easy to lose track. At GitProtect, we’ve...
The post 2026 DevOps Security Insights: What Matters Most for CISOs appeared first...]]></description>
<link>https://tsecurity.de/de/3687255/it-security-nachrichten/2026-devops-security-insights-what-matters-most-for-cisos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687255/it-security-nachrichten/2026-devops-security-insights-what-matters-most-for-cisos/</guid>
<pubDate>Wed, 22 Jul 2026 20:24:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1024" height="768" src="https://www.cyberdefensemagazine.com/wp-content/uploads/2026/07/2026-DevOps-Security-Insights-What-Matters-Most-for-CISOs.png.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" link_thumbnail="" decoding="async" loading="lazy" srcset="https://www.cyberdefensemagazine.com/wp-content/uploads/2026/07/2026-DevOps-Security-Insights-What-Matters-Most-for-CISOs.png.jpg 1024w, https://www.cyberdefensemagazine.com/wp-content/uploads/2026/07/2026-DevOps-Security-Insights-What-Matters-Most-for-CISOs.png-768x576.jpg 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px"><p>Rich threat landscape, agentic AI, vulnerabilities, third-party DevOps platforms… Securing a software supply chain is a multidimensional and complex undertaking, so it is easy to lose track. At GitProtect, we’ve...</p>
<p>The post <a href="https://www.cyberdefensemagazine.com/2026-devops-security-insights-what-matters-most-for-cisos/" data-wpel-link="internal">2026 DevOps Security Insights: What Matters Most for CISOs</a> appeared first on <a href="https://www.cyberdefensemagazine.com/" data-wpel-link="internal">Cyber Defense Magazine</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab previews auto-remediation of vulnerable dependencies]]></title>
<description><![CDATA[GitLab has released GitLab 19.2, an update to the company’s devsecops platform that allows teams to fix vulnerable dependencies automatically, use Security Review Flow to catch logic flaws that scanners miss, and run AI agents straight from the terminal, the company said. 



Highlights in GitLab...]]></description>
<link>https://tsecurity.de/de/3686997/ai-nachrichten/gitlab-previews-auto-remediation-of-vulnerable-dependencies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686997/ai-nachrichten/gitlab-previews-auto-remediation-of-vulnerable-dependencies/</guid>
<pubDate>Wed, 22 Jul 2026 18:23:04 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">GitLab has released <a href="https://about.gitlab.com/whats-new/" data-type="link" data-id="https://about.gitlab.com/whats-new/">GitLab 19.2</a>, an update to the company’s <a href="https://www.infoworld.com/article/2337499/what-is-devsecops-securing-devops-pipelines.html" data-type="link" data-id="https://www.infoworld.com/article/2337499/what-is-devsecops-securing-devops-pipelines.html">devsecops</a> platform that allows teams to fix vulnerable dependencies automatically, use Security Review Flow to catch logic flaws that scanners miss, and run AI agents straight from the terminal, the company said. </p>



<p class="wp-block-paragraph">Highlights in GitLab 19.2 include the following:</p>



<ul class="wp-block-list">
<li>Dependency Scanning Auto-Remediation, in public beta, uses AI to fix build-breaking changes and iterates until your pipeline passes, with every change governed by your existing gates and audit trail. </li>



<li>Security Review Flow, also in public beta, analyzes code changes as a security engineer would and catches authorization gaps, business-logic errors, and race conditions that static scanners structurally cannot see.</li>



<li>GitLab Duo CLI, now generally available, gives developers access to agents and multi-step agentic flows for all software life cycle tasks without leaving the terminal. </li>



<li>Custom Flows, now generally available, let teams replace manual multi-step workflows with agentic automations for software development, triggered by GitLab events.</li>
</ul>



<p class="wp-block-paragraph">“Coding agents made it possible to generate far more code and moved the bottleneck downstream to reviews and security,” said Manav Khurana, chief product and marketing officer at GitLab, in a statement. “GitLab 19.2 puts agents to work on that bottleneck: fixing vulnerable dependencies, catching the flaws scanners miss, and automating the steps in between with a person still approving what ships.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Azure DevOps Prompt Injection Targets AI Coding Agents]]></title>
<description><![CDATA[Hidden prompt injections in Azure DevOps can manipulate AI coding agents into accessing sensitive data using a developer’s permissions. The post Azure DevOps Prompt Injection Targets AI Coding Agents  appeared first on eSecurity Planet. This article has been indexed from…
Read more →
The post Azu...]]></description>
<link>https://tsecurity.de/de/3686817/it-security-nachrichten/azure-devops-prompt-injection-targets-ai-coding-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686817/it-security-nachrichten/azure-devops-prompt-injection-targets-ai-coding-agents/</guid>
<pubDate>Wed, 22 Jul 2026 17:17:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hidden prompt injections in Azure DevOps can manipulate AI coding agents into accessing sensitive data using a developer’s permissions. The post Azure DevOps Prompt Injection Targets AI Coding Agents  appeared first on eSecurity Planet. This article has been indexed from…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/azure-devops-prompt-injection-targets-ai-coding-agents/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/azure-devops-prompt-injection-targets-ai-coding-agents/">Azure DevOps Prompt Injection Targets AI Coding Agents</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Azure DevOps Prompt Injection Targets AI Coding Agents ]]></title>
<description><![CDATA[Hidden prompt injections in Azure DevOps can manipulate AI coding agents into accessing sensitive data using a developer's permissions.
The post Azure DevOps Prompt Injection Targets AI Coding Agents  appeared first on eSecurity Planet.]]></description>
<link>https://tsecurity.de/de/3686757/it-security-nachrichten/azure-devops-prompt-injection-targets-ai-coding-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686757/it-security-nachrichten/azure-devops-prompt-injection-targets-ai-coding-agents/</guid>
<pubDate>Wed, 22 Jul 2026 17:05:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hidden prompt injections in Azure DevOps can manipulate AI coding agents into accessing sensitive data using a developer's permissions.</p>
<p>The post <a href="https://www.esecurityplanet.com/threats/azure-devops-prompt-injection-targets-ai-coding-agents/">Azure DevOps Prompt Injection Targets AI Coding Agents </a> appeared first on <a href="https://www.esecurityplanet.com/">eSecurity Planet</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data]]></title>
<description><![CDATA[A newly disclosed flaw in Microsoft’s official Azure DevOps MCP server shows how an invisible comment in a pull request can silently hijack a developer’s AI coding assistant and turn it into a data-exfiltration tool. Security researchers at Manifold Security…
Read more →
The post Azure DevOps MCP...]]></description>
<link>https://tsecurity.de/de/3685897/it-security-nachrichten/azure-devops-mcp-flaw-lets-hidden-pr-comments-hijack-ai-agents-and-steal-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685897/it-security-nachrichten/azure-devops-mcp-flaw-lets-hidden-pr-comments-hijack-ai-agents-and-steal-data/</guid>
<pubDate>Wed, 22 Jul 2026 12:13:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly disclosed flaw in Microsoft’s official Azure DevOps MCP server shows how an invisible comment in a pull request can silently hijack a developer’s AI coding assistant and turn it into a data-exfiltration tool. Security researchers at Manifold Security…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/azure-devops-mcp-flaw-lets-hidden-pr-comments-hijack-ai-agents-and-steal-data/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/azure-devops-mcp-flaw-lets-hidden-pr-comments-hijack-ai-agents-and-steal-data/">Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[From outsourcing to ownership: How we brought development in-house without breaking delivery]]></title>
<description><![CDATA[Outsourcing worked – until it didn’t.



After Akirolabs achieved early market validation and onboarded its first enterprise customers, outsourcing began to create strategic limitations around scalability, intellectual property (IP) ownership, security and delivery execution.



The challenges st...]]></description>
<link>https://tsecurity.de/de/3685759/it-security-nachrichten/from-outsourcing-to-ownership-how-we-brought-development-in-house-without-breaking-delivery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685759/it-security-nachrichten/from-outsourcing-to-ownership-how-we-brought-development-in-house-without-breaking-delivery/</guid>
<pubDate>Wed, 22 Jul 2026 11:11:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Outsourcing worked – until it didn’t.</p>



<p class="wp-block-paragraph">After Akirolabs achieved early market validation and onboarded its first enterprise customers, outsourcing began to create strategic limitations around scalability, intellectual property (IP) ownership, security and delivery execution.</p>



<p class="wp-block-paragraph">The challenges started after the first enterprise customers confirmed product-market fit. At that point, delivery speed became directly tied to business growth. Product quality expectations increased. Infrastructure and security requirements became stricter. Investors started asking difficult but<a href="https://www.cio.com/article/4069909/10-outsourcing-strategy-questions-every-it-leader-must-answer.html"> </a><a href="https://www.cio.com/article/4069909/10-outsourcing-strategy-questions-every-it-leader-must-answer.html">fair questions</a> about IP ownership, operational dependencies and long-term scalability.</p>



<p class="wp-block-paragraph">Most importantly, engineering execution was no longer just an operational function – it became part of the company’s strategic advantage. That was the moment when the founders decided the company needed dedicated technology leadership to address these challenges. This is how I joined the company at the beginning of 2023. As VP of Engineering and a bit later as CTO, I led the transformation (usually known as<a href="https://www.cio.com/article/272355/outsourcing-outsourcing-definition-and-solutions.html"> </a><a href="https://www.cio.com/article/272355/outsourcing-outsourcing-definition-and-solutions.html">insourcing, repatriating or backsourcing</a>) from an outsourced model to an internal engineering organization while maintaining product delivery continuity and preparing the company for the next growth stage. The process took roughly a year and involved not only technical migration, but also organizational design, hiring, process development, infrastructure modernization and cultural transformation – everything from the ground up.</p>



<h2 class="wp-block-heading">Building an internal engineering organization while still delivering</h2>



<p class="wp-block-paragraph">One of the biggest misconceptions about insourcing is that it is primarily a technical project. It is a leadership and execution challenge.</p>



<p class="wp-block-paragraph">When I joined the company, there was effectively no internal engineering structure, limited visibility into the existing system and no clear long-term technical strategy. My first months were dedicated to understanding reality and I began with a comprehensive assessment of the codebase, operational risks, documentation quality and knowledge dependencies to determine the most viable transition strategy.</p>



<p class="wp-block-paragraph">Very early in the process, I faced a critical strategic decision: whether to gradually assume ownership of the existing platform or rebuild it internally. To make that decision, I evaluated four distinct transition models ranging from limited management insourcing to a complete internal rebuild.</p>



<p class="wp-block-paragraph">After assessing the technical, operational and long-term business implications of each approach, I selected the most demanding option: rebuilding the product internally while maintaining uninterrupted delivery for existing customers. Although riskier in the short term, a full rebuild offered the clearest route to complete IP ownership, architectural flexibility and long-term scalability.</p>



<p class="wp-block-paragraph">At the time, this decision ran counter to the approach typically taken by startups in similar situations. Most organizations gradually assume ownership of an existing codebase to minimize short-term risk and preserve delivery capacity. My assessment was that the accumulated architectural debt, fragmented knowledge distribution and long-term maintenance risks would ultimately make a phased takeover more expensive and less scalable than a controlled rebuild. The strategy required significantly higher execution discipline, but it allowed us to establish complete ownership of the platform, eliminate inherited constraints and create an architecture capable of supporting enterprise-scale growth.</p>



<p class="wp-block-paragraph">The next challenge was hiring.</p>



<p class="wp-block-paragraph">In Germany, hiring can easily take four to six months – mostly due to a typical 3-month notice period, which is incompatible with startup timelines. We solved this by building a hybrid organization structure early: a lean internal core team combined with carefully selected contractors. Instead of hiring only narrow specialists, we prioritized experienced generalists capable of operating across architecture, infrastructure, security and compliance discussions. Later, we evolved toward a<a href="https://docs.google.com/document/d/1uSc1o6hdJ5AweCsjcLzo3JAzvq1q-7ALl1MPMNWx2sQ/edit?usp=sharing"> </a><a href="https://docs.google.com/document/d/1uSc1o6hdJ5AweCsjcLzo3JAzvq1q-7ALl1MPMNWx2sQ/edit?usp=sharing">product engineering model</a>, where engineers owned broader product outcomes rather than narrowly defined technical functions.</p>



<p class="wp-block-paragraph">During the first three months, we established a core engineering team of four senior engineers. Over the following nine months, the organization expanded to roughly fifteen engineers while I strategically designed and executed the transformation of the platform’s architecture to meet the rigorous deployment and compliance standards of our first enterprise clients, including Raiffeisen Bank International and Bertelsmann. This structural overhaul allowed the company to meet the deployment, security and compliance requirements of enterprise customers that had previously been inaccessible under the outsourced model. At that point, we had already achieved complete coverage across backend, frontend, DevOps, QA and security.</p>



<p class="wp-block-paragraph">I also intentionally kept processes lightweight during the transition. Instead of introducing heavyweight frameworks, we focused on clarity of priorities, fast decision-making and execution discipline. We used Kanban over Scrum, eliminated unnecessary meetings, shortened the remaining ones and emphasized engineering culture over process overhead.</p>



<p class="wp-block-paragraph">Another major challenge was project estimation. Because dual-track development was unavoidable until the in-house platform reached production readiness, estimation accuracy had a direct impact on budget efficiency. Despite all challenges, my initial estimate ultimately proved remarkably close to the final delivery date, differing by only about a week. Accurate forecasting under conditions of parallel development streams, ongoing customer commitments and active team formation became a critical leadership challenge. Maintaining this level of predictability throughout the transition helped align engineering execution with business planning, hiring decisions and investor expectations.</p>



<p class="wp-block-paragraph">The engineering transformation enabled capabilities that contributed to Akirolabs being recognized as an IDC Innovator in Procurement in 2023, named amongst the Top 27 AI Startups in Germany in 2024, Sifted’s 100 Fastest-Growing Startups in DACH &amp; CEE 2025 and inclusion in 2024-2026 in ProcureTech100 annual recognition of procurement technology providers shaping the future of digital procurement.</p>



<h2 class="wp-block-heading">Managing risk without slowing down the business</h2>



<p class="wp-block-paragraph">The hardest part of insourcing is not writing code, selecting the technology stack, designing architecture or configuring infrastructure. It is avoiding disruption while the company is changing underneath the product. I successfully orchestrated the concurrent overhaul of product architecture, cross-functional engineering recruitment, infrastructure modernization and live customer operations under exceptionally tight margins.</p>



<p class="wp-block-paragraph">To reduce delivery risk, we approached the transition in layers.</p>



<p class="wp-block-paragraph">First, we focused on<a href="https://platformengineering.com/features/the-platform-centric-shift-why-enterprise-ai-teams-need-internal-ai-platforms-not-more-engineers/"> </a><a href="https://platformengineering.com/features/the-platform-centric-shift-why-enterprise-ai-teams-need-internal-ai-platforms-not-more-engineers/">infrastructure reliability and operational readiness</a> before feature expansion. Cloud architecture, recovery testing, permission segregation and incident management processes were implemented early, not after launch. We also introduced multiple testing stages and dedicated QA functions after learning the hard way that a “developers-only” quality control approach does not scale for complex web platforms and business domains.</p>



<p class="wp-block-paragraph">Second, we established a structured knowledge-transfer process to rapidly onboard engineers and reduce external dependencies.</p>



<p class="wp-block-paragraph">Third, we became extremely disciplined about scope management. One of the most common reasons<a href="https://www.cio.com/article/244453/whether-outsourcing-or-insourcing-cios-need-control.html"> </a><a href="https://www.cio.com/article/244453/whether-outsourcing-or-insourcing-cios-need-control.html">insourcing initiatives fail is uncontrolled change</a> during the rebuild phase. Every new feature request increases uncertainty non-linearly. We learned to separate strategic improvements from distractions and protect the core delivery roadmap aggressively. Throughout the transition, we successfully maintained uninterrupted customer operations by utilizing planned maintenance windows, achieved a near-zero-downtime migration and permanently doubled product velocity immediately following the migration.</p>



<p class="wp-block-paragraph">Beyond the technical migration itself, the transition established a repeatable operating model for scaling technology organizations beyond the product-market-fit stage. The framework combined organizational redesign, controlled knowledge repatriation, architecture modernization and enterprise-grade operational practices while maintaining uninterrupted customer delivery throughout the transformation. While the implementation was specific to Akirolabs, the underlying principles are broadly applicable to organizations seeking to transition from outsourced development to internal product ownership without disrupting business operations.</p>



<p class="wp-block-paragraph">By the time the new platform reached production readiness, I had established not only a functioning engineering organization, but also a stable operational model: internal ownership, production-grade infrastructure, security processes, scalable hiring practices and clear technology and product roadmaps.</p>



<p class="wp-block-paragraph">A positive side effect of the transition was the creation of internal UI/UX and Data Science capabilities, which later became strategically important for AI product initiatives and created a foundation for the third version of the product, which we released in mid-2025.</p>



<p class="wp-block-paragraph">My technical restructuring and migration to a secure proprietary platform reduced architectural risk, established full in-house ownership and helped strengthen investor confidence during the company’s successful €5M fundraising round in 2024.</p>



<p class="wp-block-paragraph">The transition created a stronger foundation for scale and supported the company’s continued expansion among enterprise organizations operating at Fortune 500 scale, including Ahold Delhaize, Workday, IFF, Deutsche Bahn and others.</p>



<h2 class="wp-block-heading">Lessons learned for CTOs considering insourcing</h2>



<p class="wp-block-paragraph">Looking back, several decisions made the transition successful, and several mistakes made it harder than necessary.</p>



<p class="wp-block-paragraph">The first lesson is simple: decisiveness in strategic transition is paramount to maintaining business momentum. Rapidly evaluating insourcing frameworks and defining clear boundaries with the external partner allowed us to mitigate operational downtime and execute a highly efficient migration ahead of critical market deadlines.</p>



<p class="wp-block-paragraph">Second, hire more senior people and do it as early as possible. Strong technical leaders multiply execution capacity far beyond their individual contribution. In our case, the quality of the first hires influenced architecture quality, hiring standards, delivery discipline and engineering culture for the entire organization.</p>



<p class="wp-block-paragraph">Finally, culture matters more than frameworks. Processes can be added later. Ownership mentality cannot.</p>



<p class="wp-block-paragraph">The biggest long-term advantage of bringing development in-house was not simply faster execution, not better code quality or operational cost optimization by over 30% after the transition which we also achieved. It was an alignment. Product strategy, engineering decisions, customer priorities and business goals became part of the same conversation instead of being separated by organizational boundaries. For technology companies operating in highly competitive markets, that alignment becomes a compounding advantage over time.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data]]></title>
<description><![CDATA[A newly disclosed flaw in Microsoft’s official Azure DevOps MCP server shows how an invisible comment in a pull request can silently hijack a developer’s AI coding assistant and turn it into a data-exfiltration tool. Security researchers at Manifold Security found that the bug lets an attacker wi...]]></description>
<link>https://tsecurity.de/de/3685756/it-security-nachrichten/azure-devops-mcp-flaw-lets-hidden-pr-comments-hijack-ai-agents-and-steal-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685756/it-security-nachrichten/azure-devops-mcp-flaw-lets-hidden-pr-comments-hijack-ai-agents-and-steal-data/</guid>
<pubDate>Wed, 22 Jul 2026 11:11:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly disclosed flaw in Microsoft’s official Azure DevOps MCP server shows how an invisible comment in a pull request can silently hijack a developer’s AI coding assistant and turn it into a data-exfiltration tool. Security researchers at Manifold Security found that the bug lets an attacker with access to just one project steer a […]</p>
<p>The post <a href="https://cybersecuritynews.com/azure-devops-mcp-flaw/">Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Faces Lawsuit Over Hide My Email Privacy Vulnerability]]></title>
<description><![CDATA[Apple is facing a proposed class-action lawsuit after Anthony Alvarez alleged that the company’s Hide My Email feature failed to protect users’ real email addresses as advertised. The complaint, filed in the U.S. District Court for the Northern District of California, claims Apple promoted Hide M...]]></description>
<link>https://tsecurity.de/de/3685568/it-security-nachrichten/apple-faces-lawsuit-over-hide-my-email-privacy-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685568/it-security-nachrichten/apple-faces-lawsuit-over-hide-my-email-privacy-vulnerability/</guid>
<pubDate>Wed, 22 Jul 2026 09:59:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1216" height="758" src="https://thecyberexpress.com/wp-content/uploads/Hide-My-Email.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Hide My Email" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Hide-My-Email.webp 1216w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-300x187.webp 300w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-1024x638.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-768x479.webp 768w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-600x374.webp 600w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-150x94.webp 150w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-750x468.webp 750w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-1140x711.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email.webp 1216w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-300x187.webp 300w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-1024x638.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-768x479.webp 768w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-600x374.webp 600w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-150x94.webp 150w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-750x468.webp 750w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-1140x711.webp 1140w" sizes="(max-width: 1216px) 100vw, 1216px" title="Apple Faces Lawsuit Over Hide My Email Privacy Vulnerability 1"></p><span data-contrast="auto">Apple is facing a proposed class-action lawsuit after Anthony Alvarez alleged that the company’s Hide My Email feature failed to protect users’ real email addresses as advertised. The complaint, filed in the U.S. District Court for the Northern District of California, claims Apple promoted Hide My Email as a privacy safeguard while continuing to charge customers for access through its iCloud+ subscription service.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The legal action follows a report from <a href="https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/" target="_blank" rel="nofollow noopener">404 Media</a> that revealed a reported vulnerability in Hide My Email. The report claimed the flaw could allow someone to identify a user’s actual email address from the private relay address generated by the feature. According to the report, Apple had been aware of the issue for more than a year before releasing a fix.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Hide My Email Vulnerability Becomes the Focus of Apple Lawsuit</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Apple confirmed that it deployed a patch on July 3, 2026, stating that the Hide My Email <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="29072">vulnerability</a> had been fully resolved. However, the lawsuit alleges that Apple continued marketing the feature as secure while the reported weakness remained unresolved.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The complaint states that <a href="https://thecyberexpress.com/fortinet-silent-patch-raises-concern/" target="_blank" rel="noopener">security researchers</a> first informed Apple about the vulnerability in June 2025. Although Apple acknowledged the report, Anthony Alvarez’s lawsuit claims the company did not resolve the issue for nearly a year. The filing also alleges that Apple incorrectly stated in March 2026 that the problem had been fixed, even though researchers reported that the vulnerability remained exploitable.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">How Apple’s Hide My Email Feature Works</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Hide My Email was introduced with Sign in with Apple in 2019. The feature creates unique relay addresses for supported apps and websites, allowing messages to reach a user’s inbox without revealing the person’s actual email address.</span>

<span data-contrast="auto">Apple later expanded Hide My Email through the paid iCloud+ subscription, launched alongside iOS 15 and macOS Monterey in September 2021. The iCloud+ version allows subscribers to create unlimited private relay addresses for websites, newsletters and email communication.</span>

<span data-contrast="auto">The lawsuit argues that millions of <a href="https://thecyberexpress.com/apple-security-update-fixes-flaws/" target="_blank" rel="noopener">Apple</a> users relied on Hide My Email to reduce spam, limit online tracking, protect personal information from data brokers and avoid exposure during third-party data breaches. Researchers cited in the complaint said that once a real email address is revealed, it may be linked with publicly available people-search databases, potentially exposing identities and other personal information.</span>
<h3 aria-level="2"><b><span data-contrast="none">Anthony Alvarez Claims Apple Misled Customers Over Privacy</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The complaint argues that Apple built much of its brand identity around <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-privacy/" title="privacy" data-wpil-keyword-link="linked" data-wpil-monitor-id="29071">privacy</a>, referencing marketing statements such as “Privacy. That’s iPhone,” “What happens on your iPhone, stays on your iPhone,” and descriptions of privacy as a “fundamental human right” and “core value.”</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">According to the <a href="https://storage.courtlistener.com/recap/gov.uscourts.cand.474371/gov.uscourts.cand.474371.1.0.pdf" target="_blank" rel="nofollow noopener">lawsuit</a>, Apple’s privacy messaging influenced consumer decisions and helped justify premium pricing for Apple hardware and services. The plaintiffs claim Hide My Email was promoted as a central part of those privacy commitments.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The filing alleges that Apple asked researchers not to publicly disclose details of the vulnerability instead of warning customers or temporarily disabling the feature. It claims users were never informed that their real email addresses could potentially be exposed while Apple continued presenting Hide My Email as a <a href="https://thecyberexpress.com/california-france-data-privacy-protections/" target="_blank" rel="noopener">privacy protection</a> tool.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Lawsuit Seeks Damages and Changes From Apple</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Anthony Alvarez is seeking reimbursement for iCloud+ subscription fees and other alleged financial losses. The lawsuit requests an injunction requiring Apple to either provide the privacy protection promised through Hide My Email or clearly disclose any limitations.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The complaint includes claims involving California’s Unfair Competition Law, False Advertising Law and Consumers Legal Remedies Act, along with allegations of <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="29070">fraud</a>, negligent misrepresentation, breach of contract, breach of implied warranty and unjust enrichment.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The lawsuit argues customers paid for Apple’s privacy protections in multiple ways, including iCloud+ subscription fees and premium prices associated with Apple devices marketed as offering stronger <a href="https://thecyberexpress.com/ring-camera-doorbells-privacy-security-cameras/" target="_blank" rel="noopener">privacy features</a>. Apple has stated that the July 3, 2026 patch resolved the Hide My Email issue.</span><span data-ccp-props="{}"> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents]]></title>
<description><![CDATA[A single invisible comment in an Azure DevOps pull request can turn a reviewer’s own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is…
Read more →
The post Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comme...]]></description>
<link>https://tsecurity.de/de/3685430/it-security-nachrichten/microsoft-azure-devops-mcp-flaw-lets-hidden-pr-comments-hijack-ai-review-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685430/it-security-nachrichten/microsoft-azure-devops-mcp-flaw-lets-hidden-pr-comments-hijack-ai-review-agents/</guid>
<pubDate>Wed, 22 Jul 2026 08:39:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A single invisible comment in an Azure DevOps pull request can turn a reviewer’s own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/microsoft-azure-devops-mcp-flaw-lets-hidden-pr-comments-hijack-ai-review-agents/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/microsoft-azure-devops-mcp-flaw-lets-hidden-pr-comments-hijack-ai-review-agents/">Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents]]></title>
<description><![CDATA[A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds.

The flaw is in Microsoft's official Azure DevOps MCP server, and it works because one...]]></description>
<link>https://tsecurity.de/de/3685409/it-security-nachrichten/microsoft-azure-devops-mcp-flaw-lets-hidden-pr-comments-hijack-ai-review-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685409/it-security-nachrichten/microsoft-azure-devops-mcp-flaw-lets-hidden-pr-comments-hijack-ai-review-agents/</guid>
<pubDate>Wed, 22 Jul 2026 08:25:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds.

The flaw is in Microsoft's official Azure DevOps MCP server, and it works because one of its tools returns pull request descriptions without a prompt-injection guardrail the company had]]></content:encoded>
</item>
<item>
<title><![CDATA[HHS Seeks Input on CLIA Cybersecurity Updates]]></title>
<description><![CDATA[The Centers for Medicare and Medicaid Services (CMS) and the Centers for Disease Control and Prevention (CDC) have launched a request for information to modernize the Clinical Laboratory Improvement Amendments (CLIA) of 1988, with particular attention to cybersecurity and artificial…
Read more →
...]]></description>
<link>https://tsecurity.de/de/3683885/it-security-nachrichten/hhs-seeks-input-on-clia-cybersecurity-updates/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683885/it-security-nachrichten/hhs-seeks-input-on-clia-cybersecurity-updates/</guid>
<pubDate>Tue, 21 Jul 2026 15:40:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Centers for Medicare and Medicaid Services (CMS) and the Centers for Disease Control and Prevention (CDC) have launched a request for information to modernize the Clinical Laboratory Improvement Amendments (CLIA) of 1988, with particular attention to cybersecurity and artificial…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hhs-seeks-input-on-clia-cybersecurity-updates/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hhs-seeks-input-on-clia-cybersecurity-updates/">HHS Seeks Input on CLIA Cybersecurity Updates</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-37508 | HCL DevOps Plan up to 3.0.04 cross site scripting (EUVD-2023-60603)]]></title>
<description><![CDATA[A vulnerability was found in HCL DevOps Plan up to 3.0.04. It has been classified as problematic. The impacted element is an unknown function. Performing a manipulation results in cross site scripting.

This vulnerability is known as CVE-2023-37508. Remote exploitation of the attack is possible. ...]]></description>
<link>https://tsecurity.de/de/3683441/sicherheitsluecken/cve-2023-37508-hcl-devops-plan-up-to-3004-cross-site-scripting-euvd-2023-60603/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683441/sicherheitsluecken/cve-2023-37508-hcl-devops-plan-up-to-3004-cross-site-scripting-euvd-2023-60603/</guid>
<pubDate>Tue, 21 Jul 2026 12:56:10 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/hcl:devops_plan">HCL DevOps Plan up to 3.0.04</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. The impacted element is an unknown function. Performing a manipulation results in cross site scripting.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2023-37508">CVE-2023-37508</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-37507 | HCL DevOps Plan up to 3.0.04 information disclosure (EUVD-2023-60604)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in HCL DevOps Plan up to 3.0.04. This affects an unknown part. Performing a manipulation results in information disclosure.

This vulnerability is identified as CVE-2023-37507. The attack can be initiated remotely. There is not any exploit a...]]></description>
<link>https://tsecurity.de/de/3683144/sicherheitsluecken/cve-2023-37507-hcl-devops-plan-up-to-3004-information-disclosure-euvd-2023-60604/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683144/sicherheitsluecken/cve-2023-37507-hcl-devops-plan-up-to-3004-information-disclosure-euvd-2023-60604/</guid>
<pubDate>Tue, 21 Jul 2026 11:12:17 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/hcl:devops_plan">HCL DevOps Plan up to 3.0.04</a>. This affects an unknown part. Performing a manipulation results in information disclosure.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2023-37507">CVE-2023-37507</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI impacts site reliability engineering]]></title>
<description><![CDATA[Site reliability engineers (SREs) have the tough assignment of resolving thorny performance and reliability issues. But their primary mission is to provide devops teams with operational insights and to suggest implementation improvements on business system performance, security, and overall robus...]]></description>
<link>https://tsecurity.de/de/3683121/ai-nachrichten/how-ai-impacts-site-reliability-engineering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683121/ai-nachrichten/how-ai-impacts-site-reliability-engineering/</guid>
<pubDate>Tue, 21 Jul 2026 11:05:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Site reliability engineers (SREs) have the tough assignment of resolving thorny performance and reliability issues. But their primary mission is to provide devops teams with operational insights and to suggest implementation improvements on business system performance, security, and overall robustness.</p>



<p class="wp-block-paragraph">Google introduced its <a href="https://sre.google/sre-book/part-I-introduction/">SRE playbook</a> in 2003, but it took some time for the role’s definition, tools, and techniques to become mainstream. Startups were the first to adopt observability for cloud-native applications and create dedicated SRE positions. As tools matured and SRE responsibilities became more clearly defined, larger enterprises assigned SREs to work as a bridge between devops and IT ops teams to improve resilience across a wider range of applications, APIs, and <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">data pipelines</a>.</p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/3689881/career-paths-for-devops-engineers-and-sres.html">SRE is a career path</a> for multidisciplinary engineers with strong investigative instincts, sharp data analytics skills, and the temperament to perform under pressure. It has become a critical responsibility as tech became mission-critical for enterprises, and it is <a href="https://drive.starcio.com/2025/02/emerging-genai-roles-hr-tech-security/">a growing role in the genAI era</a> as more businesses <a href="https://drive.starcio.com/2025/10/ai-agents-definitive-guide-saas-security-titans/">deploy AI agents</a>.</p>



<p class="wp-block-paragraph">But the critical need for resiliency and greater technological complexity brings new challenges for SREs. According to the <a href="https://neubird.ai/resources/state-of-production-reliability-and-ai-adoption/">2026 State of Production Reliability and AI Adoption report</a>, 44% of respondents experienced an outage linked to ignored or suppressed alerts in the past year, and 35% report their engineers occasionally ignore or dismiss alerts due to alert fatigue. More than 70% of alerts received are not actionable, according to 57% of organizations.</p>



<p class="wp-block-paragraph">So, is AI making the SRE’s role easier and helping businesses run more reliable technology operations? On the other hand, AI is also driving complexity, as companies deploy genAI tools and AI agents across more business functions and seek to automate more decision-making across operations.</p>



<h2 class="wp-block-heading">AIops and agentic ops aid SREs</h2>



<p class="wp-block-paragraph">Over the past decade, SRE responsibilities have become somewhat easier through improvements in <a href="https://www.infoworld.com/article/2263821/5-devops-practices-to-improve-application-reliability.html">monitoring platforms</a>, <a href="https://www.infoworld.com/article/3686056/best-practices-for-devops-observability.html">observability practices</a>, <a href="https://www.infoworld.com/article/2261769/what-is-the-ai-in-aiops.html">tools for centralizing operational data</a>, and <a href="https://drive.starcio.com/2022/01/aiops-cio/">AI applied in IT operations</a> (AIops). But during the heat of resolving an outage or performance issue, it’s not easy to correctly identify what system triggered the issue versus other downstream systems impacted by it.</p>



<p class="wp-block-paragraph">According to the <a href="https://komodor.com/resources/komodor-2025-enterprise-kubernetes-report/">Komodore 2025 Enterprise Kubernetes Report</a>, 79% of production incidents originate from recent system changes, including deployments and changes to compute environments. But the other 21% of incidents stem from issues outside of the business’s control, including network failures, third-party changes, and cloud provider failures.</p>



<p class="wp-block-paragraph">“SREs using AI capabilities succeed or fail in the moment an incident unfolds, when engineers are deciding what to investigate next,” says Itiel Shwartz, CTO at <a href="https://komodor.com/">Komodor</a>. “If the system streamlines root cause detection, connects signals to recent changes, and explains its reasoning in a way engineers recognize, it earns trust. If it adds uncertainty or demands extra validation, it gets sidelined, regardless of how bespoke the model behind it may be. What’s less obvious is what it takes to make AI for SREs work in production, and how different that reality is from prototypes, demos, or early internal builds.”</p>



<p class="wp-block-paragraph"><a href="https://drive.starcio.com/2022/05/aiops-ml-multicloud/">AIops</a> is not a new capability, especially in using machine learning to correlate logs, metrics, and traces across monitoring and alerting systems. IT service management and SREs have been using AIops to <a href="https://drive.starcio.com/2021/11/p1-incidents-long-resolution-times/">reduce the mean time to resolve incidents</a> and to perform accurate <a href="https://drive.starcio.com/2021/12/kpi-agile-devops-itops/">root cause analysis</a> (RCA) efficiently. <a href="https://www.infoworld.com/article/4100507/5-key-agenticops-practices-to-start-building-now.html">Agentic ops</a> is the next wave of genAI operational capabilities, including tools for monitoring AI agents, managing their access rights, and detecting AI model accuracy drift.</p>



<p class="wp-block-paragraph"> “AI is useful during major incidents because it can pull together a lot of context into a few clear sentences, which is exactly what an SRE needs in the moment,” suggests Shani Shoham, chief revenue officer at <a href="https://openobserve.ai/">OpenObserve</a>. “The complexity of architecture and the different tooling make it easier for AI than for a human, but autonomous resolution is still a way off.”</p>



<h2 class="wp-block-heading">AI’s impact on people and burnout</h2>



<p class="wp-block-paragraph">The business pressure to keep systems up, secure, and performing well is a 24/7 stressful responsibility. According to <a href="https://www.catchpoint.com/learn/sre-report-2025">The SRE Report 2025</a> from Catchpoint, 36% of SREs often or always experience elevated stress during an incident, and 28% said the stress persists even after the incident is resolved. AI capabilities may prove to be a game-changer in helping SREs avoid burnout and reduce stress.</p>



<p class="wp-block-paragraph">“AI can improve RCA by taking in a much larger incident context than any engineer can hold at 3am, reasoning across traces, logs, metrics, deploys, config changes, alerts, ownership, and recent production behavior,” says Noam Levy, founding engineer and field CTO at <a href="https://www.groundcover.com/">Groundcover</a>. “Beyond attempting a full RCA, its immediate value is distilling the signals that actually matter, reconstructing a clear timeline of cause and effect, and helping engineers separate correlation from likely causality. Once a fix is deployed, agents can also verify remediation by comparing pre- and post-fix behavior, but this depends on broad access to rich, correlated production signals and a cost model that does not discourage adoption or experimentation.”</p>



<p class="wp-block-paragraph">Not only are incidents resolved faster and with less stress, but AI can also free up SRE time to focus on proactive work and create a career path for junior developers into SRE roles. Quais Taraki, CTO at <a href="https://www.enterprisedb.com/">EDB Postgres AI</a>, adds, “AI reduces toil by automating repetitive tasks while accelerating incident resolution through copilots that correlate signals across distributed systems, allowing SREs to focus more on resilience strategies like chaos engineering and failure analysis.”</p>



<p class="wp-block-paragraph">AI can have long-lasting operational impacts, especially for organizations looking to deploy more mission-critical technology and AI capabilities. Two longer-term benefits of AI for SREs are reducing the number of bridge calls needed for incident response and the number of engineers required in “<a href="https://drive.starcio.com/2021/04/it-digital-operations-aiops/">war rooms</a>” to coordinate root cause analyses.</p>



<p class="wp-block-paragraph">“When something goes wrong, AI that guides SREs can do the full analysis, get to the root cause, and perform the remediation,” says Spiros Xanthos, founder and CEO of <a href="https://resolve.ai/">Resolve AI</a>. “AI also helps avoid many escalations, and when escalations are needed, it targets the right people from the network, infrastructure, and the application teams. AI for SREs centralizes operational intelligence, exposes tribal knowledge, and can guide more junior developers.” </p>



<h2 class="wp-block-heading">AI agent reliability</h2>



<p class="wp-block-paragraph">While AI capabilities have been a net positive in helping SREs improve system reliability, the growth of <a href="https://www.infoworld.com/article/4032989/a-developers-guide-to-code-generation.html">AI code generators</a>, <a href="https://www.infoworld.com/article/4058076/vibe-coding-and-the-future-of-software-development.html">vibe coding</a>, and <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development.html">spec-driven development</a> is adding to their workloads. <a href="https://www.braiviq.com/blog/vibe-coding-ai-development-2026-cursor-copilot-claude-code">According to one study</a>, 41% of all global code is now AI-generated, and <a href="https://www.hostinger.com/blog/vibe-coding-statistics">Gartner predicts</a> that 40% of new enterprise production software will be created using vibe coding techniques by 2028.</p>



<p class="wp-block-paragraph">But coding velocity is creating new issues for SREs as AI pull requests have 1.4 times more critical issues and 1.7 times more major issues, <a href="https://www.coderabbit.ai/blog/state-of-ai-vs-human-code-generation-report">according to CodeRabbit</a>. “AI-assisted development has created an unprecedented velocity of code reaching production, expanding surface area, edge cases, and failure rates faster than traditional SRE practices can absorb,” says Vinod Jayaraman, cofounder and CTO at <a href="https://neubird.ai/">NeuBird AI</a>. “The speed of shipping has far outpaced the speed of understanding what breaks in production. To close this loop, SREs need enterprise agents that can capture precise diagnostic context, including correlated traces, service dependencies, and anomaly timelines, and structure it as actionable input for the engineers and AI coding tools responsible for the fix.”</p>



<p class="wp-block-paragraph">The growing number of AI agents deployed to production creates new challenges. AI agents are not just code; they have multiple failure points. They are built using language models, connect to proprietary sources for context, and integrate with <a href="https://www.infoworld.com/article/4124612/5-requirements-for-using-mcp-servers-to-connect-ai-agents.html">Model Context Protocol servers</a> to support more complex workflows. Changes are ongoing and not deployment events, so the SRE’s job of identifying the source of performance and accuracy drifts isn’t trivial. </p>



<p class="wp-block-paragraph">“Traditional SRE was built for systems that fail in reproducible ways, but agents fail differently and drift when a model provider pushes an update, and behavior shifts silently with no baseline for comparison,” says Mohammed Aboul-Magd, vice president of product at <a href="https://www.sandboxaq.com/">SandboxAQ</a>. “Most organizations can’t even answer the basics: how many agents are running, what they have access to, and whether they’re still doing what they were built to do.”</p>



<p class="wp-block-paragraph">“Every time a senior engineer leaves, they take years of learned failure patterns with them, and the next outage starts from square one,” adds Ronak Desai, cofounder and CEO at <a href="https://ciroos.ai/">Ciroos</a>. “Using AI for compounding operational memory changes that, and every incident your system resolves, the AI learns it.”</p>



<p class="wp-block-paragraph">SREs should take a leadership role in emerging best practices, including defining their standards for AI agent <a href="https://www.infoworld.com/article/4061123/how-to-write-nonfunctional-requirements-for-ai-agents.html">non-functional acceptance criteria</a>, <a href="https://www.infoworld.com/article/4140832/7-safeguards-for-observable-ai-agents.html">observability practices</a>, and <a href="https://www.infoworld.com/article/4105884/10-essential-release-criteria-for-launching-ai-agents.html">release-readiness criteria</a>. SREs should update their <a href="https://www.infoworld.com/article/3684268/tools-to-manage-slos-and-error-budgets.html">service-level objectives</a> (SLOs) and define error budgets for AI agents in production.</p>



<p class="wp-block-paragraph">Ryan Downing, vice president and CIO of enterprise business solutions at <a href="https://www.principal.com/">Principal Financial Group</a>, says, “Standard SLOs and error budgets give teams the guardrails, and AI helps interpret the telemetry against those targets, reducing noise so engineers can get to the real issue faster and automate parts of remediation before customers are impacted.”</p>



<h2 class="wp-block-heading">AI raises the SRE’s business impact</h2>



<p class="wp-block-paragraph">The more dramatic shift in site reliability engineering is an evolution of its business scope. IT leaders focus on uptime, performance, and issue resolution, as well as understanding their impacts. Business leaders will look to IT and SREs to identify, determine root cause, and remediate a broader class of issues, including <a href="https://drive.starcio.com/2025/07/rogue-ai-agents-cios-govern-agentic-ecosystem/">rogue AI agents</a> and the impacts of <a href="https://www.infoworld.com/article/4040513/how-to-avoid-the-risks-of-rapidly-deploying-ai-agents.html">rapidly deploying new agentic capabilities</a>. </p>



<p class="wp-block-paragraph">“AI agents are handing SREs categories of problems they’ve never had to solve before, specifically failures defined in business terms, not technical ones,” says Blake Sherwood, distinguished technologist for AI and platform strategy at <a href="https://www.smarsh.com/">Smarsh</a>. “Traditional reliability engineering is built around latency, errors, and crashes, but agents now fail due to skipped compliance steps or outcomes that looked fine technically but were wrong contextually. Most SRE teams aren’t wired for that yet.”</p>



<p class="wp-block-paragraph">The question is whether SREs with AI-augmented tools can keep up with the velocity, complexity, and business urgency of deploying new AI business capabilities.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Sends Letters To Dozens Of OpenAI Staff Amid Legal Claims]]></title>
<description><![CDATA[Apple reportedly sends letters directly to dozens of former employees now working at OpenAI, as it seeks preservation of data This article has been indexed from Silicon UK Read the original article: Apple Sends Letters To Dozens Of OpenAI Staff…
Read more →
The post Apple Sends Letters To Dozens ...]]></description>
<link>https://tsecurity.de/de/3683042/it-security-nachrichten/apple-sends-letters-to-dozens-of-openai-staff-amid-legal-claims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683042/it-security-nachrichten/apple-sends-letters-to-dozens-of-openai-staff-amid-legal-claims/</guid>
<pubDate>Tue, 21 Jul 2026 10:38:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple reportedly sends letters directly to dozens of former employees now working at OpenAI, as it seeks preservation of data This article has been indexed from Silicon UK Read the original article: Apple Sends Letters To Dozens Of OpenAI Staff…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/apple-sends-letters-to-dozens-of-openai-staff-amid-legal-claims/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/apple-sends-letters-to-dozens-of-openai-staff-amid-legal-claims/">Apple Sends Letters To Dozens Of OpenAI Staff Amid Legal Claims</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google’s Next-Gen Gemini Delayed Over Coding Disappointment]]></title>
<description><![CDATA[Gemini 3.5 reportedly months behind schedule as Google seeks to improve coding performance to compete with Anthropic, OpenAI This article has been indexed from Silicon UK Read the original article: Google’s Next-Gen Gemini Delayed Over Coding Disappointment
Read more →
The post Google’s Next-Gen ...]]></description>
<link>https://tsecurity.de/de/3680522/it-security-nachrichten/googles-next-gen-gemini-delayed-over-coding-disappointment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680522/it-security-nachrichten/googles-next-gen-gemini-delayed-over-coding-disappointment/</guid>
<pubDate>Mon, 20 Jul 2026 09:54:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Gemini 3.5 reportedly months behind schedule as Google seeks to improve coding performance to compete with Anthropic, OpenAI This article has been indexed from Silicon UK Read the original article: Google’s Next-Gen Gemini Delayed Over Coding Disappointment</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/googles-next-gen-gemini-delayed-over-coding-disappointment/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/googles-next-gen-gemini-delayed-over-coding-disappointment/">Google’s Next-Gen Gemini Delayed Over Coding Disappointment</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[eCPPTv3 Review]]></title>
<description><![CDATA[Almost a year ago, I took the INE’s “eCPPTv3” exam, and here is my honest reviewWhy eCPPT?A year ago (May 29) I’ve bought the bundle which included 3 months of premium subscription and 2 exam attempts, thankfully a single attempt was enough for me. Back then I wasn’t really familiar with HackTheB...]]></description>
<link>https://tsecurity.de/de/3677786/hacking/ecpptv3-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677786/hacking/ecpptv3-review/</guid>
<pubDate>Sat, 18 Jul 2026 11:39:20 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Almost a year ago, I took the INE’s “eCPPTv3” exam, and here is my honest review</p><p><strong>Why eCPPT?<br></strong>A year ago (May 29) I’ve bought the bundle which included 3 months of premium subscription and 2 exam attempts, thankfully a single attempt was enough for me. Back then I wasn’t really familiar with HackTheBox, so I chose eCPPT. Now, comparing the eCPPT and CPTS exams and paths, I’d advise you to choose CPTS instead.</p><p><strong>Path: <br></strong>The path is enough to pass the exam I believe, and there is even some extra material included in the path, like the C2 module. By the way, if you have finished eJPT/eWPT, some modules (very few) might be repeated in the eCPPTv3 path. Then, there are some modules that you don’t get in the exam, e.g. the macros development part. One thing I liked a lot about the path was that most of the material is videos, and labs/skill assessments are included as well, as I am both visual and practical learner I just loved most of the path.</p><ul><li>Tip: All of the techniques you will encounter in the exam were explained in the course itself, nothing out of it — whether it’s priv.esc, brute-force, or lateral movement.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/480/1*xntBZJU8G6rhWrye9YkPYQ.png"><figcaption>Preview</figcaption></figure><p><strong>Preparation</strong>:<br>Unlike HTB, here you can start the exam any time you want, you are not required to finish the path 100% before you start the exam, which I believe is actually a huge advantage (not always though). <strong>Before you start the exam</strong>, I’d advise you to finish the following modules and be comfortable with solving the labs and CTF challenges at the end of them:</p><ul><li>PowerShell for Pentesters</li><li>Web Application Penetration Testing</li><li>Network Penetration Testing</li><li>Privilege Escalation (get really comfortable with this one)</li><li>Active Directory Penetration Testing</li></ul><p>Then, one more hint I’d give is to <strong>get extremely comfortable with brute-forcing and lateral-movement</strong>. Be patient, and don’t break under pressure — the exam is only 24 hours and expect brute forces take anywhere from seconds to 2 hours, like for real, don’t rush — sometimes you might wait 30 minutes for your brute-force to finish, and since there is such limited time, it can get heavy mentally — be ready for it, don’t panic.</p><p><strong>Exam:</strong><br>This exam was no joke — brute-force, lateral movement, AD systems, privilege escalation, web, and it keeps testing you until you get to the passing point. Since I was taking this exam a year ago, there was a problem with WinRM, which I fixed using this reddit post:<br><a href="https://www.reddit.com/r/eLearnSecurity/comments/1hpsfo2/ecppt_exam_evilwinrm_workaround/">https://www.reddit.com/r/eLearnSecurity/comments/1hpsfo2/ecppt_exam_evilwinrm_workaround/</a>. Furthermore, make sure you have organized notes on techniques and commands, tools, etc. that you covered in the course, especially from the AD, LM, PowerShell, and PrivEsc modules. One huge thing the eCPPTv3 lacks is the report — it’s “competitors” — OSCP, CPTS both require you to write a professional grade report, whereas in eCPPTv3 the report was for some reason removed.</p><p><strong>One word of advise:<br></strong>If you are wondering should you take eCPPT over CPTS, I would not advise you to take CPTS over eCPPT. Why? Because I believe that CPTS’ path is more modern when it comes to exploitation, and more hands-on, and, I believe that it’s harder than eCPPT as well, and finally CPTS costs a bit less and one huge W for HTB is that they’ve got a student subscription, which, unfortunately INE does not — but remember that CPTS and eCPPT exams differ a bit, in eCPPT all you got is 24 hours of intentse hacking with no report, while in CPTS it’s 10 days.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/669/0*Skrk17xFYS8jwh7R"><figcaption>eCPPTv3 Certified</figcaption></figure><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=522cf02bf996" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/ecpptv3-review-522cf02bf996">eCPPTv3 Review</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Funded a Stranger’s Bank Card With My Own Money; and That’s Exactly the Problem]]></title>
<description><![CDATA[A hands-on walkthrough of Broken Object Level Authorization (BOLA) on VulnBankVulnBankThere’s a moment in every appsec learner’s journey where a vulnerability stops being a bullet point on the OWASP API Top 10 and starts being something you actually did. For me, that moment was watching one user’...]]></description>
<link>https://tsecurity.de/de/3677763/hacking/i-funded-a-strangers-bank-card-with-my-own-money-and-thats-exactly-the-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677763/hacking/i-funded-a-strangers-bank-card-with-my-own-money-and-thats-exactly-the-problem/</guid>
<pubDate>Sat, 18 Jul 2026 11:21:50 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>A hands-on walkthrough of Broken Object Level Authorization (BOLA) on VulnBank</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mTehjKwtISkTLR8KwRRrRw.png"><figcaption>VulnBank</figcaption></figure><p>There’s a moment in every appsec learner’s journey where a vulnerability stops being a bullet point on the OWASP API Top 10 and starts being something you actually <em>did</em>. For me, that moment was watching one user’s card get funded by another user’s session — no exploit chain, no payload, just a number in a URL that should never have worked.</p><p>This is the walkthrough of how I found (and rigorously confirmed) a Broken Object Level Authorization vulnerability in <strong>VulnBank</strong>, an intentionally vulnerable banking application built for security training.</p><h3>What Is BOLA, Actually?</h3><p>Broken Object Level Authorization sits at <strong>#1 </strong>on the <strong>OWASP API Security Top 10 </strong>(API 1: 2023), and for good reason — it’s common, trivial to exploit, and quietly devastating.</p><p>The core idea in one sentence: <strong>the server correctly checks who you are, but never checks what you’re allowed to touch.</strong></p><p>Any API endpoint that takes an object identifier — a <strong>card_id</strong>, <strong>account_number</strong>, <strong>order_id </strong>— needs to answer two separate questions:</p><ol><li><strong>Authentication: </strong>is this a valid, logged-in user?</li><li><strong>Authorization: </strong>should <em>this </em><strong><em>specific user</em> </strong>be allowed to access <em>this specific object</em>?</li></ol><p>BOLA is what happens when an API nails question one and skips question two entirely. Usually it’s one missing clause in a query.</p><p>The vulnerable version:</p><pre>SELECT * FROM cards WHERE id = :card_id</pre><p>The fixed version:</p><pre>SELECT * FROM cards WHERE id = :card_id AND user_id = :authenticated_user_id</pre><p>That’s genuinely the whole difference and because it never breaks anything during normal use (your own IDs always belong to you), it hides in plain sight until someone deliberately tries an ID that isn’t theirs.</p><p>So that’s exactly what I did — with two accounts, on purpose, so I could prove it beyond doubt rather than just suspect it.</p><h3>Setting the Stage: Two Users, Two Cards</h3><p>Testing BOLA against yourself proves nothing — you always have legitimate access to your own resources. So I set up two separate accounts to simulate a real attacker/victim scenario.</p><h3><strong>User 1 — Jhonny</strong></h3><ul><li>I created a virtual card with a <strong>$2,500 </strong>limit.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/671/1*IzNdvQ1HNkbGSk9AEz70FQ.png"><figcaption>Jhonny’s Virtual Card</figcaption></figure><ul><li>I then funded it with <strong>$80 </strong>from the main balance.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/444/1*yyZLbn89enTTeEBs4gSKow.png"><figcaption>Funding the card</figcaption></figure><p>With the funding request captured in <strong>Burp Suite</strong>, I sent it to Repeater for closer inspection, this is the request whose <strong>card_id </strong>parameter would become the centerpiece of the whole test.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*EKOsjOROq-GWkyoTOSyHNw.png"><figcaption>Jhonny Card Request in Burp</figcaption></figure><h3><strong>User 2 — Alex</strong></h3><p>Same setup:</p><ul><li>A fresh virtual card of <strong>$2,500 </strong>limit.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/411/1*A-bryCWIEKgcBWvJSyHgGQ.png"><figcaption>Alex’s Virtual Card</figcaption></figure><ul><li>Funded with $100.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/697/1*H-zuUIktIse3J_FkKY4iRg.png"><figcaption>Funding Alex’s card</figcaption></figure><ul><li>And the same treatment — captured the request and sent it to Repeater.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MhtrbarCUBXaggWB7u-YBw.png"><figcaption>Alex’s Card Request in Burp</figcaption></figure><p>Two accounts, two cards, two independent funding requests sitting side by side. Now the real test could begin.</p><h3>Step One: Does the App Even Check Who You Are?</h3><p>Before hunting for authorization flaws, I checked the basics. I stripped the session cookie and Authorization header from a funding request entirely and sent it.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*SkZ3P_vd-a31Bxve6I1kMw.png"><figcaption>Token error (Authentication enabled)</figcaption></figure><p><strong>401 Unauthorized: "Token is missing."</strong></p><p>Good! The server clearly enforces authentication. That ruled out the simplest failure mode and pointed straight at the real question: does it check <strong><em>which</em> </strong>authenticated user is making the request, or just <strong><em>that</em> </strong>one is?</p><h3>Step Two: The Swap</h3><p>This is the actual test, and it’s almost anticlimactic in how simple it is.</p><p>I took <strong>Jhonny’s</strong> valid token and used it to fund <strong>Alex’s</strong> card:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pM9M7X-q1bMfJng1TcsNqA.png"><figcaption>Funding Alex’s card with Jhonny’s Token</figcaption></figure><p><strong>200 OK.</strong> The card funded successfully with Jhonny's session authorizing a change to Alex's card.</p><p>Then I reversed it, <strong>Alex’s</strong> token, aimed at <strong>Jhonny’s</strong> card:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-5Qqk7A4XKvrvCkqyXgRFQ.png"><figcaption>Funding Jhonny’s card with Alex’s Token</figcaption></figure><p><strong>200 OK</strong> again. Same result, opposite direction.</p><p>Neither request was rejected. The server verified that a valid token was present but never verified that the token holder actually owned the card they were funding. It simply processed whatever <strong>card_id </strong>showed up in the URL, against whichever authenticated user happened to be making the call.</p><h3>Why This Isn’t “Just a Feature”</h3><p>The first pushback any BOLA finding gets is: <strong><em>“Couldn’t this just be an intentional transfer feature?”</em></strong></p><p>It’s a fair question, and worth addressing directly.</p><p>The answer is <strong>NO</strong>, for a few concrete reasons:</p><ul><li>There was no recipient search, no username/email lookup, no way to intentionally select another user through the interface.</li><li>Neither Jhonny nor Alex received any notification or gave any consent.</li><li>The card IDs used were never exposed to either user by the application itself, they were reached only by directly editing a request in Burp, not by anything the UI ever presented as selectable.</li><li>Both requests used each user’s <em>own</em> main balance and <em>own</em> token throughout, nothing about the flow resembled a designed transfer mechanism.</li></ul><p>A designed feature has guardrails: consent steps, recipient verification, fraud checks. This had none of that, because it was never meant to be reachable in the first place.</p><h3>The Fix</h3><p>The remediation here is almost anticlimactic given the impact. This isn’t a hard problem to solve, just an easy one to forget:</p><ul><li>Every object-level query needs an explicit ownership check tied to the authenticated session: <strong>WHERE card_id = ? AND user_id = ?</strong></li><li>Better yet, enforce this centrally, an authorization layer or middleware that every object-fetching endpoint routes through, rather than relying on each developer to remember it per-endpoint</li><li>Make cross-account testing a standard part of QA and code review: test with <strong>two different authenticated accounts</strong> against each other’s objects, not just each account against its own.</li></ul><h3>The Takeaway</h3><p>BOLA doesn’t require exotic tooling or deep exploit development. It requires one thing: noticing that an ID in a URL is just a number, and asking whether the server actually checked if you were allowed to use it.</p><p>In this case, it hadn’t. Two independent accounts, each fully authenticated, could reach into each other’s resources without so much as a warning.</p><p>Authentication tells a server <em>who</em> is asking. Authorization is the separate and often forgotten question of <strong><em>what they’re allowed to ask for?</em></strong>. Every API needs both, and it’s worth checking, endpoint by endpoint, that yours actually has them.</p><p><em>This testing was performed against VulnBank, an intentionally vulnerable application built for security education and training purposes.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=a3bfc069a8b9" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/i-funded-a-strangers-bank-card-with-my-own-money-and-that-s-exactly-the-problem-a3bfc069a8b9">I Funded a Stranger’s Bank Card With My Own Money; and That’s Exactly the Problem</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TRAI Seeks IT Act Powers to Act Against Spam-Tagging Apps Like Truecaller]]></title>
<description><![CDATA[  The Telecom Regulatory Authority of India (TRAI) seeks new powers in the Information Technology (IT) Act to take action against call management apps, including Truecaller, Hiya, and Whoscall, for marking or blocking legitimate commercial calls as spam. The regulator…
Read more →
The post TRAI S...]]></description>
<link>https://tsecurity.de/de/3676671/it-security-nachrichten/trai-seeks-it-act-powers-to-act-against-spam-tagging-apps-like-truecaller/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676671/it-security-nachrichten/trai-seeks-it-act-powers-to-act-against-spam-tagging-apps-like-truecaller/</guid>
<pubDate>Fri, 17 Jul 2026 19:25:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  The Telecom Regulatory Authority of India (TRAI) seeks new powers in the Information Technology (IT) Act to take action against call management apps, including Truecaller, Hiya, and Whoscall, for marking or blocking legitimate commercial calls as spam. The regulator…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/trai-seeks-it-act-powers-to-act-against-spam-tagging-apps-like-truecaller/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/trai-seeks-it-act-powers-to-act-against-spam-tagging-apps-like-truecaller/">TRAI Seeks IT Act Powers to Act Against Spam-Tagging Apps Like Truecaller</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepSeek weighs new fundraising a month after closing first round]]></title>
<description><![CDATA[Unusually swift pace of capital injection comes as Chinese AI start-up seeks to build out infrastructure]]></description>
<link>https://tsecurity.de/de/3676201/ai-nachrichten/deepseek-weighs-new-fundraising-a-month-after-closing-first-round/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676201/ai-nachrichten/deepseek-weighs-new-fundraising-a-month-after-closing-first-round/</guid>
<pubDate>Fri, 17 Jul 2026 15:33:59 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Unusually swift pace of capital injection comes as Chinese AI start-up seeks to build out infrastructure]]></content:encoded>
</item>
<item>
<title><![CDATA[Eine Wirtschaft ganz ohne Gold: Wie das Tauschsystem in Online-Spielen funktioniert]]></title>
<description><![CDATA[Die meisten Online-Spiele funktionieren nach demselben Prinzip: Man sammelt Gold,
The post Eine Wirtschaft ganz ohne Gold: Wie das Tauschsystem in Online-Spielen funktioniert first appeared on IT-LEARNER.]]></description>
<link>https://tsecurity.de/de/3675339/it-nachrichten/eine-wirtschaft-ganz-ohne-gold-wie-das-tauschsystem-in-online-spielen-funktioniert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675339/it-nachrichten/eine-wirtschaft-ganz-ohne-gold-wie-das-tauschsystem-in-online-spielen-funktioniert/</guid>
<pubDate>Fri, 17 Jul 2026 09:18:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Die meisten Online-Spiele funktionieren nach demselben Prinzip: Man sammelt Gold,</p>
<p>The post <a rel="nofollow" href="https://it-learner.de/eine-wirtschaft-ganz-ohne-gold-wie-das-tauschsystem-in-online-spielen-funktioniert/">Eine Wirtschaft ganz ohne Gold: Wie das Tauschsystem in Online-Spielen funktioniert</a> first appeared on <a rel="nofollow" href="https://it-learner.de/">IT-LEARNER</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hide My Email class action lawsuit seeks payout without evidence of any attacks]]></title>
<description><![CDATA[A proposed class action is trying to turn Apple's unresolved Hide My Email flaw into a nationwide payout without alleging that the vulnerability was used in an attack or that the plaintiff's email address was exposed.Apple's Hide My Email serviceAnthony Alvarez filed the lawsuit against Apple on ...]]></description>
<link>https://tsecurity.de/de/3674409/ios-mac-os/hide-my-email-class-action-lawsuit-seeks-payout-without-evidence-of-any-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674409/ios-mac-os/hide-my-email-class-action-lawsuit-seeks-payout-without-evidence-of-any-attacks/</guid>
<pubDate>Thu, 16 Jul 2026 20:39:27 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A proposed class action is trying to turn Apple's unresolved Hide My Email flaw into a nationwide payout without alleging that the vulnerability was used in an attack or that the plaintiff's email address was exposed.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68269-143900-967A61C1-FA5C-4CF0-9182-D26130A192AD-xl.jpg" alt="iPhone screen on Hide my email setup page, showing a generated iCloud email address, a text field labeled Test being edited, and part of the keyboard, resting on brown leather surface" height="738"><span>Apple's Hide My Email service</span></div><br>Anthony Alvarez filed the lawsuit against Apple on July 15 in the U.S. District Court for the Northern District of California. The complaint accuses the company of false advertising, fraud, breach of contract, and other violations tied to its marketing of Hide My Email.<br><br>The filing argues that Apple sold customers privacy it couldn't provide. The claims cover the full version included with paid <a href="https://appleinsider.com/inside/icloud" title="iCloud" data-kpt="1">iCloud</a>+ plans and the more limited relay addresses generated through Sign in with Apple.<br><br>Alvarez seeks to represent four proposed classes covering U.S. Apple customers, including two California subclasses. The lawsuit seeks damages and an order requiring Apple to fix Hide My Email or clearly disclose its limitations.<br><br><br> <a href="https://appleinsider.com/articles/26/07/16/hide-my-email-class-action-lawsuit-seeks-payout-without-evidence-of-any-attacks?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244975?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your Agent Trusts That Wiki. Should It?]]></title>
<description><![CDATA[We were building a DevOps agent to help with on-call remediation. The idea was straightforward: when an incident fires, the agent reads the relevant runbook from our internal wiki, assesses the situation, and executes the appropriate remediation steps. No waiting…
Read more →
The post Your Agent ...]]></description>
<link>https://tsecurity.de/de/3673815/it-security-nachrichten/your-agent-trusts-that-wiki-should-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673815/it-security-nachrichten/your-agent-trusts-that-wiki-should-it/</guid>
<pubDate>Thu, 16 Jul 2026 16:37:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>We were building a DevOps agent to help with on-call remediation. The idea was straightforward: when an incident fires, the agent reads the relevant runbook from our internal wiki, assesses the situation, and executes the appropriate remediation steps. No waiting…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/your-agent-trusts-that-wiki-should-it/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/your-agent-trusts-that-wiki-should-it/">Your Agent Trusts That Wiki. Should It?</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepMind CEO pushes for AI industry self-regulation]]></title>
<description><![CDATA[Google DeepMind CEO Demis Hassabis is pushing for the US AI industry to self-regulate, with the support of government, as a starting point for an international creating shared international standards. In a blog post, he called for a focus on artificial general intelligence (AGI) and national secu...]]></description>
<link>https://tsecurity.de/de/3673460/it-nachrichten/deepmind-ceo-pushes-for-ai-industry-self-regulation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673460/it-nachrichten/deepmind-ceo-pushes-for-ai-industry-self-regulation/</guid>
<pubDate>Thu, 16 Jul 2026 14:33:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google DeepMind CEO Demis Hassabis is pushing for the US AI industry to self-regulate, with the support of government, as a starting point for an international creating shared international standards. In a blog post, he called for a focus on <a href="https://www.computerworld.com/article/4174181/google-talks-singularity-while-scaling-up-agentic-ai-for-enterprises-2.html">artificial general intelligence (AGI)</a> and national security. </p>



<p class="wp-block-paragraph">But it is precisely that focus on national security that may make the results of such an effort, assuming it happens, less than palatable outside of the US.</p>



<p class="wp-block-paragraph">“The rapid progress we’re seeing in AI requires a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous,” <a href="https://demishassabis.substack.com/p/a-framework-for-frontier-ai-and-the-dawning-of-a-new-age" target="_blank" rel="noreferrer noopener">Hassabis wrote</a>. “The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.”</p>



<p class="wp-block-paragraph">He noted, however, that the funding would need to be substantial, and would most likely come from industry, to allow the new body to attract world-class technical talent and obtain the necessary compute resources for large-scale testing.</p>



<p class="wp-block-paragraph">Hassabis proposed that the organization “be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security,” and that AI vendor participants be encouraged to adopt best practices such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research.</p>



<p class="wp-block-paragraph">This is not the first time Hassabis has <a href="https://www.computerworld.com/article/4178398/deepmind-ceo-agi-could-be-here-in-three-years.html" target="_blank">expressed worries about AGI</a>. </p>



<p class="wp-block-paragraph">DeepMind was involved in an earlier <a href="https://www.cio.com/article/4168122/us-government-agency-to-safety-test-frontier-ai-models-before-release.html" target="_blank">US government initiative evaluating AI safety</a>, alongside Microsoft and xAI (now SpaceXAI) working with the Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce. It allowed CAISI to conduct pre-deployment evaluations and targeted research to “better assess frontier AI capabilities and advance the state of AI security.”  </p>



<h2 class="wp-block-heading">The rest of the world may have concerns</h2>



<p class="wp-block-paragraph">Analysts and consultants were mixed about the move, with most expressing concerns about whether an industry-focused group would prioritize the public’s best interests.</p>



<p class="wp-block-paragraph">“Self-regulation is not viable because it implies everyone is able to regulate themselves and will do so in line with the best interests of the public. Most tech vendors don’t have the capacity to self-regulate. They would just prefer a set of rules within which they can operate,” said Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>. “For-profit organizations are required to do what is best for their shareholders, and external regulation ensures that those organizations are never in a conflict of interest where they have to choose between what is good for their shareholders and what is good for the public.”</p>



<p class="wp-block-paragraph">And, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, given the international nature of AI models, an effort coordinated by the US government might alienate other countries. </p>



<p class="wp-block-paragraph">“National security is the proposal’s accelerator in Washington and its poison pill abroad: the framing that opens the only gate available at home invites foreign capitals to read the institution as an instrument of American strategy,” he pointed out. </p>



<p class="wp-block-paragraph">“The map is already plural,” he said. “Brussels switches on enforcement powers over general-purpose models [starting in August 2026], London runs the AI Security Institute, and Beijing licenses on its own terms. California and New York have legislated for frontier models at home. The durable route is shared technical evidence with sovereign enforcement, sealed through mutual recognition rather than deference, with India and the other major non-Western markets holding authorship rather than seats.”</p>



<p class="wp-block-paragraph">Gogia added that the rules enacted by even such a group may not address all of the key concerns of enterprise IT. A US government effort along the lines that Hassabis is proposing would result in testing that “sits close to intelligence and industrial policy, and those functions will not stay neatly separated. A model can pass every catastrophic-risk test and still fail the enterprise on privacy, reliability, and liability,” he noted.</p>



<p class="wp-block-paragraph">Walmart’s former director of cybersecurity <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, who is now an independent cybersecurity consultant, said he found the proposal “well-intentioned, but it addresses a highly polarized topic at a time when commercial interests carry unprecedented political influence, which is not always applied benevolently.”</p>



<p class="wp-block-paragraph">He added, “an exclusive US standard that is not globally respected or enforceable would likely fail to achieve its core purpose and would place US companies at a competitive disadvantage.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that a deep dive into how <a href="https://www.finra.org/" target="_blank" rel="noreferrer noopener">FINRA</a> operates today is illustrative of what IT leaders can expect from this effort, assuming the industry adopts that model.</p>



<p class="wp-block-paragraph">“When the CEOs of the five companies that would be regulated are also the primary drafters of the standards, the standards will reflect those companies’ interests. FINRA has an independent board, but the operational reality is that member firm perspectives dominate the working groups that write the actual rules,” he said. “There is no reason to expect an AI equivalent to work differently, and every reason to expect it to work worse, because AI standardization is happening faster than any industry has ever attempted to standardize itself, and speed is the enemy of independent oversight.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, was even more emphatically opposed to the Hassabis proposal.</p>



<p class="wp-block-paragraph">“Asking Big Tech companies to self-police is analogous to allowing foxes to guard the henhouse. It hasn’t worked to date, and it won’t work going forward. Expecting these organizations to somehow change their ways at this point in time represents the height of naïve thinking,” Levy said. “The framework proposed by Demis Hassabis is a self-serving roadmap for an industry bent on racing to the AI horizon regardless of the harms caused along the way. It is impossible to quantify the dangers to broader society should frameworks allowing self-regulation become the norm.”</p>



<h2 class="wp-block-heading">Some love the proposal</h2>



<p class="wp-block-paragraph">An almost completely opposite stance came from <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, who applauded the proposed move.</p>



<p class="wp-block-paragraph">“This is one of the rare setups where industry self-regulation has a real shot, and enterprise IT should be enthusiastically rooting for it,” he said. “It fails when harms are externalized, such as in social media content moderation. Or when the overseer outsources judgment to the overseen, such as the FAA’s delegation to Boeing before the 737 MAX. It works when everyone in the industry shares the catastrophic downside.”</p>



<p class="wp-block-paragraph">He suggested, however, that the best precedent here isn’t FINRA, it’s INPO, the Institute of Nuclear Power Operations, which the nuclear industry created within months of the <a href="https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/3mile-isle" target="_blank" rel="noreferrer noopener">1979 Three Mile Island partial reactor meltdown</a> “on the logic that an accident anywhere is an accident everywhere. INPO peer-reviews every US plant, its evaluations move insurance premiums, and it sits on top of the NRC’s statutory floor. That is a public-private stack very close to what Hassabis is describing. Frontier AI has the same structure: one lab’s catastrophic failure brings regulation down on all of them.”</p>



<p class="wp-block-paragraph">For enterprise CIOs and other IT executives, Goryunov said, that model has the potential for being a big win.</p>



<p class="wp-block-paragraph"><strong>“</strong>Today, every enterprise duplicates the same AI diligence of red-teaming, eval suites, governance committees and each does so with less information than any certifying body would have,” Goryunov said. “A credible standards regime does for AI what UL did for electrical equipment and SOC2 did for cloud: it converts an unknowable risk into a procurable product and gives boards a defensible standard of care. That’s not red tape. That’s peace of mind with an audit trail.”</p>



<p class="wp-block-paragraph">However, Mahapatra said, “the countervailing view is that the alternative to industry-led standards is probably not thoughtful legislation. It is probably no standards, or state-by-state fragmentation, or the current pattern of ex-post enforcement actions where regulators surface concerns years after harm has already occurred.” </p>



<p class="wp-block-paragraph">Thus, he noted, “Hassabis is making the reasonable argument that imperfect fast standards are better than perfect slow ones, and there is genuine merit to that view for topics like agent identity, evaluation methodology, and interoperability, which are exactly the areas <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">OpenClaw is also targeting</a>.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepMind CEO pushes for AI industry self-regulation]]></title>
<description><![CDATA[Google DeepMind CEO Demis Hassabis is pushing for the US AI industry to self-regulate, with the support of government, as a starting point for an international creating shared international standards. In a blog post, he called for a focus on artificial general intelligence (AGI) and national secu...]]></description>
<link>https://tsecurity.de/de/3673451/it-nachrichten/deepmind-ceo-pushes-for-ai-industry-self-regulation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673451/it-nachrichten/deepmind-ceo-pushes-for-ai-industry-self-regulation/</guid>
<pubDate>Thu, 16 Jul 2026 14:33:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google DeepMind CEO Demis Hassabis is pushing for the US AI industry to self-regulate, with the support of government, as a starting point for an international creating shared international standards. In a blog post, he called for a focus on <a href="https://www.computerworld.com/article/4174181/google-talks-singularity-while-scaling-up-agentic-ai-for-enterprises-2.html">artificial general intelligence (AGI)</a> and national security. </p>



<p class="wp-block-paragraph">But it is precisely that focus on national security that may make the results of such an effort, assuming it happens, less than palatable outside of the US.</p>



<p class="wp-block-paragraph">“The rapid progress we’re seeing in AI requires a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous,” <a href="https://demishassabis.substack.com/p/a-framework-for-frontier-ai-and-the-dawning-of-a-new-age" target="_blank" rel="noreferrer noopener">Hassabis wrote</a>. “The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.”</p>



<p class="wp-block-paragraph">He noted, however, that the funding would need to be substantial, and would most likely come from industry, to allow the new body to attract world-class technical talent and obtain the necessary compute resources for large-scale testing.</p>



<p class="wp-block-paragraph">Hassabis proposed that the organization “be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security,” and that AI vendor participants be encouraged to adopt best practices such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research.</p>



<p class="wp-block-paragraph">This is not the first time Hassabis has <a href="https://www.computerworld.com/article/4178398/deepmind-ceo-agi-could-be-here-in-three-years.html" target="_blank">expressed worries about AGI</a>. </p>



<p class="wp-block-paragraph">DeepMind was involved in an earlier <a href="https://www.cio.com/article/4168122/us-government-agency-to-safety-test-frontier-ai-models-before-release.html" target="_blank">US government initiative evaluating AI safety</a>, alongside Microsoft and xAI (now SpaceXAI) working with the Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce. It allowed CAISI to conduct pre-deployment evaluations and targeted research to “better assess frontier AI capabilities and advance the state of AI security.”  </p>



<h2 class="wp-block-heading">The rest of the world may have concerns</h2>



<p class="wp-block-paragraph">Analysts and consultants were mixed about the move, with most expressing concerns about whether an industry-focused group would prioritize the public’s best interests.</p>



<p class="wp-block-paragraph">“Self-regulation is not viable because it implies everyone is able to regulate themselves and will do so in line with the best interests of the public. Most tech vendors don’t have the capacity to self-regulate. They would just prefer a set of rules within which they can operate,” said Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>. “For-profit organizations are required to do what is best for their shareholders, and external regulation ensures that those organizations are never in a conflict of interest where they have to choose between what is good for their shareholders and what is good for the public.”</p>



<p class="wp-block-paragraph">And, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, given the international nature of AI models, an effort coordinated by the US government might alienate other countries. </p>



<p class="wp-block-paragraph">“National security is the proposal’s accelerator in Washington and its poison pill abroad: the framing that opens the only gate available at home invites foreign capitals to read the institution as an instrument of American strategy,” he pointed out. </p>



<p class="wp-block-paragraph">“The map is already plural,” he said. “Brussels switches on enforcement powers over general-purpose models [starting in August 2026], London runs the AI Security Institute, and Beijing licenses on its own terms. California and New York have legislated for frontier models at home. The durable route is shared technical evidence with sovereign enforcement, sealed through mutual recognition rather than deference, with India and the other major non-Western markets holding authorship rather than seats.”</p>



<p class="wp-block-paragraph">Gogia added that the rules enacted by even such a group may not address all of the key concerns of enterprise IT. A US government effort along the lines that Hassabis is proposing would result in testing that “sits close to intelligence and industrial policy, and those functions will not stay neatly separated. A model can pass every catastrophic-risk test and still fail the enterprise on privacy, reliability, and liability,” he noted.</p>



<p class="wp-block-paragraph">Walmart’s former director of cybersecurity <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, who is now an independent cybersecurity consultant, said he found the proposal “well-intentioned, but it addresses a highly polarized topic at a time when commercial interests carry unprecedented political influence, which is not always applied benevolently.”</p>



<p class="wp-block-paragraph">He added, “an exclusive US standard that is not globally respected or enforceable would likely fail to achieve its core purpose and would place US companies at a competitive disadvantage.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that a deep dive into how <a href="https://www.finra.org/" target="_blank" rel="noreferrer noopener">FINRA</a> operates today is illustrative of what IT leaders can expect from this effort, assuming the industry adopts that model.</p>



<p class="wp-block-paragraph">“When the CEOs of the five companies that would be regulated are also the primary drafters of the standards, the standards will reflect those companies’ interests. FINRA has an independent board, but the operational reality is that member firm perspectives dominate the working groups that write the actual rules,” he said. “There is no reason to expect an AI equivalent to work differently, and every reason to expect it to work worse, because AI standardization is happening faster than any industry has ever attempted to standardize itself, and speed is the enemy of independent oversight.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, was even more emphatically opposed to the Hassabis proposal.</p>



<p class="wp-block-paragraph">“Asking Big Tech companies to self-police is analogous to allowing foxes to guard the henhouse. It hasn’t worked to date, and it won’t work going forward. Expecting these organizations to somehow change their ways at this point in time represents the height of naïve thinking,” Levy said. “The framework proposed by Demis Hassabis is a self-serving roadmap for an industry bent on racing to the AI horizon regardless of the harms caused along the way. It is impossible to quantify the dangers to broader society should frameworks allowing self-regulation become the norm.”</p>



<h2 class="wp-block-heading">Some love the proposal</h2>



<p class="wp-block-paragraph">An almost completely opposite stance came from <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, who applauded the proposed move.</p>



<p class="wp-block-paragraph">“This is one of the rare setups where industry self-regulation has a real shot, and enterprise IT should be enthusiastically rooting for it,” he said. “It fails when harms are externalized, such as in social media content moderation. Or when the overseer outsources judgment to the overseen, such as the FAA’s delegation to Boeing before the 737 MAX. It works when everyone in the industry shares the catastrophic downside.”</p>



<p class="wp-block-paragraph">He suggested, however, that the best precedent here isn’t FINRA, it’s INPO, the Institute of Nuclear Power Operations, which the nuclear industry created within months of the <a href="https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/3mile-isle" target="_blank" rel="noreferrer noopener">1979 Three Mile Island partial reactor meltdown</a> “on the logic that an accident anywhere is an accident everywhere. INPO peer-reviews every US plant, its evaluations move insurance premiums, and it sits on top of the NRC’s statutory floor. That is a public-private stack very close to what Hassabis is describing. Frontier AI has the same structure: one lab’s catastrophic failure brings regulation down on all of them.”</p>



<p class="wp-block-paragraph">For enterprise CIOs and other IT executives, Goryunov said, that model has the potential for being a big win.</p>



<p class="wp-block-paragraph"><strong>“</strong>Today, every enterprise duplicates the same AI diligence of red-teaming, eval suites, governance committees and each does so with less information than any certifying body would have,” Goryunov said. “A credible standards regime does for AI what UL did for electrical equipment and SOC2 did for cloud: it converts an unknowable risk into a procurable product and gives boards a defensible standard of care. That’s not red tape. That’s peace of mind with an audit trail.”</p>



<p class="wp-block-paragraph">However, Mahapatra said, “the countervailing view is that the alternative to industry-led standards is probably not thoughtful legislation. It is probably no standards, or state-by-state fragmentation, or the current pattern of ex-post enforcement actions where regulators surface concerns years after harm has already occurred.” </p>



<p class="wp-block-paragraph">Thus, he noted, “Hassabis is making the reasonable argument that imperfect fast standards are better than perfect slow ones, and there is genuine merit to that view for topics like agent identity, evaluation methodology, and interoperability, which are exactly the areas <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">OpenClaw is also targeting</a>.”</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.cio.com/article/4197497/deepmind-ceo-pushes-for-ai-industry-self-regulation.html">CIO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[19 AgentOps tools for monitoring AI activity, issues, and costs]]></title>
<description><![CDATA[With AI increasingly tucked into every cranny of the enterprise, someone has had to step up and provide the tools necessary to discover, track, and monitor all the agents and LLMs and keep them humming along in their various workflows. Thankfully, the DevOps world answered the call, building the ...]]></description>
<link>https://tsecurity.de/de/3673038/it-security-nachrichten/19-agentops-tools-for-monitoring-ai-activity-issues-and-costs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673038/it-security-nachrichten/19-agentops-tools-for-monitoring-ai-activity-issues-and-costs/</guid>
<pubDate>Thu, 16 Jul 2026 12:09:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">With AI increasingly tucked into every cranny of the enterprise, someone has had to step up and provide the tools necessary to discover, track, and monitor all the agents and LLMs and keep them humming along in their various workflows. Thankfully, the DevOps world answered the call, building the tools to support our new overlords in an emerging subdiscipline interchangeably called “<a href="https://www.cio.com/article/196239/what-is-aiops-injecting-intelligence-into-it-operations.html">AIOps</a>,” “AgentOps,” and sometimes “agent observability.”</p>



<p class="wp-block-paragraph">Many of the challenges involved in AgentOps are similar to those tackled by traditional DevOps tools and processes. After all, at their foundation, LLMs are just software running on hardware somewhere. Typical issues involving RAM and disk space are just as important in the agent world, maybe more so because AI operations are even more greedy about consuming storage than regular software is.</p>



<p class="wp-block-paragraph">Many of the companies supporting agent observability are big names in DevOps circles, having adapted their stacks to address the idiosyncrasies of modern LLMs. IT teams maintaining enterprise agents can treat the LLMs as just one node in a big graph filled with services that are constantly swapping packets and triggering software jobs. Latency and resource constraints must be managed because end-users don’t care whether it’s an LLM, a database, or a plain-old Python script that’s failing, bringing their work to a grinding halt.</p>



<p class="wp-block-paragraph">But new AI-specific challenges are opening the door to newcomers that are building tools with the peculiarities of LLMs in mind — for example, keeping deeper logs filled with records of prompts. LLMs are also often very non-deterministic by design, making it trickier to pinpoint failure modes. And then there’s the fact that an agent will give a perfectly intelligent answer one minute and hallucinate the next.</p>



<p class="wp-block-paragraph">Relying on many of the same approaches that DevOps tools do, AgentOps tools watch for misbehavior and flag anything out of the ordinary for deeper analysis. This may be as simple as fixing slow responses, but it can also include AI hallucinations and other issues born of LLMs’ non-determanism.</p>



<p class="wp-block-paragraph">Teams trying to choose which agent observability tools is best for their use case should look at the size and nature of their agentic systems and projects. Are they adding AI agent features to an existing product or application, or are they building agentic systems from scratch? Are they more focused on maintaining a stable LLM operation or iterating on new approaches? Is AI the center of attention or just an add-on that’s meant to improve an existing stack?<br><br>The AgentOps and agent observability options listed below share many of the same features but differ in their focus and their attention to the challenges organizations will encounter when incorporating agents into their stacks. Each tool offers a worthwhile place to start understanding how to care for the growing presence of AI in the production world.</p>



<h2 class="wp-block-heading">AgentOps.ai</h2>



<p class="wp-block-paragraph">When teams of agents work together, tracking the conversations are essential for understanding and debugging what’s happening. The SDK from <a href="http://agentops.ai/">AgentOps.ai records</a> events so that the creators can replay past behavior to track details such as token counts, spending, latency, and more. Available as a service and on-premises.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> <a href="https://www.agentops.ai/#pricing">Starts at $40 per month </a>plus usage costs at $0.20 per 1M tokens</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Replay analytics with “time-travel debugging”</p>



<p class="wp-block-paragraph"><em>Best suited for:</em> Complex agent debugging</p>



<h2 class="wp-block-heading">Arize Phoenix</h2>



<p class="wp-block-paragraph">Debugging prompts and LLM responses requires a nuanced understanding of just what’s happening, in part because of the non-determinism that often enters the process. <a href="https://arize.com/phoenix/">Phoenix</a> from Arize supports this process with robust tracing and the ability to score the results for more precise iteration. Their system can track the results and tool calls from a variety of major platforms (Anthropic, AWS, OpenAI, etc.) that are initiated by the major frameworks (LangChain, LlamaIndex, DSPy, etc.). The result is insight into what data is triggering what chain of responses.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier; <a href="https://arize.com/pricing/">Pro plan</a> starts at $50 per month plus costs tied to events</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> LLM-as-a-Judge metrics for tracking quality</p>



<p class="wp-block-paragraph"><em>Best suited for:</em> Teams focusing on iterating for accuracy and quality</p>



<h2 class="wp-block-heading">BigPanda</h2>



<p class="wp-block-paragraph"><a href="https://www.bigpanda.io/">BigPanda</a> has always offered solutions for tracking performance of complex systems. Now the company is drilling deeper into the challenge of detecting and ending the problems that come from models that go awry. BigPanda’s main system relies on historical data and machine learning algorithms to flag issues. Its own agent layer connects the problematic nodes and errant models while dispatching alerts to the right team members.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> “Value-based” table on <a href="https://www.bigpanda.io/pricing/">request</a></p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Automated triage for faster response</p>



<p class="wp-block-paragraph"><em>Best suited for:</em> Large teams seeking to reduce alert fatigue from large customer base</p>



<h2 class="wp-block-heading">Braintrust</h2>



<p class="wp-block-paragraph">Setting up an effective improvement cycle for an AI agent requires a strong feedback loop from production data to the agent’s next generation. <a href="https://www.braintrust.dev/">Braintrust</a> watches the production workload and creates test vectors that expose how an agent may be drifting, regressing, or departing from its path. The tool automates much of the testing and scoring feedback loop so problematic patterns can be discovered and addressed. A core part of the offering is a specialized data store that can track large and sometimes deeply nested collections of tests and their results. Their approach may be summarized by one of their tag lines: “trace everything.”</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Free starter tier; <a href="https://www.braintrust.dev/pricing">Pro plan</a> starts at $249 with some usage-based costs covered</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Highly scalable trace ingestion</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams developing strong guardrails through continuous testing</p>



<h2 class="wp-block-heading">Chronicle Labs</h2>



<p class="wp-block-paragraph">When it’s time to release a new version of an agent into the wild, the <a href="https://chronicle-labs.com/">platform from Chronicle Labs </a>specializes in staging it and testing it with a collection of use tests and regression cases. The tools are also helpful during development cycles. “Backtest your agent against reality,” their sales material promises, with a set of tools that mines the production telemetry for solid test vectors that stress every part of the agent with prompts and challenges that the agent will encounter after leaving the safety of the lab.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> On <a href="https://chronicle-labs.com/book-call">request</a></p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Back-testing options for complex testing regimes</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams chasing strong models with good fidelity to reality</p>



<h2 class="wp-block-heading">Comet Opik</h2>



<p class="wp-block-paragraph">Building a dashboard for tracking every in-flow and out-flow to agents is one way to be ready to watch for and solve problems. <a href="https://www.comet.com/site/products/opik/">Opik from Comet </a>is just such a tool. The DevOps teams can track each call and add its own automated routines to examine the results, score them based on 30-plus metrics, and if desired, send it off to another LLM to evaluate the results. Agents that are constantly failing stand out. DevOps teams can also ask questions like, “Who is using this model and racking up all of the bills?” The same goes for MCP skills and other cogs in the machine.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Free tiers for open source and small projects; <a href="https://www.comet.com/site/pricing/">Pro plan</a> starts at $19 per month with usage limits</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Auto-scoring with 30-plus metrics for evaluating traces</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams focusing on RAG and agentic workflows</p>



<h2 class="wp-block-heading">Datadog</h2>



<p class="wp-block-paragraph">DevOps teams that rely on <a href="https://www.datadoghq.com/">Datadog</a> to track logs across collections of services can also use it to track LLM operations, which are, of course, just another source and sink for data. It will track performance such as time to first token and offer insight into what might be causing an issue, such as lack of memory. Results then get plugged into the same cost-tracking mechanism so the bean counters can predict when the budget will run out. After all, the CFO likely doesn’t care whether the bill comes from an LLM or an old-school S3 storage bucket. Datadog integrates AI into their tools by treating these models as just another source of data.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier with <a href="https://www.datadoghq.com/pricing/">multiple paid tiers</a> for various levels of enterprise monitoring</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Large installed base with broad focus on more than LLMs</p>



<p class="wp-block-paragraph"><em>Best for:</em> Large enterprise teams working with established infrastructure</p>



<h2 class="wp-block-heading">Dynatrace</h2>



<p class="wp-block-paragraph">For more than 20 years, <a href="https://www.dynatrace.com/">Dynatrace</a> has been delivering tools that track dataflows across the full stack. Now that AIs are finding roles in many of the nodes in this complex graph, they’re expanding to track how various AI agents can interact. They want to build one platform that helps track the root cause and, often now, deploy solutions autonomously. They want to focus on being ready to support complex networks of agents that detect problems in either performance or security and then work within defined guardrails to fix them. Determining the right role for their own AI-powered agents is a key part of the product.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> <a href="https://www.dynatrace.com/pricing/">Plans</a> start at $7 per month with larger plans designed for full enterprise monitoring</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> High level of autonomous monitoring designed for large installations</p>



<p class="wp-block-paragraph"><em>Best for: </em>Complex, hybrid environments mixing LLMs with traditional services</p>



<h2 class="wp-block-heading">Galileo</h2>



<p class="wp-block-paragraph">Placing some AI systems into production is often a harrowing experience because the actual performance is impossible to predict, even with the most rigorous tests. <a href="https://galileo.ai/">Galileo</a> offers guardrails that track performance and watch for any behavior that deviates from the ground truth. Their “LLM-as-judge” systems are distilled into compact models that can be run locally for lower costs and faster performance.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier; Pro plans start at $50 per month with usage-based limits and costs</p>



<p class="wp-block-paragraph"><em>Standout feature: </em>Real-time guardrails for deployed agents</p>



<p class="wp-block-paragraph"><em>Best for:</em> Security-conscious installations that need to defend against hallucination and data leakage</p>



<h2 class="wp-block-heading">Grafana Labs</h2>



<p class="wp-block-paragraph">Long the go-to source for<a href="https://grafana.com/oss/"> open source </a>telemetry, <a href="https://grafana.com/products/cloud/ai-assistant/?pg=hp&amp;plcmt=txt-img-alternating">Grafana Labs</a> now tracks performance of AI models in constellations of services. Grafana tracks the evolution of answers across the agentic network to recognize how small changes or hallucinations can spin out of control. It bills its system as “actually useful AI” and has even trademarked it. Its cloud assistant can configure and reconfigure the Grafana dash to offer the right level of observability. Its system includes AI-level analysis that can flag models that are responding quickly but offering bad answers because of problems such as model drift or context degradation.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Basic free tier; <a href="https://grafana.com/pricing/">Pro plan</a> begins at $19 per month, includes better retention and some usage-based fees </p>



<p class="wp-block-paragraph"><em>Standout feature: </em>Full-stack tool with fully integrated LLM tools</p>



<p class="wp-block-paragraph"><em>Best for:</em> Large, enterprise-scale system adding AI</p>



<h2 class="wp-block-heading">Helicone</h2>



<p class="wp-block-paragraph">Sometimes shoehorning in another tool into the chain can be tricky. <a href="https://www.helicone.ai/">Helicone</a> is designed as a smart network proxy that will route all model requests while keeping solid debugging records from the data as it goes by. The data it captures can be turned into nice charts that make it easy to spot latency issues or model failures. Naturally, tracking AI spend is also a feature in much demand as bills continue to climb.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier; <a href="https://www.helicone.ai/pricing">Pro plan</a> starts at $79 per month, includes features such as team collaboration and improved querying</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Proxy-based integration</p>



<p class="wp-block-paragraph"><em>Best for:</em> Development teams who want to add better monitoring features quickly</p>



<h2 class="wp-block-heading">Laminar</h2>



<p class="wp-block-paragraph">Tracking agents in development and production means building strong storehouses of data enumerating what happened. <a href="https://laminar.sh/">Laminar</a> works closely with OpenTelemetry to follow agents operating in production so that flaws and failure modes can be understood from log files stored efficiently with their own compression scheme. Developers can search through traces with an SQL-ish language and Laminar’s transcript view illuminates what happened. When necessary, the traces can enable developers to scroll back in time and replay the same inputs for debugging. The goal is to offer deep insights with high-level visibility of how well the agents are meeting business objectives.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier; “Hobby” tier that adds more features at $30; <a href="https://laminar.sh/pricing">Pro level</a> starts at $150 per month</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Open-source license makes self-hosting a viable option</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams fully able to leverage open-source responsibilities</p>



<h2 class="wp-block-heading">LangChain LangSmith</h2>



<p class="wp-block-paragraph">Real-time data from agents is essential for managing any mutli-agent system in production. LangSmith from <a href="https://www.langchain.com/">LangChain</a> traces costs, tools, and progress toward solutions for a wide collection of agents using SDKs for Python, TypeScript, Go, and Java. The OpenTelemetry-based solution watches for anomalies, issuing warnings and alerts through dashboards and communication channels such as PagerDuty. Deeper analysis can reveal issues such as topic clustering or odd patterns of failure. Coordination with agent deployment platforms such as LangGraph and deepagents ensures greater focus on successful resolution of assignments.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Free for solo developers; <a href="https://www.langchain.com/pricing">Pro teams</a> start at $39 per person per month </p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Systematic approach to regression testing of prompts</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams relying on LangChain and LangGraph frameworks for supporting complex agentic behavior</p>



<h2 class="wp-block-heading">Lunary</h2>



<p class="wp-block-paragraph">Watching the user experience is essential for building AI applications such as chatbots and assistants. <a href="https://lunary.ai/">Lunary</a> offers a proxy that traces all interactions and then builds analytical dashboards for measuring metrics such as user satisfaction or model costs. One common usage is finding frequent topics and looking at the responses to ensure they deliver. When prompts aren’t perfect, Lunary lets teams iterate on the prompt text until the right answers are coming out. Its proxy structure and common API format enables Lunary to promise to work with “any LLM, any framework.”</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Free tier; <a href="https://lunary.ai/pricing">Pro plan</a> starts at $20 per month</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Deep integration with humans for reviewing and optimizing results</p>



<p class="wp-block-paragraph"><em>Best for:</em> Startups focused on rapid prompt innovation</p>



<h2 class="wp-block-heading">NewRelic</h2>



<p class="wp-block-paragraph">The platform that began tracking performance of some web applications is now powerful enough to track the flows of data through complex agentic ecologies. <a href="https://newrelic.com/platform/ai-observability">NewRelic’s</a> AI-driven monitoring watches for golden signals that can indicate misbehavior or worse throughout the entire lifecycle. It tracks every detail of the interactions through protocols such as MCP and then makes this available to the AI engineers responsible for performance. The dashboard provides the insights necessary to watch for toxic behavior, overt bias, drift, and overblown hallucinations. Predicting and maybe even controlling the cost is also a growing role as tokenomics becomes as important as response time.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Free tier; Pro plan fees available through website</p>



<p class="wp-block-paragraph"><em>Standout feature: </em>Full-stack support with hundreds of integrations with other tools</p>



<p class="wp-block-paragraph"><em>Best for:</em> Established enterprise teams mixing in AI</p>



<h2 class="wp-block-heading">Nova AI Ops</h2>



<p class="wp-block-paragraph">The goal of <a href="https://novaaiops.com/">Nova AI Ops </a>is to deliver a team of agents that watch over a cloud and make it, at least partially, self-healing. Each agent uses a mixture of predictive AI and machine learning to watch cloud telemetry reports for anomalies. Then they calculate the “blast radius” and decide whether this is a problem that can be fixed automatically “while you sleep” or saved for the human supervisors. These tools are aimed not just on LLM operations but on the stack as a whole.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier; <a href="https://novaaiops.com/pricing">Standard pricing </a> begins at $40 per user per month with usage billing</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Focus on software reliability engineering helps teams deliver stable stacks</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams that want to integrate LLMs into incident response and stability management</p>



<h2 class="wp-block-heading">Splunk</h2>



<p class="wp-block-paragraph">The platform that began delivering smart logging is now fully AI capable, offering solutions that can watch over agents with much the same way that it continues to track microservices. <a href="https://www.splunk.com/en_us/solutions/splunk-artificial-intelligence.html">Splunk</a> now includes a fairly large amount of predictive AI for learning from the information in the logs and then turning this learning into fast solutions. This AI assistant can track deployed AI models connected by protocols such as MCP and watch over behavior while delivering the ability for users to drill down and explore what’s working and what’s failing. Their AI Canvas is meant to offer a central hub where the AI scientists can track both the local behavior of the models as well as their role in a larger data ecosystem.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> <a href="https://www.splunk.com/en_us/resources/splunk-pricing-options.html">Activity-based pricing</a> tracks usage of LLM backends and storage</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Ready to scale to large enterprise stacks</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams with legacy systems that are folding in agentic options</p>



<h2 class="wp-block-heading">SuperPenguin</h2>



<p class="wp-block-paragraph">One of the most important parts of an AI service is the bill. <a href="https://superpenguin.ai/#features">SuperPenguin</a> is a product designed to track consumption and make predictions so that the CFO won’t be surprised. The goal is to provide solid estimates about the total cost of each product by allocating costs to customers, features, and teams. If there’s a sudden shift, a “spike detector” will raise an alarm so that dev teams can ensure that the AI spend is worth it.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier for experimentation; Growth tier for teams, starting at $30 per month; <a href="https://superpenguin.ai/#pricing">Pro tier </a>offers deeper options starting at $200 per month</p>



<p class="wp-block-paragraph"><em>Standout feature: </em>Strong accounting with invoice reconciliation and PR-level usage tracking</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams that need precise cost accounting</p>



<h2 class="wp-block-heading">Vellum</h2>



<p class="wp-block-paragraph">Prompt engineers spend time fussing over the details of tweaking, improving, and enhancing the words that guide the LLM. <a href="https://www.vellum.ai/">Vellum</a> started as a company that would provide the pipeline so that you could manage and improve the prompts that ran again and again. Now the system is growing more powerful, offering a higher level of automation that lets you meta-manage the prompt chain. They’ve also begun marketing it as a form of personal assistant with pre-built connections to many of the major services such as Gmail. Its <a href="https://github.com/vellum-ai/llm-cost-optimizer">llm-cost-optimizer </a>can juggle multiple options while finding a cheaper way to execute a prompt, a process the company suggests can save 60% or more.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Open-source free tier; Pro plan starts at $35 per month</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Focus on multi-model pipelines for true agentic solutions</p>



<p class="wp-block-paragraph"><em>Best for:</em> Product teams with complex prompt engineering workflows</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-56877 - Skillable SCORM userId authorisation bypass]]></title>
<description><![CDATA[Posted by Greg via Fulldisclosure on Jul 15Skillable's SCORM lab launch endpoint validates a launch token but
enforces per-user allocation limits using a browser-supplied userId
that is not bound to the validated token. An authenticated learner
can modify this identifier to bypass configured limi...]]></description>
<link>https://tsecurity.de/de/3672372/it-security-nachrichten/cve-2026-56877-skillable-scorm-userid-authorisation-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672372/it-security-nachrichten/cve-2026-56877-skillable-scorm-userid-authorisation-bypass/</guid>
<pubDate>Thu, 16 Jul 2026 07:08:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Posted by Greg via Fulldisclosure on Jul 15</p>Skillable's SCORM lab launch endpoint validates a launch token but<br>
enforces per-user allocation limits using a browser-supplied userId<br>
that is not bound to the validated token. An authenticated learner<br>
can modify this identifier to bypass configured limits, launch<br>
concurrent lab instances, and consume another learner's allocation.<br>
Skillable states that no fix is planned for the legacy SCORM launch<br>
path. CVE-2026-56877 was assigned by...<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 Tipps, um Data Products zu entwickeln]]></title>
<description><![CDATA[width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px">Wenn KI-Agenten Geschäftswert liefern sollen, können Data Products hilfreich sein.Gorodenkoff / Shutterstock



Data Products tragen dazu bei, die Art und Weise zu standardisieren, wie Rohdaten, Data-Warehouse-, sowie logis...]]></description>
<link>https://tsecurity.de/de/3672305/it-security-nachrichten/5-tipps-um-data-products-zu-entwickeln/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672305/it-security-nachrichten/5-tipps-um-data-products-zu-entwickeln/</guid>
<pubDate>Thu, 16 Jul 2026 06:06:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Wenn KI-Agenten Geschäftswert liefern sollen, können Data Products hilfreich sein.</figcaption></figure><p class="imageCredit">Gorodenkoff / Shutterstock</p></div>



<p class="wp-block-paragraph">Data Products tragen dazu bei, die Art und Weise zu standardisieren, wie Rohdaten, Data-Warehouse-, sowie logische Data-Lake-Ansichten kombiniert und genutzt werden, um Analyse- und KI-Funktionen bereitzustellen. Indem sie <a href="https://medium.com/data-mesh-learning/what-exactly-is-a-data-product-7f6935a17912" target="_blank" rel="noreferrer noopener">Datenprodukte</a> entwickeln, können Teams in Unternehmen einen Großteil der im Vorfeld erforderlichen Daten-Pipelines sowie Governance- und Management-Tasks optimieren. Darüber hinaus gewährleisten diese auch, dass Mensch <a href="https://www.computerwoche.de/article/4132787/wie-ki-agenten-daten-konsumieren-sollten.html" target="_blank">und KI</a> auf vertrauenswürdige Datenressourcen zugreifen.  </p>



<p class="wp-block-paragraph">Kochen bietet an dieser Stelle eine hilfreiche Analogie: Sie könnten sich dazu entscheiden, für Ihr Lieblingsgericht ausschließlich auf frische Zutaten zu setzen. Dieser Ansatz funktioniert gut, wenn Sie sowohl die Zeit als auch die nötigen Fähigkeiten dafür mitbringen. Wenn nicht, setzen Sie eventuell lieber auf Convenience-Bestandteile – insbesondere unter Zeitdruck. Datenprodukte bieten eine vergleichbare Zeitersparnis – Analytics- und <a href="https://www.computerwoche.de/article/4170715/so-integrieren-sie-ki-ohne-benutzer-zu-verprellen.html" target="_blank">KI-Funktionen</a> bauen in diesem Fall auf konsistenten, (vor)optimierten „Zutaten“ auf.</p>



<p class="wp-block-paragraph">Die folgenden fünf Tipps sollten Sie bei Ihrer Data-Product-Initiative unbedingt verinnerlichen.</p>



<h2 class="wp-block-heading">1. Data Products strategisch nutzen</h2>



<p class="wp-block-paragraph">Die meisten Unternehmen können es sich nicht leisten, für jede Datenvisualisierung, jedes Machine-Learning-Modell oder jeden <a href="https://www.computerwoche.de/article/4189343/was-ki-agenten-wirklich-kosten.html" target="_blank">KI-Agenten</a> eigene Datenprodukte zu entwickeln. Schließlich ist das mit Kosten und Zeitaufwand verbunden. Dazu kommt: Sobald ein Data Product bereitgestellt ist, müssen die Produktmanager für fortlaufenden Support und ein entsprechendes Lifecycle-Management sorgen. Die erste entscheidende Frage ist also, in welchen Fällen es für agile Daten-Teams Sinn macht, Datenprodukte zu entwickeln – und wie dabei priorisiert werden sollte.   </p>



<p class="wp-block-paragraph">Ein Ansatzpunkt besteht darin, das Data Product auf einen einzelnen Datensatz herunterzubrechen und sich zu überlegen, was es bedeutet, diesen zum Produkt zu machen. <a href="https://www.linkedin.com/in/dswbg" target="_blank" rel="noreferrer noopener">Danielle Ben-Gera</a>, Vice President of Engineering bei Crunchbase, erklärt: „Ein Datensatz sollte erst dann zu einem Datenprodukt werden, wenn sich mehrere Teams bei Entscheidungen – oder zum Support von Anwendungen – darauf verlassen.“</p>



<p class="wp-block-paragraph">Dabei seien eine angemessene Governance, klare Zuständigkeiten, Versionierungen und ein kontrollierter Lebenszyklus für Änderungen essenziell, warnt die Managerin: „Ansonsten liefert man nur instabile Pipelines aus, die die nachgelagerten Workflows zum Erliegen bringen.“</p>



<p class="wp-block-paragraph">Eine andere Überlegung, die zu Data Products führt, ist die Nutzung von Daten außerhalb der Governance. An dieser Stelle kann ein Datenprodukt einen taktischen Ansatz darstellen, wie <a href="https://www.linkedin.com/in/yaad-oren-77a7823" target="_blank" rel="noreferrer noopener">Yaad Oren</a>, Global Head of Research and Innovation bei SAP, nahelegt: „Wenn Datensätze teamübergreifend ohne strenge Governance, klar definierte Prozesse oder eindeutige Zuständigkeiten genutzt werden, ist Unternehmen zu empfehlen, ein Data Product zu entwickeln. Datenprodukte, die in einer einheitlichen Datenbasis verankert sind, beseitigen Silos, schaffen ein gemeinsames Verständnis über die Daten und etablieren einen sicheren, standardisierten Zugriff auf diese.“</p>



<p class="wp-block-paragraph">Eine dritte Möglichkeit, Datenprodukte strategisch zu nutzen, ist, diese für definierte Kunden in wiederverwendbarer Form zu entwickeln, um Effizienzgewinne einzufahren. Wenn ein solches Data Product erfordert, mehrere Datenquellen miteinander zu kombinieren, ist das Vision Statement und qualifizierter Business Value besonders wichtig. <a href="https://www.linkedin.com/in/christopherzangrilli" target="_blank" rel="noreferrer noopener">Christopher Zangrilli</a>, Vice President of Technology Strategy beim Compliance-Dienstleister Vertex, erklärt: „Führungskräfte sollten sich fragen, ob die Daten die Cycle Times optimieren, die Entscheidungsgenauigkeit verbessern oder Compliance-Risiken mindern, um den Business Impact einzuordnen. Wenn Governance, Change Management, Qualität und Messverfahren von Beginn an integriert sind, wandeln sich Datenprodukte von experimentellen Tools zu strategischen Ressourcen.“</p>



<h2 class="wp-block-heading">2. Datenprodukte standardisieren</h2>



<p class="wp-block-paragraph">Produkte im Supermarkt sind mit einer Verpackung versehen, auf der eine detaillierte Liste der Inhaltsstoffe, ein Verfallsdatum und ein Preis angegeben sind. Ganz ähnlich sollten Data-Governance-Verantwortliche vorgehen – und standardisieren, wie Data Products definiert, katalogisiert und gemanagt werden. Wie und warum, erklärt <a href="https://www.linkedin.com/in/abhisharmab" target="_blank" rel="noreferrer noopener">Abhi Sharma</a>, Mitbegründer und CEO des KI-Anbieters Relyance AI: „Jedes moderne Datenprodukt sollte vier Fragen klar beantworten: Woher stammen die Daten, wie werden sie systemübergreifend transformiert, wer oder was nutzt sie und welche Governance-Verpflichtungen fallen dabei an? Ohne diesen durchgängigen Kontext entwickeln Teams Funktionen auf der Grundlage von Daten, die sie nicht vollständig verstehen.“</p>



<p class="wp-block-paragraph">Obwohl Lebensmittelhersteller ihre Inhaltsstoffe veröffentlichen und mit Blick auf Gefahren wie allergische Reaktionen kennzeichnen, dokumentieren nur wenige die Herkunft ihrer Rohstoffe und welchen Weg diese vom Erzeuger zum Händler nehmen. Geht es darum, Data Products in streng regulierten Branchen zu entwickeln, kann es allerdings erforderlich sein, genau das zu tun – und die <a href="https://www.computerwoche.de/article/2804614/was-ist-data-lineage.html" target="_blank">Data Lineage</a> zu erfassen. Besonders wichtig ist das, wenn es darum geht, Datenquellen für KI-Applikationen zu standardisieren.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/carterpage" target="_blank" rel="noreferrer noopener">Carter Page</a>, Executive Vice President of Research and Development beim Dev-Spezialisten Astronomer, weiß, was anderenfalls droht: „Ohne Data Lineage arbeiten Teams im Blindflug und Governance verkommt zu reaktiver Fehlerbehebung. Wenn Teams dagegen nachvollziehen können, woher die Daten stammen, wie sie transformiert wurden und welche Systeme darauf angewiesen sind, werden Aktualisierungen vorhersehbar, die richtigen Pipelines getestet, die betroffenen Stakeholder benachrichtigt und grundlegende Änderungen dokumentiert. Bevor es dadurch zu Incidents kommt.“</p>



<h2 class="wp-block-heading">3. Data Products nachhaltig managen</h2>



<p class="wp-block-paragraph">Lebenszyklusmanagement erfordert bei <a href="https://www.computerwoche.de/article/4004872/die-besten-apis-um-ki-zu-integrieren.html" target="_blank">APIs</a>, Anwendungen oder KI-Modellen, einen Release-Plan für Optimierungen, Fehlerbehebungen und andere notwendige Updates festzulegen. Geht es hingegen um Datenprodukte, kommen mehrere, verwandte Disziplinen zusammen, wie <a href="https://www.linkedin.com/in/ulf-viney-2618a" target="_blank" rel="noreferrer noopener">Ulf Viney</a>, EVP of Engineering beim KI-Datenspezialisten Precisely, erklärt: „Um den Lebenszyklus von Data Products zu managen, braucht es Versionierung, Testing, strukturierte Deployments und Stakeolder-Kommunikation.“</p>



<p class="wp-block-paragraph">Ein weiterer grundlegender Unterschied bei Datenprodukten: Ihr Lifecycle Management ist eng damit verbunden, wie die zugrundeliegenden Datensätze wachsen – beziehungsweise, welche strukturelle Veränderungen diese durchlaufen. Ein Data Product, das zwar funktioniert, aber nicht veränderungsresistent ist oder keine Warnmeldungen ausgibt, wenn Fehlerbehebungen erforderlich sind, kann nachgelagerte Anwendungsfälle beeinträchtigen und das Vertrauen der Stakeholder und Nutzer in die Daten untergraben. Insbesondere letzteres gilt es zu verhindern. Wie, weiß <a href="https://www.linkedin.com/in/bethanysehon" target="_blank" rel="noreferrer noopener">Bethany Sehon</a>, Senior Director of Enterprise Data bei Capital One: „Ein nachhaltiges und skalierbares <a href="https://www.computerwoche.de/article/4030328/so-verandert-ki-ihre-grc-strategie.html" target="_blank">Governance-Framework</a> kann sicherstellen, dass Daten leicht zu finden, zu verstehen und zu nutzen sind.“</p>



<p class="wp-block-paragraph">Teams, die geschäftskritische Echtzeit-Datenprodukte managen, die mehrere nachgelagerte Analytics- und KI-Anwendungsfälle unterfüttern, sind die folgenden DevOps- und Data-Governance-Praktiken zu empfehlen:</p>



<ul class="wp-block-list">
<li>Legen Sie <strong>unverhandelbare Data-Governance-Kriterien</strong> fest – insbesondere, wenn es darum geht, Datenqualitäts-Benchmarks zu setzen, etwaige Verzerrungen zu identifizieren und Datenschutzrichtlinien einzuhalten.</li>



<li>Nutzen Sie <strong>fortschrittliche CI/CD-Pipelines</strong>, <strong>Continuous Deployment</strong> sowie <strong>Continuous Testing</strong> und automatisieren Sie Produktions-Deployments.</li>



<li>Stellen Sie sicher, dass sämtliche Datenintegrationen über <strong>„observable“ DataOps</strong> verfügen, Datenqualitätsprobleme überprüft werden und Alerts ausgesendet werden, wenn die Pipelines zum Erliegen kommen. Um Requests und Incidents zu bearbeiten, sollten IT-Services zudem entsprechend definiert werden.</li>



<li>Stützen Sie sich auf <strong>Plattform-Strategien</strong> wenn es um Datenmanagement geht – zum Beispiel im Hinblick auf Data Fabrics, <a href="https://www.computerwoche.de/article/3493645/data-security-posture-management-die-besten-dspm-tools.html" target="_blank">DSPM</a>, Dokumentenverarbeitung und Vektordatenbanken.</li>
</ul>



<h2 class="wp-block-heading">4. Datenprodukte verargumentieren</h2>



<p class="wp-block-paragraph">Ein Data Product auf die Beine zu stellen, ist leider kein Garant dafür, dass dieses auch angenommen wird. Das verdeutlichen auch die Beispiele von Reusable Code, API-Nutzung oder DevOps-Tools: Sie alle zielten darauf ab, Entwicklern das Arbeitsleben leichter zu machen und die Qualität zu verbessern. Trotzdem nahmen viele Teams lieber eine „Not invented here“-Haltung ein und setzten lieber auf Eigenentwicklungen statt die Standards anderer.</p>



<p class="wp-block-paragraph">Datenprodukte stehen allerdings vor noch größeren Herausforderungen. Ganz besonders, wenn sie darauf abzielen, Datensilos zu konsolidieren oder Tabellenkalkulationen zu eliminieren. Um die Akzetanz zu fördern (und Feedback einzuholen), sollten die für die jeweiligen Data Products verantwortlichen Produktmanager deshalb ein <a href="https://www.computerwoche.de/article/2797747/mit-dem-richtigen-change-modell-zum-ziel.html" target="_blank">Change-Management-Programm</a> entwickeln. Förderlich ist dabei, darzulegen, wie das Datenprodukt auf den kulturellen Change und die KI-Strategie des Unternehmens einzahlt – etwa indem es die Demokratisierung von KI vorantreibt und die Kompetenz im Umgang mit der Technologie optimiert.</p>



<h2 class="wp-block-heading">5. Data Products richtig evaluieren</h2>



<p class="wp-block-paragraph">Der Geschäftswert eines kundenorientierten Produkts wird häufig gemessen anhand der <strong>Auswirkungen auf den Umsatz</strong>, der <strong>Nutzungs-Metriken</strong> sowie der <strong>Kundenzufriedenheit</strong>. Interne, mitarbeiterorientierte Produkte lassen sich hingegen anhand ihrer <strong>Workflow-Effizienz</strong>, ihrem Potenzial für <strong>Produktivitätssteigerungen</strong> und der <strong>Mitarbeiterzufriedenheit</strong> evaluieren.</p>



<p class="wp-block-paragraph">„Zu viele Unternehmen behandeln Datenprodukte immer noch als technische Outputs und nicht als strategische Assets“, kritisiert <a href="https://www.linkedin.com/in/dziv1" target="_blank" rel="noreferrer noopener">Daniel Ziv</a>, Global Vice President of AI and Analytics beim KI-Anbieter Verint. Der wahre Wert von Data Products lasse sich daran ablesen, wie einzigartig die generierten Daten sind, wie viel messbaren Einfluss sie auf Entscheidungen nehmen, meint der Manager: „Wenn jedes Unternehmen Zugang zu denselben KI-Modellen hat, ergibt sich der Wettbewerbsvorteil aus ‚uniquen‘ Daten und der Geschwindigkeit, mit der diese in Maßnahmen umgesetzt werden können.“</p>



<p class="wp-block-paragraph">Eine Best Practice auf die IT-Entscheider in diesem Zusammenhang zurückgreifen können, ist es, <a href="https://www.forbes.com/sites/betsyatkins/2019/04/16/board-of-directors-and-the-digital-revolution/" target="_blank" rel="noreferrer noopener">Metriken heranzuziehen</a>, die Aufschluss über die Geschwindigkeit digitaler Transformationsvorhaben geben. Dazu gehören etwa:  </p>



<ul class="wp-block-list">
<li>„Time to Data“,</li>



<li>„Time to Decision“,</li>



<li>„Time to Innovation“, und</li>



<li>„Time to Value“.</li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist </strong><a href="https://www.infoworld.com/article/4192856/five-tips-for-developing-data-products.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[USAF wants to replace $30 million MQ-9 Reaper drones with cheaper UAVs after "dozens" were lost in Iran, costing taxpayers billions]]></title>
<description><![CDATA[The Pentagon seeks a cheaper long-range drone after costly MQ-9 losses raised concerns about future battlefield sustainability and affordability.]]></description>
<link>https://tsecurity.de/de/3672074/it-nachrichten/usaf-wants-to-replace-30-million-mq-9-reaper-drones-with-cheaper-uavs-after-dozens-were-lost-in-iran-costing-taxpayers-billions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672074/it-nachrichten/usaf-wants-to-replace-30-million-mq-9-reaper-drones-with-cheaper-uavs-after-dozens-were-lost-in-iran-costing-taxpayers-billions/</guid>
<pubDate>Thu, 16 Jul 2026 01:32:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Pentagon seeks a cheaper long-range drone after costly MQ-9 losses raised concerns about future battlefield sustainability and affordability.]]></content:encoded>
</item>
<item>
<title><![CDATA[Thinking Machines open sources first multimodal language model, Inkling, focused on low cost and 'resistance to censorship']]></title>
<description><![CDATA[Enterprises looking to move more of their agentic AI workloads to open weights models they can customize, control and run on-premises or in virtual private clouds have a strong new contender to consider.Today, Thinking Machines—the highly capitalized American AI startup founded by former OpenAI C...]]></description>
<link>https://tsecurity.de/de/3672034/it-nachrichten/thinking-machines-open-sources-first-multimodal-language-model-inkling-focused-on-low-cost-and-resistance-to-censorship/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672034/it-nachrichten/thinking-machines-open-sources-first-multimodal-language-model-inkling-focused-on-low-cost-and-resistance-to-censorship/</guid>
<pubDate>Thu, 16 Jul 2026 00:46:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprises looking to move more of their agentic AI workloads to open weights models they can customize, control and run on-premises or in virtual private clouds have a strong new contender to consider.</p><p>Today, Thinking Machines—the highly capitalized American AI startup founded by former OpenAI CTO Mira Murati—<a href="https://thinkingmachines.ai/news/introducing-inkling/">released Inkling</a>, its first major language model under an<a href="https://choosealicense.com/licenses/apache-2.0/"> enterprise-friendly Apache 2.0 open source license</a>, and it boasts high, if sub state-of-the-art, performance for open weights models on third-party benchmarks, specifically software engineering (77.6% on SWE-bench Verified, where it beats fellow U.S. open rival Nvidia Nemotron 3's 71.9%) and voice understanding (91.4% on VoiceBench compared to 94.4% for Gemini 3.1 Pro on high reasoning effort).</p><p>Another differentiator: Thinking Machines notes that Inkling was designed "to answer directly on topics that may be subject to censorship," offering enterprises concerned about factual outputs, irrespective of controversy or sensitivity, a more trustworthy option. </p><p>Coming in at 975 billion total parameters, Inkling is a natively multimodal, open-weights Mixture-of-Experts (MoE) system capable of reasoning across text, images, and audio. The weights <a href="https://huggingface.co/thinkingmachines/Inkling">are already available on Hugging Face</a> and the company's own model training application programming interface (API), <a href="https://thinkingmachines.ai/tinker/">Tinker</a>.</p><p>Designed to balance cost against performance through a novel "controllable thinking effort" mechanism, the model represents a significant departure from the black-box scaling strategies of frontier competitors.</p><p>Alongside the flagship model, Thinking Machines also announced a preview of Inkling-Small, a lighter 276-billion-parameter alternative optimized for workloads where low latency and cost are paramount.</p><h2><b>Benchmarks Show a Powerful, High-End, Sub State-of-the-Art Model</b></h2><p>While Inkling is a formidable multimodal engine, it lands in a fiercely competitive 2026 open-weight landscape characterized by highly specialized MoE architectures. Rather than attempting to dominate every leaderboard, Thinking Machines explicitly designed Inkling—with 975 billion total and 41 billion active parameters—as a broad, balanced generalist. </p><p>For example, it comes in near the middle high-end of benchmark performance 1257 on Design Arena’s Agentic Web Dev leaderboard measuring human scores of frontend web design. </p><p>But China’s leading AI labs have produced models with elite reasoning and coding capabilities, posing a stiff challenge to Inkling's generalist approach and ultimately outperforming it on general and coding benchmarks.</p><ul><li><p><b>GLM 5.2:</b> Widely considered the top open-weight reasoning model available in the benchmark set, GLM 5.2 outperforms Inkling on pure coding, agentic, and complex reasoning tasks. It scores 62.1% on SWEBench Pro (Public) compared to Inkling’s 54.3%, and a massive 82.7 on Terminal Bench 2.1 against Inkling’s 63.8. GLM 5.2 also holds the edge in text-only reasoning, scoring 40.1% on HLE (text only) versus Inkling's 30.0%.</p></li><li><p><b>DeepSeek V4 Pro:</b> DeepSeek maintains an edge in several strict coding and factuality domains, beating Inkling on SWEBench Verified (80.6% vs. 77.6%) and SimpleQA Verified (57.0% vs. 43.9%). However, Inkling successfully overtakes DeepSeek V4 Pro in mathematical problem-solving, achieving 97.1% on AIME 2026 compared to DeepSeek's 96.7%.</p></li><li><p><b>Kimi K2.6:</b> This model outpaces Inkling across multiple technical benchmarks, delivering higher scores on GPQA Diamond (91.1% vs. 87.9%), BrowseComp (83.2% vs. 77.1%), and HLE with tools (54.0% vs. 46.0%). Yet Inkling proves more resilient on general chat instruction following, scoring 79.8% on IFBench compared to Kimi K2.6's 76.0%.</p></li></ul><p>Against its primary U.S.-based open-weight competition, Inkling demonstrates strong parity and frequent superiority.</p><ul><li><p><b>Nemotron 3 Ultra:</b> Inkling consistently outperforms this U.S. rival across reasoning and coding. Inkling posts 97.1% on AIME 2026 and 77.6% on SWEBench Verified, beating Nemotron's 94.2% and 70.7%, respectively. Furthermore, Inkling significantly leads in agentic workflows, scoring 74.1% on MCP Atlas against Nemotron's 44.7%.</p></li></ul><p>When compared to closed-source juggernauts like Claude Fable 5, GPT 5.6 Sol, and Gemini 3.1 Pro, Inkling trails in peak reasoning and software engineering autonomy, but remains highly competitive in multimodality.</p><ul><li><p><b>Coding and Reasoning:</b> Closed models maintain a commanding lead. Claude Fable 5 (max) hits 95.0% on SWEBench Verified and 53.3% on HLE (text only), far outpacing Inkling's 77.6% and 30.0%. GPT 5.6 Sol dominates Terminal Bench 2.1 with an 89.5, easily clearing Inkling's 63.8.</p></li><li><p><b>Native Multimodality:</b> Inkling's native visual and audio capabilities hold their own. On the MMMU Pro (Standard 10) vision benchmark, Inkling's 73.3% is competitive, though trailing Claude Fable 5's 84.2% and GPT 5.6 Sol's 83.0%. In audio processing, Inkling scores a highly respectable 77.2% on MMAU, keeping it within striking distance of Gemini 3.1 Pro's 82.5%.</p></li></ul><p>If an enterprise workflow demands elite software engineering autonomy or the highest bounds of text-only reasoning, models like GLM 5.2 or proprietary systems like Claude Fable 5 maintain the edge. </p><p>However, Inkling carves out a unique and highly defensible position: it is the most capable open-weight foundation model that natively fuses text, vision, and audio, while simultaneously offering developers direct programmatic control over the cost-to-performance ratio. </p><h2><b>The Shift from Static Reasoning to Controllable Thinking</b></h2><p>Rather than attempting to build a singular "god model" optimized strictly for state-of-the-art benchmark domination, Thinking Machines engineered Inkling for adaptability and efficiency in real-world workflows.</p><p>The standout feature of this release is Inkling's "controllable thinking effort." Developers can programmatically adjust the model's reasoning budget—scaling from 0.2 to 0.99—to dictate how hard the AI should "think" before generating an output. </p><p>As the company noted, "Inkling's continuous thinking effort lets you pick your point on the cost/performance curve—reaching the same score with a fraction of the tokens".</p><p>In practical terms, this allows enterprises to deploy Inkling with lower token expenditure for simpler tasks, while cranking up the compute overhead for complex, multi-step reasoning challenges. However, by keeping the thinking effort lower and generating fewer tokens, the cost-conscious enterprise can achieve high quality results and performance on simple tasks while spending less money, or, in the case of those running models locally, less costs on energy and compute resources.</p><p>During the model’s large-scale reinforcement learning (RL) training over 30 million rollouts, researchers observed an emergent phenomenon they called "chain of thought condensation". Over time, Inkling naturally learned to compress its internal reasoning steps—dropping grammatical overhead and connectives—while reaching the same accurate conclusions, resulting in drastically reduced latency.</p><h2><b>Epistemics and Censorship Resistance</b></h2><p>A notable element of Thinking Machines' release is its explicit focus on the model's epistemics—specifically its calibration, instruction following, and resistance to censorship. </p><p>In an ecosystem where open-weight models adopt either overly restrictive safety guardrails or echo state-aligned ideological talking points, Inkling was intentionally trained to answer directly on politically sensitive or heavily censored topics.</p><p>To validate this approach, Thinking Machines submitted Inkling to the <i>Propaganda and Censorship Eval</i> developed by AI startup Cognition. According to the published findings, Inkling demonstrated "strong patterns of censorship non-compliance," effectively resisting ideological capture or boilerplate refusals when presented with sensitive subjects.</p><p>Despite its resistance to censorship, the model maintains a robust defense against genuinely malicious, dangerous, or illegal queries. On the StrongREJECT benchmark—which tests responses to unambiguous harmful requests—Inkling scored 98.6%, placing it in line with strict frontier safety standards. Furthermore, on the FORTRESS benchmark, Inkling successfully navigated the line between safety and over-refusal: it achieved a 78.0% refusal rate on adversarial queries (such as those involving weapons, cyberattacks, or violence) while maintaining a 95.9% compliance rate on benign, look-alike queries.</p><p>Thinking Machines noted that typical open-weight vulnerabilities remain within the architecture. Internal safety evaluations revealed an "occasional tendency to comply with role-play and indirectly framed prompts concerning harmful topics". The company advised enterprise developers to treat the model's built-in refusals as just one layer of security, recommending the downstream deployment of external moderation tools—such as Llama Guard—to filter adversarial jailbreaks and enforce use-case-specific safety policies at the application level.</p><h2><b>Under the Hood: Architecture and Multimodality</b></h2><p>Inkling's scale is staggering, yet sparse. The MoE architecture features 975 billion total parameters, but only 41 billion parameters are active during any given token generation. It supports a massive context window of 1 million tokens and diverges from typical transformer models by using relative positional embeddings instead of the industry-standard Rotary Positional Embedding (RoPE).</p><p>True to the company's foundational vision, Inkling was trained from scratch to be natively multimodal. Unlike models that rely on bolted-on external encoders, Inkling uses an encoder-free early fusion approach. It directly ingests audio as discrete dMel spectrograms and visual data as 40x40 pixel patches via a hierarchical multi-layer perceptron (hMLP), projecting all modalities into a shared hidden space.</p><h2><b>Licensing: True Open-Source for the Enterprise</b></h2><p>For enterprise IT teams and developers, the most disruptive aspect of Inkling may be its licensing. Inkling is released under the permissive Apache 2.0 license.</p><p>In an ecosystem where many so-called "open" models from Western labs are tethered to dual-use commercial licenses, acceptable use restrictions, or revenue caps, an Apache 2.0 designation makes Inkling a true open-source foundation. This gives developers the legal freedom to download, modify, integrate, and commercialize the model weights entirely royalty-free.</p><p>The model is readily deployable across major open-source inference libraries—including SGLang, vLLM, TokenSpeed, and llama.cpp—and comes with a native NVFP4 quantized checkpoint optimized for NVIDIA Blackwell systems.</p><h2><b>Community Reactions: The Engineering Feat</b></h2><p>The AI community's response has been swift, praising both the model's openness and the underlying engineering execution.</p><p>In a<a href="https://x.com/johnschulman2/status/2077460227327467982"> post on X</a>, Thinking Machines co-founder John Schulman reflected on the rapid development cycle: "Inkling is out today, with open weights and in Tinker. It's been fun to watch this one come together: pretraining began last winter, and starting in mid-January a small team built up the coding, reasoning, and agentic training from there. We learned a lot building it, and I hope people find good uses for it."</p><div></div><p>Horace He, a researcher at Thinking Machines (previously from PyTorch), underscored the difficulty of the task in <a href="https://x.com/cHHillee/status/2077457790423969806">another post on X</a>: "It truly takes a village to release a model, perhaps especially an open weights model. Actually doing the entire process from scratch, from data to pretraining to posttraining to actual release, gives a lot of appreciation for anyone who does it!"</p><div></div><p>The broader open-source ecosystem has also embraced the technical integrations. Lysandre Debut, the Chief Open-Source Officer at Hugging Face, shared his enthusiasm regarding the model's optimization<a href="https://x.com/LysandreJik/status/2077459011285512267"> in his own X post</a>: "One thing I find quite striking is how much easier accelerating models has become... We replaced the model's causal Conv1D with the `causal-conv1d` kernel. One line changed, +4% tokens per second. We then replaced its attention implementation with FlashAttention-4. Another single change, another +11%. That's a total throughput improvement of about 15%, without changing the model architecture or retraining anything."</p><p>Tiezhen Wang, an ecosystem growth expert and ex-Googler, celebrated the release as a massive win for the open-source community, listing the model's impressive specifications on X, highlighting its "975B total, 41B active" size, "Native MTP support," and the highly coveted "Apache 2.0 license."</p><h2><b>Background: The Road to Inkling</b></h2><p>To understand the significance of Inkling, one has to look back at the rapid trajectory of Thinking Machines over the past 18 months.</p><p>When<a href="https://venturebeat.com/technology/ex-openai-cto-mira-murati-unveils-thinking-machines-a-startup-focused-on-multimodality-human-ai-collaboration"> Mira Murati departed OpenAI in late 2024 to found Thinking Machines</a> alongside industry veterans like John Schulman and Barret Zoph, the stated goal was to pivot away from building isolated autonomous agents. Instead, the company aimed to build flexible, multimodal systems designed for genuine human-AI collaboration and open science.</p><p>By July 2025, the startup had secured a historic $2 billion seed round led by Andreessen Horowitz at a $12 billion valuation. At the time, Murati promised the<a href="https://venturebeat.com/technology/mira-murati-says-her-startup-thinking-machines-will-release-new-product-in-months-with-significant-open-source-component"> impending release of a product with a "significant open source component" </a>to empower researchers and startups.</p><p>The company’s philosophy began coming into sharper focus in October 2025 with the launch of <a href="https://venturebeat.com/technology/thinking-machines-first-official-product-is-here-meet-tinker-an-api-for">Tinker</a>, a Python-based API for large language model fine-tuning that gave researchers granular control over training pipelines without the friction of distributed compute management.</p><p>That same month, Thinking Machines researcher <a href="https://venturebeat.com/ai/thinking-machines-challenges-openais-ai-scaling-strategy-first">Rafael Rafailov delivered a provocative critique of the AI industry at TED AI</a>. He argued that the current trajectory of simply throwing more compute at models was fundamentally flawed, noting that today's systems take shortcuts—like wrapping code in<code> try/except</code> blocks—because they are trained strictly for task completion rather than genuine learning. </p><p>Rafailov posited that the first artificial superintelligence would not be a "god model," but rather a "superhuman learner" capable of meta-learning and internalizing abstractions. Inkling’s architecture—specifically its controllable thinking effort and its ability to organically compress its chain of thought during RL—feels like the first tangible realization of Rafailov's thesis.</p><p>In May 2026, the lab teased its technical prowess with the<a href="https://venturebeat.com/technology/thinking-machines-shows-off-preview-of-near-realtime-ai-voice-and-video-conversation-with-new-interaction-models"> research preview of TML-Interaction-Small</a>, a system that eliminated "turn-based" chat by processing inputs and outputs simultaneously in 200ms chunks. This "full-duplex" breakthrough proved the company could build highly responsive, natively multimodal models from scratch.</p><p>Now, with Inkling out in the wild, Thinking Machines has delivered on its foundational promises. By offering a massive, natively multimodal model under a true open-source license, they aren't just giving developers a new tool—they are attempting to fundamentally rewrite the economics and accessibility of frontier AI development.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Artificial Intelligence]]></title>
<description><![CDATA[Latest from todaynewsDeepMind CEO again pushes for a frontier AI standards bodyDemis Hassabis argues that a US government-led industry effort is needed to keep AGI-like developments safe; analysts aren’t so sure.By Evan SchumanJul 15, 20268 minsArtificial IntelligenceGovernmentLaws and Regulation...]]></description>
<link>https://tsecurity.de/de/3671869/ai-nachrichten/artificial-intelligence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671869/ai-nachrichten/artificial-intelligence/</guid>
<pubDate>Wed, 15 Jul 2026 23:02:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><section class="latest-content"><div class="container"><header class="latest-content__header"><h2 class="latest-content__title sr-only"><span>Latest from today</span></h2></header><div class="grid latest-content__content"><div class="col-12 col-7@md col-8@lg"><div class="latest-content__content-featured"><a class="card card--xxl " href="https://www.computerworld.com/article/4197511/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body-2.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">news</span></div><div class="card__image"><div class="insider-image"><div class="image"><img width="400px" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197511-0-18848000-1784149211-shutterstock_2540223947.jpg?quality=50&amp;strip=all&amp;w=1046" data-id="idg_render_hero_index_one_card_image" sizes="
            (min-resolution: 3dppx) and (max-width: 600px) 900px,
            (min-resolution: 3dppx) and (max-width: 1200px) 1200px,

            (min-resolution: 2dppx) and (max-width: 600px) 900px,
            (min-resolution: 2dppx) and (max-width: 1200px) 1200px,

            (min-resolution: 1dppx) and (max-width: 600px) 900px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1300px" alt="Image" loading="eager"></div></div></div><h3 class="card__title">DeepMind CEO again pushes for a frontier AI standards body</h3><p class="card__description">Demis Hassabis argues that a US government-led industry effort is needed to keep AGI-like developments safe; analysts aren’t so sure.</p><div class="card__info"><span>By Evan Schuman</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T20:59:29+00:00">Jul 15, 2026</span></span><span>8 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Government</span></span><span class="card__tag"><span class="tag">Laws and Regulations</span></span></div></a>
		</div><div class="grid grid--cols-7@md grid--cols-8@lg latest-content__content-main"><div class="col-12 col-7@md col-4@lg latest-content__card-main"><a class="card " href="https://www.computerworld.com/article/4197437/apples-openai-lawsuit-the-lunacy-of-trying-to-limit-what-ex-employees-can-tell-future-employers.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">opinion</span></div><div class="card__image">
			<div class="insider-image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197437-0-98299000-1784131210-thinkstockphotos-493608259-100632547-orig.jpg?quality=50&amp;strip=all&amp;w=697" data-id="idg_render_hero_index_two_three_break" sizes="(min-resolution: 3dppx) and (max-width: 600px) 600px,
            (min-resolution: 3dppx) and (max-width: 1200px) 900px,

            (min-resolution: 2dppx) and (max-width: 600px) 600px,
            (min-resolution: 2dppx) and (max-width: 1200px) 900px,

            (min-resolution: 1dppx) and (max-width: 600px) 600px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1024px" alt="Image"></div></div></div><h3 class="card__title">Apple’s OpenAI lawsuit: The lunacy of trying to limit what ex-employees can tell future employers</h3><div class="card__info"><span>By Evan Schuman</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T15:59:35+00:00">Jul 15, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Government</span></span><span class="card__tag"><span class="tag">Laws and Regulations</span></span></div></a></div><div class="col-12 col-7@md col-4@lg latest-content__card-main"><span class="nativo-loading"></span><a class="card nativo" href="https://www.computerworld.com/article/4197338/what-problems-would-an-ai-speaker-from-openai-actually-solve.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">opinion</span></div><div class="card__image">
			<div class="insider-image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197338-0-98391100-1784130807-Apple-HomePod-mini-color-lineup.jpg?quality=50&amp;strip=all&amp;w=697" data-id="idg_render_hero_index_two_three_break" sizes="(min-resolution: 3dppx) and (max-width: 600px) 600px,
            (min-resolution: 3dppx) and (max-width: 1200px) 900px,

            (min-resolution: 2dppx) and (max-width: 600px) 600px,
            (min-resolution: 2dppx) and (max-width: 1200px) 900px,

            (min-resolution: 1dppx) and (max-width: 600px) 600px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1024px" alt="Image"></div></div></div><h3 class="card__title">What problems would an AI speaker from OpenAI actually solve?</h3><div class="card__info"><span>By Jonny Evans</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T15:52:45+00:00">Jul 15, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Vendors and Providers</span></span></div></a></div></div></div><div class="col-12 col-5@md col-4@lg latest-content__content-secondary"><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4192438/how-to-unionize-your-tech-workplace.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">feature</span></div><h3 class="card__title">How to unionize your tech workplace</h3><div class="card__info"><span>By Robert Mitchell</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T11:00:00+00:00">Jul 15, 2026</span></span><span>18 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Careers</span></span><span class="card__tag"><span class="tag">IT Jobs</span></span><span class="card__tag"><span class="tag">Technology Industry</span></span></div></a>
		</div><div class="latest-content__card-secondary"><span class="nativo-loading"></span><a class="card nativo" href="https://www.computerworld.com/article/1613762/android-widgets.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">tip</span></div><h3 class="card__title">5 wild ways to make Android widgets more useful</h3><div class="card__info"><span>By JR Raphael</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T09:45:00+00:00">Jul 15, 2026</span></span><span>12 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Android</span></span><span class="card__tag"><span class="tag">Mobile Apps</span></span><span class="card__tag"><span class="tag">Smartphones</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4197029/microsoft-is-forcing-an-enterprise-transition-to-passkeys.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Microsoft is forcing an enterprise transition to passkeys</h3><div class="card__info"><span>By Taryn Plumb</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T02:04:06+00:00">Jul 14, 2026</span></span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Access Control</span></span><span class="card__tag"><span class="tag">Authentication</span></span><span class="card__tag"><span class="tag">Identity and Access Management</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196704/siri-ai-steals-the-show-as-the-ios-27-public-beta-lands.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Siri AI steals the show as the iOS 27 public beta lands</h3><div class="card__info"><span>By Jonny Evans</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T15:47:35+00:00">Jul 14, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Operating Systems</span></span><span class="card__tag"><span class="tag">iOS</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196309/with-its-latest-layoffs-microsoft-goes-all-in-on-ai.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">opinion</span></div><h3 class="card__title">With its latest layoffs, Microsoft goes all in on AI</h3><div class="card__info"><span>By Preston Gralla</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T11:00:00+00:00">Jul 14, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">IT Strategy</span></span><span class="card__tag"><span class="tag">Microsoft</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196652/forg365-industrializes-microsoft-365-phishing-with-ai-generated-lures.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Forg365 industrializes Microsoft 365 phishing with AI-generated lures</h3><div class="card__info"><span>By Prasanth Aby Thomas</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T09:51:16+00:00">Jul 14, 2026</span></span><span>4 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Microsoft 365</span></span><span class="card__tag"><span class="tag">Office Suites</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></a>
		</div></div></div></div></section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><div class="content-listing-articles"><div class="container"><h2 class="content-listing-articles__title">Articles</h2><div class="content-listing-articles__container content-listing-articles__container--collapsed" data-collapse-articles="6" data-content-listing-articles><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’</h3><p class="card__description">Analysts and consultants applaud the move as potentially delivering the development consistency that the current offerings lack, but some worry that treating the company as neutral is a mistake.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Evan Schuman</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>8 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Nonprofits</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196262/ai-is-killing-low-cost-smartphones.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news analysis</span></div><h3 class="card__title">AI is killing low cost smartphones</h3><p class="card__description">Data from Omdia and Counterpoint shows that while Apple and Samsung thrive, the rest of the industry takes a dive</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Mobile Phones</span></span><span class="card__tag"><span class="tag">Smartphones</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196220/meta-pulls-instagram-ai-feature-amid-privacy-concerns.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Meta pulls Instagram AI feature amid privacy concerns</h3><p class="card__description">By specifying a public account, users could allow the AI ​​model to use the person’s images as a reference without the account holder being notified.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Viktor Eriksson</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>1 min</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Instagram</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195176/qa-how-google-plans-to-reinvent-the-spreadsheet-with-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">feature</span></div><h3 class="card__title">Q&amp;A: How Google plans to reinvent the spreadsheet with AI</h3><p class="card__description">Soon, Google wants to see AI doing the spreadsheet busywork, says Eric Birnbaum, director of product management for Google Sheets.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Matthew Finnegan</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>10 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Google Sheets</span></span><span class="card__tag"><span class="tag">Google Workspace</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4194931/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">brandpost</span><span class="card__sponsor-text">Sponsored by Tether</span></div><h3 class="card__title">Physical AI will see the fusion of robotics and AI transform the world</h3><p class="card__description"></p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By tether</span></div> <div class="card__info card__info--light"><span>Jul 9, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news analysis</span></div><h3 class="card__title">‘Rotten to its core’ — Apple files an explosive lawsuit against OpenAI</h3><p class="card__description">Apple accuses OpenAI and former Apple Vice President Tang Tan of extensive coordinated data theft and asks whether OpenAI’s hardware plans are based around exfiltrated Apple info.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 11, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195657/apple-is-prepping-for-life-after-the-ai-gold-rush.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">opinion</span></div><h3 class="card__title">Apple is prepping for life after the AI gold rush</h3><p class="card__description">The company's interest in compression of AI models is the right approach.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 11, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195678/microsoft-exchange-server-on-prem-gets-a-little-harder-to-use.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Microsoft Exchange Server on prem gets a little harder to use</h3><p class="card__description">The lightweight web client is going away, placing more demands on systems still clinging to Microsoft’s on-prem email system.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Email Clients</span></span><span class="card__tag"><span class="tag">Microsoft Exchange</span></span><span class="card__tag"><span class="tag">Microsoft Outlook</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195636/mistral-joins-rush-to-build-physical-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Mistral joins rush to build physical AI</h3><p class="card__description">Its Robostral Navigate AI model needs input from just one color camera, doing without Lidar, depth sensors, or multiple viewpoints.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Robotics</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195628/apple-will-buy-more-us-made-components-from-broadcom.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Apple will buy more US-made components from Broadcom</h3><p class="card__description">Chips and thin-film bulk acoustic resonator (FBAR) filters are on the menu.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Networking</span></span><span class="card__tag"><span class="tag">Wi-Fi</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195528/meta-launches-low-cost-muse-spark-1-1-as-enterprise-ai-spending-comes-under-scrutiny-2.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Meta launches low-cost Muse Spark 1.1 as enterprise AI spending comes under scrutiny</h3><p class="card__description">Meta says the model delivers competitive performance against OpenAI, Anthropic, and Google offerings while costing a fraction as much to run.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Anirban Ghoshal</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/1614899/android-contacts-management-ultimate-guide.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">how-to</span></div><h3 class="card__title">The ultimate guide to Android contacts management</h3><p class="card__description">Your Android phone's contacts are much more than just a glorified Rolodex. Ready for an unexpected productivity upgrade? </p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By JR Raphael</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>16 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Android</span></span><span class="card__tag"><span class="tag">Google</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195494/openai-launches-chatgpt-work-as-it-broadens-gpt-5-6-rollout-2.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">OpenAI launches ChatGPT Work as it broadens GPT-5.6 rollout</h3><p class="card__description">The enterprise AI agent combines ChatGPT, Codex, and GPT-5.6 to automate workplace tasks as OpenAI broadens rollout of its latest frontier models.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Gyana Swain</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></div></div></a></div></div><div class="grid content-listing-articles__button-wrapper">
			<div class="col-6 col-4@md col-start-5@md"><div class="content-listing-articles__button-show">
					<button class="button button--tertiary" type="button" data-toggle="expand">
						<span>Show more</span>
						<span>
							<svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
								<use xlink:href="#icon-chevron-down"></use>
							</svg>
						</span>
					</button>
				</div>
				<div class="content-listing-articles__button-show content-listing-articles__button-show--hide">
					<button class="button button--tertiary" type="button" data-toggle="collapse">
						<span>Show less</span>
						<span>
							<svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
								<use xlink:href="#icon-chevron-up"></use>
							</svg>
						</span>
					</button>
				</div></div><div class="col-6 col-4@md content-listing-articles__button-view-all">
						<a class="button" href="https://www.computerworld.com/artificial-intelligence/feed/page/2/" target="_blank"> View all </a></div></div></div></div><section class="suggested-content-upcoming-events"><div class="container">
				<h2 class="suggested-content-upcoming-events__title">Upcoming Events</h2><a class="grid suggested-content-upcoming-events__item" href="https://event.foundryco.com/cio-100-uk/" aria-label="Go to content"><div class="col-12 col-3@md suggested-content-upcoming-events__date-label dd"><span class="date-label">Sep/24</span></div><div class="col-12 col-4@md col-5@xl suggested-content-upcoming-events__image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/03/4141846-0-37933000-1772809522-CIO-Summit-2025_17.jpg?quality=50&amp;strip=all&amp;w=1045" alt="Image"></div></div>
			<div class="col-12 col-5@md col-4@xl suggested-content-upcoming-events__card">
				<div class="card card--xl">
					<div class="card__header"><span class="card__content-type">conference</span><span class="card__external-link-icon" data-url="https://event.foundryco.com/cio-100-uk/"><svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg"> <use xlink:href="#icon-arrow-up-right-from-square"></use></svg></span></div><h3 class="card__title">CIO 100 Awards &amp; Conference UK</h3><div class="card__info card__info--light"><span>24 Sep 2026</span><span>London, UK</span></div>
		<div class="card__tags"><span class="card__tag"><span class="tag">Microsoft 365</span></span></div></div>
			</div>
		</a><a class="grid suggested-content-upcoming-events__item" href="https://event.foundryco.com/cso-awards-conference-uk/" aria-label="Go to content"><div class="col-12 col-3@md suggested-content-upcoming-events__date-label dd"><span class="date-label">Nov/26</span></div><div class="col-12 col-4@md col-5@xl suggested-content-upcoming-events__image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4141741-0-97812100-1780312469-60CB82BE-5D6E-40E0-8E5E-0151C8C46E7F.jpg?quality=50&amp;strip=all&amp;w=929" alt="Image"></div></div>
			<div class="col-12 col-5@md col-4@xl suggested-content-upcoming-events__card">
				<div class="card card--xl">
					<div class="card__header"><span class="card__content-type">conference</span><span class="card__external-link-icon" data-url="https://event.foundryco.com/cso-awards-conference-uk/"><svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg"> <use xlink:href="#icon-arrow-up-right-from-square"></use></svg></span></div><h3 class="card__title">CSO Awards &amp; Conference UK</h3><div class="card__info card__info--light"><span>26 Nov 2026</span><span>London, UK</span></div>
		<div class="card__tags"><span class="card__tag"><span class="tag">Cyberattacks</span></span></div></div>
			</div>
		</a></div><div class="suggested-content-upcoming-events__button-container container">
						<a class="button" href="https://www.computerworld.com/events/"> View all events</a>
					</div>
				
			</section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><section class="related-content-resources">
				<div class="container">
				<h2 class="related-content-resources__title">Resources</h2><div class="grid related-content-resources__content"><div class="col-12 col-7@md col-8@lg grid grid--cols-7@md grid--cols-8@lg related-content-resources__main-content">
			<div class="col-12 col-7@md col-6@lg">
				<a class="card card--xxl" href="https://us.resources.computerworld.com/resources/accelerate-your-cloud-migration-with-atlassian-fastshift-6?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
					<div class="card__header">
						<span class="card__content-type">whitepaper</span>
					</div>
					<h3 class="card__title">Accelerate your cloud migration with Atlassian FastShift</h3>
					<p class="card__description"></p><p>Turn an Atlassian cloud migration into a faster, more predictable transformation. In this session, you’ll walk through the FastShift playbook.</p>
<p>The post <a rel="nofollow" href="https://com.wp.idg.zone/resources/accelerate-your-cloud-migration-with-atlassian-fastshift-6/">Accelerate your cloud migration with Atlassian FastShift</a> appeared first on <a rel="nofollow" href="https://com.wp.idg.zone/">Whitepaper Repository –</a>.</p>

					<div class="card__info">
						<span>
						By 
						Atlassian
						</span>
					</div>
					<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
			</div>
			<div class="col-2 related-content-resources__featured-image-wrapper">
				<img width="400px" loading="lazy" class="related-content-resources__image-featured" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040704.83.png" alt="Image">
			</div>
		</div><div class="col-12 col-5@md col-4@lg col-start-9@lg related-content-resources__cards"><div class="grid grid--cols-5@md grid--cols-4@lg related-content-resources__card-wrapper">
				<div class="col-12 col-5@md col-3@lg">
					<a class="card card--sm" href="https://us.resources.computerworld.com/resources/warum-sich-teams-fur-cloud-entscheiden-9?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
						<div class="card__header">
							<span class="card__content-type">whitepaper</span>
						</div>
						<h3 class="card__title">Warum sich Teams für Cloud entscheiden</h3>
						<div class="card__info">
							<span>
							By 
							Atlassian
							</span>
						</div>
						<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
				</div>
				<div class="col-1">
					<img width="400px" loading="lazy" class="related-content-resources__image-side" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040716.4772.png" alt="Image">
				</div>
			</div><div class="grid grid--cols-5@md grid--cols-4@lg related-content-resources__card-wrapper">
				<div class="col-12 col-5@md col-3@lg">
					<a class="card card--sm" href="https://us.resources.computerworld.com/resources/pourquoi-les-equipes-optent-pour-la-solution-cloud-3?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
						<div class="card__header">
							<span class="card__content-type">whitepaper</span>
						</div>
						<h3 class="card__title">Pourquoi les équipes optent pour la solution cloud</h3>
						<div class="card__info">
							<span>
							By 
							Atlassian
							</span>
						</div>
						<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
				</div>
				<div class="col-1">
					<img width="400px" loading="lazy" class="related-content-resources__image-side" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040728.9116.png" alt="Image">
				</div>
			</div></div>
		</div><div class="related-content-resources__button-container">
			<a class="button" target="_blank" href="https://us.resources.computerworld.com/"> View all </a>
		</div></div>
			</section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><section class="related-content-podcasts"><div class="container"><h2 class="related-content-podcasts__title">Podcasts</h2><div class="grid related-content-podcasts__content"><a class="col-12 col-7@md col-8@lg grid grid--cols-7@md grid--cols-8@lg related-content-podcasts__main-content" href="https://www.computerworld.com/podcasts/2-minute-tech-briefing/" aria-label="Go to content"><div class="col-12 col-7@md col-2@lg related-content-podcasts__image">
			<div class="image image--aspect-ratio-1-1">
				<img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2025/11/100065453-0-01782600-1762961273-2-min-tech-briefing-logo-16x9-4.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Image">
			</div>
		</div><div class="col-12 col-7@md col-6@lg"><div class="card card--xl"><div class="card__header"><span class="card__content-type"> podcasts</span></div><h3 class="card__title">2-Minute Tech Briefing</h3><p class="card__description">Catch up on the latest enterprise IT news in a fast-paced video briefing with host Arnold Davick. Listen to the show on Computerworld, YouTube, Apple and Spotify.</p><div class="card__info card__info--light"><span>81  episodes</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Emerging Technology</span></span></div></div></div></a><ul class="col-12 col-5@md col-4@lg col-start-9@lg related-content-podcasts__cards"><li class="related-content-podcasts__card"><a href="https://www.computerworld.com/podcast/4176380/microsoft-copilot-growth-claudebleed-risk-linkedin-gdpr-complaint-ep-84.html" aria-label="Go to episode"><div class="related-content-podcasts__episode-label">
			<span class="episode-label">
				<span> Ep. 81</span>
				<span>
				<svg class="icon" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
					<use xlink:href="#icon-podcast"></use>
				</svg>
			</span>
			</span>
		</div><div class="card card--xs"><h3 class="card__title">Microsoft Copilot Growth, ClaudeBleed Risk, LinkedIn GDPR Complaint | Ep. 84</h3><div class="card__info">
				<span>By Arnold Davick</span>
			</div><div class="card__info card__info--light">
			<span>Mar 20, 2024</span><span>2 mins</span>
		</div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></a></li><li class="related-content-podcasts__card"><a href="https://www.computerworld.com/podcast/4176367/chrome-gemini-ai-agents-cisa-infrastructure-cyber-resilience-ep-83.html" aria-label="Go to episode"><div class="related-content-podcasts__episode-label">
			<span class="episode-label">
				<span> Ep. 80</span>
				<span>
				<svg class="icon" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
					<use xlink:href="#icon-podcast"></use>
				</svg>
			</span>
			</span>
		</div><div class="card card--xs"><h3 class="card__title">Chrome Gemini, AI Agents, CISA Infrastructure Cyber Resilience | Ep. 83</h3><div class="card__info">
				<span>By Arnold Davick</span>
			</div><div class="card__info card__info--light">
			<span>Mar 20, 2024</span><span>2 mins</span>
		</div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></a></li></ul></div></div></section><section class="related-content-video"><div class="container"><h2 class="related-content-video__title">Video on demand</h2><div class="grid related-content-video__main">        <div class="col-12 col-4@lg related-content-video__main-card card card--xl">
            <div class="card__header"><span class="card__content-type">video</span></div>            
            <a class="card card--xl" href="https://www.computerworld.com/video/4196734/why-ai-agents-fail-when-enterprises-dont-define-the-job.html" aria-label="Go to content">
                <h3 class="card__title">Why AI agents fail when enterprises don’t define the job</h3>            </a>
                            <p class="card__description mt-3">Enterprises are investing heavily in AI agents, but many projects fail when companies skip clear goals, guardrails, governance and success metrics.</p>
            
                         <div class="card__info card__info--light"><span>Jul 14, 2026 </span><span>33 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">IT Governance</span></span></div>        </div>
                <div class="col-12 col-8@lg related-content-video__video">
                            <div class="youtube-video">
                    &gt;
					
				</div>                </div>
                    </div>
        </div><div class="related-content-video__cards-container">
                        <div class="related-content-video__cards-wrap">
                            <ul class="grid related-content-video__cards">        <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4193952/why-enterprise-ai-projects-stall-before-delivering-real-value.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4193952-0-52301800-1783446508-youtube-thumbnail-gu6x40jhZ1s_3cbf50.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">Why enterprise AI projects stall before delivering real value</h3>
                                         <div class="card__info card__info--light"><span>Jul 7, 2026 </span><span>29 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">ROI and Metrics</span></span></div>                </div>
            </a>
        </li>
                <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4191262/how-ai-is-breaking-job-interviews-skills-testing-and-evaluation.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4191262-0-24248500-1782847008-youtube-thumbnail-lVEejCXC4lU_b223c5.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">How AI is breaking job interviews, skills testing and evaluation</h3>
                                         <div class="card__info card__info--light"><span>Jun 30, 2026 </span><span>32 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Hiring</span></span><span class="card__tag"><span class="tag">IT Skills and Training</span></span></div>                </div>
            </a>
        </li>
                <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4188534/how-ai-is-reshaping-cybersecurity.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4188534-0-45176600-1782243369-youtube-thumbnail-5DLoQMU0nZc_de9df9.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">How AI is reshaping cybersecurity</h3>
                                         <div class="card__info card__info--light"><span>Jun 23, 2026 </span><span>44 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Cyberattacks</span></span><span class="card__tag"><span class="tag">Cybercrime</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div>                </div>
            </a>
        </li>
        </ul></div></div><div class="related-content-video__button-container"><a class="button" target="_self" href="https://www.computerworld.com/videos/">See all videos</a></div></section></div><section class="suggested-content-various"><div class="container"><div class="grid suggested-content-various__content"><div class="col-12 col-3@lg">
			<h2 class="suggested-content-various__title">Show me more</h2><div class="suggested-content-various__filters"><span class="suggested-content-various__filter"><button class="chip chip--filter chip--active" type="button" data-filter-key="latest">Latest</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="article">Articles</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="podcast">Podcasts</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="video">Videos</button></span></div>
		</div><div class="col-12 col-9@lg suggested-content-various__items-wrap"><div class="grid grid--cols-9@lg suggested-content-various__items"><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4195055/apple-finally-calls-time-on-15-year-old-device-support.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">opinion</span> </div> <h3 class="card__title">Apple finally calls time on 15-year-old device support</h3> <div class="card__info"><span>By Jonny Evans</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T16:15:14+00:00">Jul 9, 2026</span><span>4 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Smartphones</span></span><span class="card__tag"><span class="tag">iPhone</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4195055-0-47500100-1783613766-iPhone4s_3up_Photo_Siri_Sprgbd_PRINT.jpg?quality=50&amp;strip=all&amp;w=219" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4194931/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">brandpost</span> <span class="card__sponsor-text">Sponsored by Tether</span></div> <h3 class="card__title">Physical AI will see the fusion of robotics and AI transform the world</h3> <div class="card__info"><span>By tether</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T11:11:53+00:00">9 Jul 2026</span><span>6 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4194931-0-76347600-1783595551-QVAC-Paid-Ad-1-_-1200-x-800.png?w=375" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4194914/spacexai-launches-grok-4-5-touts-lower-coding-task-costs-than-ai-rivals-2.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">news</span> </div> <h3 class="card__title">SpaceXAI launches Grok 4.5, touts lower coding-task costs than AI rivals</h3> <div class="card__info"><span>By Prasanth Aby Thomas</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T10:26:11+00:00">Jul 9, 2026</span><span>5 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Developer</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4194914-0-24417700-1783592810-AI-vibe-coding-one-hand-is-robot-one-hand-is-human.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4176380/microsoft-copilot-growth-claudebleed-risk-linkedin-gdpr-complaint-ep-84.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">Microsoft Copilot Growth, ClaudeBleed Risk, LinkedIn GDPR Complaint | Ep. 84</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-22T15:04:16+00:00">May 22, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-46106000-1779462321-youtube-thumbnail-5PkKYThsKy8.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4176367/chrome-gemini-ai-agents-cisa-infrastructure-cyber-resilience-ep-83.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">Chrome Gemini, AI Agents, CISA Infrastructure Cyber Resilience | Ep. 83</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-22T14:53:18+00:00">May 22, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-06017100-1779461653-youtube-thumbnail-XH7vduM7uz8.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4172579/ai-triage-gains-model-reviews-ask-jeeves-shutdown-ep-82.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">AI Triage Gains, Model Reviews, Ask Jeeves Shutdown | Ep. 82</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-18T19:31:15+00:00">May 18, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-62824900-1779132751-youtube-thumbnail-P3R6blMndrU.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4185559/why-ai-agents-could-create-a-new-control-and-security-crisis.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">Why AI agents could create a new control and security crisis</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-16T11:47:15+00:00">Jun 16, 2026</span><span>28 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">IT Governance</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4185559-0-48713800-1781610470-youtube-thumbnail-uPpd9EJ4iNI_55eb26.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4182978/does-quality-suffer-when-ai-generates-code.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">Does quality suffer when AI generates code?</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-09T14:32:51+00:00">Jun 9, 2026</span><span>35 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Code Security</span></span><span class="card__tag"><span class="tag">Developer</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4182978-0-61230000-1781015610-youtube-thumbnail-1hAfDQkuyhs_faa994.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4180043/what-happens-when-ai-starts-selling-to-ai.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">What happens when AI starts selling to AI?</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-02T15:00:42+00:00">Jun 2, 2026</span><span>38 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Procurement Software</span></span><span class="card__tag"><span class="tag">Salesforce Automation </span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4180043-0-78180900-1780412479-youtube-thumbnail-jPv-TAenlto_c79318.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div></div></div></div></div></section>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepMind CEO again pushes for a frontier AI standards body]]></title>
<description><![CDATA[Google DeepMind CEO Demis Hassabis on Tuesday reiterated his push for an AI industry self-regulation effort, led by the US government, that is particularly focused on artificial general intelligence (AGI) and national security. 



But it is precisely that focus on national security that may make...]]></description>
<link>https://tsecurity.de/de/3671860/it-nachrichten/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671860/it-nachrichten/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body/</guid>
<pubDate>Wed, 15 Jul 2026 23:01:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google DeepMind CEO Demis Hassabis on Tuesday reiterated his push for an AI industry self-regulation effort, led by the US government, that is particularly focused on <a href="https://www.computerworld.com/article/4174181/google-talks-singularity-while-scaling-up-agentic-ai-for-enterprises-2.html" target="_blank">artificial general intelligence (AGI)</a> and national security. </p>



<p class="wp-block-paragraph">But it is precisely that focus on national security that may make the results of such an effort, assuming it happens, less than palatable outside of the US.</p>



<p class="wp-block-paragraph">“The rapid progress we’re seeing in AI requires a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous,” <a href="https://demishassabis.substack.com/p/a-framework-for-frontier-ai-and-the-dawning-of-a-new-age" target="_blank" rel="noreferrer noopener">Hassabis wrote</a>. “The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.”</p>



<p class="wp-block-paragraph">He noted, however, that the funding would need to be substantial, and would most likely come from industry, to allow the new body to attract world-class technical talent and obtain the necessary compute resources for large-scale testing.</p>



<p class="wp-block-paragraph">Hassabis said he would propose that the organization “be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security,” and that AI vendor participants would be encouraged to adopt best practices, such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research.</p>



<p class="wp-block-paragraph">This is not the first time Hassabis has <a href="https://www.computerworld.com/article/4178398/deepmind-ceo-agi-could-be-here-in-three-years.html" target="_blank">expressed worries about AGI</a>. He has already worked on <a href="https://www.cio.com/article/4168122/us-government-agency-to-safety-test-frontier-ai-models-before-release.html" target="_blank">a US government initiative evaluating AI safety</a>, which involved DeepMind, Microsoft and xAI (now SpaceXAI) working with the Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce. It allowed CAISI to conduct pre-deployment evaluations and targeted research to “better assess frontier AI capabilities and advance the state of AI security.”  </p>



<h2 class="wp-block-heading">The rest of the world may have concerns</h2>



<p class="wp-block-paragraph">Analysts and consultants were mixed about the move, with most expressing concerns about whether an industry-focused group would prioritize the public’s best interests.</p>



<p class="wp-block-paragraph">“Self-regulation is not viable because it implies everyone is able to regulate themselves and will do so in line with the best interests of the public. Most tech vendors don’t have the capacity to self-regulate. They would just prefer a set of rules within which they can operate,” said Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>. “For-profit organizations are required to do what is best for their shareholders, and external regulation ensures that those organizations are never in a conflict of interest where they have to choose between what is good for their shareholders and what is good for the public.”</p>



<p class="wp-block-paragraph">And, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, given the international nature of AI models, an effort coordinated by the US government might alienate other countries. </p>



<p class="wp-block-paragraph">“National security is the proposal’s accelerator in Washington and its poison pill abroad: the framing that opens the only gate available at home invites foreign capitals to read the institution as an instrument of American strategy,” he pointed out. </p>



<p class="wp-block-paragraph">“The map is already plural,” he said. “Brussels switches on enforcement powers over general-purpose models [starting in August 2026], London runs the AI Security Institute, and Beijing licenses on its own terms. California and New York have legislated for frontier models at home. The durable route is shared technical evidence with sovereign enforcement, sealed through mutual recognition rather than deference, with India and the other major non-Western markets holding authorship rather than seats.”</p>



<p class="wp-block-paragraph">Gogia added that the rules enacted by even such a group may not address all of the key concerns of enterprise IT. A US government effort along the lines that Hassabis is proposing would result in testing that “sits close to intelligence and industrial policy, and those functions will not stay neatly separated. A model can pass every catastrophic-risk test and still fail the enterprise on privacy, reliability, and liability,” he noted.</p>



<p class="wp-block-paragraph">Walmart’s former director of cybersecurity <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, who is now an independent cybersecurity consultant, said he found the proposal “well-intentioned, but it addresses a highly polarized topic at a time when commercial interests carry unprecedented political influence, which is not always applied benevolently.”</p>



<p class="wp-block-paragraph">He added, “an exclusive US standard that is not globally respected or enforceable would likely fail to achieve its core purpose and would place US companies at a competitive disadvantage.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that a deep dive into how <a href="https://www.finra.org/" target="_blank" rel="noreferrer noopener">FINRA</a> operates today is illustrative of what IT leaders can expect from this effort, assuming the industry adopts that model.</p>



<p class="wp-block-paragraph">“When the CEOs of the five companies that would be regulated are also the primary drafters of the standards, the standards will reflect those companies’ interests. FINRA has an independent board, but the operational reality is that member firm perspectives dominate the working groups that write the actual rules,” he said. “There is no reason to expect an AI equivalent to work differently, and every reason to expect it to work worse, because AI standardization is happening faster than any industry has ever attempted to standardize itself, and speed is the enemy of independent oversight.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, was even more emphatically opposed to the Hassabis proposal.</p>



<p class="wp-block-paragraph">“Asking Big Tech companies to self-police is analogous to allowing foxes to guard the henhouse. It hasn’t worked to date, and it won’t work going forward. Expecting these organizations to somehow change their ways at this point in time represents the height of naïve thinking,” Levy said. “The framework proposed by Demis Hassabis is a self-serving roadmap for an industry bent on racing to the AI horizon regardless of the harms caused along the way. It is impossible to quantify the dangers to broader society should frameworks allowing self-regulation become the norm.”</p>



<h2 class="wp-block-heading">Some love the proposal</h2>



<p class="wp-block-paragraph">An almost completely opposite stance came from <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, who applauded the proposed move.</p>



<p class="wp-block-paragraph">“This is one of the rare setups where industry self-regulation has a real shot, and enterprise IT should be enthusiastically rooting for it,” he said. “It fails when harms are externalized, such as in social media content moderation. Or when the overseer outsources judgment to the overseen, such as the FAA’s delegation to Boeing before the 737 MAX. It works when everyone in the industry shares the catastrophic downside.”</p>



<p class="wp-block-paragraph">He suggested, however, that the best precedent here isn’t FINRA, it’s INPO, the Institute of Nuclear Power Operations, which the nuclear industry created within months of the <a href="https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/3mile-isle" target="_blank" rel="noreferrer noopener">1979 Three Mile Island partial reactor meltdown</a> “on the logic that an accident anywhere is an accident everywhere. INPO peer-reviews every US plant, its evaluations move insurance premiums, and it sits on top of the NRC’s statutory floor. That is a public-private stack very close to what Hassabis is describing. Frontier AI has the same structure: one lab’s catastrophic failure brings regulation down on all of them.”</p>



<p class="wp-block-paragraph">For enterprise CIOs and other IT executives, Goryunov said, that model has the potential for being a big win.</p>



<p class="wp-block-paragraph"><strong>“</strong>Today, every enterprise duplicates the same AI diligence of red-teaming, eval suites, governance committees and each does so with less information than any certifying body would have,” Goryunov said. “A credible standards regime does for AI what UL did for electrical equipment and SOC2 did for cloud: it converts an unknowable risk into a procurable product and gives boards a defensible standard of care. That’s not red tape. That’s peace of mind with an audit trail.”</p>



<p class="wp-block-paragraph">However, Mahapatra said, “the countervailing view is that the alternative to industry-led standards is probably not thoughtful legislation. It is probably no standards, or state-by-state fragmentation, or the current pattern of ex-post enforcement actions where regulators surface concerns years after harm has already occurred.” </p>



<p class="wp-block-paragraph">Thus, he noted, “Hassabis is making the reasonable argument that imperfect fast standards are better than perfect slow ones, and there is genuine merit to that view for topics like agent identity, evaluation methodology, and interoperability, which are exactly the areas <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">OpenClaw is also targeting</a>.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepMind CEO again pushes for a frontier AI standards body]]></title>
<description><![CDATA[Google DeepMind CEO Demis Hassabis on Tuesday reiterated his push for an AI industry self-regulation effort, led by the US government, that is particularly focused on artificial general intelligence (AGI) and national security. 



But it is precisely that focus on national security that may make...]]></description>
<link>https://tsecurity.de/de/3671859/it-nachrichten/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671859/it-nachrichten/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body/</guid>
<pubDate>Wed, 15 Jul 2026 23:01:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google DeepMind CEO Demis Hassabis on Tuesday reiterated his push for an AI industry self-regulation effort, led by the US government, that is particularly focused on <a href="https://www.computerworld.com/article/4174181/google-talks-singularity-while-scaling-up-agentic-ai-for-enterprises-2.html" target="_blank">artificial general intelligence (AGI)</a> and national security. </p>



<p class="wp-block-paragraph">But it is precisely that focus on national security that may make the results of such an effort, assuming it happens, less than palatable outside of the US.</p>



<p class="wp-block-paragraph">“The rapid progress we’re seeing in AI requires a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous,” <a href="https://demishassabis.substack.com/p/a-framework-for-frontier-ai-and-the-dawning-of-a-new-age" target="_blank" rel="noreferrer noopener">Hassabis wrote</a>. “The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.”</p>



<p class="wp-block-paragraph">He noted, however, that the funding would need to be substantial, and would most likely come from industry, to allow the new body to attract world-class technical talent and obtain the necessary compute resources for large-scale testing.</p>



<p class="wp-block-paragraph">Hassabis said he would propose that the organization “be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security,” and that AI vendor participants would be encouraged to adopt best practices, such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research.</p>



<p class="wp-block-paragraph">This is not the first time Hassabis has <a href="https://www.computerworld.com/article/4178398/deepmind-ceo-agi-could-be-here-in-three-years.html" target="_blank">expressed worries about AGI</a>. He has already worked on <a href="https://www.cio.com/article/4168122/us-government-agency-to-safety-test-frontier-ai-models-before-release.html" target="_blank">a US government initiative evaluating AI safety</a>, which involved DeepMind, Microsoft and xAI (now SpaceXAI) working with the Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce. It allowed CAISI to conduct pre-deployment evaluations and targeted research to “better assess frontier AI capabilities and advance the state of AI security.”  </p>



<h2 class="wp-block-heading">The rest of the world may have concerns</h2>



<p class="wp-block-paragraph">Analysts and consultants were mixed about the move, with most expressing concerns about whether an industry-focused group would prioritize the public’s best interests.</p>



<p class="wp-block-paragraph">“Self-regulation is not viable because it implies everyone is able to regulate themselves and will do so in line with the best interests of the public. Most tech vendors don’t have the capacity to self-regulate. They would just prefer a set of rules within which they can operate,” said Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>. “For-profit organizations are required to do what is best for their shareholders, and external regulation ensures that those organizations are never in a conflict of interest where they have to choose between what is good for their shareholders and what is good for the public.”</p>



<p class="wp-block-paragraph">And, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, given the international nature of AI models, an effort coordinated by the US government might alienate other countries. </p>



<p class="wp-block-paragraph">“National security is the proposal’s accelerator in Washington and its poison pill abroad: the framing that opens the only gate available at home invites foreign capitals to read the institution as an instrument of American strategy,” he pointed out. </p>



<p class="wp-block-paragraph">“The map is already plural,” he said. “Brussels switches on enforcement powers over general-purpose models [starting in August 2026], London runs the AI Security Institute, and Beijing licenses on its own terms. California and New York have legislated for frontier models at home. The durable route is shared technical evidence with sovereign enforcement, sealed through mutual recognition rather than deference, with India and the other major non-Western markets holding authorship rather than seats.”</p>



<p class="wp-block-paragraph">Gogia added that the rules enacted by even such a group may not address all of the key concerns of enterprise IT. A US government effort along the lines that Hassabis is proposing would result in testing that “sits close to intelligence and industrial policy, and those functions will not stay neatly separated. A model can pass every catastrophic-risk test and still fail the enterprise on privacy, reliability, and liability,” he noted.</p>



<p class="wp-block-paragraph">Walmart’s former director of cybersecurity <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, who is now an independent cybersecurity consultant, said he found the proposal “well-intentioned, but it addresses a highly polarized topic at a time when commercial interests carry unprecedented political influence, which is not always applied benevolently.”</p>



<p class="wp-block-paragraph">He added, “an exclusive US standard that is not globally respected or enforceable would likely fail to achieve its core purpose and would place US companies at a competitive disadvantage.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that a deep dive into how <a href="https://www.finra.org/" target="_blank" rel="noreferrer noopener">FINRA</a> operates today is illustrative of what IT leaders can expect from this effort, assuming the industry adopts that model.</p>



<p class="wp-block-paragraph">“When the CEOs of the five companies that would be regulated are also the primary drafters of the standards, the standards will reflect those companies’ interests. FINRA has an independent board, but the operational reality is that member firm perspectives dominate the working groups that write the actual rules,” he said. “There is no reason to expect an AI equivalent to work differently, and every reason to expect it to work worse, because AI standardization is happening faster than any industry has ever attempted to standardize itself, and speed is the enemy of independent oversight.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, was even more emphatically opposed to the Hassabis proposal.</p>



<p class="wp-block-paragraph">“Asking Big Tech companies to self-police is analogous to allowing foxes to guard the henhouse. It hasn’t worked to date, and it won’t work going forward. Expecting these organizations to somehow change their ways at this point in time represents the height of naïve thinking,” Levy said. “The framework proposed by Demis Hassabis is a self-serving roadmap for an industry bent on racing to the AI horizon regardless of the harms caused along the way. It is impossible to quantify the dangers to broader society should frameworks allowing self-regulation become the norm.”</p>



<h2 class="wp-block-heading">Some love the proposal</h2>



<p class="wp-block-paragraph">An almost completely opposite stance came from <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, who applauded the proposed move.</p>



<p class="wp-block-paragraph">“This is one of the rare setups where industry self-regulation has a real shot, and enterprise IT should be enthusiastically rooting for it,” he said. “It fails when harms are externalized, such as in social media content moderation. Or when the overseer outsources judgment to the overseen, such as the FAA’s delegation to Boeing before the 737 MAX. It works when everyone in the industry shares the catastrophic downside.”</p>



<p class="wp-block-paragraph">He suggested, however, that the best precedent here isn’t FINRA, it’s INPO, the Institute of Nuclear Power Operations, which the nuclear industry created within months of the <a href="https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/3mile-isle" target="_blank" rel="noreferrer noopener">1979 Three Mile Island partial reactor meltdown</a> “on the logic that an accident anywhere is an accident everywhere. INPO peer-reviews every US plant, its evaluations move insurance premiums, and it sits on top of the NRC’s statutory floor. That is a public-private stack very close to what Hassabis is describing. Frontier AI has the same structure: one lab’s catastrophic failure brings regulation down on all of them.”</p>



<p class="wp-block-paragraph">For enterprise CIOs and other IT executives, Goryunov said, that model has the potential for being a big win.</p>



<p class="wp-block-paragraph"><strong>“</strong>Today, every enterprise duplicates the same AI diligence of red-teaming, eval suites, governance committees and each does so with less information than any certifying body would have,” Goryunov said. “A credible standards regime does for AI what UL did for electrical equipment and SOC2 did for cloud: it converts an unknowable risk into a procurable product and gives boards a defensible standard of care. That’s not red tape. That’s peace of mind with an audit trail.”</p>



<p class="wp-block-paragraph">However, Mahapatra said, “the countervailing view is that the alternative to industry-led standards is probably not thoughtful legislation. It is probably no standards, or state-by-state fragmentation, or the current pattern of ex-post enforcement actions where regulators surface concerns years after harm has already occurred.” </p>



<p class="wp-block-paragraph">Thus, he noted, “Hassabis is making the reasonable argument that imperfect fast standards are better than perfect slow ones, and there is genuine merit to that view for topics like agent identity, evaluation methodology, and interoperability, which are exactly the areas <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">OpenClaw is also targeting</a>.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on CIO.com.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’]]></title>
<description><![CDATA[OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that the popular platform has thus far lacked. Still, some worry about the risks created by the move. 



“Our ambition is for OpenClaw...]]></description>
<link>https://tsecurity.de/de/3671162/ai-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671162/ai-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:35 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that <a href="https://www.computerworld.com/article/4128257/openclaw-the-ai-agent-thats-got-humans-taking-orders-from-bots.html" target="_blank">the popular platform </a>has thus far lacked. Still, some worry about the risks created by the move. </p>



<p class="wp-block-paragraph">“Our ambition is for OpenClaw to be the Switzerland of AI. Neutral ground where every model and every lab can plug into the technology and collaborate on standards in the era of agents,” <a href="https://openclaw.ai/blog/introducing-openclaw-foundation/" target="_blank" rel="noreferrer noopener">OpenClaw said in a post</a>. “That work is already underway in Foundation-convened councils on agent identity, agent profiles, evals, and enterprise deployment.”</p>



<p class="wp-block-paragraph">The statement, co-authored by OpenClaw creator <a href="https://www.linkedin.com/in/steipete/" target="_blank" rel="noreferrer noopener">Peter Steinberger</a>, pointed out, “the great open source projects of our time — Linux, Apache, Mozilla — endure because a neutral steward stands behind them. That is the role we are taking on to keep OpenClaw MIT licensed, open, and independent so that everyone building on it can trust it will be here for the long term.”</p>



<p class="wp-block-paragraph">But it reassured users that the original OpenClaw leadership is still in charge.</p>



<p class="wp-block-paragraph">“Peter built this thing and Peter keeps making the calls, especially the technical ones. Since joining OpenAI earlier this year, he has continued to steward OpenClaw as an open and independent project, and OpenAI has made a commitment to keep it that way,” the post said. “The foundation is here to serve: good governance, stable funding, and paying the people who keep the claws alive.”</p>



<p class="wp-block-paragraph">However, some analysts and consultants were skeptical about how much true independence Steinberger would have, given his salaried role with OpenAI. </p>



<h2 class="wp-block-heading">Neutrality claim in question</h2>



<p class="wp-block-paragraph">“The Switzerland of AI neutrality claim collapses under its own announcement,” said <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520. “OpenAI runs a team [at OpenAI] called Claw Labs that Peter leads and OpenAI is a major donor to OpenClaw. The ‘neutral steward’s’ chief technical decision maker is employed by one of the competing labs it is supposed to be neutral with.” To OpenAI, he said, OpenClaw is closer to a tax-exempt nonprofit subsidiary than it is to a neutral ‘Switzerland of AI.’</p>



<p class="wp-block-paragraph">He pointed out that, in addition, Microsoft is shipping <a href="https://www.computerworld.com/article/4173442/enterpriseclaw-wants-to-bring-governance-to-the-openclaw-era-2.html" target="_blank">the enterprise version</a> of OpenClaw, and Nvidia is shipping the hardware bundle. “This is being called the Switzerland of AI, but Switzerland does not have its central bank run by France,” he observed.</p>



<p class="wp-block-paragraph">Kenney said that what the new OpenClaw has actually built is “a shared dependency that several competitors fund, staff, and steer, wrapped in a nonprofit structure. Enterprise IT should understand that structure, because treating OpenClaw as neutral is a mistake,” adding that CIOs need to look at this development devoid of the emotional component. </p>



<p class="wp-block-paragraph">“There is a strategic irony here that CIOs should sit with,” Kenney said. “If OpenClaw succeeds at becoming the universal agent substrate, then every model plugs into the same identity layer, the same profiles, and the same deployment plumbing. The thing every vendor is racing to own becomes a commodity that nobody owns.” He pointed out that, in the short term, that is genuinely good news for buyers because it means less lock-in and more portability.</p>



<p class="wp-block-paragraph">“But,” he said, “when the connective tissue is free and natural, the only labs that benefit are the ones with the best models and the deepest distribution. Commoditize the layer below you and you compete on the layer where you are already strongest. The foundation is not a charity. It is the biggest players agreeing to stop fighting over the plumbing so they can fight over the water, and the enterprise is the one paying the water bill either way.”</p>



<h2 class="wp-block-heading">Good news, bad news</h2>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy, liked the potential consistency that could emerge from the structural change, given the complexity of agent development today. </p>



<p class="wp-block-paragraph">“We are seeing a lot of OpenClaw variants hit the market, such as those from Nvidia as well as competing products from cloud and SaaS vendors. A common base helps solidify the common parts,” Andersen noted. “That said, a common challenge is the sustainability of these open source foundations over time. In addition to releasing code, these foundations need funding to evolve and grow. And that funding needs to come from continued momentum to incentivize existing members to increase investment and recruit new members to join.”</p>



<p class="wp-block-paragraph">Andersen stressed that IT buyers need to keep an eye on the roadmap for any OpenClaw variant they choose to deploy, “as that will directly impact the foundation, and the momentum of the foundation and common base. If the common base loses momentum, it can lead to forks, or just a loss of innovation. When that happens, members tend to back away, which puts customers in limbo.”</p>



<p class="wp-block-paragraph">But not everyone sees the promised structure as entirely good for IT.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/ishraqkhann/" target="_blank" rel="noreferrer noopener">Ishraq Khan</a>, CEO at coding productivity tool vendor Kodezi, said, “most CIOs do not want to bet their future entirely on a single model vendor. They want Claude for some workloads, GPT for others, open models for sensitive environments, and potentially internally fine-tuned systems for specific use cases. The problem is that every vendor currently brings its own identity system, tool interfaces, permissions model, and operational assumptions. That fragmentation does not scale.”</p>



<p class="wp-block-paragraph">He said, “the risk if standards fail is straightforward: every vendor builds its own closed ecosystem, enterprises become locked into individual stacks, and security becomes dramatically harder. The opportunity if OpenClaw succeeds is equally significant: enterprises get portable agents, common identity standards, interoperable tooling, and a healthier competitive market around models rather than ecosystems.”</p>



<h2 class="wp-block-heading">Will it remain a nonprofit?</h2>



<p class="wp-block-paragraph">However, said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, one of the key details that IT executives will want to keep in mind is that OpenAI also began as a nonprofit, but it was quickly <a href="https://www.computerworld.com/article/4056490/openai-microsoft-discuss-shape-of-future-relationship.html" target="_blank">seen as not adhering to nonprofit objectives</a>. </p>



<p class="wp-block-paragraph">“OpenAI’s transition from a nonprofit research organization into a more complex structure highlighted the challenge of maintaining mission alignment while scaling technology, capital, partnerships, and commercial operations,” Greis said. “OpenClaw has the opportunity to address some of those governance questions earlier by establishing clear principles around neutrality, transparency, and decision-making before the ecosystem becomes even larger and more valuable.”</p>



<p class="wp-block-paragraph">He noted, “we have seen this pattern before with technologies like Linux and Kubernetes. The strongest open ecosystems succeeded because they created trusted foundations that enterprises could build upon. The technology was important, but the governance model that underpinned it was equally critical.”</p>



<h2 class="wp-block-heading">Risks are ‘squarely in IT’s lap’</h2>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, echoed Greis’ concerns. </p>



<p class="wp-block-paragraph">“CIOs shouldn’t assume that this nonprofit will always be a nonprofit, or confuse being a nonprofit with actually being neutral or unbiased,” he said. “The risks are squarely in IT’s lap: autonomous agents ‘with their own identity’ acting on a user’s behalf blow straight through traditional IAM assumptions. Issues, such as agent identity, auditability, secret handling. Identity boundaries have not yet been reliably solved. Until they are, enterprises should treat OpenClaw agents like privileged service accounts, not like a browser plugin.”</p>



<p class="wp-block-paragraph">Independent cybersecurity and risk advisor <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a> pointed to another IT exposure that might come from this OpenClaw transition: Cost.</p>



<p class="wp-block-paragraph">“OpenClaw currently has a very high token burn rate in usage, which presents a significant cost consideration for large-scale enterprise adoption,” he said. “The skills marketplace introduces <a href="https://www.csoonline.com/article/4129867/what-cisos-need-to-know-about-clawdbot-i-mean-moltbot-i-mean-openclaw.html" target="_blank">a new supply chain threat </a>that enterprises will need to manage. Threat management, and specifically handling <a href="https://www.csoonline.com/article/4135449/compromised-npm-package-silently-installs-openclaw-on-developer-machines.html" target="_blank">external marketplace elements</a>, can be highly challenging for open-source operations. Ultimately, at scale, enterprise adoption could become a difficult balancing act between managing high operational costs and securing an expanded security surface.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">Computerworld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Port releases vibe coding platform for dev and platform teams]]></title>
<description><![CDATA[Port has rolled out Port AI Builder, a vibe coding platform designed for software development and platform engineering teams.



Announced July 14, Port AI Builder lets teams create and run agentic workflows in natural language, with built-in human-in-the-loop review and approval. The platform le...]]></description>
<link>https://tsecurity.de/de/3671155/ai-nachrichten/port-releases-vibe-coding-platform-for-dev-and-platform-teams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671155/ai-nachrichten/port-releases-vibe-coding-platform-for-dev-and-platform-teams/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:24 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Port has rolled out Port AI Builder, a vibe coding platform designed for software development and platform engineering teams.</p>



<p class="wp-block-paragraph">Announced July 14, Port AI Builder lets teams create and run agentic workflows in natural language, with built-in human-in-the-loop review and approval. The platform lets organizations apply AI agents across the SDLC (software development life cycle), drawing on domain skills spanning site reliability engineering, devops, architecture, security, AI governance, data modeling, and UX, while maintaining governance and visibility, the company said. Port AI Builder is available through free and paid subscriptions.</p>



<p class="wp-block-paragraph">Port AI Builder works on top of Port’s Agentic SDLC Platform, which provides the context lake, workflow orchestration, agent management, and governance that enterprises need to operationalize AI SDLC, according to the company. The new AI Builder lets teams build production-grade workflows in minutes, for use cases such as autonomous resolution, AI cost management, and engineering performance tracking, without losing control, Port said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ship faster with GitHub, Vercel, and Firestore]]></title>
<description><![CDATA[These days, application developers can take their pick from a vast menu of architectural solutions. We can choose from the well-understood to the experimental, and from blended solutions in between. Several powerful middle-ground technologies that emerged during the cloud revolution have really c...]]></description>
<link>https://tsecurity.de/de/3671151/ai-nachrichten/ship-faster-with-github-vercel-and-firestore/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671151/ai-nachrichten/ship-faster-with-github-vercel-and-firestore/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:19 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">These days, application developers can take their pick from a vast menu of architectural solutions. We can choose from the well-understood to the experimental, and from blended solutions in between. Several powerful middle-ground technologies that emerged during the cloud revolution have really come of age. Here we’ll take a look at putting together three of the most impressive: GitHub, Vercel, and Firestore.</p>



<p class="wp-block-paragraph">Each of these is an important tool in its own right that can be used to attack specific problems. In combination, they not only meet the needs of several important application scenarios, but they have a superpower—the ability to dramatically shorten the distance between development and deployment.</p>



<p class="wp-block-paragraph">There is nothing quite as gratifying as putting your hands on just the right mix of tools for a given need.</p>



<h2 class="wp-block-heading">A ‘no-ops’ stack built for speed</h2>



<p class="wp-block-paragraph">If your primary goal is sheer development velocity, you would be hard-pressed to top this architecture. This “no-ops” stack collapses the distance between your local IDE and a globally distributed production environment. You are essentially trading the overhead of managing VMs and load balancers for the sheer speed of committing code and watching it deploy automatically.</p>



<p class="wp-block-paragraph">While each component is highly flexible, adopting them requires a specific, event-driven mindset. There are a few finicky bits to manage, mostly around routing environment variables securely and designing around stateless back-end functions. But the constraints are obvious and well-documented.</p>



<p class="wp-block-paragraph">Before we look more closely, let’s quickly identify the kinds of apps that are a perfect fit here, along with those that are workable and those that really merit a different approach.</p>



<ul class="wp-block-list">
<li>The sweet spot (deploy and go): AI-mediated applications, asynchronous game back ends, and real-time collaborative B2B dashboards. This architecture perfectly absorbs the unpredictable latency of LLM APIs and instantly syncs state across multiple clients without requiring you to build custom WebSocket infrastructure.</li>



<li>The middle ground (workable, with trade-offs): Headless e-commerce, moderate IoT telemetry, and apps requiring scheduled batch processing. You will encounter friction if your catalog relies on deeply relational SQL constraints, or if your background reporting jobs take longer than a few minutes and hit serverless execution limits.</li>



<li>The danger zone (look elsewhere): High-frequency trading, fast-paced action multiplayer games, heavy data ETL pipelines, and core financial ledgers. Serverless architectures cannot natively hold open the persistent WebSockets required for twitch-reflex data, and heavy compute tasks will abruptly time out.</li>
</ul>



<p class="wp-block-paragraph">We should mention that these categories are not mutually exclusive. Many enterprise applications, such as a full-scale e-commerce platform, straddle these lines. You might use Vercel and Firestore to build a lightning-fast, reactive storefront that handles ephemeral user state like shopping carts, while simultaneously “stitching in” a managed SQL database like Supabase or PlanetScale. This hybrid approach allows you to maintain the relational integrity required for back-office inventory and financial ledgers and pair it with the front-end velocity this stack provides.</p>



<h2 class="wp-block-heading">GitHub: the bedrock</h2>



<p class="wp-block-paragraph">I don’t need to introduce you to <a href="https://www.infoworld.com/article/2266566/what-is-github-more-than-git-version-control-in-the-cloud.html" data-type="link" data-id="https://www.infoworld.com/article/2266566/what-is-github-more-than-git-version-control-in-the-cloud.html">GitHub</a>. It is a central element of the development landscape. I still remember CVS and SVN with a certain nostalgia, but the enhancements of <a href="https://www.infoworld.com/article/2334697/what-is-git-version-control-for-collaborative-programming.html" data-type="link" data-id="https://www.infoworld.com/article/2334697/what-is-git-version-control-for-collaborative-programming.html">Git</a> speak for themselves. When combined with the orchestration powers of GitHub, it is no wonder that virtually the whole industry has adopted this type of platform.</p>



<p class="wp-block-paragraph">Git plus GitHub gives you an enormous amount of power already, in terms of how you can organize and automate your projects. But there is a next-level experience in combining GitHub and Vercel. For <a href="https://www.infoworld.com/article/2263137/what-is-javascript-the-full-stack-programming-language.html" data-type="link" data-id="https://www.infoworld.com/article/2263137/what-is-javascript-the-full-stack-programming-language.html">JavaScript</a>-based projects, you can take simple GitHub pushes and turn them into instantly deployed clients and serverless functions. It is one of the cleanest and least fiddly ways to move from raw code on your local machine to a globally deployed, full-stack architecture.</p>



<h2 class="wp-block-heading">Vercel: the nexus</h2>



<p class="wp-block-paragraph">Vercel is more than just a deployment host. It is a control plane that ties this high-velocity, no-ops architecture together. Alongside GitHub and Firestore, Vercel’s deeper strength is its ability to act as an orchestration layer between your reactive front end and external stateful services.</p>



<p class="wp-block-paragraph">Vercel has a great amount of facility in fine-tuning what branches go to what environment and helpful features like instant rollback. You can just log into Vercel’s dashboard for your project and see the history of deployments and any errors and logs. It’s a simple menu choice to roll back to a historical version or compare one version against another.</p>



<p class="wp-block-paragraph">When you “stitch in” third-party services (such as a managed SQL database like <a href="https://www.infoworld.com/article/4168581/developing-local-first-apps-with-react-supabase-and-powersync.html" data-type="link" data-id="https://www.infoworld.com/article/4168581/developing-local-first-apps-with-react-supabase-and-powersync.html">Supabase</a> or a payment processor like Stripe), Vercel’s serverless functions become the lightweight interface, and Vercel’s the adapters handle the communication. You offload the integration logic (the service layer) to Vercel’s global Edge Network, keeping your UI and back end clean, responsive, and decoupled. </p>



<p class="wp-block-paragraph">In short, Vercel allows you to get the speed of the “no-ops” development life cycle without sacrificing the complex transactional integrity required for some applications like enterprise inventory systems. </p>



<h2 class="wp-block-heading">Firestore: the datastore</h2>



<p class="wp-block-paragraph">Firestore is an extremely lightweight, NoSQL, cloud datastore. It has a great deal of add-on power, but its core value proposition is that it accepts virtually any data you stuff into it and it provides event-driven subscriptions to data changes.</p>



<p class="wp-block-paragraph">These two capabilities together make Firestore about as straightforward a solution to a managed back end as you can imagine. You subscribe to collections or even fields and then you simply stick “unstructured” data (read: JSON with variable fields) in and the client waits for the changes it is interested in.</p>



<p class="wp-block-paragraph">This is so streamlined that one can just point the browser (or native mobile app) directly at Firestore and listen for events. Which immediately raises the question of identity, for auth and for data visibility, but hold on—Firestore’s third superpower is that it has an authentication module <em>that actually works. </em>What I mean is, it is actually pretty simple and yet confidently secures your app.</p>



<p class="wp-block-paragraph">Sometimes auth solutions seem either too simple (and yet opaque) or too mired in the nitty gritty. <a href="https://docs.cloud.google.com/firestore/native/docs/authentication" data-type="link" data-id="https://docs.cloud.google.com/firestore/native/docs/authentication">Firestore auth</a> will let you do some basic configuration and start using a reasonable auth almost immediately. </p>



<p class="wp-block-paragraph">Not to belabor the point, but having a realistic and attainable auth solution elevates your stack to a production grade—one that can handle many real-world applications. Firestore auth plays nicely with other important APIs, like Stripe. Typically, auth is a major feature that feels like off-roading in a Honda Civic, but Firestore’s approach to auth, <em>added to this particular stack</em>, feels like a normal speed bump. It’s just another component you plug in, rather than a tentacled alien you weave into the your code.</p>



<h2 class="wp-block-heading">The limits of the velocity stack</h2>



<p class="wp-block-paragraph">This architecture combines components that are optimized for flexibility. That same character also introduces distinct limitations. Understanding these is essential before committing production workloads.</p>



<h3 class="wp-block-heading">The serverless life cycle</h3>



<p class="wp-block-paragraph">Serverless functions are spun up to handle requests. They close out soon afterward and lose any state. For that reason, they cannot natively hold open persistent WebSockets. If your system requires continuous, sub-millisecond, bidirectional streams—like a real-time multiplayer action game or a high-frequency trading dashboard—pure serverless will fight you all the way. You are forced to introduce a third-party managed WebSocket service to route messages back to your stateless endpoints via HTTP webhooks.</p>



<h3 class="wp-block-heading">The execution time ceiling</h3>



<p class="wp-block-paragraph">Vercel (like all serverless platforms) enforces strict timeouts on operations. While enterprise tiers might grant you up to 15 minutes, standard functions often time out after 10 to 60 seconds. Long-running tasks like video transcoding, database scripts, or orchestrating multi-step AI agent workflows, which might take 20 minutes to resolve, will run up against these limits. Heavy-lifting tasks must be offloaded to a dedicated, long-running service like Google Cloud Run, or broken into smaller, asynchronous chunks via message queues.</p>



<h3 class="wp-block-heading">The cold start reality</h3>



<p class="wp-block-paragraph">While the industry has made massive strides in minimizing initialization times—particularly with lightweight edge networks—traditional Node.js-based serverless functions still experience cold starts. If a function has not been invoked recently, or if traffic spikes require a new instance to spin up concurrently, the first request will take a noticeable latency hit as the container provisions and the code loads.</p>



<h3 class="wp-block-heading">API instead of RAM</h3>



<p class="wp-block-paragraph">In a traditional server environment, you can store transient data in global RAM, allowing subsequent requests to access shared context instantly. In the serverless model, every request might hit a fresh container. Therefore, <em>all</em> shared context must be externalized. Although Firestore serves brilliantly as the state manager, relying on a database for high-frequency, sub-millisecond, ephemeral caching introduces network latency and per-operation costs. That said, using a shared RAM state on a server is non-trivial also, unless you are using a single app server and VM (because high-availability or fail-over requirements will lessen the RAM win on a traditional server).</p>



<h2 class="wp-block-heading">Tuning for velocity and control</h2>



<p class="wp-block-paragraph">Every architectural decision is a trade-off. There are no cost-free choices. By adopting the GitHub, Vercel, and Firestore stack, you are explicitly maximizing feature velocity over fine-grained control.</p>



<p class="wp-block-paragraph">You lose the ability to tweak the underlying operating system, hold open persistent sockets, or run hour-long back-end scripts. In exchange, you gain an architecture that scales from zero to global distribution instantly, requires virtually no devops maintenance, and perfectly absorbs the asynchronous, event-driven realities of modern application development.</p>



<p class="wp-block-paragraph">For the right application—whether it is a fast-moving prototype or an enterprise AI copilot—this stack doesn’t just save time; it fundamentally changes how quickly a small team (or a single person) can impact the market. You stop worrying about build chains, load balancers, and server patches, and you focus on the central mission: shipping features.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration]]></title>
<description><![CDATA[Australia and India have unveiled the Australia-India PACTS, a new framework designed to deepen bilateral cooperation on cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence research.
The new partnership replaces the 2020 Framework Arrangement on Cyber a...]]></description>
<link>https://tsecurity.de/de/3670079/it-security-nachrichten/australia-india-pacts-to-deepen-cybersecurity-and-tech-collaboration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670079/it-security-nachrichten/australia-india-pacts-to-deepen-cybersecurity-and-tech-collaboration/</guid>
<pubDate>Wed, 15 Jul 2026 10:53:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Australia-India-PACTS.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Australia-India PACTS" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Australia-India-PACTS.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Australia-India-PACTS-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Australia-India-PACTS-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Australia-India-PACTS-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Australia-India-PACTS-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Australia-India-PACTS-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Australia-India-PACTS-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Australia-India-PACTS-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Australia-India-PACTS.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Australia-India-PACTS-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Australia-India-PACTS-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Australia-India-PACTS-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Australia-India-PACTS-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Australia-India-PACTS-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Australia-India-PACTS-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Australia-India-PACTS-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration 1"></p><div class="qMYqUG_convSearchResultHighlightRoot">
<div class="" data-turn-id-container="request-WEB:3f2d8641-ed2f-4e41-9b67-d9341ade6940-37" data-is-intersecting="true"><section class="text-token-text-primary w-full focus:outline-none has-data-writing-block:pointer-events-none [&amp;:has([data-writing-block])&gt;*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" data-turn-id="request-WEB:3f2d8641-ed2f-4e41-9b67-d9341ade6940-37" data-turn-id-container="request-WEB:3f2d8641-ed2f-4e41-9b67-d9341ade6940-37" data-testid="conversation-turn-20" data-turn="assistant">
<div class="text-base my-auto mx-auto pb-15 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)">
<div class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn" data-conversation-screenshot-content="">
<div class="flex max-w-full flex-col gap-4 grow">
<div class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;]:mt-1" dir="auto" tabindex="0" data-message-author-role="assistant" data-message-id="3b665ced-2928-4ba6-bb09-6a2dbd91b392" data-message-model-slug="gpt-5-5" data-turn-start-message="true">
<div class="flex w-full flex-col gap-1 empty:hidden">
<div class="markdown prose dark:prose-invert wrap-break-word w-full light markdown-new-styling">
<p class="PDq2pG_selectionAnchorContainer" data-start="393" data-end="928">Australia and India have unveiled the Australia-India PACTS, a new framework designed to deepen bilateral cooperation on cybersecurity, critical technologies, <a href="https://thecyberexpress.com/supply-chain-resilience-for-2025/" target="_blank" rel="noopener">supply chain resilience</a>, digital resilience, and defence research.</p>
<p class="PDq2pG_selectionAnchorContainer" data-start="393" data-end="928">The new partnership replaces the 2020 Framework Arrangement on Cyber and Cyber Enabled Critical Technology Cooperation and aims to strengthen national security, economic growth, and regional stability across the Indo-Pacific.</p>
<p data-start="930" data-end="1272">The two countries said the Australia-India Partnership on Cyber, Critical Technologies and Supply Chains (PACTS) builds on two decades of research collaboration, operational coordination, and policy engagement. It also reflects their shared commitment to creating secure digital ecosystems while promoting trusted technology partnerships.</p>

<h3 data-section-id="1ovx9ma" data-start="1274" data-end="1388"><strong><span role="text">Australia-India PACTS Built on Five Pillars</span></strong></h3>
<p data-start="1390" data-end="1778">The Australia-India PACTS is <a href="https://www.pib.gov.in/PressReleasePage.aspx?PRID=2282692&amp;reg=48&amp;lang=1" target="_blank" rel="nofollow noopener">structured around five pillars</a> that will drive collaboration between governments, research institutions, universities, and the private sector. The framework is intended to increase two-way investment in emerging technologies while supporting innovation and the commercialisation of research.</p>
<p data-start="1780" data-end="2233">The first pillar focuses on supply chain resilience by strengthening trusted technology supply chains and promoting secure trade. Both countries will establish a bilateral mechanism for trusted vendor frameworks and work together to improve undersea cable security through the Quad Partnership for Cable Connectivity and Resilience. The partnership also includes collaboration on semiconductor research, critical minerals, and trade diversification.</p>

<h3 data-section-id="1rg2ozr" data-start="2235" data-end="2369"><strong><span role="text">Australia-India PACTS Expands Critical Technology Collaboration</span></strong></h3>
<p data-start="2371" data-end="2593">The second pillar focuses on critical technologies, with Australia and India planning to strengthen cooperation in artificial intelligence, telecommunications, biotechnology, advanced materials, and space technologies.</p>
<p data-start="2595" data-end="2990">The framework also supports the development of international standards for trustworthy AI and encourages collaboration between academic institutions and industry to promote responsible AI deployment. The two countries will also explore joint research, investment initiatives, and commercial partnerships in emerging technologies to strengthen long-term economic security across the Indo-Pacific.</p>

<h3 data-section-id="1luthla" data-start="2992" data-end="3110"><strong><span role="text">Australia-India Prioritises Cybersecurity</span></strong></h3>
<p data-start="3112" data-end="3388">A major component of the partnership is Australia India <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank" rel="noopener" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28972">cybersecurity</a> cooperation. Under the third pillar, both governments will work together to counter <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28971">cybercrime</a>, deter malicious cyber activity, strengthen cyber policy coordination, and protect critical infrastructure.</p>
<p data-start="3390" data-end="3674">The framework proposes a consolidated bilateral mechanism for <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="28974">cyber</a> and ICT cooperation, expanded engagement in United Nations cyber processes, increased trade opportunities for cybersecurity businesses, and practical workshops involving government agencies and industry stakeholders.</p>
<p data-start="3676" data-end="3804">The partnership will also establish a cyber technology skills incubator to promote knowledge exchange and workforce development.</p>

<h3 data-section-id="11ppccm" data-start="3806" data-end="3926"><strong><span role="text">Australia-India PACTS Advances Digital Resilience</span></strong></h3>
<p data-start="3928" data-end="4254">The fourth pillar focuses on digital resilience across the Indo-Pacific. Australia and India will collaborate on trusted Digital Public Infrastructure initiatives and promote scalable digital solutions that support connectivity, healthcare, education, renewable energy, critical infrastructure, and digital transformation.</p>
<p data-start="4256" data-end="4423">The partnership also seeks to expand pilot projects that help countries across the region build adaptable digital ecosystems while strengthening regional capabilities.</p>

<h3 data-section-id="1b1f973" data-start="4425" data-end="4469"><strong>Defence Research and Governance Framework</strong></h3>
<p data-start="4471" data-end="4717">The fifth pillar strengthens defence science collaboration through joint research, innovation partnerships, and greater engagement between Australia's Defence Science and Technology Group and India's Defence Research and Development Organisation.</p>
<p data-start="4719" data-end="4866">Areas of cooperation include maritime surveillance, advanced materials, defence innovation, and stronger links between defence start-up ecosystems.</p>
<p data-start="4868" data-end="5327">The Australia-India PACTS will be jointly overseen by the Australian Deputy Secretary of the International and Security Group within the Department of the Prime Minister and Cabinet and the Indian Deputy National Security Advisor. Annual Senior Officials Meetings will review progress, assess emerging cyber and technology <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risks" data-wpil-keyword-link="linked" data-wpil-monitor-id="28973">risks</a>, and identify future collaborative projects under each pillar.</p>
<p data-start="5329" data-end="5752" data-is-last-node="" data-is-only-node="">With the launch of Australia-India Partnership on Cyber, <a href="https://thecyberexpress.com/cybersecurity-for-critical-infrastructure/" target="_blank" rel="noopener">Critical Technologies</a> and Supply Chains (PACTS), both countries have outlined a long-term roadmap that brings together cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence cooperation under a single strategic framework aimed at strengthening security and technology collaboration across the Indo-Pacific.</p>

</div>
</div>
</div>
</div>
</div>
</div>
</section></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fünf Regeln für Datenbankmonitoring, das wirklich etwas bringt]]></title>
<description><![CDATA[Wer seine Datenbanken nur überwacht, um Ausfälle zu bemerken, verschenkt Potenzial. Der DevOps-Anbieter Redgate hat aufgeschrieben, was aus seiner Sicht gutes Monitoring ausmacht und wo Unternehmen typischerweise falsch abbiegen.

Tags:]]></description>
<link>https://tsecurity.de/de/3669799/it-security-nachrichten/fuenf-regeln-fuer-datenbankmonitoring-das-wirklich-etwas-bringt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669799/it-security-nachrichten/fuenf-regeln-fuer-datenbankmonitoring-das-wirklich-etwas-bringt/</guid>
<pubDate>Wed, 15 Jul 2026 08:52:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/08/Datenbank-1920-shutterstock-2754168051.jpg" class="attachment-full size-full wp-post-image" alt="Datenbank" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/08/Datenbank-1920-shutterstock-2754168051.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/08/Datenbank-1920-shutterstock-2754168051-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/08/Datenbank-1920-shutterstock-2754168051-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/08/Datenbank-1920-shutterstock-2754168051-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/08/Datenbank-1920-shutterstock-2754168051-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Fünf Regeln für Datenbankmonitoring, das wirklich etwas bringt 1"></p>
    Wer seine Datenbanken nur überwacht, um Ausfälle zu bemerken, verschenkt Potenzial. Der DevOps-Anbieter Redgate hat aufgeschrieben, was aus seiner Sicht gutes Monitoring ausmacht und wo Unternehmen typischerweise falsch abbiegen.

<p>Tags: </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepSeek weighs new fundraising a month after closing first round]]></title>
<description><![CDATA[Unusually swift pace of capital injection comes as Chinese AI start-up seeks to build out infrastructure]]></description>
<link>https://tsecurity.de/de/3667671/ai-nachrichten/deepseek-weighs-new-fundraising-a-month-after-closing-first-round/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667671/ai-nachrichten/deepseek-weighs-new-fundraising-a-month-after-closing-first-round/</guid>
<pubDate>Tue, 14 Jul 2026 12:50:00 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Unusually swift pace of capital injection comes as Chinese AI start-up seeks to build out infrastructure]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI agents are shaping the future of work]]></title>
<description><![CDATA[I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing function...]]></description>
<link>https://tsecurity.de/de/3667534/it-security-nachrichten/how-ai-agents-are-shaping-the-future-of-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667534/it-security-nachrichten/how-ai-agents-are-shaping-the-future-of-work/</guid>
<pubDate>Tue, 14 Jul 2026 12:07:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing functionality.  </p>



<p class="wp-block-paragraph">At the end of 2025, Anthropic and OpenAI launched new AI models and code-generating capabilities. More developers tried <a href="https://www.infoworld.com/article/4058076/vibe-coding-and-the-future-of-software-development.html">vibe coding</a>, and some platforms launched <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development.html">spec-driven development capabilities</a>. By February 2026, even The New York Times reported that <a href="https://www.nytimes.com/2026/02/18/opinion/ai-software.html">the AI disruption had arrived</a>, noting that code generators were building “apps that may be flawed, but credible.”</p>



<p class="wp-block-paragraph">Wall Street investors took notice of the code-generation improvements and other disruptive factors, driving a selloff in SaaS stocks, now referred to as the “<a href="https://www.bloomberg.com/news/articles/2026-02-03/-get-me-out-traders-dump-software-stocks-as-ai-fears-take-hold">SaaSpocalypse</a>.” Part of their concern stemmed from the belief that CIOs would use AI to <a href="https://www.cio.com/article/4148303/cios-rethink-softwares-future-as-ai-agents-advance.html">write software that would replace SaaS solutions</a>.</p>



<h2 class="wp-block-heading">AI innovations from SaaS and solution providers</h2>



<p class="wp-block-paragraph">But I thought differently and wrote a response in my article asking whether <a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html">AI is the end of SaaS as we know it</a>. CIOs might use AI to accelerate application modernization, but I doubt they would replace their ERP, CRM, and even smaller SaaS point solutions by building them.</p>



<p class="wp-block-paragraph">Instead, I believed it would be SaaS companies that would take the most advantage of AI code-generation capabilities.</p>



<p class="wp-block-paragraph">This hypothesis drove me to attend nine conferences this spring to see how SaaS companies were launching AI agents and defining a new future of work. I wrote eight articles on <a href="https://drive.starcio.com/cios-need-to-know">what CIOs need to know</a> about data management, agile organizations, marketing, ERPs, critical process management, and other evolutions to plan for in the AI era.</p>



<p class="wp-block-paragraph">Now, looking across all nine conferences, I can draw some conclusions about how AI agents are shaping the future of work. Here are my learnings and what CIOs need to consider when evaluating and deploying AI agents in the workplace.</p>



<h2 class="wp-block-heading">Agentic, human-in-the-middle, or augmenting human?</h2>



<p class="wp-block-paragraph">SaaS companies have very distinct perspectives on the future of work, including the extent to which humans will play which roles and whether and how quickly we’ll see agentic, fully automated work.</p>



<p class="wp-block-paragraph">For example, Atlassian proclaimed, “<a href="https://www.atlassian.com/company/events">step into the future of human-AI collaboration</a>,” while SAP unveiled “<a href="https://news.sap.com/2026/05/sap-sapphire-sap-unveils-autonomous-enterprise/">the autonomous enterprise</a>.” Snowflake aimed to “<a href="https://www.snowflake.com/en/summit/">make AI real for business</a>,” while Appian targeted “<a href="https://www.appianworld.com/">serious AI built on process</a>.”</p>



<p class="wp-block-paragraph">These vendors’ marketers had to decide whether to lead with AI, people, or business in their messaging, but so must CIOs as they contemplate their AI strategies and how to get employees to fully adopt AI agents.</p>



<p class="wp-block-paragraph">Some CIOs see a fully automated agentic AI as the future, with human-in-the-middle as a transitional phase as departments build trust in AI agents’ decision-making and automation capabilities.</p>



<p class="wp-block-paragraph">Other CIOs see AI more as a tool that delivers productivity improvements by augmenting human decision-making capabilities. Many of these CIOs see human augmentation as essential to supporting critical thinking, innovation, and creativity.</p>



<p class="wp-block-paragraph"><a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html">Deloitte’s State of AI Report</a>, published in January, provides a benchmark. It states that 36% of IT leaders expect at least 10% of their jobs to be fully automated in the next year, and 82% expect to reach that benchmark in three years.</p>



<p class="wp-block-paragraph">Many organizations will have a mix of AI agents, choosing automation where reliability at scale is possible, but opting for human augmentation in operationally critical or customer-facing domains. But how CIOs position AI agents is not only an operational strategy; it’s also a cultural statement that shapes employees’ embrace of AI and whether <a href="https://drive.starcio.com/2026/03/ai-leadership-job-at-risk-or-career-opportunity/">detractors vocalize job-loss fears</a>.</p>



<p class="wp-block-paragraph">In the short term, it will also weigh in on which AI agents to use from different partners and which areas to build in-house.</p>



<h2 class="wp-block-heading">Many options to test and deploy AI agents</h2>



<p class="wp-block-paragraph">Many solution providers are demonstrating significantly more AI agents this year. For example, SAP went from <a href="https://drive.starcio.com/2026/05/autonomous-enterprise-ai-cios/">40 Joule Agents in 2025 to over 200 in 2026.</a> Three technology capabilities are fueling this significant growth:</p>



<ul class="wp-block-list">
<li>Adobe, Appian, Boomi, Cisco, Domo, Salesforce, SAP, Snowflake, and others offer <a href="https://www.infoworld.com/article/3497094/does-your-organization-need-a-data-fabric.html">data fabrics</a> and <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">data-pipeline</a> capabilities to connect data sources outside the primary workflows supported by their platforms. Appian, Pega, Quickbase, and SAP also centralize business process automation, an important starting point for developing AI agents.  </li>



<li><a href="https://www.infoworld.com/article/4124612/5-requirements-for-using-mcp-servers-to-connect-ai-agents.html">MCP servers</a> enable integration and communication between AI agents and are used to facilitate multistep agentic workflows. Virtually all the companies announcing major investments in AI agents are also announcing MCP integration capabilities and related partnerships.</li>



<li>Solution providers are not just using AI code-generating capabilities; many are launching their own AI agent development tools. The first beneficiaries of these development tools are the solution providers themselves and their integration partners, who use them to accelerate the development of AI agents and make them available to customers.</li>
</ul>



<p class="wp-block-paragraph">The result is that <a href="https://drive.starcio.com/2025/10/ai-agents-definitive-guide-saas-security-titans/">CIOs will have many options about which agents to test</a>, but will have to dedicate analysts to understand the capability, cost, and compliance trade-offs. Additionally, expect AI agent capabilities to evolve significantly over the next few years, so CIOs should continuously revisit their decisions regarding deployed AI agents, focusing on performance, benefits, and ROI.</p>



<p class="wp-block-paragraph">CIOs should also watch for signs of <a href="https://www.cio.com/article/1247890/7-steps-for-turning-shadow-it-into-a-competitive-edge.html">shadow AI</a> and employee confusion about which AI agents to experiment with on different platforms. The AI strategy should include a transparent, defined process for selecting, reviewing, evaluating, procuring, deploying, driving adoption, monitoring, and collecting end-user feedback around AI agents.</p>



<h2 class="wp-block-heading">AI development capabilities for engineers and citizen builders</h2>



<p class="wp-block-paragraph">The apparent ease-of-use of AI code generators may lead some engineering teams to <a href="https://www.cio.com/article/4097339/your-next-big-ai-decision-isnt-build-vs-buy-its-how-to-combine-the-two.html">build AI agents rather than buy them</a> from SaaS providers. But CIOs should quickly realize that coding is just one step in developing AI agents, and that aggressively pursuing a build strategy can lead to <a href="https://www.cio.com/article/4178324/7-sources-of-ai-debt-and-how-to-avoid-them.html">AI debt</a> and <a href="https://www.cio.com/article/4107377/cios-will-underestimate-ai-infrastructure-costs-by-30.html">increased AI costs</a>.</p>



<p class="wp-block-paragraph">DevOps teams can code AI agents using tools such as Claude, Codex, Lovable, and Replit — a do-it-yourself approach. Some SaaS companies are providing an alternative, with AI agent development tools that leverage the data, infrastructure, and governance baked into their platforms. Many of these development tools offer flexibility, allowing developer teams to select AI models and development environments.</p>



<p class="wp-block-paragraph">Examples of new and enhanced AI development tools I saw at conferences this quarter include:</p>



<ul class="wp-block-list">
<li><a href="https://appian.com/blog/2025/appian-25-4-release-enterprise-ai-agents">Appian Composer and Agent Studio</a></li>



<li><a href="https://www.atlassian.com/software/rovo-dev">Atlassian Rovo Dev</a></li>



<li><a href="https://boomi.com/platform/companion/">Boomi Companion</a></li>



<li><a href="https://www.cisco.com/site/us/en/solutions/artificial-intelligence/agentic-ops/cloud-control-studio/index.html">Cisco Cloud Control Studio</a></li>



<li><a href="https://www.domo.com/app-catalyst">Domo App Catalyst</a></li>



<li><a href="https://www.pega.com/about/news/press-releases/pega-harnesses-best-practices-and-ai-coding-agents-build-apps-mission">Pega Infinity Studio</a></li>



<li><a href="https://www.quickbase.com/pave">Quickbase Pave</a></li>



<li><a href="https://www.snowflake.com/en/product/snowflake-coco/">Snowflake CoCo</a></li>



<li><a href="https://www.sap.com/products/artificial-intelligence/joule-studio.html">SAP Joule Studio</a>.</li>
</ul>



<p class="wp-block-paragraph">I also reviewed <a href="https://www.nutanix.com/solutions/ai">Nutanix Agentic AI</a>, a platform-as-a-service for accelerating the deployment of agentic AI workloads, and <a href="https://www.adobe.com/products/firefly/features/ai-assistant.html">Adobe Firefly AI Assistant</a> for creatives.</p>



<p class="wp-block-paragraph">These development tools can target different audiences. Some look like low-code development tools targeted at software developers, whereas others are <a href="https://drive.starcio.com/2026/05/low-code-in-the-ai-era-cios-need-to-know/">no-code and enable citizen developers</a>, i.e., businesspeople, to <a href="https://www.cio.com/article/4176062/cios-are-enlisting-business-users-to-vibe-code-their-own-apps.html">develop applications and agents</a>. Additionally, some of these tools support spec-driven development and generate artifacts such as product requirement documents (PRDs), data models, and testing capabilities.</p>



<p class="wp-block-paragraph">Before commissioning AI development for apps and agents, CIOs should sponsor proofs of technical, data, modeling, security, and governance capabilities.</p>



<h2 class="wp-block-heading">The context layer powering AI agents</h2>



<p class="wp-block-paragraph">Between AI agents and the enterprise’s intelligence, including structured data sources, defined business processes, and agent interactions (both human-to-agent and agent-to-agent), lies an evolving “context layer.”</p>



<p class="wp-block-paragraph">This layer refers to the enterprise knowledge that AI agents draw on when evaluating signals and recommending or taking actions. Context may include a knowledge graph, a semantic layer, cleansed document repositories, and other knowledge bases.</p>



<p class="wp-block-paragraph">The context layer, skills, tools, out-of-the-box agents, and governance capabilities are some areas to review where solution providers differentiate. Some examples: </p>



<ul class="wp-block-list">
<li>Many support the <a href="https://open-semantic-interchange.org/">Open Semantic Interchange</a>, and some brand their context layers, such as the <a href="https://www.atlassian.com/platform/teamwork-graph">Atlassian Teamwork Graph</a>, <a href="https://boomi.com/knowledge-hub-early-access/">Boomi Knowledge Hub</a>, and the <a href="https://www.sap.com/products/artificial-intelligence/knowledge-graph.html">SAP Knowledge Graph</a>.</li>



<li>Some are branding their guardrails, such as <a href="https://business.adobe.com/products/brand-intelligence.html">Adobe’s AI Brand Intelligence</a>, <a href="https://appian.com/products/platform/artificial-intelligence">Appian’s Private AI</a>, and <a href="https://www.quickbase.com/intelligence-pack/ai-control-center">Quickbase AI Control Center</a>.</li>



<li>To manage AI agents at scale, some are extending the notion of data catalogs and other governance tools to the AI domain with products such as <a href="https://boomi.com/platform/connect/">Boomi Connect</a>, <a href="https://www.sap.com/products/artificial-intelligence/ai-agent-hub.html">SAP AI Agent Hub</a>, and <a href="https://www.snowflake.com/en/product/features/horizon/">Snowflake Horizon Catalog</a>.</li>
</ul>



<p class="wp-block-paragraph">CIOs should recognize that while solution providers will compete on capabilities, the real “secret sauce” of the context layer lies in the company’s trusted data, well-defined business processes, and employee adoption of AI agents.</p>



<h2 class="wp-block-heading">Conversational user experiences and coworkers</h2>



<p class="wp-block-paragraph">AI agents use the context layer, but also tap into skills, which encode the procedures they can follow, and tools, which prescribe the actions they can take. Before AI agents are ready to pilot, their governance, including permissions, approval gates, and other guardrails, must be defined. Other capabilities to look for when defining AI agents include orchestration, testing evals, and observability.</p>



<p class="wp-block-paragraph">In 2025, many solution providers bolted on AI agents to their existing user experiences. This year, many solution providers showcased new conversational user experiences that employees can use instead of traditional ones built with forms, flows, reports, and static dashboards. Conversational user experiences are where AI agents and people come together, whether it’s human-in-the-middle or human augmentation.</p>



<p class="wp-block-paragraph">Solution providers also grouped their AI agents into assistants or coworkers. For example, <a href="https://business.adobe.com/products/cx-enterprise-coworker.html">Adobe CX Coworker</a> illustrates human augmentation, helping marketers manage campaigns with prompts and monitor their performance. SAP launched <a href="https://www.sap.com/products/artificial-intelligence/ai-assistant.html">Joule Assistants</a> across several business functions, including finance, human capital, supply chain, and customer experience. Other assistants, such as <a href="https://docs.appian.com/suite/help/26.5/appian-ai-copilot.html">Appian AI Copilot</a>, <a href="https://www.atlassian.com/software/rovo">Atlassian Rovo</a>, <a href="https://www.cisco.com/site/us/en/solutions/artificial-intelligence/ai-assistant/index.html">Cisco AI Assistant</a>, <a href="https://www.nutanix.com/blog/nutanix-intelligent-virtual-agent">Nutanix NIVA</a>, and <a href="https://www.snowflake.com/en/product/snowflake-cowork/">Snowflake CoWork</a>, offer AI-first user experiences to assist different end-user types.</p>



<p class="wp-block-paragraph">CIOs should demo these <a href="https://www.infoworld.com/article/4178415/what-will-ai-first-ux-look-like.html">AI-first user experiences</a> to glimpse the future of work.</p>



<p class="wp-block-paragraph">Developers are already getting used to these experiences through code generators and vibe coding tools. Now, similar capabilities are being tailored across all business functions. CIOs should ramp up their <a href="https://www.cio.com/article/4082282/preparing-your-workforce-for-ai-agents-a-change-management-guide.html">change management programs</a> to accelerate the adoption of these AI capabilities.</p>



<p class="wp-block-paragraph">Solution providers are showcasing AI capabilities that can help CIOs <a href="https://drive.starcio.com/2026/04/ai-reshaping-business-not-digital-transformation-yet/">reshape their businesses</a>. But in Q2, there were only a few examples of how AI can help CIOs drive growth, evolve business models, or embed AI into customer-facing products. I expect to see a wave of further AI innovations that will go beyond productivity improvements and efficiencies and help CIOs pursue <a href="https://drive.starcio.com/2025/02/cios-drive-genai-digital-transformation/">growth-driving digital transformation strategies</a>.  </p>



<p class="wp-block-paragraph"><em>Sacolick travelled to conferences mentioned in this article as a guest of Adobe, Appian, Atlassian, Domo, Nutanix, SAP, and Snowflake. In addition, he was hired by Quickbase to speak at its conference.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-56458 | HCL HCL DevOps Deploy up to 8.2.1.0 CORS information disclosure]]></title>
<description><![CDATA[A vulnerability was found in HCL HCL DevOps Deploy up to 8.2.1.0. It has been classified as problematic. This affects an unknown function of the component CORS. The manipulation leads to information disclosure.

This vulnerability is referenced as CVE-2026-56458. Remote exploitation of the attack...]]></description>
<link>https://tsecurity.de/de/3667153/sicherheitsluecken/cve-2026-56458-hcl-hcl-devops-deploy-up-to-8210-cors-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667153/sicherheitsluecken/cve-2026-56458-hcl-hcl-devops-deploy-up-to-8210-cors-information-disclosure/</guid>
<pubDate>Tue, 14 Jul 2026 09:23:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/hcl:hcl_devops_deploy">HCL HCL DevOps Deploy up to 8.2.1.0</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown function of the component <em>CORS</em>. The manipulation leads to information disclosure.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-56458">CVE-2026-56458</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-56459 | HCL HCL DevOps Deploy/HCL Launch Log File information disclosure]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in HCL HCL DevOps Deploy and HCL Launch. Affected by this issue is some unknown functionality of the component Log File Handler. Performing a manipulation results in information disclosure.

This vulnerability is cataloged as CVE-2026-56...]]></description>
<link>https://tsecurity.de/de/3667150/sicherheitsluecken/cve-2026-56459-hcl-hcl-devops-deployhcl-launch-log-file-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667150/sicherheitsluecken/cve-2026-56459-hcl-hcl-devops-deployhcl-launch-log-file-information-disclosure/</guid>
<pubDate>Tue, 14 Jul 2026 09:23:23 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/hcl:hcl_devops_deploy">HCL HCL DevOps Deploy and HCL Launch</a>. Affected by this issue is some unknown functionality of the component <em>Log File Handler</em>. Performing a manipulation results in information disclosure.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-56459">CVE-2026-56459</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersecurity jobs available right now: July 14, 2026]]></title>
<description><![CDATA[Cyber Network Engineer Fiserv | USA | On-site – View job details As a Cyber Network Engineer, you will lead the design, governance, and security review of enterprise network architectures across on-premises and cloud environments. You will provide expertise in network security technologies, asses...]]></description>
<link>https://tsecurity.de/de/3666837/it-security-nachrichten/cybersecurity-jobs-available-right-now-july-14-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666837/it-security-nachrichten/cybersecurity-jobs-available-right-now-july-14-2026/</guid>
<pubDate>Tue, 14 Jul 2026 06:22:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cyber Network Engineer Fiserv | USA | On-site – View job details As a Cyber Network Engineer, you will lead the design, governance, and security review of enterprise network architectures across on-premises and cloud environments. You will provide expertise in network security technologies, assess security risks, define security standards, and collaborate with engineering and DevOps teams to integrate security into infrastructure and automation. You will also evaluate security telemetry and threat intelligence to improve network … <a href="https://www.helpnetsecurity.com/2026/07/14/cybersecurity-jobs-available-right-now-july-14-2026/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/14/cybersecurity-jobs-available-right-now-july-14-2026/">Cybersecurity jobs available right now: July 14, 2026</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’]]></title>
<description><![CDATA[OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that the popular platform has thus far lacked. Still, some worry about the risks created by the move. 



“Our ambition is for OpenClaw...]]></description>
<link>https://tsecurity.de/de/3666484/it-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666484/it-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</guid>
<pubDate>Mon, 13 Jul 2026 23:17:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that <a href="https://www.computerworld.com/article/4128257/openclaw-the-ai-agent-thats-got-humans-taking-orders-from-bots.html" target="_blank">the popular platform </a>has thus far lacked. Still, some worry about the risks created by the move. </p>



<p class="wp-block-paragraph">“Our ambition is for OpenClaw to be the Switzerland of AI. Neutral ground where every model and every lab can plug into the technology and collaborate on standards in the era of agents,” <a href="https://openclaw.ai/blog/introducing-openclaw-foundation/" target="_blank" rel="noreferrer noopener">OpenClaw said in a post</a>. “That work is already underway in Foundation-convened councils on agent identity, agent profiles, evals, and enterprise deployment.”</p>



<p class="wp-block-paragraph">The statement, co-authored by OpenClaw creator <a href="https://www.linkedin.com/in/steipete/" target="_blank" rel="noreferrer noopener">Peter Steinberger</a>, pointed out, “the great open source projects of our time — Linux, Apache, Mozilla — endure because a neutral steward stands behind them. That is the role we are taking on to keep OpenClaw MIT licensed, open, and independent so that everyone building on it can trust it will be here for the long term.”</p>



<p class="wp-block-paragraph">But it reassured users that the original OpenClaw leadership is still in charge.</p>



<p class="wp-block-paragraph">“Peter built this thing and Peter keeps making the calls, especially the technical ones. Since joining OpenAI earlier this year, he has continued to steward OpenClaw as an open and independent project, and OpenAI has made a commitment to keep it that way,” the post said. “The foundation is here to serve: good governance, stable funding, and paying the people who keep the claws alive.”</p>



<p class="wp-block-paragraph">However, some analysts and consultants were skeptical about how much true independence Steinberger would have, given his salaried role with OpenAI. </p>



<h2 class="wp-block-heading">Neutrality claim in question</h2>



<p class="wp-block-paragraph">“The Switzerland of AI neutrality claim collapses under its own announcement,” said <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520. “OpenAI runs a team [at OpenAI] called Claw Labs that Peter leads and OpenAI is a major donor to OpenClaw. The ‘neutral steward’s’ chief technical decision maker is employed by one of the competing labs it is supposed to be neutral with.” To OpenAI, he said, OpenClaw is closer to a tax-exempt nonprofit subsidiary than it is to a neutral ‘Switzerland of AI.’</p>



<p class="wp-block-paragraph">He pointed out that, in addition, Microsoft is shipping <a href="https://www.computerworld.com/article/4173442/enterpriseclaw-wants-to-bring-governance-to-the-openclaw-era-2.html" target="_blank">the enterprise version</a> of OpenClaw, and Nvidia is shipping the hardware bundle. “This is being called the Switzerland of AI, but Switzerland does not have its central bank run by France,” he observed.</p>



<p class="wp-block-paragraph">Kenney said that what the new OpenClaw has actually built is “a shared dependency that several competitors fund, staff, and steer, wrapped in a nonprofit structure. Enterprise IT should understand that structure, because treating OpenClaw as neutral is a mistake,” adding that CIOs need to look at this development devoid of the emotional component. </p>



<p class="wp-block-paragraph">“There is a strategic irony here that CIOs should sit with,” Kenney said. “If OpenClaw succeeds at becoming the universal agent substrate, then every model plugs into the same identity layer, the same profiles, and the same deployment plumbing. The thing every vendor is racing to own becomes a commodity that nobody owns.” He pointed out that, in the short term, that is genuinely good news for buyers because it means less lock-in and more portability.</p>



<p class="wp-block-paragraph">“But,” he said, “when the connective tissue is free and natural, the only labs that benefit are the ones with the best models and the deepest distribution. Commoditize the layer below you and you compete on the layer where you are already strongest. The foundation is not a charity. It is the biggest players agreeing to stop fighting over the plumbing so they can fight over the water, and the enterprise is the one paying the water bill either way.”</p>



<h2 class="wp-block-heading">Good news, bad news</h2>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy, liked the potential consistency that could emerge from the structural change, given the complexity of agent development today. </p>



<p class="wp-block-paragraph">“We are seeing a lot of OpenClaw variants hit the market, such as those from Nvidia as well as competing products from cloud and SaaS vendors. A common base helps solidify the common parts,” Andersen noted. “That said, a common challenge is the sustainability of these open source foundations over time. In addition to releasing code, these foundations need funding to evolve and grow. And that funding needs to come from continued momentum to incentivize existing members to increase investment and recruit new members to join.”</p>



<p class="wp-block-paragraph">Andersen stressed that IT buyers need to keep an eye on the roadmap for any OpenClaw variant they choose to deploy, “as that will directly impact the foundation, and the momentum of the foundation and common base. If the common base loses momentum, it can lead to forks, or just a loss of innovation. When that happens, members tend to back away, which puts customers in limbo.”</p>



<p class="wp-block-paragraph">But not everyone sees the promised structure as entirely good for IT.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/ishraqkhann/" target="_blank" rel="noreferrer noopener">Ishraq Khan</a>, CEO at coding productivity tool vendor Kodezi, said, “most CIOs do not want to bet their future entirely on a single model vendor. They want Claude for some workloads, GPT for others, open models for sensitive environments, and potentially internally fine-tuned systems for specific use cases. The problem is that every vendor currently brings its own identity system, tool interfaces, permissions model, and operational assumptions. That fragmentation does not scale.”</p>



<p class="wp-block-paragraph">He said, “the risk if standards fail is straightforward: every vendor builds its own closed ecosystem, enterprises become locked into individual stacks, and security becomes dramatically harder. The opportunity if OpenClaw succeeds is equally significant: enterprises get portable agents, common identity standards, interoperable tooling, and a healthier competitive market around models rather than ecosystems.”</p>



<h2 class="wp-block-heading">Will it remain a nonprofit?</h2>



<p class="wp-block-paragraph">However, said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, one of the key details that IT executives will want to keep in mind is that OpenAI also began as a nonprofit, but it was quickly <a href="https://www.computerworld.com/article/4056490/openai-microsoft-discuss-shape-of-future-relationship.html" target="_blank">seen as not adhering to nonprofit objectives</a>. </p>



<p class="wp-block-paragraph">“OpenAI’s transition from a nonprofit research organization into a more complex structure highlighted the challenge of maintaining mission alignment while scaling technology, capital, partnerships, and commercial operations,” Greis said. “OpenClaw has the opportunity to address some of those governance questions earlier by establishing clear principles around neutrality, transparency, and decision-making before the ecosystem becomes even larger and more valuable.”</p>



<p class="wp-block-paragraph">He noted, “we have seen this pattern before with technologies like Linux and Kubernetes. The strongest open ecosystems succeeded because they created trusted foundations that enterprises could build upon. The technology was important, but the governance model that underpinned it was equally critical.”</p>



<h2 class="wp-block-heading">Risks are ‘squarely in IT’s lap’</h2>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, echoed Greis’ concerns. </p>



<p class="wp-block-paragraph">“CIOs shouldn’t assume that this nonprofit will always be a nonprofit, or confuse being a nonprofit with actually being neutral or unbiased,” he said. “The risks are squarely in IT’s lap: autonomous agents ‘with their own identity’ acting on a user’s behalf blow straight through traditional IAM assumptions. Issues, such as agent identity, auditability, secret handling. Identity boundaries have not yet been reliably solved. Until they are, enterprises should treat OpenClaw agents like privileged service accounts, not like a browser plugin.”</p>



<p class="wp-block-paragraph">Independent cybersecurity and risk advisor <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a> pointed to another IT exposure that might come from this OpenClaw transition: Cost.</p>



<p class="wp-block-paragraph">“OpenClaw currently has a very high token burn rate in usage, which presents a significant cost consideration for large-scale enterprise adoption,” he said. “The skills marketplace introduces <a href="https://www.csoonline.com/article/4129867/what-cisos-need-to-know-about-clawdbot-i-mean-moltbot-i-mean-openclaw.html" target="_blank">a new supply chain threat </a>that enterprises will need to manage. Threat management, and specifically handling <a href="https://www.csoonline.com/article/4135449/compromised-npm-package-silently-installs-openclaw-on-developer-machines.html" target="_blank">external marketplace elements</a>, can be highly challenging for open-source operations. Ultimately, at scale, enterprise adoption could become a difficult balancing act between managing high operational costs and securing an expanded security surface.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-56460 | HCL HCL DevOps Deploy/HCL Launch API information disclosure]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in HCL HCL DevOps Deploy and HCL Launch. This vulnerability affects unknown code of the component API. The manipulation leads to information disclosure.

This vulnerability is documented as CVE-2026-56460. The attack can be initiated remotel...]]></description>
<link>https://tsecurity.de/de/3666374/sicherheitsluecken/cve-2026-56460-hcl-hcl-devops-deployhcl-launch-api-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666374/sicherheitsluecken/cve-2026-56460-hcl-hcl-devops-deployhcl-launch-api-information-disclosure/</guid>
<pubDate>Mon, 13 Jul 2026 22:25:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/hcl:hcl_devops_deploy">HCL HCL DevOps Deploy and HCL Launch</a>. This vulnerability affects unknown code of the component <em>API</em>. The manipulation leads to information disclosure.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-56460">CVE-2026-56460</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Konferenz für Software-Entwicklung und Künstliche Intelligenz der Informatik Aktuell]]></title>
<description><![CDATA[IT-Security · DevOps · Datenbanken · Java. ☰. Entwicklung · Betrieb · Management ... Sicherheit und nachhaltige IT-Strategien. KI statt Software ...]]></description>
<link>https://tsecurity.de/de/3665847/it-security-nachrichten/konferenz-fuer-software-entwicklung-und-kuenstliche-intelligenz-der-informatik-aktuell/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665847/it-security-nachrichten/konferenz-fuer-software-entwicklung-und-kuenstliche-intelligenz-der-informatik-aktuell/</guid>
<pubDate>Mon, 13 Jul 2026 18:23:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>IT</b>-<b>Security</b> · DevOps · Datenbanken · Java. ☰. Entwicklung · Betrieb · Management ... Sicherheit und nachhaltige IT-Strategien. KI statt Software ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Do programming certifications still matter?]]></title>
<description><![CDATA[If you’re a software developer or architect, you might wonder if programming certifications are still worth the effort, especially in the era of rapid AI-driven evolution. The short answer is, it depends.



“Certifications are shifting from a checkbox to a compass. They’re less about proving you...]]></description>
<link>https://tsecurity.de/de/3665678/ai-nachrichten/do-programming-certifications-still-matter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665678/ai-nachrichten/do-programming-certifications-still-matter/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:44 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">If you’re a software developer or architect, you might wonder if programming certifications are still worth the effort, especially in the era of rapid <a href="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html" data-type="link" data-id="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html">AI-driven evolution</a>. The short answer is, it depends.</p>



<p class="wp-block-paragraph">“Certifications are shifting from a checkbox to a compass. They’re less about proving you memorized syntax and more about proving you can architect systems, instruct AI coding assistants, and solve problems end-to-end,” says Faizel Khan, lead AI engineer at <a href="https://landingpoint.com/">Landing Point</a>, an executive search and recruiting firm.</p>



<p class="wp-block-paragraph">“In the AI era, fewer students will get trained on the job, which means they have to train themselves,” Khan says. “Certifications—especially architectural ones like AWS, Kubernetes, Terraform—are still the clearest path to do that.”</p>



<h2 class="wp-block-heading">Pros and cons of programming certifications</h2>



<p class="wp-block-paragraph">It’s not all black and white when it comes to deciding whether to pursue programming certifications. The effort involves both pros and cons.</p>



<p class="wp-block-paragraph">“In terms of pros, certifications concretely demonstrate that you have a skillset at a documented level,” says Chris Riccio, vice president of engineering at <a href="https://uplevelteam.com/">Uplevel</a>, an engineering optimization system provider. “They also show that you’ve put in the time and effort to learn, study, and prepare.”</p>



<p class="wp-block-paragraph">Programming certifications are “a useful way to validate foundational skills and show that someone understands core concepts,” says Greg Fuller, vice president of Skillsoft’s training provider, <a href="https://www.codecademy.com/">Codecademy</a>. “They’re especially helpful for people entering the field or shifting from adjacent roles.”</p>



<p class="wp-block-paragraph">Certifications offer a structured path to demonstrate proficiency, and they can confirm your ability to build and deploy in various environments, Fuller says.</p>



<p class="wp-block-paragraph">These types of certifications often demonstrate baseline proficiency and continuous learning, says Reshmi Ramachandran, head of partnerships and GTM strategy for <a href="https://www.cprime.com/">Cprime</a>, a consultancy. “These are often key indications of proficiency for companies looking to filter large candidate pools,” she says.</p>



<p class="wp-block-paragraph">Certifications really do two things, Khan adds. “First, they force you to learn by doing,” he says. “If you’re taking AWS Solutions Architect or Terraform, you don’t pass by guessing—you plan, build, and test systems. That practice matters. Second, they act as a public signal. Think of it like a micro-degree. You’re not just saying, ‘I know cloud.’ You’re showing you’ve crossed a bar that thousands of other engineers recognize.”</p>



<p class="wp-block-paragraph">But there are cons, too. “In tech, employers don’t just want credentials, they want proof you can deliver,” says Kevin Miller, CTO at <a href="https://www.ifs.com/industries/manufacturing/industrial-manufacturing">IFS</a>, a maker of factory automation software. “Programming certifications can be a valuable indicator of your baseline knowledge and competencies, especially if you’re early in your career or pivoting into tech, but their importance is dwindling.”</p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/generative-ai/">AI tools</a> that can generate, debug, and optimize code are <a href="https://www.infoworld.com/article/4077352/85-of-developers-use-ai-regularly-jetbrains-survey.html" data-type="link" data-id="https://www.infoworld.com/article/4077352/85-of-developers-use-ai-regularly-jetbrains-survey.html">already performing tasks once done by entry-level developers</a>, “which means fewer traditional programming roles are available,” Miller says. “As a result, the job market is becoming more competitive, and certifications aren’t seen as the noteworthy achievement they once were.”</p>



<p class="wp-block-paragraph">What’s more, not all certifications carry the same weight, Riccio says. “Some may reflect only familiarity rather than true expertise,” he says. “Certifications also often measure ‘book knowledge’ rather than practical experience, and they don’t always map clearly to the requirements of a specific role.”</p>



<p class="wp-block-paragraph">Programming certifications “can be a helpful signal, especially for confirming baseline knowledge in areas like cloud, security, or devops, but they’re not the full picture,” says Morgan Watts, vice president of IT at <a href="https://developer.8x8.com/">8×8</a>, a contact center platform developer.</p>



<p class="wp-block-paragraph">“I’m more interested in a candidate’s attitude and aptitude: what problems they’ve solved, what they’ve built, and how they’ve approached challenges,” Watts says. “Certifications can show commitment and discipline, and they’re especially useful in highly specialized roles. But I’m cautious when someone presents a laundry list of certifications with little evidence of real-world application.”</p>



<p class="wp-block-paragraph">A certification without experience doesn’t carry much weight, Watts says, and over-certification can sometimes signal the wrong focus. “Ultimately, it’s the ability to apply knowledge, collaborate, and adapt that sets great developers apart,” he says.</p>



<p class="wp-block-paragraph">Finally, certifications can age fast, Khan says. “Tech stacks evolve and a badge from two years ago may already feel dusty,” he says. “And some certifications are paper-thin—multiple-choice exams that don’t prove you can debug production at 2 a.m. So, the risk is you collect badges but still can’t ship.”</p>



<h2 class="wp-block-heading">Which certifications will get you noticed?</h2>



<p class="wp-block-paragraph">Despite the drawbacks, certifications are still very much in demand, and some carry more weight than others.</p>



<p class="wp-block-paragraph">The most in-demand certifications are typically platform-based—Amazon Web Services (AWS), Google Cloud Platform (GCP), Microsoft Azure, and others, Riccio says. “Many of these platforms provide managed services that integrate with existing systems or serve as the glue between them,” he says. “Today’s engineering teams aren’t just building standalone systems in isolation; they’re using other systems to store data, orchestrate business workflows, and connect applications.”</p>



<p class="wp-block-paragraph">A certification that demonstrates the ability to build solutions on these platforms can put a development professional ahead of the competition, Riccio says.</p>



<p class="wp-block-paragraph">“The certifications I see in highest demand tend to reflect the evolving tech landscape,” Watts says. “Cloud certifications from AWS, Azure, and GCP are incredibly valuable, especially as distributed systems become the norm.”</p>



<p class="wp-block-paragraph">Also in demand are certifications for <a href="https://www.infoworld.com/article/3632270/the-devops-certifications-tech-companies-want.html">devops and CI/CD tools</a> including <a href="https://www.infoworld.com/article/3529526/how-to-succeed-with-kubernetes.html">Kubernetes</a>, <a href="https://www.infoworld.com/article/2257241/why-you-should-use-docker-and-oci-containers.html">Docker</a>, and <a href="https://www.infoworld.com/article/2260091/what-is-jenkins-the-ci-server-explained.html">Jenkins</a>, Watts says, “because deployment automation and reliability are critical at scale. Also, with AI reshaping development, we’re seeing growing interest in certifications around machine learning, data science, and AI model integration. These certifications stand out because they align directly with the skills that teams need to move faster and more intelligently.”</p>



<aside class="sidebar large">
<h3>More about developer certifications</h3>
<p>Learn more about developer courses and certifications tech companies want:</p>
<ul>
<li><a href="https://www.infoworld.com/article/4055032/ai-developer-certifications-tech-companies-want.html">AI developer certifications</a></li>
<li><a href="https://www.infoworld.com/article/3583466/the-machine-learning-certifications-tech-companies-want.html">Machine learning certifications</a></li>
<li><a href="https://www.infoworld.com/article/2337635/4-cloud-certifications-that-will-help-you-stand-out.html">Cloud development certifications</a></li>
<li><a href="https://www.infoworld.com/article/3632270/the-devops-certifications-tech-companies-want.html">Devops and CI/CD certifications</a></li>
</ul>
</aside>




<p class="wp-block-paragraph">On the AI front, certifications in <a href="https://www.infoworld.com/article/2255099/what-is-tensorflow-the-machine-learning-library-explained.html">TensorFlow</a> and other <a href="https://www.infoworld.com/article/3583466/the-machine-learning-certifications-tech-companies-want.html">machine learning platforms</a> are gaining traction as organizations look to embed AI across the development process, Watts says. “These are the certifications that align closely with where modern engineering is headed—scalable, secure, and AI-enabled,” he says.</p>



<p class="wp-block-paragraph">And then there are <a href="https://www.csoonline.com/article/3970107/the-14-most-valuable-cybersecurity-certifications.html">cybersecurity credentials</a> that continue to be in high demand. Security certifications, such as CompTIA Security+ or Certified Ethical Hacker, “have become essential as every company faces increasing cyber threats and compliance requirements,” Miller says.</p>



<p class="wp-block-paragraph">“Core programming certifications are still a bit niche, but the adjacent skills, like those that help developers deploy, secure, and scale their code, are driving demand,” Fuller says. “Companies want developers who understand the full lifecycle, not just how to write code.”</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3980325/the-java-certifications-tech-companies-want.html">The best Java certifications for software developers</a>.</strong></p>



<h2 class="wp-block-heading">Certifications in the hiring process</h2>



<p class="wp-block-paragraph">Experts are clear that programming certifications alone will not get you the job. But they do play a role in the hiring process.</p>



<p class="wp-block-paragraph">“The information technology world is characterized by rapid and continuous evolution, including the skills and knowledge required to work in the field,” says Diane Rafferty, managing director of the National Technology Group at <a href="https://www.atriumglobal.com/">Atrium</a>, a global talent solutions and extended workforce management firm.</p>



<p class="wp-block-paragraph">“Certifications not only prove that you have the skills and knowledge needed, but they also show employers that you’re invested in your education and career growth,” Rafferty says. “They can give you a competitive edge when looking for a job, as many companies now require candidates to have them.”</p>



<p class="wp-block-paragraph">Certifications are one part of the hiring equation, “but never the only part,” Watts says. “They help validate that a candidate has taken the time to build foundational knowledge, and that’s a good sign. But I put more weight on how a person thinks, solves problems, and contributes to the team. I look for people who are curious and proactive, who are learning because they want to, not just because a course told them to.”</p>



<p class="wp-block-paragraph">Certifications can also play a valuable role in retention, Watts says. “I encourage team members to pursue growth, and when they invest in their own development, the whole organization benefits,” he says. “But again, it’s that balance of knowledge, attitude, and applied experience that really moves the needle.”</p>



<p class="wp-block-paragraph">Certifications “may allow you to breeze through the initial résumé screening process, potentially getting you to the next stage faster,” Riccio says. “At a minimum, they will set your profile apart from the rest of the pack. They also demonstrate that you’ve reached a baseline level of expertise, allowing hiring managers to quickly evaluate whether you have the skills for the role.”</p>



<p class="wp-block-paragraph">Employers today “care far less about whether someone has passed an exam and far more about whether they can apply knowledge effectively in real-world situations, leverage AI tools, and solve complex problems,” Miller says. “A certification might get someone an interview, but being able to demonstrate problem-solving skills, teamwork, and adaptability will really make them stand out.”</p>



<h2 class="wp-block-heading">Popular programming certifications</h2>



<p class="wp-block-paragraph">The following certifications consistently rose to the top in my conversations with tech leaders and hiring managers.</p>



<h3 class="wp-block-heading">AWS Certified Developer—Associate</h3>



<p class="wp-block-paragraph">Showcases skills and knowledge in developing, optimizing, packaging, and deploying applications, using CI/CD workflows, and identifying and resolving application issues, according to AWS. This certification is said to be a good starting point on the AWS certification journey for professionals in IT or cloud developer job roles.</p>



<h3 class="wp-block-heading">Azure Developer Associate</h3>



<p class="wp-block-paragraph">This certificate from Microsoft is intended for developers participating in all phases of cloud development, including design, deployment, maintenance, and monitoring. The course teaches developers how to create end-to-end solutions in Microsoft Azure, using the Microsoft Learn Sandbox environment to access Azure resources and services.</p>



<h3 class="wp-block-heading">Certified Kubernetes Application Developer (CKAD)</h3>



<p class="wp-block-paragraph">This certification was created by the Linux Foundation and Cloud Native Computing Foundation. It demonstrates that candidates can design, build, and deploy cloud-native applications for Kubernetes.</p>



<h3 class="wp-block-heading">Certified Secure Software Lifecycle Professional (CSSLP)</h3>



<p class="wp-block-paragraph">This certification, from ISC2, focuses on secure software development practices. It recognizes leading application security skills and demonstrates advanced technical skills and knowledge needed for authentication, authorization, and auditing throughout the software development lifecycle.</p>



<h3 class="wp-block-heading">Databricks Certified Machine Learning Professional</h3>



<p class="wp-block-paragraph">Professionals learn about the latest data and AI techniques and how they can use the Databricks Data Intelligence Platform to build a variety of solutions across data engineering, data warehousing, data science, and AI.</p>



<h3 class="wp-block-heading">Professional Cloud Architect</h3>



<p class="wp-block-paragraph">This certification from Google assesses the ability to design and plan a cloud solution architecture, manage and provision the cloud solution infrastructure, design for security and compliance, analyze and optimize technical and business processes manage implementations of cloud architecture, and ensure solution and operations reliability.</p>



<h3 class="wp-block-heading">Terraform Associate</h3>



<p class="wp-block-paragraph">This certification from HashiCorp is for cloud engineers specializing in operations, IT, or development who know the basic concepts and skills associated with Terraform. It validates foundational skills in using <a href="https://www.infoworld.com/article/3893387/how-terraform-is-evolving-infrastructure-as-code.html">Terraform</a> for <a href="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html">infrastructure as code</a> development.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is devops? Bringing dev and ops together to build better software]]></title>
<description><![CDATA[A portmanteau of “development” and “operations,” devops emerged as a way of bringing together two previously separate groups responsible for the building and deploying of software.



In the old world, developers (devs) typically wrote code before throwing it over to the system administrators (op...]]></description>
<link>https://tsecurity.de/de/3665673/ai-nachrichten/what-is-devops-bringing-dev-and-ops-together-to-build-better-software/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665673/ai-nachrichten/what-is-devops-bringing-dev-and-ops-together-to-build-better-software/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:38 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A portmanteau of “development” and “operations,” devops emerged as a way of bringing together two previously separate groups responsible for the building and deploying of software.</p>



<p class="wp-block-paragraph">In the old world, developers (devs) typically wrote code before throwing it over to the system administrators (operations, or ops) to deploy and integrate that code. But as the industry shifted towards <a href="https://www.infoworld.com/article/2259475/what-is-agile-methodology-modern-software-development-explained.html">agile development</a> and <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html">cloud-native computing</a>, many organizations reoriented around modern, cloud-native practices in the pursuit of faster, better releases.</p>



<p class="wp-block-paragraph">This required a new way to perform these key functions in a more streamlined, efficient, and cohesive way, one where the old frustrations of disconnected dev and ops functions would be eliminated. With two groups working together, developers can rapidly roll out small code enhancements via <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">continuous integration and delivery</a> rather than spending years on “big bang” product releases.</p>



<p class="wp-block-paragraph">Devops was born at cloud-native companies like Facebook, Netflix, Spotify, and Amazon; but it’s become one of the defining technology industry trends of the past decade, primarily because it bridges so many of the changes that have shaped modern software development.</p>



<p class="wp-block-paragraph">As agile development and cloud-native computing have become ubiquitous, devops has enabled the entire industry to speed up its software development cycles. Thus, devops has now thoroughly infiltrated the enterprise, especially in organizations that rely on software to run their business, such as banks, airlines, and retailers. <a>And it’s spawned a host of other “ops” practices, some of which we’ll touch on here.</a><a href="https://www.infoworld.com/article/2255028/what-is-devops-bringing-dev-and-ops-together-for-better-software.html#_msocom_1">[JF1]</a> </p>



<h2 class="wp-block-heading"><strong>Devops practices</strong></h2>



<p class="wp-block-paragraph">Devops requires a shift in mindset from both sides of the dev and ops divide. Development teams should focus on learning and adopting agile processes, standardizing platforms, and helping drive operational efficiencies. Operations teams must now focus on improving stability and velocity, while also reducing costs by working hand in hand with the developer team.</p>



<p class="wp-block-paragraph">Broadly speaking, these teams need to all speak a common language and there needs to be a shared goal and understanding of each other’s key skills for devops to thrive.</p>



<p class="wp-block-paragraph">More specifically, engineers Damon Edwards and John Willis <a href="https://www.devopsgroup.com/insights/resources/diagrams/all/calms-model-of-devops/">created the CALMS model</a> to bring together what are commonly understood to be the key principles of devops:</p>



<ul class="wp-block-list">
<li>Culture: One that embraces <a href="https://www.infoworld.com/article/2259475/what-is-agile-methodology-modern-software-development-explained.html">agile methodologies</a> and is open to change, constant improvement, and accountability for the end-to-end quality of software.</li>



<li>Automation: Automating away toil is a key goal for any devops team.</li>



<li>Lean: Ensuring the smooth flow of software through key steps as quickly as possible.</li>



<li>Measurement: You can’t improve what you don’t measure. Devops pushes for a culture of constant measurement and feedback that can be used to improve and pivot as required, on the fly.</li>



<li>Sharing: Knowledge sharing across an organization is a key tenet of devops.</li>
</ul>



<p class="wp-block-paragraph">“Who could go back to the old way of trying to figure out how to get your laptop environment looking the same as the production environment? All these things make it so clear that there’s a better way to work. I think it’s very tough to turn back once you’ve done things like continuous integration, like continuous delivery. Once you’ve experienced it, it’s really tough to go back to the old way of doing things,” Kim <a href="https://www.infoworld.com/article/2258333/devops-expert-gene-kim-how-devops-helps-business-meet-challenging-times.html">told InfoWorld</a>.</p>



<h2 class="wp-block-heading"><strong>What is a devops engineer?</strong></h2>



<p class="wp-block-paragraph">Naturally, the emergence of devops has spawned a whole new set of job titles, most prominent of which is the catch-all <a href="https://www.infoworld.com/article/2259407/what-is-a-devops-engineer-and-how-do-you-become-one.html">devops engineer</a>.</p>



<p class="wp-block-paragraph">Generally speaking, this role is the natural evolution of the system administrator — but in a world where developers and ops work in close tandem to deliver better software. This person should have a blend of programming and system administrator skills so that he or she can effectively bridge those two sides of the team.</p>



<p class="wp-block-paragraph">That bridging of the two sides requires strong social skills more than technical. As Kim put it, “one of the most important skills, abilities, traits needed in these pioneering rebellions — using devops to overthrow the ancient powerful order, who are very happy to do things the way they have for 30 to 40 years — are the cross-functional skills to be able to reach across the table to their business counterparts and help solve problems.”</p>



<p class="wp-block-paragraph">This person, or team of people, will also have to be a born optimizer, tasked with continually improving the speed and quality of software delivery from the team, be that through better practices, removing bottlenecks, or applying automation to smooth out software delivery.</p>



<p class="wp-block-paragraph">The good news is that these skills are valuable to the enterprise. <a href="https://www.infoworld.com/article/2263101/devops-salaries-continued-to-rise-during-the-pandemic.html">Salaries for this set of job titles have risen steadily over the years</a>, with 95% of devops practitioners making more than $75,000 a year in salary in 2020 in the United States. In Europe and the UK, where salaries are lower across the board, 71% made more than $50,000 a year in 2020, up from 67% in 2019.</p>



<h2 class="wp-block-heading"><strong>Key devops tools</strong></h2>



<p class="wp-block-paragraph">While devops is at its heart a cultural shift, a set of tools has emerged to help organizations adopt devops practices.</p>



<p class="wp-block-paragraph">This stack typically includes <a href="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html">infrastructure as code</a>, configuration management, collaboration, version control, <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">continuous integration and delivery (CI/CD)</a>, deployment automation, testing, and monitoring tools.</p>



<p class="wp-block-paragraph">Here are some of the tools/categories that are increasingly relevant in 2025, and what is changing:</p>



<ul class="wp-block-list">
<li><strong>CI/CD and delivery automation</strong>: Traditional tools like Jenkins remain in many stacks, but newer orchestration tools and CLI-driven or GitOps-centric platforms are growing in importance (e.g. ArgoCD, Flux, Tekton). Also, platforms that integrate more tightly with monitoring, secrets management, drift detection, and policy enforcement are gaining traction.</li>



<li><strong>Security, compliance, and devsecops tooling</strong>: Security tools are increasingly integrated into devops pipelines. Expect to see more use of static analysis (SAST), dynamic testing (DAST), dependency and supply chain scanning (SCA), secret management, and policy as code. The push is toward embedding security earlier and <a href="https://www.infoworld.com/article/3965374/bringing-devops-devsecops-and-mlops-together.html">bridging gaps between dev, security, and machine learning teams</a>. (InfoWorld:)</li>



<li><strong>AI  and automation augmentation</strong>: AI-assisted tools are increasingly part of tooling stacks: auto-suggestions in CI/CD, anomaly detection, predictive scaling, intelligent test suite selection, and more. The hope is that these tools will reduce manual interventions and improve reliability. Tools that are “AI ready”—that is, they integrate well with AI or have mature built-in automation or assistance—increasingly <a href="https://www.infoworld.com/article/4052402/how-to-choose-the-right-ai-agent-development-tools.html">stand out from the pack</a>.</li>
</ul>



<h2 class="wp-block-heading"><strong>Devops challenges</strong></h2>



<p class="wp-block-paragraph">Even as devops becomes more widely adopted, there remain real obstacles that can slow progress or limit impact. One major challenge is the persistent <strong>skills gap</strong>. The modern devops engineer (or team) is expected to master not just source control, CI/CD, and scripting, but also cloud architecture, infrastructure as code, security best practices, observability, and strong cross-team communication. In many organizations these capabilities are uneven: some teams excel, others lag behind. A 2024 survey showed that while 83% of developers report participating in devops activities, <a href="https://www.infoworld.com/article/2337172/most-developers-have-adopted-devops-survey-says.html">using multiple CI/CD tools was correlated with <em>worse</em> performance</a> — a sign that complexity without deep expertise can backfire.</p>



<p class="wp-block-paragraph"><strong>Toolchain fragmentation and complexity </strong>is a related issue. Devops toolchains have sprouted into a sometimes bewildering array of packages and techniques to master: version control, CI build/test, security scanning, artifact management, monitoring, observability, deployment, secret management, and more.</p>



<p class="wp-block-paragraph">The more tools you have, the more difficult it becomes to integrate them cleanly, manage their versions, ensure compatibility, and avoid duplicated effort. Organizations often get stuck with “tool sprawl” — tools chosen by different teams, legacy systems, or overlapping functionalities — which introduce friction, maintenance burden, and sometimes vulnerabilities.</p>



<p class="wp-block-paragraph">Finally, although devops has spread far and wide, there is still <strong>cultural resistance and alignment</strong>. Devops isn’t just about tools and processes; it’s about collaboration, shared responsibility, and continuous feedback. Teams rooted in traditional silos (dev vs ops, or security separate) may <a href="https://www.infoworld.com/article/2337372/10-big-devops-mistakes-and-how-to-avoid-them.html">resist changes to roles and workflows</a>. Leadership support, communication of shared goals, trust, and allowance for continuous learning are all necessary.</p>



<p class="wp-block-paragraph">Many CIOs <a href="https://www.cio.com/article/3552944/6-enterprise-devops-mistakes-to-avoid.html">focus too much on tools or implementation first</a>, rather than organizational culture and behaviors; but without addressing culture, even the best tools or processes may not yield the hoped-for velocity, quality, or reliability. Organizations that succeed here tend to have proactive strategies: dedicated training programs, mentorship, internal “guilds,” pairing junior and senior engineers, and making sure leadership supports ongoing learning rather than one-off bootcamps.</p>



<h2 class="wp-block-heading"><strong>Why do devops?</strong></h2>



<p class="wp-block-paragraph">Whoever you ask will tell you that devops is a major culture shift for organizations, so why go through that pain at all?</p>



<p class="wp-block-paragraph">Devops aims to combine the formerly conflicting aims of developers and system administrators. Under its principles, all software development aims to meet business demands, add functionality, and improve the usability of applications while also ensuring those applications are stable, secure, and reliable. Done right, this improves the velocity and quality of your output, while also improving the lives of those working on these outcomes.</p>



<h2 class="wp-block-heading"><strong>Does devops save money — or add cost?</strong></h2>



<p class="wp-block-paragraph">Devops teams are recognizing that speed and agility are only part of success — unchecked cloud bills and waste undermine long-term sustainability. Waste in devops often comes in the form of “<a href="https://www.infoworld.com/article/4010176/devops-debt-the-hidden-tax-on-innovation.html?utm_source=chatgpt.com">devops</a> debt”— idle cloud capacity, dead code, or false-positive security alerts—which was called a “<a href="https://www.infoworld.com/article/4010176/devops-debt-the-hidden-tax-on-innovation.html">hidden tax on innovation</a>” in recent Java-environment studies.</p>



<p class="wp-block-paragraph"> Embedding <a href="https://www.cio.com/article/3839075/finops-breaks-out-of-the-cloud.html">finops</a> practices can help fight these costs. Teams should <a href="https://www.infoworld.com/article/4013485/how-to-shift-left-on-finops-and-why-you-need-to.html">shift left on cost</a>: estimating costs when spinning up new environments, resizing instances, and scaling down unused resources before they become runaway expenses.</p>



<h2 class="wp-block-heading"><strong>How to start with devops</strong></h2>



<p class="wp-block-paragraph">There are lots of resources for help getting started with devops, <a href="https://www.amazon.com/DevOps-Handbook-World-Class-Reliability-Organizations-ebook/dp/B01M9ASFQ3">including Kim’s own <em>Devops Handbook</em></a>, or you can enlist the help of external consultants. But you have to be methodical and focus on your people more than on the tools and technology you will eventually use <a href="https://www.infoworld.com/article/2258896/6-ways-to-secure-buy-in-for-your-devops-journey.html">if you want to ensure lasting buy-in across the business</a>.</p>



<p class="wp-block-paragraph">A proven route to achieving this is a “land and expand” strategy, where a small group starts by mapping key value streams and identifying a single product team or workload for trialing devops practices. If this team is successful in proving the value of the shift, you will likely start to get interest from other teams and from senior leadership.</p>



<p class="wp-block-paragraph">If you are at the start of your devops journey, however, make sure you are prepared for the disruption a change like this can have on your organization, and keep your eye on the prize of building better, faster, stronger software.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<p class="wp-block-paragraph"><a></a></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">More on devops:</p>



<ul class="wp-block-list">
<li><a href="https://www.infoworld.com/article/4010176/devops-debt-the-hidden-tax-on-innovation.html">Devops debt: The hidden tax on innovation</a></li>



<li><a href="https://www.infoworld.com/article/2337372/10-big-devops-mistakes-and-how-to-avoid-them.html">10 big devops mistakes and how to avoid them</a></li>



<li><a href="https://www.infoworld.com/article/3621681/smarter-devops-how-to-avoid-deployment-horrors.html">Smarter devops: How to avoid deployment horrors</a><div class="card__info"></div></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud native explained: How to build scalable, resilient applications]]></title>
<description><![CDATA[What is cloud native? Cloud native defined



The term “cloud-native computing” encompasses the modern approach to building and running software applications that exploit the flexibility, scalability, and resilience of cloud computing. The phrase is a catch-all that encompasses not just the speci...]]></description>
<link>https://tsecurity.de/de/3665670/ai-nachrichten/cloud-native-explained-how-to-build-scalable-resilient-applications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665670/ai-nachrichten/cloud-native-explained-how-to-build-scalable-resilient-applications/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:33 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading"><strong>What is cloud native? Cloud native defined</strong></h2>



<p class="wp-block-paragraph">The term “cloud-native computing” encompasses the modern approach to building and running software applications that exploit the flexibility, scalability, and resilience of cloud computing. The phrase is a catch-all that encompasses not just the specific architecture choices and environments used to build applications for the public cloud, but also the software engineering techniques and philosophies used by cloud developers.</p>



<p class="wp-block-paragraph">The <a href="https://www.cncf.io/">Cloud Native Computing Foundation</a> (CNCF) is an open source organization that hosts many important cloud-related projects and helps set the tone for the world of cloud development. The CNCF offers its own definition of cloud native:</p>



<p class="wp-block-paragraph"><em>Cloud native practices empower organizations to develop, build, and deploy workloads in computing environments (public, private, hybrid cloud) to meet their organizational needs at scale in a programmatic and repeatable manner. It is characterized by loosely coupled systems that interoperate in a manner that is secure, resilient, manageable, sustainable, and observable.</em></p>



<p class="wp-block-paragraph"><em>Cloud native technologies and architectures typically consist of some combination of containers, service meshes, multi-tenancy, microservices, immutable infrastructure, serverless, and declarative APIs — this list is not exhaustive.</em></p>



<p class="wp-block-paragraph">This definition is a good start, but as cloud infrastructure becomes ubiquitous, the cloud native world is beginning to spread behind the core of this definition. We’ll explore that evolution as well, and look into the near future of cloud-native computing.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<h2 class="wp-block-heading"><strong>Cloud native architectural principles</strong></h2>



<p class="wp-block-paragraph">Let’s start by exploring the pillars of cloud-native architecture. Many of these technologies and techniques were considered innovative and even revolutionary when they hit the market over the past few decades, but now have become widely accepted across the software development landscape.</p>



<p class="wp-block-paragraph"><strong>Microservices. </strong>One of the huge cultural shifts that made cloud-native computing possible was the move from huge, monolithic applications to <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices</a>: small, loosely coupled, and independently deployable components that work together to form a cloud-native application. These microservices can be scaled across cloud environments, though (as we’ll see in a moment) this makes systems more complex.</p>



<p class="wp-block-paragraph"><strong>Containers and orchestration. </strong>In could-native architectures, individual microservices are executed inside <em>containers </em>— lightweight, portable virtual execution environments that can run on a variety of servers and cloud platforms. Containers insulate the developers from having to worry about the underlying machines on which their code will execute. That is, all they have to do is write to the container environment. </p>



<p class="wp-block-paragraph">Getting the containers to run properly and communicate with one another is where the complexity of cloud native computing starts to emerge. Initially, containers were created and managed by relatively simple platforms, the most common of which was <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Docker</a>. But as cloud-native applications got more complex, container orchestration platforms<em> </em>that augmented Docker’s functionality emerged, such as Kubernetes, which allows you to deploy and manage multi-container applications at scale. Kubernetes is critical to cloud native computing as we know it — it’s worth noting that the CNCF was set up as a <a href="https://www.zdnet.com/article/cloud-native-computing-foundation-seeks-to-bring-more-cloud-and-container-unity/">spinoff of the Linux Foundation on the same day that Kubernetes 1.0 was announced</a> — and adhering to <a href="https://www.infoworld.com/article/2338688/6-best-practices-to-keep-kubernetes-costs-under-control.html">Kubernetes best practices</a> is an important key to cloud native success. </p>



<p class="wp-block-paragraph"><strong>Open standards and APIs. </strong>The fact that containers and cloud platforms are largely defined by open standards and <a href="https://www.infoworld.com/article/3800992/open-source-trends-for-2025-and-beyond.html">open source technologies</a> is the secret sauce that makes all this modularity and orchestration possible, and <a href="https://www.infoworld.com/article/3529600/how-do-you-govern-a-sprawling-disparate-api-portfolio.html">standardized and documented APIs </a>offer the means of communication between distributed components of a larger application. In theory, anyway, this standardization means that every component should be able to communicate with other components of an application without knowing about their inner workings, or about the inner workings of the various platform layers on which everything operates.</p>



<p class="wp-block-paragraph"><strong>DevOps, agile methodologies, and infrastructure as code. </strong>Because cloud-native applications exist as a series of small, discrete units of functionality, cloud-native teams can build and update them using agile philosophies like <a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">DevOps</a>, which promotes <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">rapid, iterative CI/CD development</a>. This enables teams to deliver business value more quickly and more reliably.</p>



<p class="wp-block-paragraph">The virtualized nature of cloud environments also make them great candidates for <a href="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html">infrastructure as code</a> (IaC), a practice in which teams use tools like <a href="https://developer.hashicorp.com/terraform/intro">Terraform</a>, <a href="https://www.pulumi.com/">Pulumi</a>, and <a href="https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/Welcome.html">AWS CloudFormation</a>, to manage infrastructure declaratively and version those declarations just like application code. IaC boosts automation, repeatability, and resilience across environments—all big advantages in the cloud world. IaC also goes hand-in-hand with the concept of <em>immutable infrastructure</em>—the idea that, once deployed, infastructure-level entities like virtual machines, containers, or network appliances don’t change, which makes them easier to manage and secure. IaC stores declarative configuration code in version control, which creates an audit log of any changes.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/04/5_things_cloud_native.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Chart listing five things to love and five things to fear when considiering cloud native" class="wp-image-3970036" width="1024" height="472" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>There’s a lot to love about cloud-native architectures, but there are also several things to be wary of when considering it.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<h2 class="wp-block-heading"><strong>How the cloud-native stack is expanding</strong></h2>



<p class="wp-block-paragraph">As cloud-native development becomes the norm, the cloud-native ecosystem is expanding; the CNCF maintains a graphical representation of what it calls the  <a href="https://landscape.cncf.io/">cloud native landscape</a> that hammers home to expansive and bewildering variety of products, services, and open source projects that contribute to (and seek to profit from) to cloud-native computing. And there are a number of areas where new and developing tools are complicating the picture sketched out by the pillars we discussed above.   </p>



<p class="wp-block-paragraph"><strong>An expanding Kubernetes ecosystem.</strong> <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes </a>is complex, and teams now rely on an <a href="https://www.infoworld.com/article/2265338/13-tools-that-make-kubernetes-better.html">entire ecosystem of projects </a>to get the most out of it: <a href="https://www.infoworld.com/article/2264445/helm-3-package-manager-arrives-for-kubernetes.html">Helm</a> for packaging, <a href="https://argo-cd.readthedocs.io/en/stable/">ArgoCD </a>for GitOps-style deployments, and <a href="https://kustomize.io/">Kustomize </a>for configuration management. And just as Kubernetes augmented Docker for enterprise-scale deployments. Kubernetes itself has been augmented and expanded by <a href="https://www.infoworld.com/article/2261159/what-is-a-service-mesh-easier-container-networking.html">service mesh</a> offerings like <a href="https://istio.io/">Istio </a>and <a href="https://linkerd.io/">Linkerd</a><strong>, </strong>which offer fine-grained traffic control and improved security</p>



<p class="wp-block-paragraph"><strong>Observability needs. </strong>The complex and distributed world of cloud-native computing requires in-depth <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a> to ensure that developers and admins have a handle on what’s happening with their applications. <a href="https://www.infoworld.com/article/2337343/what-observability-means-for-cloud-operations.html">Cloud-native observability</a> uses distributed tracing and aggregated logs to provide deep insight into performance and reliability. Tools like <a href="https://www.infoworld.com/article/2246709/prometheus-unbound-open-source-cloud-monitoring.html">Prometheus</a>, <a href="https://www.infoworld.com/article/2337267/grafana-shining-a-light-into-kubernetes-clusters.html">Grafana</a>, <a href="https://www.cncf.io/projects/jaeger/">Jaeger</a>, and <a href="https://opentelemetry.io/">OpenTelemetry</a> support comprehensive, real-time observability across the stack.</p>



<p class="wp-block-paragraph"><strong>Serverless computing.  </strong><a href="https://www.infoworld.com/article/2261831/what-is-serverless-serverless-computing-explained.html">Serverless computing</a>, particularly in its function-as-a-service guise, offers to strip needed compute resources down to their bare minimum, with functions running on service provider clouds using exactly as much as they need and no more. Because these services can be exposed as endpoints via APIs, they are increasingly integrated into distributed applications, operating side-by-side with functionality provided by containerized microservices. Watch out, though: the big FaaS providers (<a href="https://www.infoworld.com/article/2265860/aws-lambda-tutorial-get-started-with-serverless-computing.html">Amazon</a>, <a href="https://www.infoworld.com/article/2255377/how-to-work-with-azure-functions-in-csharp.html">Microsoft</a>, and <a href="https://www.infoworld.com/article/2243861/google-takes-aims-at-aws-lambda-with-cloud-functions.html">Google</a>) would love to lock you in to their ecosystems.  </p>



<p class="wp-block-paragraph"><strong>FinOps. </strong><a href="http://infoworld.com/article/2238873/what-is-cloud-computing.html">Cloud computing</a> was initially billed as a way to cut costs — no need to pay for an in-house data center that you barely use — but in practice it replaces capex with opex, and sometimes you can run up truly shocking cloud service bills if you aren’t careful. Serverless computing is one way to cut down on those costs, but financial operations, or <a href="https://www.cio.com/article/416337/what-is-finops-your-guide-to-cloud-cost-management.html">FinOps</a>, is a more systematic discipline that aims to aligns engineering, finance, and product to optimize cloud spending. <a href="https://www.infoworld.com/article/2338592/6-finops-best-practices-to-reduce-cloud-costs.html">FinOps best practices</a> make use of those observability tools to best determine what departments and applications are eating up resources.</p>



<h2 class="wp-block-heading"><strong>How cloud-native architecture is adapting to AI workloads</strong></h2>



<p class="wp-block-paragraph">Enterprises deploy larger AI models and make use of more and more real-time inference services. That’s putting demands on cloud-native systems and forcing them to adapt to remain scalable and reliable.</p>



<p class="wp-block-paragraph">For instance, organizations are <a href="https://www.infoworld.com/article/4057189/the-rise-of-ai-ready-private-clouds.html">re-engineering cloud environments</a> around GPU-accelerated clusters, low-latency networking, and predictable orchestration. These needs align with established cloud-native patterns: containers package AI services consistently, while Kubernetes provides resilient scheduling and horizontal scale for inference workloads that can spike without warning.</p>



<p class="wp-block-paragraph">Kubernetes itself is <a href="https://www.infoworld.com/article/4045563/evolving-kubernetes-for-generative-ai-inference.html">changing to better support AI inference</a>, adding hardware-aware scheduling for GPUs, model-specific autoscaling behavior, and deeper observability into inference pipelines. These enhancements make Kubernetes a more natural platform for serving generative AI workloads.</p>



<p class="wp-block-paragraph">AI’s resource demands are amplifying traditional cloud-native challenges. Observability becomes more complex as inference paths span GPUs, CPUs, vector databases, and distributed storage. <a href="https://www.cio.com/article/416337/what-is-finops-your-guide-to-cloud-cost-management.html">FinOps</a> teams contend with cost volatility from training and inference bursts. And security teams must track new risks around model provenance, data access, and supply-chain integrity.</p>



<h2 class="wp-block-heading"><strong>Application frameworks for building distributed cloud-native apps</strong></h2>



<p class="wp-block-paragraph">Microsoft’s Aspire is one of the most visible examples of a shift towards application frameworks to simplify how teams build distributed systems. Opinionated frameworks like Aspire provide structure, observability, and integration out of the box so developer don’t need to stitch together containers, microservices, and orchestration tooling by hand.</p>



<p class="wp-block-paragraph">Aspire in particular is a <a href="https://www.infoworld.com/article/4023638/taking-net-aspire-for-a-spin.html">prescriptive framework for cloud-native applications</a>, bundling containerized services, environment configuration, health checks, and observability into a unified development model. Aspire provides defaults for service-to-service communication, configuration, and deployment, along with a built-in dashboard for visibility across distributed components.</p>



<p class="wp-block-paragraph">While Aspire was originally aligned with Microsoft’s .<a href="https://www.infoworld.com/article/2264488/what-is-the-net-framework-microsofts-answer-to-java.html">NET platform</a>,Redmond now sees it as having a<strong>  </strong><a href="https://www.infoworld.com/article/4085051/aspires-polyglot-future.html?utm_source=chatgpt.com">polyglot future</a>. This positions Aspire as part of a broader trend: frameworks that help teams build cloud-native, service-oriented systems without being locked into a single language ecosystem. Several other frameworks are gaining traction: Dapr provides a portable runtime that abstracts many of the plumbing tasks in cloud-native distributed applications, and Orleans offers an actor-model-based framework for large-scale systems in the .NET world, and Akka gives JVM teams a mature, reactive toolkit for elastic, resilient services.</p>



<h2 class="wp-block-heading"><strong>Frameworks and tools in the expanding cloud-native ecosystem</strong></h2>



<p class="wp-block-paragraph">While frameworks like Aspire simplify how developers compose and structure distributed applications, most cloud-native systems still depend on a broader ecosystem of platforms and operational tooling. This deeper layer is where much of the complexity—and innovation—of cloud-native computing lives, particularly as Kubernetes continues to serve as the industry’s control plane for modern infrastructure.</p>



<p class="wp-block-paragraph">Kubernetes provides the core abstractions for deploying and orchestrating containerized workloads at scale. Managed distributions such as Google Kubernetes Engine (GKE), Amazon EKS, <a href="https://www.infoworld.com/article/4058764/smoother-kubernetes-sailing-with-aks-automatic.html">Azure AKS</a>, and Red Hat OpenShift build on these primitives with security, lifecycle automation, and enterprise support. Platform vendors are increasingly automating cluster operations—upgrades, scaling, remediation—to reduce the operational burden on engineering teams.</p>



<p class="wp-block-paragraph">Surrounding Kubernetes is a rapidly expanding ecosystem of complementary frameworks and tools. <a href="https://www.infoworld.com/article/2261159/what-is-a-service-mesh-easier-container-networking.html">Service meshes</a> like Istio and Linkerd provide fine-grained traffic management, policy enforcement, and mTLS-based security across microservices. <a href="https://www.infoworld.com/article/2259088/what-is-gitops-extending-devops-to-kubernetes-and-beyond.html">GitOps</a> platforms such as Argo CD and Flux bring declarative, version-controlled deployments to cloud-native environments. Meanwhile, projects like Crossplane turn Kubernetes into a universal control plane for cloud infrastructure, letting teams provision databases, queues, and storage through familiar Kubernetes APIs. These tools illustrate how cloud-native development now spans multiple layers: developer-focused application frameworks like Aspire at the top, and a powerful, evolving Kubernetes ecosystem underneath that keeps modern distributed applications running.</p>



<h2 class="wp-block-heading"><strong>Advantages and challenges for cloud-native development</strong></h2>



<p class="wp-block-paragraph">Cloud native has become so ubiquitous that its advantages are almost taken for granted at this point, but it’s worth reflecting on the beneficial shift the cloud native paradigm represents. Huge, monolithic codebases that saw updates rolled out once every couple of years have been replaced by microservice-based applications that can be improved continuously. Cloud-based deployments, when managed correctly, make better use of compute resources and allow companies to offer their products as SaaS or PaaS services. </p>



<p class="wp-block-paragraph">But <a href="https://www.infoworld.com/article/2337882/the-downsides-of-cloud-native-solutions.html">cloud-native deployments come with a number of challenges</a>, too:</p>



<ul class="wp-block-list">
<li><strong>Complexity and operational overhead: </strong>You’ll have noticed by now that many of the cloud-native tools we’ve discussed, like service meshes and observability tools, are needed to deal with the complexity of cloud-native applications and environments. Individual microservices are deceptively simple, but coordinating them all in a distributed environment is a big lift.</li>



<li><strong>Security: </strong>More services executing on more machines, communicating by open APIs, all adds up to a bigger attack surface for hackers. <a href="https://www.csoonline.com/article/572501/managing-container-vulnerability-risks-tools-and-best-practices.html">Containers</a> and <a href="https://www.csoonline.com/article/3618243/securing-cloud-native-applications-why-a-comprehensive-api-security-strategy-is-essential.html">APIs</a> each have their own special security needs, and a <a href="https://www.infoworld.com/article/2259477/open-policy-agent-a-general-purpose-policy-engine-for-cloud-native.html">policy engine</a> can be an important tool for imposing a security baseline on a sprawling cloud-native app. <a href="https://www.csoonline.com/article/564095/what-is-devsecops-developing-more-secure-applications.html">DevSecOps</a>, which adds security to DevOps, has become an important cloud-native development practice to try to close these gaps.</li>



<li><strong>Vendor lock-in: </strong>This may come as a surprise, since cloud-native is based on open standards and open source. But there are differences in how the big cloud and serverless providers works, and once you’ve written code with one provider in mind, <a href="https://www.infoworld.com/article/2337012/get-used-to-cloud-vendor-lock-in.html">it can be hard to migrate elsewhere</a>.</li>



<li><strong>A persistent skills gap: </strong>Cloud-native computing and development may have years under its belt at this point, but the number of developers who are truly skilled in this arena is a smaller portion of the workforce than you’d think. Companies <a href="https://www.infoworld.com/article/3484912/a-strategic-road-map-for-navigating-the-cloud-skills-shortage.html">face difficult choices in bridging this skills gap</a>, whether that’s bidding up salaries, working to upskill current workers, or allowing remote work so they can cast a wide net. </li>
</ul>



<h2 class="wp-block-heading">Cloud native in the real world</h2>



<p class="wp-block-paragraph">Cloud native computing is often associated with giants like Netflix, Spotify, Uber, and AirBNB, where many of its technologies were pioneered in the early ’10s. But the CNCF’s <a href="https://www.cncf.io/case-studies/">Case Studies page</a> provides an in-depth look at how cloud native technologies are helping companies. Examples include the following:</p>



<ul class="wp-block-list">
<li>A UK-based payment technology company that can <a href="https://www.cncf.io/case-studies/form3/">switch between data centers and clouds</a> with zero downtime</li>



<li>A software company whose product collects and analyzes data from IoT devices — and can <a href="https://www.cncf.io/case-studies/tempestive/">scale up</a> as the number of gadgets grows</li>



<li>A Czech web service company that managed to <a href="https://www.cncf.io/case-studies/seznam/">improve performance while reducing costs</a> by migrating to the cloud</li>
</ul>



<p class="wp-block-paragraph">Cloud-native infrastructure’s capability to quickly scale up to large workloads also make it an attractive platform for developing AI/ML applications: another one of those CNCF case studies looks at how IBM uses Kubernetes to <a href="https://www.cncf.io/case-studies/ibmwatsonxassistant/">train its Watsonx assistant</a>. The big three providers are putting a lot of effort into pitching their platforms as the place for you to develop your own generative AI tools, with offerings like <a href="https://www.infoworld.com/article/3608598/microsoft-rebrands-azure-ai-studio-to-azure-ai-foundry.html">Azure AI Foundry,</a><a href="https://www.infoworld.com/article/3959648/google-unveils-firebase-studio-for-ai-app-development.html">Google Firebase Studio</a>, and <a href="https://www.infoworld.com/article/2336139/amazon-bedrock-a-solid-generative-ai-foundation.html">Amazon Bedrock</a>. It seems clear that cloud native technology is ready for what comes next.</p>



<h2 class="wp-block-heading">Learn more about related cloud-native technologies:</h2>



<ul class="wp-block-list">
<li><a href="https://www.infoworld.com/article/2256066/what-is-paas-platform-as-a-service-a-simpler-way-to-build-software-applications.html">Platform-as-a-service (PaaS) explained</a></li>



<li><a href="https://www.infoworld.com/article/2238873/what-is-cloud-computing.html">What is cloud computing</a></li>



<li><a href="https://www.infoworld.com/article/2256706/what-is-multicloud-the-next-step-in-cloud-computing.html">Multicloud explained</a></li>



<li><a href="https://www.infoworld.com/article/2259475/what-is-agile-methodology-modern-software-development-explained.html">Agile methodology explained</a></li>



<li><a href="https://www.infoworld.com/article/2259487/how-to-excel-in-agile-software-development.html">Agile development best practices</a></li>



<li><a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">Devops explained</a></li>



<li><a href="https://www.infoworld.com/article/2266905/devops-best-practices-the-5-methods-you-should-adopt.html">Devops best practices</a></li>



<li><a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">Microservices explained</a></li>



<li><a href="https://www.infoworld.com/article/2253197/tutorial-how-to-build-microservices-apps.html">Microservices tutorial</a></li>



<li><a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Docker and Linux containers explained</a></li>



<li><a href="https://www.infoworld.com/article/2254159/how-to-get-started-with-kubernetes-2.html">Kubernetes tutorial</a></li>



<li><a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">CI/CD (continuous integration and continuous delivery) explained</a></li>



<li><a href="https://www.infoworld.com/article/2268012/get-started-with-cicd-automating-application-delivery-with-cicd-pipelines.html">CI/CD best practices</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is cloud computing? From infrastructure to autonomous, agentic-driven ecosystems]]></title>
<description><![CDATA[Cloud computing continues to be the platform of choice for large applications and a driver of innovation in enterprise technology. Gartner forecasts public cloud spending alone to  the public cloud services market alone will reach $1.42 trillion in current U.S. dollars, driven by AI workloads and...]]></description>
<link>https://tsecurity.de/de/3665669/ai-nachrichten/what-is-cloud-computing-from-infrastructure-to-autonomous-agentic-driven-ecosystems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665669/ai-nachrichten/what-is-cloud-computing-from-infrastructure-to-autonomous-agentic-driven-ecosystems/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h3 class="wp-block-heading"></h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2337750/when-will-cloud-computing-stop-growing.html">Cloud computing</a> continues to be the <a href="https://www.cio.com/article/482179/volkswagen-drives-the-automotive-industry-cloud-forward.html">platform of choice for large applications</a> and a <a href="https://www.infoworld.com/article/2336917/cloud-computing-is-reinventing-cars-and-trucks.html">driver of innovation</a> in enterprise technology. <a href="https://www.gartner.com/en/newsroom/press-releases/2024-05-20-gartner-forecasts-worldwide-public-cloud-end-user-spending-to-surpass-675-billion-in-2024#:~:text=Worldwide%20end-user%20spending%20on,(GenAI)%20and%20application%20modernization.">Gartner </a>forecasts public cloud spending alone to  the<a href="https://www.gartner.com/en/documents/6302015#:~:text=Summary,AI%20workloads%20and%20enterprise%20modernization."> public cloud services market alone </a>will reach $1.42 trillion in current U.S. dollars, driven by AI workloads and enterprise modernization.</p>



<p class="wp-block-paragraph">Driving this growth are the rise of <a href="https://www.infoworld.com/article/2262333/youre-doing-cloud-based-ai-and-machine-learning-wrong.html">AI and machine learning on the cloud</a>, <a href="https://www.infoworld.com/article/2335144/what-happened-to-edge-computing.html">adoption of edge computing</a>, the maturation of <a href="https://www.infoworld.com/article/3406501/what-is-serverless-serverless-computing-explained.html">serverless computing</a>, the emergence of <a href="https://www.infoworld.com/article/3584433/are-you-ready-for-multicloud-a-checklist.html">multicloud strategies</a>, improved security and privacy, and more sustainable cloud practices.</p>



<h2 class="wp-block-heading">What is cloud computing?</h2>



<p class="wp-block-paragraph">While often used broadly, the term cloud computing is defined as an abstraction of compute, storage, and network infrastructure assembled as a platform on which applications and systems are deployed quickly and scaled on the fly.</p>



<p class="wp-block-paragraph">Most cloud customers consume <a href="https://www.cio.com/article/2097657/6-cloud-market-forces-impacting-it-strategies-today.html">public cloud </a>computing services over the internet, which are hosted in large, remote data centers maintained by cloud providers. The most common type of cloud computing, SaaS (software as service), delivers prebuilt applications to the browsers of customers who pay per seat or by usage, exemplified by such popular apps as Salesforce, Google Docs, or Microsoft Teams.</p>



<h3><strong> 5 top trends in cloud computing</strong></h3>

<ol>
<li><strong>Agentic cloud ecosystems: </strong> The shift from AI as a tool to AI as an autonomous operator within cloud environments.</li>
<li><strong>Sovereign and localized clouds: </strong> Meeting strict national data residency and digital sovereignty laws.</li>
<li><strong>Specialized AI hardware access: </strong> Navigating the GPU capacity crunch through reserved instances and boutique AI clouds.</li>
<li><strong>Integrated greenOps: </strong>Merging cost optimization with mandatory carbon-footprint reporting.</li>
<li><strong>Industry-specific walled gardens: </strong> The maturation of vertical clouds into highly regulated, precompliant environments for finance and healthcare.</li>
</ol>






<p class="wp-block-paragraph">Next in line is IaaS (infrastructure as a service), which offers vast, virtualized compute, storage, and network infrastructure upon which customers build their own applications, often with the aid of providers’ <a href="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html">API</a>-accessible services.</p>



<p class="wp-block-paragraph">When people refer to the “the cloud” today, they most often mean the big IaaS providers: AWS (Amazon Web Services), Google Cloud Platform, or Microsoft Azure. All three have become ecosystems of services that go way beyond infrastructure and include developer tools, serverless computing, machine learning services and APIs, data warehouses, and thousands of other services. With both SaaS and IaaS, a key benefit is agility. Customers gain new capabilities almost instantly without the capital investment in hardware or software on-premises — and they can instantly scale the cloud resources they consume up or down as needed.</p>



<p class="wp-block-paragraph">According to <a href="https://foundryco.com/research/cloud-computing/">Foundry’s Cloud Computing Study, 2025</a>, enterprises are moving to the cloud to improve security and/or governance, increase scalability​, accelerate adoption of artificial intelligence and machine learning and other new technologies, replace on-premises legacy technology, ​improve employee productivity, and ensure disaster recovery and business continuity.</p>



<h2 class="wp-block-heading">Hyperscalers now dominate cloud services</h2>



<p class="wp-block-paragraph">The largest cloud service providers are often described as hyperscalers, due to their capability to provide large-scale data centers across the globe. Hyperscalers typically offer a wide range of cloud services, including IaaS, PaaS, SaaS, and more.</p>



<p class="wp-block-paragraph">As mentioned above, notable hyperscalers include Amazon Web Services (AWS), Google Cloud Platform, and Microsoft Azure. They offer the following capabilities.</p>



<ul class="wp-block-list">
<li><strong>Scalability</strong>: Hyperscalers can handle massive workloads and scale resources up or down quickly.</li>



<li><strong>Cost-effectiveness</strong>: Hyperscalers often offer competitive pricing and economies of scale.</li>



<li><strong>Global reach</strong>: Hyperscalers operate data centers around the world, providing low-latency access to customers in different regions.</li>



<li><strong>Innovation</strong>: Hyperscalers are at the forefront of cloud innovation, offering new services and features.</li>
</ul>



<h3 class="wp-block-heading">Challenges of working with hyperscalers</h3>



<ul class="wp-block-list">
<li><strong>Vendor lock-in</strong>: Relying heavily on a single hyperscaler can create <a href="https://www.cio.com/article/648048/hyperscalers-in-crosshairs-for-anti-competitive-pricing-and-lock-in.html">vendor lock-in</a>, making it difficult to switch to another provider and charging large egress fees if you do move.</li>



<li><strong>Complexity</strong>: Hyperscalers offer a vast array of services, which can be overwhelming for some customers.</li>



<li><strong>Security concerns</strong>: Because hyperscalers handle sensitive data, security is a major concern.</li>
</ul>



<h2 class="wp-block-heading"><strong>AI, Agents, and the Sovereign Cloud</strong></h2>



<p class="wp-block-paragraph">The AI-enabled enterprise has moved beyond simple chatbots. The focus has shifted to <strong>agentic workflows </strong>— autonomous systems that reside in the cloud and possess the authority to execute business processes, manage cloud spend, and self-patch security vulnerabilities without human intervention.</p>



<h3 class="wp-block-heading"><strong>The shift to agentic infrastructure</strong></h3>



<p class="wp-block-paragraph">Cloud providers are no longer just selling compute. They are selling <strong>inference-as-a-service</strong>. Modern cloud budgets are now dominated by the high cost of specialized GPU clusters (such as Nvidia’s Blackwell architecture). This has led to the rise of boutique AI clouds that compete with hyperscalers by offering bare-metal access to the latest silicon specifically for model training and fine-tuning.</p>



<h3 class="wp-block-heading"><strong>Data sovereignty and private AI</strong></h3>



<p class="wp-block-paragraph">A major shift in late 2025 is the move away from public AI models for sensitive data. Organizations are increasingly using retrieval-augmented generation (RAG) within walled garden environments. This ensures that a company’s proprietary data never leaves their specific cloud instance to train a provider’s base model.</p>



<p class="wp-block-paragraph">Furthermore, sovereign AI has become a requirement for global operations. Governments now demand that the AI models processing their citizens’ data be hosted on infrastructure that is owned, operated, and governed within their own borders.</p>



<h3 class="wp-block-heading"><strong>The challenges of ghost AI</strong></h3>



<p class="wp-block-paragraph">Just as shadow IT plagued the 2010s, ghost AI—unauthorized AI agents running on corporate cloud accounts — has become a primary security risk. Managing these autonomous entities requires a new layer of <strong>AI governance</strong>, where the cloud provider automatically audits the intent and permissions of every running agent to prevent runaway costs or data leaks.</p>



<h2 class="wp-block-heading">Cloud computing definitions</h2>



<p class="wp-block-paragraph">In 2011, <a href="https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-145.pdf">NIST posted a PDF</a> that divided cloud computing into three “service models” — SaaS, IaaS, and PaaS (platform as a service) — the latter being a controlled environment within which customers develop and run applications. These three categories have largely stood the test of time, although most PaaS solutions now are made available as services within IaaS ecosystems rather than as dedicated PaaS clouds.</p>



<p class="wp-block-paragraph">Two evolutionary trends stand out since NIST’s threefold definition. One is the long and growing list of subcategories within SaaS, IaaS, and PaaS, some of which blur the lines between categories. The other is the explosion of API-accessible services available in the cloud, particularly within IaaS ecosystems. The cloud has become a crucible of innovation where many emerging technologies appear first as services, a big attraction for business customers who understand the potential competitive advantages of early adoption.</p>



<h3 class="wp-block-heading"><strong>SaaS (software as a service) definition</strong></h3>



<p class="wp-block-paragraph">This type of cloud computing delivers applications over the internet, typically with a browser-based user interface. Today, most software companies offer their wares via <a href="https://www.infoworld.com/article/2256637/what-is-saas-software-as-a-service-defined.html">SaaS </a>— if not exclusively, then at least as an option.</p>



<p class="wp-block-paragraph">The most popular SaaS applications for business are <a href="https://www.computerworld.com/article/3570821/google-workspace-explained-googles-answer-to-microsoft-365.html">Google’s G Suite</a> and <a href="https://www.computerworld.com/article/1710782/office-2021-vs-microsoft-365-office-365-how-to-choose.html">Microsoft’s Office 365</a>. Most enterprise applications, including giant <a href="https://www.cio.com/article/272362/what-is-erp-key-features-of-top-enterprise-resource-planning-systems.html">ERP</a> suites from Oracle and SAP, come in both SaaS and on-premises versions. SaaS applications typically offer extensive configuration options as well as development environments that enable customers to code their own modifications and additions. They also enable data integration with on-prem applications.</p>



<h3 class="wp-block-heading"><strong>IaaS (infrastructure as a service) definition</strong></h3>



<p class="wp-block-paragraph">At a basic level, <a href="https://www.infoworld.com/article/2255598/what-is-iaas-your-data-center-in-the-cloud.html">IaaS </a>cloud providers offer virtualized compute, storage, and networking over the internet on a pay-per-use basis. Think of it as a data center maintained by someone else, remotely, but with a software layer that virtualizes all those resources and automates customers’ ability to allocate them with little trouble.</p>



<p class="wp-block-paragraph">But that’s just the basics. The full array of services offered by the major public IaaS providers is staggering: <a href="https://www.infoworld.com/article/2269279/the-era-of-the-cloud-database-has-finally-begun.html">highly scalable databases</a>, virtual private networks, <a href="https://www.infoworld.com/article/2255434/what-is-big-data-analytics-fast-answers-from-diverse-data-sets.html">big data analytics</a>, <a href="https://www.infoworld.com/article/2259367/buyers-guide-how-to-choose-a-cloud-machine-learning-platform.html">AI and machine learning services</a>, application platforms, developer tools, <a href="https://www.infoworld.com/article/3215275/what-is-devops-transforming-software-development.html">devops</a> tools, and so on. Amazon Web Services was the first IaaS provider and remains the leader, followed by <a href="https://www.infoworld.com/article/2269424/azure-cloud-services-guide-the-right-tools-for-the-job.html">Microsoft Azure</a>, <a href="https://www.infoworld.com/article/2263677/google-cloud-platform-services-guide-the-right-tools-for-the-job.html">Google Cloud Platform</a>, <a href="https://www.infoworld.com/article/2256709/ibm-cloud-services-guide-the-right-tools-for-the-job.html">IBM Cloud</a>, and <a href="https://www.infoworld.com/article/3529339/oracle-cloudworld-2024-10-key-takeaways-from-the-big-annual-event.html">Oracle Cloud</a>.</p>



<h3 class="wp-block-heading"><strong>PaaS (platform as a service) definition</strong></h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2256066/what-is-paas-platform-as-a-service-a-simpler-way-to-build-software-applications.html">PaaS</a> provides sets of services and workflows that specifically target developers, who can use shared tools, processes, and APIs to accelerate the development, testing, and deployment of applications. Salesforce’s <a href="https://www.infoworld.com/article/2257217/5-foolish-reasons-youre-not-using-heroku.html">Heroku</a> and Salesforce Platform (formerly Force.com) are popular public cloud PaaS offerings; <a href="https://www.infoworld.com/article/2258957/cloud-foundry-stages-a-comeback.html">Cloud Foundry</a> and Red Hat’s <a href="https://www.infoworld.com/article/2261552/red-hat-openshift-adds-containers-and-microservices-features-for-developers.html">OpenShift</a> can be deployed on premises or accessed through the major public clouds. For enterprises, PaaS can ensure that developers have ready access to resources, follow certain processes, and use only a specific array of services, while operators maintain the underlying infrastructure.</p>



<h3 class="wp-block-heading"><strong>FaaS (function as a service) definition</strong></h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2256402/paas-caas-or-faas-how-to-choose.html">FaaS</a>, the original and most basic version of <a href="https://www.infoworld.com/article/2266283/serverless-in-the-cloud-aws-vs-google-cloud-vs-microsoft-azure.html">serverless computing</a>, adds another layer of abstraction to PaaS, so that developers are insulated from everything in the stack below their code. Instead of futzing with virtual servers, containers, and application runtimes, developers upload narrowly functional blocks of code, and set them to be triggered by a certain event (such as a form submission or uploaded file). All of the major clouds offer FaaS on top of IaaS: <a href="https://www.infoworld.com/article/2265897/aws-lambda-tutorial-get-started-with-serverless-computing-2.html">AWS Lambda</a>, <a href="https://www.infoworld.com/article/2255377/how-to-work-with-azure-functions-in-csharp.html">Azure Functions</a>, <a href="https://www.infoworld.com/article/2243861/google-takes-aims-at-aws-lambda-with-cloud-functions.html">Google Cloud Functions</a>, and IBM Cloud Functions. A special benefit of FaaS applications is that they consume no IaaS resources until an event occurs, reducing pay-per-use fees.</p>



<h3 class="wp-block-heading"><strong>Private cloud definition</strong></h3>



<p class="wp-block-paragraph">A <a href="https://www.infoworld.com/article/2179737/build-your-own-private-cloud-2.html">private cloud</a> downsizes the technologies used to run IaaS public clouds into software that can be deployed and operated in a customer’s data center. As with a public cloud, internal customers can provision their own virtual resources to build, test, and run applications, with metering to charge back departments for resource consumption. For administrators, the private cloud amounts to the ultimate in data center automation, minimizing manual provisioning and management.</p>



<p class="wp-block-paragraph">VMware remains a force in the private cloud software market, but the acquisition by Broadcom has created confusion and raised concerns among some customers about potential changes in pricing, licensing, and support. This could lead some organizations to explore alternative solutions.</p>



<p class="wp-block-paragraph">OpenStack continues to be a popular open-source choice for building private clouds. It offers a flexible and customizable platform that can be tailored to specific needs. However, OpenStack can be complex to deploy and manage, and it may require significant expertise to maintain.</p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/3268073/what-is-kubernetes-your-next-application-platform.html">Kubernetes</a>, a container orchestration platform that has gained significant traction in recent years, is often used in conjunction with other technologies like OpenStack to build <a href="https://www.infoworld.com/article/3281046/what-is-cloud-native-the-modern-way-to-develop-software.html">cloud-native</a> applications. Red Hat OpenShift is a comprehensive cloud platform based on Kubernetes that provides a managed experience for deploying and managing <a href="https://www.infoworld.com/article/3310941/why-you-should-use-docker-and-containers.html">container</a>-based, applications.</p>



<p class="wp-block-paragraph">Many cloud providers offer their own cloud-native platforms and tools, such as <a href="https://www.networkworld.com/article/968169/aws-rolls-out-outposts-for-on-premises-hybrid-cloud.html">AWS Outposts</a>, <a href="https://www.infoworld.com/article/2253985/a-cloud-in-your-datacenter-microsoft-azure-stack-arrives.html">Azure Stack</a>, and <a href="https://www.infoworld.com/article/2257617/what-is-google-cloud-anthos-managed-kubernetes-everywhere.html">Google Cloud Anthos</a>.</p>



<p class="wp-block-paragraph">Common factors to consider when evaluating private cloud platforms include the following:</p>



<ol class="wp-block-list">
<li><strong>Pricing</strong>: The initial cost of deployment and ongoing maintenance costs.</li>



<li><strong>Complexity</strong>: The level of technical expertise needed to manage the platform.</li>



<li><strong>Flexibility</strong>: The ability to customize the platform to meet specific needs.</li>



<li><strong>Vendor lock-in</strong>: The degree to which the organization is tied to a particular vendor.</li>



<li><strong>Security</strong>: The security features and capabilities of the platform.</li>



<li><strong>Scalability</strong>: The capability to expand the platform to meet future needs.</li>
</ol>



<h3 class="wp-block-heading"><strong>Hybrid cloud definition</strong></h3>



<p class="wp-block-paragraph">A <a href="https://www.infoworld.com/article/2257084/hybrid-cloud-private-cloud-public-cloud-multicloud-how-to-choose.html">hybrid cloud</a> is the integration of a private cloud with a public cloud. At its most developed, the hybrid cloud involves creating parallel environments in which applications can move easily between private and public clouds. In other instances, databases may stay in the customer data center and integrate with public cloud applications — or virtualized data center workloads may be replicated to the cloud during times of peak demand. The types of integrations between private and public clouds vary widely, but they must be extensive to earn a hybrid cloud designation.</p>



<h3 class="wp-block-heading"><strong>Public APIs (application programming interfaces) definition</strong></h3>



<p class="wp-block-paragraph">Just as SaaS delivers applications to users over the internet, public <a href="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html">APIs</a> offer developers application functionality that can be accessed programmatically. For example, in building web applications, developers often tap into the Google Maps API to provide driving directions; to integrate with social media, developers may call upon APIs maintained by Twitter, Facebook, or LinkedIn. <a href="https://www.infoworld.com/article/2253662/get-started-with-twilios-programmable-video-api.html">Twilio</a> has built a successful business delivering telephony and messaging services via public APIs. Ultimately, any business can provision its own public APIs to enable customers to consume data or access application functionality.</p>



<h3 class="wp-block-heading"><strong>iPaaS (integration platform as a service) definition</strong></h3>



<p class="wp-block-paragraph">Data integration is a key issue for any sizeable company, but particularly for those that adopt SaaS at scale. iPaaS providers typically offer prebuilt connectors for sharing data among popular SaaS applications and on-premises enterprise applications, though providers may focus more or less on business-to-business and e-commerce integrations, cloud integrations, or traditional SOA-style integrations. iPaaS offerings in the cloud from such providers as Dell Boomi, Informatica, MuleSoft, and SnapLogic also let users implement data mapping, transformations, and workflows as part of the integration-building process.</p>



<h3 class="wp-block-heading"><strong>IDaaS (identity as a service) definition</strong></h3>



<p class="wp-block-paragraph">The most difficult security issue related to <a href="https://www.infoworld.com/article/2268884/why-cloud-computing-is-always-a-good-question.html">cloud computing</a> is managing user identity and its associated rights and permissions across data centers and pubic cloud sites. <a href="https://www.csoonline.com/article/572759/idaas-explained-how-it-compares-to-iam.html">IDaaS providers</a> maintain cloud-based user profiles that authenticate users and enable access to resources or applications based on security policies, user groups, and individual privileges. The ability to integrate with various directory services (Active Directory, LDAP, etc.) and provide single sign-on across business-oriented SaaS applications is essential.</p>



<p class="wp-block-paragraph">Leaders in IDaaS include Microsoft, IBM, Google, Oracle, Okta, Capgemini, Okta, Junio Corporation, OneLogin, and JumpCloud. <strong> </strong></p>



<h3 class="wp-block-heading"><strong>Collaboration platforms</strong></h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/3595255/slack-adds-templates-to-help-users-kick-off-projects-quicker.html">Collaboration solutions such as Slack</a> and <a href="https://www.computerworld.com/article/3593909/microsoft-combines-teams-chat-and-channels-in-ui-refresh.html">Microsoft Teams</a> have become vital messaging platforms that enable groups to communicate and work together effectively. Basically, these solutions are relatively simple SaaS applications that support chat-style messaging along with file sharing and audio or video communication. Most offer APIs to facilitate integrations with other systems and enable third-party developers to create and share add-ins that augment functionality.</p>



<h3 class="wp-block-heading"><strong>Vertical clouds</strong></h3>



<p class="wp-block-paragraph">Key providers in such industries as financial services, healthcare, retail, life sciences, and manufacturing provide PaaS clouds to enable customers to build vertical applications that tap into industry-specific, API-accessible services. Vertical clouds can dramatically reduce the time to market for vertical applications and accelerate domain-specific B2B integrations. Most vertical clouds are built with the intent of nurturing partner ecosystems.</p>



<h2 class="wp-block-heading"><strong>Other cloud computing considerations</strong></h2>



<p class="wp-block-paragraph">The most widely accepted definition of cloud computing means that you run your workloads on someone else’s servers, but this is not the same as outsourcing. Virtual cloud resources and even SaaS applications must be configured and maintained by the customer. Consider these factors when planning a cloud initiative.</p>



<h3 class="wp-block-heading"><strong>Cloud computing security considerations</strong></h3>



<p class="wp-block-paragraph">Objections to the public cloud generally begin with <a href="https://www.csoonline.com/article/555213/top-cloud-security-threats.html">cloud security</a>, although the major public clouds have proven themselves much less susceptible to attack than the average enterprise data center.</p>



<p class="wp-block-paragraph">Of greater concern is the integration of security policy and identity management between customers and public cloud providers. In addition, government regulation may forbid customers from allowing sensitive data off-premises. Other concerns include the risk of outages and the long-term operational costs of public cloud services.</p>



<h3 class="wp-block-heading"><strong>Multicloud management considerations</strong></h3>



<p class="wp-block-paragraph">To enhance their operational efficiency, reduce costs, and improve security, many companies are increasingly turning to <a href="https://www.infoworld.com/article/2335587/can-cloud-computing-be-truly-federated.html">multicloud strategies</a>. By distributing workloads across <a href="https://www.infoworld.com/article/2336303/are-the-different-public-clouds-really-that-different.html">multiple cloud providers</a>, organizations can avoid vendor lock-in, <a href="https://www.infoworld.com/article/2261783/3-cloud-architecture-patterns-that-optimize-scalability-and-cost.html">optimize costs</a>, and leverage the best-of-breed services offered by different providers.</p>



<p class="wp-block-paragraph">This multicloud approach also improves performance and reliability by minimizing downtime and optimizing latency. Additionally, multicloud strategies strengthen security by diversifying the attack surface and facilitating compliance with industry regulations. Finally, by replicating critical workloads across multiple regions and providers, companies can establish robust disaster recovery and business continuity plans, ensuring minimal disruption in the event of catastrophic failures.</p>



<p class="wp-block-paragraph">The bar to qualify as a <a href="https://www.infoworld.com/article/2256706/what-is-multicloud-the-next-step-in-cloud-computing.html">multicloud</a> adopter is low: A customer just needs to use more than one public cloud service. However, depending on the number and variety of cloud services involved, managing multiple clouds can become complex from both a cost optimization and a technology perspective.</p>



<p class="wp-block-paragraph">In some cases, customers subscribe to multiple cloud services simply to avoid dependence on a single provider. A more sophisticated approach is to select public clouds based on the unique services they offer and, in some cases, integrate them. For example, developers might want to use Google’s <a href="https://www.infoworld.com/article/2336686/google-vertex-ai-studio-puts-the-promise-in-generative-ai.html">Vertex AI Studio</a> on Google Cloud Platform to build AI-driven applications, but prefer <a href="https://www.infoworld.com/article/2260091/what-is-jenkins-the-ci-server-explained.html">Jenkins</a> hosted on the CloudBees platform for <a href="https://www.infoworld.com/article/3271126/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">continuous integration</a>.</p>



<p class="wp-block-paragraph">To control costs and reduce management overhead, some customers opt for <a href="https://www.infoworld.com/article/3520828/how-cloud-custodian-conquered-cloud-resource-management.html">cloud management platforms</a> (CMPs) and/or cloud service brokers (CSBs), which let you manage multiple clouds as if they were one cloud. The problem is that these solutions tend to limit customers to such common-denominator services as storage and compute, ignoring the panoply of services that make each cloud unique.</p>



<h3 class="wp-block-heading"><strong>Edge computing considerations</strong></h3>



<p class="wp-block-paragraph">You often see <a href="https://www.networkworld.com/article/964305/what-is-edge-computing-and-how-it-s-changing-the-network.html">edge computing</a> incorrectly described as an alternative to cloud computing. Edge computing is about moving compute to local devices in a highly distributed system, typically as a layer around a cloud computing core. There is typically a cloud involved to orchestrate all of the devices and take in their data, then analyze it or otherwise act on it. </p>



<h3 class="wp-block-heading"><strong>To the cloud and back – why repatriation is real</strong></h3>



<p class="wp-block-paragraph">While public cloud offers scalability and flexibility, some enterprises are opting to <a href="https://www.infoworld.com/article/2336102/why-companies-are-leaving-the-cloud.html">return to on-premises infrastructure</a> due to rising costs, data security concerns, performance issues, vendor lock-in, and regulatory compliance challenges. While the public cloud offers scalability and flexibility, on-premises infrastructure provides greater control, customization, and potential cost savings in certain scenarios leading some technology decision-makers to <a href="https://www.infoworld.com/article/2336835/do-you-need-to-repatriate-from-the-cloud.html">consider repatriation</a>. However, a hybrid cloud approach, combining public and private cloud, often offers the best balance of benefits.</p>



<p class="wp-block-paragraph">More specific reasons to repatriate including the following:</p>



<ul class="wp-block-list">
<li>Unanticipated costs, such as data transfer fees, storage charges, and <a href="https://www.infoworld.com/article/2336430/why-public-cloud-providers-are-cutting-egress-fees.html">egress fees</a>, can quickly escalate, especially for large-scale cloud deployments.  </li>



<li>Inaccurate resource provisioning or underutilization can lead to higher-than-expected costs.</li>



<li>Stricter <a href="https://www.infoworld.com/article/3545268/why-cloud-security-outranks-cost-and-scalability.html">data privacy regulations</a> require organizations to store and process data within specific geographic boundaries.  </li>



<li>For highly sensitive data, companies may prefer to maintain greater control over security measures and access permissions. </li>



<li><a href="https://www.infoworld.com/article/2338856/cloud-may-be-overpriced-compared-to-on-premises-systems.html">On-premises infrastructure</a> can offer lower latency, particularly for applications requiring real-time processing or high-performance computing.  </li>



<li>Overreliance on a single cloud provider can limit flexibility and increase costs. Repatriation allows organizations to diversify their infrastructure and reduce vendor dependency.  </li>



<li>Industries with stringent compliance requirements may find it easier to meet standards with on-premises infrastructure.  </li>



<li>On-premises environments offer greater control over hardware, software, and network configurations, allowing for customized solutions.  </li>
</ul>



<h2 class="wp-block-heading"><strong>Benefits of cloud computing</strong></h2>



<p class="wp-block-paragraph">The cloud’s main appeal is to reduce the time to market of applications that need to scale dynamically. Increasingly, however, developers are drawn to the cloud by the abundance of advanced new services that can be incorporated into applications, from machine learning to internet of things (IoT) connectivity.</p>



<p class="wp-block-paragraph">Although businesses sometimes migrate legacy applications to the cloud to reduce data center resource requirements, the real benefits accrue to new applications that take advantage of cloud services and “cloud native” attributes. The latter include <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices architecture</a>, <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Linux containers</a> to enhance application portability, and container management solutions such as <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-your-next-application-platform.html">Kubernetes</a> that orchestrate container-based services. <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html">Cloud-native</a> approaches and solutions can be part of either public or private clouds and help enable highly efficient <a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">devops</a> workflows.</p>



<p class="wp-block-paragraph">Cloud computing, be it public or private or hybrid or multicloud, has become the platform of choice for large applications, particularly customer-facing ones that need to change frequently or scale dynamically. More significantly, the major public clouds now lead the way in enterprise technology development, debuting new advances before they appear anywhere else. Workload by workload, enterprises are opting for the cloud, where an endless parade of exciting new technologies invite innovative use.</p>



<p class="wp-block-paragraph">SaaS has its roots in the ASP (application service provider) trend of the early 2000s, when providers would run applications for business customers in the provider’s data center, with dedicated instances for each customer. The ASP model was a spectacular failure because it quickly became impossible for providers to maintain so many separate instances, particularly as customers demanded customizations and updates.</p>



<p class="wp-block-paragraph">Salesforce is widely considered the first company to launch a highly successful SaaS application using <a href="https://www.infoworld.com/article/2335534/the-evolution-of-multitenancy-for-cloud-computing.html">multitenancy</a> — a defining characteristic of the SaaS model. Rather than each Salesforce customer getting its own application instance, customers who subscribe to the company’s salesforce automation software share a single, large, dynamically scaled instance of an application (like tenants sharing an apartment building), while storing their data in separate, secure repositories on the SaaS provider’s servers. Fixes can be rolled out behind the scenes with zero downtime and customers can receive UX or functionality improvements as they become available.</p>



<p class="wp-block-paragraph"></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is GitOps? Extending devops to Kubernetes and beyond]]></title>
<description><![CDATA[Over the past decade, software development has been shaped by two closely related transformations. One is the rise of devops and continuous integration and continuous delivery (CI/CD), which brought development and operations teams together around automated, incremental software delivery.



The ...]]></description>
<link>https://tsecurity.de/de/3665667/ai-nachrichten/what-is-gitops-extending-devops-to-kubernetes-and-beyond/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665667/ai-nachrichten/what-is-gitops-extending-devops-to-kubernetes-and-beyond/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:29 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Over the past decade, software development has been shaped by two closely related transformations. One is the rise of <a href="https://www.infoworld.com/article/2255028/what-is-devops-bringing-dev-and-ops-together-for-better-software.html">devops</a> and <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">continuous integration and continuous delivery</a> (CI/CD), which brought development and operations teams together around automated, incremental software delivery.</p>



<p class="wp-block-paragraph">The other is the shift from monolithic applications to distributed, cloud-native systems built from microservices and containers, typically managed by orchestration platforms such as <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a>.</p>



<p class="wp-block-paragraph">While Kubernetes and similar platforms simplify many aspects of running distributed applications, operating these systems at scale is still complicated. Configuration sprawl, environment drift, and the need for rapid, reliable change all introduce operational challenges. GitOps emerged as a way to address those challenges by extending familiar devops and CI/CD techniques beyond application code and into infrastructure and system configuration.</p>



<p class="wp-block-paragraph">At the heart of GitOps is the concept of <a href="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html">infrastructure as code</a> (IaC). In a GitOps model, not only application code but also infrastructure definitions, deployment configurations, and operational settings are described in files stored in a version control system. Automated processes continuously compare the running system with those declarations and work to bring the live environment back into alignment when differences appear.</p>



<p class="wp-block-paragraph">In this approach, the version control repository serves as the system of record for how applications and their supporting infrastructure should look in production. Changes flow through the same review, approval, and automation pipelines that developers already use for software, bringing greater consistency, traceability, and repeatability to cloud-native operations.</p>



<p class="wp-block-paragraph">At a high level, GitOps refers to a set of operational practices for managing cloud-native systems using declarative configuration, version control, and automated reconciliation. Rather than treating infrastructure and application configuration as mutable runtime state, GitOps treats them as versioned artifacts that move through the same review, testing, and deployment processes as application code.</p>



<h2 class="wp-block-heading"><strong>GitOps defined</strong></h2>



<p class="wp-block-paragraph">The term GitOps was originally coined and popularized by Weaveworks, which helped formalize the approach in the context of Kubernetes operations. While that early work shaped the way GitOps was discussed and implemented, GitOps has since evolved into a broadly adopted, vendor-neutral pattern. Today, it describes a shared set of ideas rather than a specific product or platform.</p>



<p class="wp-block-paragraph">The defining characteristic of GitOps is its reliance on declarative configuration stored in a version control system. Instead of issuing imperative commands to change live systems, teams describe the desired state of applications and infrastructure in configuration files. Automated agents then continuously compare that declared state with what is actually running and work to reconcile any differences. This pull-based model—where systems converge toward the desired state defined in version control—provides built-in drift detection, repeatability, and a clear audit trail for every change.</p>



<p class="wp-block-paragraph">Because GitOps centers on configuration files stored in a version control system, familiar software development practices carry over naturally. Changes are proposed through commits, reviewed before being accepted, and tracked over time. Rollbacks are accomplished by reverting to known-good versions, and the history of how a system evolved is preserved alongside the configuration itself.</p>



<p class="wp-block-paragraph">While the use of <a href="https://www.infoworld.com/article/2334697/what-is-git-version-control-for-collaborative-programming.html">Git</a> as the version control system is not strictly required, it has become the default choice because of its ubiquity in modern devops workflows and its strong support for collaboration and change management, so its place in the name has stuck.</p>



<aside class="sidebar">
<h3><strong> GitOps vs. IaC </strong></h3>
<p>Infrastructure as code (IaC) and GitOps are closely related, but they solve different problems. </p>
<p>IaC focuses on how infrastructure is defined. Servers, networks, and services are described using declarative configuration files, which are then applied by automation tools. GitOps builds on IaC by adding an operating model around those definitions. In a GitOps workflow, the desired state of systems is stored in a version control repository and treated as the system of record. Automated agents continuously compare the running environment with that desired state and reconcile any differences.</p>
<p>The key distinction is persistence. IaC provisions infrastructure; GitOps keeps systems in the intended state over time. By using pull-based reconciliation and continuous drift detection, GitOps extends IaC into a day-to-day operational discipline.
</p>

</aside>



<h2 class="wp-block-heading"><strong>What is the CI/CD process?</strong></h2>



<p class="wp-block-paragraph">A complete look at CI/CD is beyond the scope of this article—<a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">see the InfoWorld explainer on the subject</a>—but we need to say a few words about CI/CD because it’s at the core of how GitOps works. The <em>continuous integration</em> half of CI/CD is enabled by version control repositories like Git: Developers can make constant small improvements to their codebase, rather than rolling out huge, monolithic new versions every few months or years. The <em>continuous deployment</em> piece is made possible by automated systems called <em>pipelines</em> that build, test, and deploy the new code to production.</p>



<p class="wp-block-paragraph">Again, we keep talking about <em>code </em>here, and that usually summons up visions of executable code written in a programming language such as C or Java or JavaScript. But in GitOps, the “code” we’re managing is largely made up of configuration files. This isn’t just a minor detail — it’s at the heart of what GitOps does. These config files are, as we’ve said, the “single source of truth” describing what our system should look like. They are <em>declarative </em>rather than instructive. That means that instead of saying “start up ten servers,” the configuration file will simply say, “this system includes ten servers.”</p>



<p class="wp-block-paragraph"><strong>GitOps and Kubernetes</strong></p>



<p class="wp-block-paragraph">GitOps first took hold in the Kubernetes ecosystem, where declarative configuration and continuous reconciliation are core design principles. As a result, Kubernetes remains the most common and best-understood environment for applying GitOps practices. A typical GitOps-driven update process for a Kubernetes application looks like this:</p>



<ol start="1" class="wp-block-list">
<li>A developer proposes a change by committing updated application code or configuration to a version control repository, usually through a pull request.</li>



<li>That change is reviewed and approved, then merged into the main branch.</li>



<li>The merge triggers an automated CI/CD pipeline that tests the change, builds new artifacts if needed, and publishes them to a registry.</li>



<li>A GitOps controller or similar automated agent detects the updated desired state stored in version control.</li>



<li>The controller compares that desired state with the current state of the Kubernetes cluster and applies the necessary changes to bring the cluster back into alignment.</li>
</ol>



<p class="wp-block-paragraph">This pull-based reconciliation loop—where the cluster continuously converges toward the desired state defined in version control—is central to how GitOps works in practice. While Kubernetes provides a natural fit for this model, it represents just one canonical use case. The same patterns increasingly apply to infrastructure provisioning, policy enforcement, and multi-cluster operations beyond Kubernetes itself.</p>



<h2 class="wp-block-heading"><strong>GitOps tooling in practice: Argo CD, Flux, and the ecosystem</strong></h2>



<p class="wp-block-paragraph">GitOps is enabled by a set of tools that embody the principles we’ve outlined, with some open-source projects emerging as de facto standards in cloud-native environments.</p>



<p class="wp-block-paragraph">At the center of the GitOps ecosystem is Argo CD, an open-source controller that continuously monitors a version control repository and ensures that the state of running systems matches the declared desired state. Argo CD is widely used in Kubernetes environments because it directly implements pull-based reconciliation: it compares the desired state stored in Git with the cluster’s actual state and applies changes to correct any drift.</p>



<p class="wp-block-paragraph">Alongside Argo CD, Flux is another prominent open source GitOps engine. Both Flux and Argo CD help teams adopt GitOps workflows by managing the synchronization loop between code and runtime, but they differ in operational philosophy, integration surfaces, and ecosystem fit.</p>



<p class="wp-block-paragraph">GitOps tooling often appears as part of broader platforms or integrated stacks rather than as isolated utilities. For example, <a href="https://www.infoworld.com/article/4006297/top-6-multicloud-management-systems.html">multicloud and cluster management solutions</a> now routinely include GitOps support, with Argo CD or compatible controllers bundled alongside deployment, policy, and governance capabilities.</p>



<p class="wp-block-paragraph">In addition to Flux and Argo CD, a range of auxiliary tools contribute to a complete GitOps ecosystem: policy as code engines (e.g., Open Policy Agent), drift detection systems, and infrastructure provisioning tools that mesh with Git-centric workflows.</p>



<h2 class="wp-block-heading"><strong>GitOps, devops, and normalization</strong></h2>



<p class="wp-block-paragraph">GitOps grew out of the same forces that drove devops into mainstream IT practice, and in its early days, GitOps was often discussed as a distinct extension of devops, specifically tailored to managing declarative infrastructure and Kubernetes-centric systems. At the time, GitOps was still relatively new and <a href="http://infoworld.com/article/2265546/why-gitops-isnt-ready-for-the-mainstream-yet.html">not yet widely adopted outside cloud-native pioneers</a>.</p>



<p class="wp-block-paragraph">Over the last several years, however, GitOps practices have become deeply woven into how teams operate modern cloud environments. Rather than being treated as an optional add-on or marketing term, the core ideas of GitOps — using version-controlled, declarative configuration and automated reconciliation loops to continuously align running systems with intended state — are now part of standard operational practice in many Kubernetes-centric shops. In this sense, GitOps has shifted from a buzzword about what might be possible to a baseline pattern for cloud-native operations, much like devops itself did years earlier.</p>



<p class="wp-block-paragraph">In environments where Kubernetes and declarative systems are the norm, GitOps workflows are the default way teams manage and deploy change. Many organizations now implement these patterns without explicitly calling them “GitOps,” just as few teams today explicitly say they do “CI/CD” even though continuous pipelines are taken for granted. The term has become less prominent in marketing, but its practices are often embedded in pipelines, controllers, and platform tooling.</p>



<p class="wp-block-paragraph">That normalization shows up in how GitOps workflows are woven into broader operational frameworks. For example, <a href="https://www.infoworld.com/article/2338225/what-is-platform-engineering-evolving-devops.html">platform engineering</a> teams frequently build internal developer platforms that encapsulate GitOps patterns behind standardized developer APIs, making the pattern invisible to most application teams while still providing the auditability and automation that GitOps promises.</p>



<h2 class="wp-block-heading"><strong>GitOps beyond Kubernetes: infrastructure, policy, and drift</strong></h2>



<p class="wp-block-paragraph">While GitOps first gained traction as a way to manage Kubernetes deployments, its core principles apply broadly to infrastructure and operational concerns beyond any single orchestration platform. GitOps treats desired state as declarative configuration stored in version control and uses automated reconciliation to ensure running systems align with that state. That pattern naturally extends to infrastructure provisioning, policy enforcement, configuration drift detection, and governance workflows across diverse environments.</p>



<p class="wp-block-paragraph">In modern operational stacks, infrastructure is increasingly defined declaratively, whether through Kubernetes manifests, Terraform modules, or other infrastructure-as-code formats. Storing these declarations in version control enables the same peer-review, auditability, and rollback practices developers already use for application code. Automated tooling then continuously detects when the live infrastructure diverges from the declared state and works to bring it back into alignment, reducing the risk of configuration drift and inadvertent misconfigurations.</p>



<p class="wp-block-paragraph">Configuration drift — the state where an environment has diverged from what’s declared in version control — remains a major operational headache, especially in complex, dynamic systems. Drift can arise from ad hoc fixes, emergency updates, or manual changes made outside normal pipelines, and it can lead to inconsistencies, outages, and security gaps. By continually checking running systems against the desired state in Git and reconciling deviations automatically, GitOps workflows help teams keep environments predictable and auditable.</p>



<p class="wp-block-paragraph">Policy enforcement and compliance are another natural extension of GitOps patterns. As organizations adopt declarative practices, policy-as-code engines and drift detection systems can be woven into GitOps pipelines to validate that proposed configurations meet security, compliance, or operational standards before they’re ever applied to running systems. Embedding policy checks into declarative workflows brings consistency to governance while preserving the automation and speed that devops teams expect.</p>



<h2 class="wp-block-heading"><strong>GitOps – beyond Kubernetes</strong></h2>



<p class="wp-block-paragraph">GitOps began as a way to bring devops discipline to Kubernetes operations, but its longer-term impact has been more subtle. In many ways, it’s been absorbed into the fabric of modern cloud-native operations, where declarative configuration, version control, and automated reconciliation are taken for granted. Today, GitOps is less about a specific set of tools or a named practice and more about an operational mindset. By treating infrastructure and configuration as versioned, auditable artifacts and relying on automation to enforce consistency, GitOps helps teams manage complexity at scale. Even as the term itself fades from the spotlight, the practices it introduced continue to shape how distributed systems are built, deployed, and operated.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SpaceX Seeks FCC Approval for 100,000 Gen3 Satellites]]></title>
<description><![CDATA[SpaceX’s proposed Gen3 network could expand satellite capacity for enterprise connectivity, but the FCC has not approved the 100,000-satellite request. Deployment, pricing and service availability remain unresolved.
The post SpaceX Seeks FCC Approval for 100,000 Gen3 Satellites appeared first on ...]]></description>
<link>https://tsecurity.de/de/3665576/it-nachrichten/spacex-seeks-fcc-approval-for-100000-gen3-satellites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665576/it-nachrichten/spacex-seeks-fcc-approval-for-100000-gen3-satellites/</guid>
<pubDate>Mon, 13 Jul 2026 16:32:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>SpaceX’s proposed Gen3 network could expand satellite capacity for enterprise connectivity, but the FCC has not approved the 100,000-satellite request. Deployment, pricing and service availability remain unresolved.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-spacex-gen3-fcc-approval/">SpaceX Seeks FCC Approval for 100,000 Gen3 Satellites</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Where the software development jobs are now]]></title>
<description><![CDATA[While many technology companies have slowed hiring or even launched significant layoffs, that doesn’t mean job opportunities have dried up for software developers. In fact, skilled developers—particularly those with knowledge of AI—are in demand in other industries.



The key to success for deve...]]></description>
<link>https://tsecurity.de/de/3664782/ai-nachrichten/where-the-software-development-jobs-are-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664782/ai-nachrichten/where-the-software-development-jobs-are-now/</guid>
<pubDate>Mon, 13 Jul 2026 11:33:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>While many technology companies have slowed hiring or even launched <a href="https://www.trueup.io/layoffs" data-type="link" data-id="https://www.trueup.io/layoffs">significant layoffs</a>, that doesn’t mean job opportunities have dried up for software developers. In fact, skilled developers—particularly those with <a href="https://www.infoworld.com/article/4025073/9-ai-development-skills-tech-companies-want.html" data-type="link" data-id="https://www.infoworld.com/article/4025073/9-ai-development-skills-tech-companies-want.html">knowledge of AI</a>—are in demand in other industries.</p>



<p>The key to success for developers looking to snatch up these roles is to be well-prepared to meet the needs of potential employers in a variety of sectors.</p>



<p>“The demand for developers in non-tech sectors is real and growing, but the roles look different from what you’d find at a software company,” says <a href="https://drexel.edu/cci/about/directory/A/Awasthi-Pragati/" data-type="link" data-id="https://drexel.edu/cci/about/directory/A/Awasthi-Pragati/">Pragati Awasthi</a>, assistant teaching professor of AI and data science at Drexel University.</p>



<p>“Across all these sectors, the common thread is that software is no longer a support function; it is embedded in core operations,” Awasthi says. “The developer in these environments is often the person translating domain-specific business problems into technical solutions, which requires a different profile than a pure product engineer at a tech firm.”</p>



<h2 class="wp-block-heading">Opportunity knocks</h2>



<p>The tech industry has long been a mainstay as far as employing software developers. But as these businesses trim staffs in efforts to cut expenses, that has impacted the hiring landscape. Even as the tech sector scales back, however, companies in industries such as financial services/fintech, healthcare/healthtech, retail/ecommerce, and manufacturing are looking to acquire programming talent.</p>



<p>“The unifying factor is data complexity,” Awasthi says. “These industries generate large volumes of sensitive, regulated, or operationally critical data, and they need developers who can build and maintain systems that handle it responsibly.”</p>



<p>While recruiting firm Summit Search Group has placed developers in roles with technology companies, “it is just as common to recruit them for roles outside this niche,” says <a href="https://www.linkedin.com/in/matterhard/" data-type="link" data-id="https://www.linkedin.com/in/matterhard/">Matt Erhard</a>, managing partner at the company. “There are actually a fairly wide variety of roles available for developers in industries beyond tech,” Erhard says.</p>



<p>For example, in financial services Summit Search Group has seen significant hiring for back-end and data engineers who can build and maintain fraud detection systems, digital banking platforms, and regulatory tools, Erhard says. In healthcare, companies are hiring developers to build AI-driven diagnostics platforms and patient portals, or to work with systems that manage electronic health records, he says.</p>



<p>In manufacturing and industrial companies, developers are needed for systems integration and embedded software related to predictive maintenance, <a href="https://www.networkworld.com/article/963923/what-is-iot-the-internet-of-things-explained.html" data-type="link" data-id="https://www.networkworld.com/article/963923/what-is-iot-the-internet-of-things-explained.html">Internet of Things</a> (IoT) systems, and smart factories. And in retail and ecommerce, there’s strong demand for <a href="https://www.infoworld.com/article/2259033/full-stack-developer-what-it-is-and-how-you-can-become-one.html" data-type="link" data-id="https://www.infoworld.com/article/2259033/full-stack-developer-what-it-is-and-how-you-can-become-one.html">full-stack developers</a> and data developers who can handle logistics systems, omni-channel platforms, and personalization engines, Erhard says.</p>



<p>“One significant function where we’ve been placing developer talent lately is in developing business systems and internal applications,” Erhard says. These roles often have titles such as systems engineer or application developer, and professionals are hired to handle tasks such as customizing customer relationship management (CRM) or enterprise resource planning (ERP) platforms, building workflow automation tools or modernizing legacy systems, he says.</p>



<p>Other core functions for which Summit Search Group has placed a lot of developers include data, analytics, and AI-enablement. “That could be directly involved with <a href="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html">data engineering</a> or in building tools like reporting systems and <a href="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html">ETL [extract, transform, load]</a> pipelines,” Erhard says.</p>



<p>The firm also has handled searches for developers who can build and maintain customer-facing products for banking, healthcare, and retail companies, such as mobile apps or digital platforms customers can use to interact with companies.</p>



<p>Randstad Digital, a provider of global technology talent, sees demand for roles including web developers, system developers, and app developers. “These professionals would work on anything from customer-facing platforms to internal tools,” says <a href="https://www.linkedin.com/in/mpmorris36/" data-type="link" data-id="https://www.linkedin.com/in/mpmorris36/">Michael Morris</a>, global head of platform and talent at the company. “Non-tech companies are also often hiring roles like software architecture and <a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html" data-type="link" data-id="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">devops</a> to help scale existing technology. These involve being more ingrained in the business, like building a supply chain system for a retailer, rather than creating individual tech products like you would at a technology company.”</p>



<h2 class="wp-block-heading">Prep for success</h2>



<p>To increases the chances of success at landing developer jobs outside of the tech industry, development professionals would be wise to follow some good practices.</p>



<h3 class="wp-block-heading">Boost AI skills</h3>



<p>One best practice is to boost skills in using AI-powered tools and get familiar with all things AI.</p>



<p>“Get fluent with AI-assisted development and its limits,” Awasthi says. “This is not optional. Organizations across every sector expect developers to use AI coding tools productively. But the more durable skill is knowing when AI output is wrong, incomplete, or unsuitable for a regulated context. That critical evaluation capacity is what non-tech employers are increasingly trying to hire.”</p>



<p>AI does not necessarily replace the need for human developers so much as it changes the skills profile for those roles, Erhard says. “The biggest difference in recent years is that AI literacy is now a non-negotiable,” he says. “At minimum, developers today need to understand concepts like <a href="https://www.infoworld.com/article/4122440/what-is-prompt-engineering-the-art-of-ai-orchestration.html" data-type="link" data-id="https://www.infoworld.com/article/4122440/what-is-prompt-engineering-the-art-of-ai-orchestration.html">prompt engineering</a> and how to use AI tools to improve their efficiency.”</p>



<p>One thing many job candidates don’t expect is that the rise of AI has also increased the importance of high-level skills such as problem framing, system design, and cross-functional communication,” Erhard says. “Essentially, if something is related to development but too complex or nuanced for an AI to handle effectively, then the demand is high for human developers who have that expertise,” he says.</p>



<p>Candidates who land roles consistently have experience building AI-augmented workflows along with standard coding skills, Erhard says. “Employers increasingly expect to hire developers who can leverage AI, so demonstrating this experience on your résumé can be very beneficial,” he says.</p>



<h3 class="wp-block-heading">Gain domain knowledge</h3>



<p>Summit Search Group is seeing high demand for developers with deep domain knowledge in an organization’s specific industry. “So, for instance, if someone is both an experienced developer and has expertise in healthcare compliance, or financial regulations, then those candidates tend to be very sought after,” Erhard says.</p>



<p>Domain fluency is an underrated skill, Awasthi says. “A developer who understands healthcare compliance, financial regulation, or manufacturing process logic is significantly harder to replace than one who only writes clean code,” she says. “AI can generate boilerplate. It cannot navigate a HIPAA audit or explain a model’s output to a compliance officer.”</p>



<p>Development professionals should “pick an industry and learn it seriously; not just the technology stack but the regulatory environment, the business model, and the actual problems practitioners face,” Awasthi says. “A developer who has read about HIPAA, or spent time understanding credit risk, is immediately more valuable in those hiring contexts.”</p>



<p>It’s also vital to demonstrate real-world, practical application of skills, not just credentials. “The strongest candidates have projects in their portfolio that directly tie to and solve real business problems,” Erhard says.</p>



<h3 class="wp-block-heading">Acquire soft skills</h3>



<p>And then there are the soft skills that are becoming more of a differentiator than they were in the past. As AI handles more routine coding, human developers are expected to make more architectural decisions and collaborate across departments, Erhard says. “Strong communication and problem-solving skills are critical for many of the developer roles that we’re filling today,” he says.</p>



<p>While technical skills are still relevant for developers using and managing AI tools, “they also need to develop the skill of ‘deeper thinking’ and learn how to think one step ahead,” Morris says. “This includes skills like system design mastery—understanding the macro view and learning how <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices</a>, databases, and third-party APIs interact securely and efficiently.”</p>



<p>They also should become deeply fluent in the AI coding tools commonly used in their particular industry, with a strong understanding of how to prompt them for optimal output, Morris says. Product context awareness is also useful. “AI doesn’t know what the customer wants, but you do,” Morris says. “Understanding the business problem and the end-user experience is a requirement for being able to guide LLMs.”</p>



<h3 class="wp-block-heading">Master debugging and incident response</h3>



<p>Developers looking to break into non-tech sectors also should develop skills in debugging and incident response, Morris says. “Complex systems with multiple AI agents can, and will, fail, which means companies need humans to trace logic flaws to get the system back on track,” he says. “A mastery of root-cause analysis is a critical skill.”</p>



<p>“Security, compliance, and reliability are very important in non-tech industries like finance and healthcare,” says <a href="https://www.linkedin.com/in/rohit-agarwal/" data-type="link" data-id="https://www.linkedin.com/in/rohit-agarwal/">Rohit Agarwal</a>, co-founder of Zenius, a remote hiring company. “So employers want developers who also know regulatory environments well.”</p>



<h3 class="wp-block-heading">Network and keep learning</h3>



<p>To successfully pivot from jobs at tech companies, “continuous learning, upskilling, and building hybrid skills that combine technical and business knowledge are essential,” Morris says. “With the right preparation, tech professionals can adapt and continue to thrive in meaningful, dynamic careers.”</p>



<p>It’s also a good idea to join talent communities in fields of interest and “engage with other members in conversations that increase your knowledge through the collective intelligence of the community,” Morris says. “Take advantage of AI skilling opportunities relevant for your role, or better yet, where you want to go next. Experiment with the technology either on your own or through structured programs.” Ultimately, be curious and proactive, he says.</p>



<p>“I’d also recommend developers not to ignore referrals, direct outreach, and industry-specific communities during job search,” Agarwal says. “There are often a lot more opportunities available than the ones posted online.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Japan's Space Agency Conducts First Test Flight For Experimental Reusable Rocket]]></title>
<description><![CDATA["Japan's experimental reusable rocket took off and safely landed in a first test flight Saturday," reports the Associated Press, as Japan "seeks to achieve the technology key to cut launch costs and compete in the global space market dominated by SpaceX."


The RV-X rocket lifted off, hovered and...]]></description>
<link>https://tsecurity.de/de/3664721/it-security-nachrichten/japans-space-agency-conducts-first-test-flight-for-experimental-reusable-rocket/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664721/it-security-nachrichten/japans-space-agency-conducts-first-test-flight-for-experimental-reusable-rocket/</guid>
<pubDate>Mon, 13 Jul 2026 11:08:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["Japan's experimental reusable rocket took off and safely landed in a first test flight Saturday," reports the Associated Press, as Japan "seeks to achieve the technology key to cut launch costs and compete in the global space market dominated by SpaceX."


The RV-X rocket lifted off, hovered and moved horizontally before landing [watch the video here] during its less than one-minute flight at the Japan Aerospace Exploration Agency's Noshiro Testing Center in northeastern Japan, which was livestreamed by the NVS, a group of space fans...
Saturday's flight is a step forward for Japan in achieving the technology needed to develop a lower cost successor to the country's current mainstay, single-use H3 series.
 
Japan's test comes the same week that China recovered an orbital booster rocket for the first time.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Japan's+Space+Agency+Conducts+First+Test+Flight+For+Experimental+Reusable+Rocket%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F13%2F0522200%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F13%2F0522200%2Fjapans-space-agency-conducts-first-test-flight-for-experimental-reusable-rocket%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/07/13/0522200/japans-space-agency-conducts-first-test-flight-for-experimental-reusable-rocket?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT hiring sees a boost as software development jobs slowly bounce back]]></title>
<description><![CDATA[Tech job postings rose for the sixth straight month in June, as employers are increasingly on the hunt for qualified talent to support major technological initiatives, according to the most recent CompTIA Tech Jobs Report.



“June’s employment data suggests that employers are ramping up their te...]]></description>
<link>https://tsecurity.de/de/3664702/it-nachrichten/it-hiring-sees-a-boost-as-software-development-jobs-slowly-bounce-back/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664702/it-nachrichten/it-hiring-sees-a-boost-as-software-development-jobs-slowly-bounce-back/</guid>
<pubDate>Mon, 13 Jul 2026 11:03:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Tech job postings rose for the sixth straight month in June, as employers are increasingly on the hunt for qualified talent to support major technological initiatives, according to the most recent <a href="https://www.comptia.org/en-us/resources/research/tech-jobs-report/" rel="nofollow">CompTIA Tech Jobs Report</a>.</p>



<p>“June’s employment data suggests that employers are ramping up their technology investments and hiring the talent needed to support them,” said Seth Robinson, vice president for industry research at CompTIA, in a press release. “Even as some tech companies announce layoffs, employers in other industries are accelerating digital transformation initiatives and moving from AI experimentation to implementation.”</p>



<p><a href="https://www.dice.com/hiring/recruitment/reports/tech-hiring-myths-vs-reality" rel="nofollow">Data from Dice</a> supports this growth, with its report showing AI/ML job title postings up 173% year over year from Q1 2025 to Q1 2026 — roles that typically offer median salaries 22% higher than the overall IT market. Hiring for jobs in data analysis (10%), cybersecurity (4%), and IT support (1%) have also seen increases. Tech postings in the finance and banking industry are up 47%, with manufacturing IT jobs up by 27% and IT roles in the insurance, aerospace, and defense sectors up by 23%, pointing to growth for IT across a range of sectors.</p>



<p>Software development jobs, however, are still on the decline from last year, down 22% from 2025, according to Dice, but it looks like that trend may soon shift. Data from CompTIA shows that software developer and software engineer job postings were the top roles for June (49k postings), followed by systems engineer (36k), tech support specialist (27k), data analyst (21k), and DevOps engineer (19k).</p>



<p>The catalyst for sparking a boost in software development hiring can be attributed to the release of Claude Code in late February 2025, according to <a href="https://www.hiringlab.org/2026/07/08/ai-and-job-postings-from-destruction-to-creation/" rel="nofollow">data from the Indeed Hiring Lab</a>. Since Claude Code’s release, Indeed has tracked a rise of 15% for software development job postings in the US, despite overall job postings declining by 7%. The report highlights how this rebound comes after a “low starting point,” so while the increases seem high, <a href="https://www.cio.com/article/3951133/remember-when-developers-reigned-supreme-the-market-for-software-coding-goes-soft.html">it’s because they had a long way to go</a>.</p>



<p>Despite this increase in job postings, software development jobs still hover somewhere around 27.5% below their pre-pandemic levels, while overall job postings have remained relatively stable since 2020. It’s also important to note that 71% of the increase of software development job postings between May 2025 and May 2026 has been for senior-level roles, with 37% mentioning AI in the title.</p>



<p>This indicates that there is merit to the concerns around <a href="https://www.cio.com/article/4189865/how-ai-automation-is-reshaping-the-it-leadership-pipeline.html">how AI automation is reshaping the IT leadership pipeline</a>. IT leaders will need to <a href="https://www.cio.com/article/4188578/how-to-keep-your-it-talent-pipeline-from-collapsing.html">remain mindful of how AI impacts hiring</a> — and avoid leaving entry-level workers in the dust as hiring rebounds.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[(g+) Artificial Intelligence: Who cleans up after the vibe-coding party?]]></title>
<description><![CDATA[Our obsession with AI code-writing tools is overwhelming the web's unsung human caretakers. Von Sam Learner (KI, Softwareentwicklung)]]></description>
<link>https://tsecurity.de/de/3664592/it-nachrichten/g-artificial-intelligence-who-cleans-up-after-the-vibe-coding-party/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664592/it-nachrichten/g-artificial-intelligence-who-cleans-up-after-the-vibe-coding-party/</guid>
<pubDate>Mon, 13 Jul 2026 10:03:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Our obsession with AI code-writing tools is overwhelming the web's unsung human caretakers. Von Sam Learner (<a href="https://www.golem.de/specials/ki/">KI</a>, <a href="https://www.golem.de/specials/softwareentwicklung/">Softwareentwicklung</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=210787&amp;page=1&amp;ts=1783928882" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[India Orders Telegram to Crack Down on Pirated Movies and OTT Content, Seeks Compliance Report]]></title>
<description><![CDATA[  Ministry of Information and Broadcasting (MIB) has directed the messaging platform Telegram to take down the pirated films, OTT content and other audio-visual material uploaded on it. It also called upon the company to put in place measures to…
Read more →
The post India Orders Telegram to Crac...]]></description>
<link>https://tsecurity.de/de/3663680/it-security-nachrichten/india-orders-telegram-to-crack-down-on-pirated-movies-and-ott-content-seeks-compliance-report/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663680/it-security-nachrichten/india-orders-telegram-to-crack-down-on-pirated-movies-and-ott-content-seeks-compliance-report/</guid>
<pubDate>Sun, 12 Jul 2026 19:53:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  Ministry of Information and Broadcasting (MIB) has directed the messaging platform Telegram to take down the pirated films, OTT content and other audio-visual material uploaded on it. It also called upon the company to put in place measures to…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/india-orders-telegram-to-crack-down-on-pirated-movies-and-ott-content-seeks-compliance-report/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/india-orders-telegram-to-crack-down-on-pirated-movies-and-ott-content-seeks-compliance-report/">India Orders Telegram to Crack Down on Pirated Movies and OTT Content, Seeks Compliance Report</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Mercari reduced request latency by 15% with Cloud Profiler]]></title>
<description><![CDATA[Editor’s note: For retailers, predicting consumers’ desires and demand is the holy grail. For retail IT, the goal is understanding the performance of your ecommerce applications. Here, Japanese online retailer Mercari shows how they used Cloud Profiler and Trace to understand a complex microservi...]]></description>
<link>https://tsecurity.de/de/3662835/it-security-nachrichten/how-mercari-reduced-request-latency-by-15-with-cloud-profiler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662835/it-security-nachrichten/how-mercari-reduced-request-latency-by-15-with-cloud-profiler/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p><i><b>Editor’s note</b>: For retailers, predicting consumers’ desires and demand is the holy grail. For retail IT, the goal is understanding the performance of your ecommerce applications. Here, Japanese online retailer Mercari shows how they used Cloud Profiler and Trace to understand a complex microservices-based application running on Google Cloud, to meet rigorous SLOs as demand shifts for their products. </i></p><p>The events of 2020 have accelerated ecommerce, increasing demand for and traffic on online marketplaces. Analyst eMarketer <a href="https://www.emarketer.com/content/us-ecommerce-will-rise-18-2020-amid-pandemic?ecid=NL1001" target="_blank">predicts</a> that ecommerce sales in the United States will grow 18% in 2020, against an overall fall in total retail sales of 10.5% for the year. Likewise, our business—Japan-headquartered consumer-to-consumer marketplace <a href="https://www.mercari.com/us/help_center/article/22" target="_blank">Mercari Inc</a>—is growing rapidly. In the United States alone, we have seen 74% year-on-year growth in monthly average users to 3.4 million. A big part of our success are our robust payment and deposit systems and AI-based fraud monitoring, which enable sellers to list items for purchase and buyers to complete transactions safely. </p><p>Mercari started as a monolithic application but as complexity grew we decided to transition to a microservices architecture. And through it all, tools like Cloud Profiler and Cloud Trace helped us track down performance problems in our code, significantly improving latency.</p><h3>A microservices menagerie</h3><p>Today, we run 80+ microservices on Google Cloud with a mix of languages including Go, Python, JavaScript and Java. To deliver this new architecture, we created a gateway-like microservice to route traffic from soon-to-be migrated monolithic service to the Google Cloud microservices, which  delivers a range of features. </p><p>After creating several microservices, we identified common requirements and created a template to accelerate their development. These common requirements included: </p><ul><li><p>Exporting metrics to Prometheus</p></li><li><p>A gRPC server and interceptors</p></li><li><p>Error Reporting, Cloud Trace and Cloud Profiler. Error Reporting counts, analyzes and aggregates crashes in running cloud services, while Cloud Trace provides a view of requests as they flow through microservices and Cloud Profiler shows how microservices consume CPU, memory and threads.  </p></li></ul><p>We then used Python to create a template for machine learning services, also expediting the creation of new microservices. This has enabled us to grow the number of microservices we use in order to address new requirements. However, as our microservices proliferated, we needed to efficiently monitor and understand their performance. </p><h3>Maintaining SLO a challenge</h3><p>In particular, we needed to monitor the impact of new versions on the production environment and the efficiency of production operations, so we could maintain our service level objective (SLO) for success rates of 99.95% and 350 milliseconds for 95% latency. </p><p>Our engineering team also uses canary deployments to detect issues with new versions of major services. However, despite applying these measures, we found it challenging to maintain our SLO when our business grew faster than expected or during unanticipated spikes in demand. Some issues can be obvious or easy to detect. For example, if a service is experiencing high CPU utilization, we could simply place or fine tune our horizontal pod autoscaler (HPA) to resolve the problem. However, other issues may be less obvious. For example, a drop in performance may not directly be tied to a specific release—it may instead be due to unexpected requests, or may arise from changes to multiple functions in a single code release. </p><h3>Using Cloud Profiler and Cloud Trace to minimize performance issues</h3><p>In particular, our business-critical UserStats service, which tracks the speed with which a user replies to a message and how fast and reliably a seller ships an item, recently started performing poorly. </p><p>New feature requirements had prompted us to track how often a seller cancels an order and provide statistics. However, while adding this new functionality, the change refactored other functions, meaning we were unable to identify the function experiencing reduced performance. Since most of our services are enabled with Cloud Profiler and Cloud Trace, we turned to these products to investigate and identify the root cause.  </p><p>Before the change:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        <a href="https://storage.googleapis.com/gweb-cloudblog-publish/images/Using_Cloud_Profiler_and_Cloud_Trace.max-2800x2800.jpg" rel="external" target="_blank">
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Using_Cloud_Profiler_and_Cloud_Trace.max-1000x1000.jpg" alt="Using Cloud Profiler and Cloud Trace.jpg">
        
        </a>
      
        <figcaption class="article-image__caption "><i>Click to enlarge</i></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>After the change:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        <a href="https://storage.googleapis.com/gweb-cloudblog-publish/images/Using_Cloud_Profiler_and_Cloud_Trace_2_1.max-2800x2800.jpg" rel="external" target="_blank">
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Using_Cloud_Profiler_and_Cloud_Trace_2_1.max-1000x1000.jpg" alt="Using Cloud Profiler and Cloud Trace 2 (1).jpg">
        
        </a>
      
        <figcaption class="article-image__caption "><i>Click to enlarge</i></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>These two Cloud Profiler views show the CPU time of the call stack increased from 457 milliseconds to 904 milliseconds, with most of the delta attributable to the <b>_UserStats_SellerCancelStats_Handler</b> function. But because other functions also saw variations in their CPU consumption, and because calls occurred in parallel, we found it difficult to identify the cause of latency increases. The fact that this function call was necessary meant we could not remove the entire function. </p><p>We checked Cloud Trace and confirmed the function call had increased overall latency on some requests, similar to below:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        <a href="https://storage.googleapis.com/gweb-cloudblog-publish/images/trace_waterfall_view.max-2800x2800.jpg" rel="external" target="_blank">
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/trace_waterfall_view.max-1000x1000.jpg" alt="trace waterfall view.jpg">
        
        </a>
      
        <figcaption class="article-image__caption "><i>Click to enlarge</i></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>We analyzed the service with Cloud Profiler and identified hot spots that were contributing to the increase in CPU time consumption. We optimized these hot functions, deployed the new code, used Cloud Profiler to verify that the changes had the desired effect of reducing the CPU time. Doing so, we were able to improve latency by 10% to 15%!</p><h3>Simplifying the DevOps experience</h3><p>Before adopting Cloud Profiler, profiling production services was a tedious and manual undertaking involving recompiling with debug flags; deployment to production environments, and using disparate  tools to collect profiles and perform analysis. Containerization only increased this complexity, further reducing developer productivity. </p><p>Cloud Profiler enables us to continuously profile production environments with small and simple code changes, replacing the tedious work previously required to set up environments for performance analysis. <a href="https://cloud.google.com/profiler/docs/about-profiler#performance_impact">Low overhead</a> continuous profiling with Cloud Profiler helps us react swiftly to changes in service performance by root causing and resolving issues quickly.</p><p>Further, tools such as Cloud Trace and Cloud Profiler require minimal effort to setup and provide a consistent DevOps experience for our service owners. This is particularly important as we grow in the United States and elsewhere. Without Google Cloud, monitoring, debugging and profiling across production environments that feature a mix of languages, technology stacks, frameworks and containers would be extremely challenging and time-consuming. The release of new features and experiences in tools such as Cloud Profiler make us glad we chose Google Cloud as our primary cloud platform. We will continue to work with new features and provide feedback to Google Cloud, so it can continue to provide a better service to users.  </p><p><i>Visit the Google Cloud website to learn more about <a href="https://cloud.google.com/profiler">Cloud Profiler</a> and <a href="https://cloud.google.com/trace">Cloud Trace</a>.</i></p></div>
<div class="block-related_article_tout">





<div class="uni-related-article-tout h-c-page">
  <section class="h-c-grid">
    <a href="https://cloud.google.com/blog/topics/customers/mercari-relies-on-google-cloud-premium-support-and-technical-account-management/" data-analytics='{
                       "event": "page interaction",
                       "category": "article lead",
                       "action": "related article - inline",
                       "label": "article: {slug}"
                     }' class="uni-related-article-tout__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
        h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3 uni-click-tracker">
      <div class="uni-related-article-tout__inner-wrapper">
        <p class="uni-related-article-tout__eyebrow h-c-eyebrow">Related Article</p>

        <div class="uni-related-article-tout__content-wrapper">
          <div class="uni-related-article-tout__image-wrapper">
            <div class="uni-related-article-tout__image"></div>
          </div>
          <div class="uni-related-article-tout__content">
            <h4 class="uni-related-article-tout__header h-has-bottom-margin">Mercari: Faster and more efficient development with the help of Google Cloud</h4>
            <p class="uni-related-article-tout__body">Technical implementation can be challenging, and many businesses can benefit from hands-on support from their cloud provider. Learn how w...</p>
            <div class="cta module-cta h-c-copy  uni-related-article-tout__cta muted">
              <span class="nowrap">Read Article
                <svg class="icon h-c-icon" role="presentation">
                  <use xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#mi-arrow-forward"></use>
                </svg>
              </span>
            </div>
          </div>
        </div>
      </div>
    </a>
  </section>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Software-Engineering-Tage der Informatik Aktuell: Konferenz für Software-Entwicklung und ...]]></title>
<description><![CDATA[IT-Security · DevOps · Datenbanken · Java. ☰. Entwicklung · Betrieb · Management ... Sicherheit und nachhaltige IT-Strategien. Eberhard ...]]></description>
<link>https://tsecurity.de/de/3662085/it-security-nachrichten/software-engineering-tage-der-informatik-aktuell-konferenz-fuer-software-entwicklung-und/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662085/it-security-nachrichten/software-engineering-tage-der-informatik-aktuell-konferenz-fuer-software-entwicklung-und/</guid>
<pubDate>Sat, 11 Jul 2026 17:37:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>IT</b>-<b>Security</b> · DevOps · Datenbanken · Java. ☰. Entwicklung · Betrieb · Management ... Sicherheit und nachhaltige IT-Strategien. Eberhard ...]]></content:encoded>
</item>
<item>
<title><![CDATA[57% of enterprises have watched AI agents be confidently wrong. The fix is an agentic context layer, but who has one?]]></title>
<description><![CDATA[An enterprise AI agent answers with total confidence, but the number is wrong. Nobody catches it until someone traces it back to a stale metric definition or a document the retrieval system never pulled. The model did not fail. The context it was given did.In the past six months, 57% of enterpris...]]></description>
<link>https://tsecurity.de/de/3660872/it-nachrichten/57-of-enterprises-have-watched-ai-agents-be-confidently-wrong-the-fix-is-an-agentic-context-layer-but-who-has-one/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660872/it-nachrichten/57-of-enterprises-have-watched-ai-agents-be-confidently-wrong-the-fix-is-an-agentic-context-layer-but-who-has-one/</guid>
<pubDate>Fri, 10 Jul 2026 23:47:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An enterprise AI agent answers with total confidence, but the number is wrong. Nobody catches it until someone traces it back to a stale metric definition or a document the retrieval system never pulled. The model did not fail. The context it was given did.</p><p>In the past six months, 57% of enterprises traced a confident but wrong AI agent answer to missing or inconsistent business context, and 31% said it happened more than once, according to a VB Pulse June 2026 survey of 101 qualified enterprises with more than 100 employees.</p><p>The reason is not hard to find. Retrieval over documents is the default way agents get business context for 38% of enterprises, nearly double the next closest approach. The way most enterprises choose a retrieval system compounds the problem. Ease of ingestion and operational simplicity lead the selection criteria, with retrieval accuracy running behind both. The accuracy problem only shows up after the system is already live.</p><p>There is a known fix for this, a governed context layer every agent reads from instead of guessing. Vendors are racing to roll out context platforms while most enterprises are still figuring out what it is.</p><h2>75% don't have an agentic context layer yet</h2><p>The context layer is meant to be a shared model of what business data actually means, built once and referenced consistently instead of re-derived by every agent that touches it. </p><p>The VentureBeat research shows the enterprise response to that idea is broad but unfinished. Twenty-five percent of respondents run one in production. Thirty-four percent are building one right now. The remaining 41% have not started.</p><p>Among companies already building or running a governed context layer, 78% report a confident-wrong failure — an AI agent that answered with total certainty and was still wrong. Among companies with no plans to build a layer, only 20% report the same thing. Companies that already got burned are far more likely to be building the fix. Companies that haven't been burned yet see no urgency.</p><h2>What governed context looks like when someone actually builds one</h2><p>Every major data and AI platform vendor is now building some version of this layer, and they are not converging on the same architecture. </p><ul><li><p><a href="https://venturebeat.com/data/sql-query-logs-hold-the-context-ai-agents-need-to-stop-hallucinating-joins">DataHub</a> is treating catalog metadata and years of analyst query behavior as a knowledge source, then keeping it current as a living system rather than a static wiki. </p></li><li><p>Microsoft's<a href="https://venturebeat.com/data/enterprise-ai-agents-keep-operating-from-different-versions-of-reality"> Fabric IQ</a> is building a business ontology that any agent, not just Microsoft's own, can query over MCP. </p></li><li><p><a href="https://venturebeat.com/data/ai-agents-need-context-everywhere-they-run-even-where-the-cloud-cant-follow">Couchbase</a> is pushing agent memory and context retrieval down to the edge, arguing the operational database is a more natural home for it than a search or analytics layer bolted on after the fact. </p></li><li><p>Pinecone's<a href="https://venturebeat.com/data/the-rag-era-is-ending-for-agentic-ai-a-new-compilation-stage-knowledge-layer-is-what-comes-next"> Nexus</a> is compiling structural logic into the metadata layer ahead of runtime, betting that agents need pre-built structure more than they need faster search.</p></li><li><p>Snowflake runs a two-layer system,<a href="https://venturebeat.com/data/ai-agents-keep-giving-confident-wrong-answers-the-context-layer-is-enterprise-ais-next-production-problem"> Horizon Context</a> for customer-managed definitions and Cortex Sense for context the platform infers on its own. </p></li><li><p>Oracle's<a href="https://venturebeat.com/data/oracle-converges-the-ai-data-stack-to-give-enterprise-agents-a-single"> Unified Memory Core</a> takes the opposite approach, folding vector, graph and relational data into one transactional engine so there is no sync layer left to go stale. </p></li><li><p>Google's<a href="https://venturebeat.com/data/the-modern-data-stack-was-built-for-humans-asking-questions-google-just-rebuilt-its-for-agents-taking-action"> Knowledge Catalog</a> mines query logs and usage patterns to curate semantic context automatically.</p></li><li><p>AWS's<a href="https://venturebeat.com/data/aws-enters-the-context-layer-race-with-a-graph-that-learns-from-agents-not-manual-curation"> Context</a> service makes the same bet, a knowledge graph that gets smarter from how agents actually use it rather than from manual re-curation.</p></li></ul><h2>Analysts converge on one diagnosis</h2><p>The vendor approaches differ. What analysts and practitioners have told VentureBeat about the underlying problem, across a run of interviews this year, does not.</p><p>When<a href="https://venturebeat.com/data/sql-query-logs-hold-the-context-ai-agents-need-to-stop-hallucinating-joins"> DataHub's context layer push</a> landed this spring, Constellation Research VP and principal analyst Michael Ni framed the stakes in blunt terms. "Whoever controls runtime context controls the AI decision layer for enterprise data," Ni said. He was equally direct about how far any single product actually gets a buyer. "Vector memory isn't business meaning, business meaning isn't governance and governance isn't execution," Ni said.</p><p>In the same interview, BARC analyst Kevin Petrie pointed to a narrower but concrete gap. Most context platforms concentrate on structured tables, he said, which give agents trusted facts but miss the harder, messier context locked in documents and unstructured content, exactly the material a business actually runs on day to day.</p><p>Stephanie Walter, practice leader for AI Stack at HyperFRAME Research, made a related point earlier this year when VentureBeat asked her about<a href="https://venturebeat.com/data/context-architecture-is-replacing-rag-as-agentic-ai-pushes-enterprise-retrieval-to-its-limits"> enterprise context fragmentation</a>. </p><p>"The market is converging on the same conclusion," Walter said. "Agents don't just need more tokens or better models. They need governed, current, low-latency context." She made a similar case in an earlier review of<a href="https://venturebeat.com/data/the-rag-era-is-ending-for-agentic-ai-a-new-compilation-stage-knowledge-layer-is-what-comes-next"> Pinecone's Nexus launch</a>, careful not to overstate how new any of this is. Nexus, she said, "shifts knowledge work from runtime chaos to pre-compiled structure. But it's an evolution of RAG architecture, not a complete reinvention." </p><p>Gartner's Arun Chandrasekaran, reviewing the same launch, offered the more forward-looking read. Agentic AI, he said, is moving from pure information retrieval toward a reasoning architecture, one where long context works as short-term memory and a vector database functions as deep storage underneath it.</p><p>The fragmentation problem shows up hardest at the practitioner level, where separate tools for retrieval, memory and access control were never built to agree with each other. Steven Dickens, CEO and principal analyst at HyperFRAME Research, put it bluntly after <a href="https://venturebeat.com/data/oracle-converges-the-ai-data-stack-to-give-enterprise-agents-a-single">Oracle's AI database push</a> landed this spring. "Data teams are exhausted by fragmentation fatigue," Dickens said. "Managing a separate vector store, graph database and relational system just to power one agent is a DevOps nightmare." </p><p>Matt Kimball at Moor Insights and Strategy, in that same story, put the production reality more simply. Getting an agent working is not the hard part, he said. The struggle is running it in production, where the goal becomes removing the distance between data and execution rather than adding another layer on top of it.</p><h2>What this means for enterprises</h2><p>Here's what this adds up to for enterprises building on this layer.</p><p><b>Retrieval alone will not close the context gap.</b> RAG is the default source for context in most enterprises today, and it is also the layer most closely associated with the confident-wrong-answer failure. Adding more documents or a bigger index does not fix a definition that is inconsistent across systems.</p><p><b>The semantic context layer is where the budget is actually moving, even where it hasn't shipped. </b>Fifty-eight percent of enterprises are already engaged — building or in production — but only 25% have actually gotten a layer live. That gap shows where enterprises have decided to spend, not where they've arrived.</p><p><b>No single vendor owns the architecture yet, and that is likely to stay true for a while.</b> Enterprises evaluating this layer should expect to integrate rather than pick a single winner, at least for the next several quarters.</p><p><b>The buying decision is happening this year, and it is concentrated among the companies already burned by it.</b> Fifty-seven percent of enterprises plan to switch or add a retrieval or context platform within the next twelve months. That intent is not spread evenly. Enterprises that reported a repeat confident-wrong failure plan to switch or add a provider at roughly 81%, against 32% among enterprises that never hit the problem. The companies shopping for new context tooling right now are largely the ones whose agents already got it wrong. </p><p>The agents are already running. The context underneath most of them is still being built, and the vendor selling the fix is being chosen this year.</p><p><i>This data will be part of a broader conversation at </i><a href="https://venturebeat.com/vbtransform2026"><i>VB Transform 2026</i></a><i> on July 14 and 15 in Menlo Park: the context gap enterprises are racing to close, and which of the emerging approaches — governed semantic layers, hybrid retrieval, provider-native bundles — actually holds up in production.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI job titles expand beyond tech as IT hiring remains strong]]></title>
<description><![CDATA[New research from Indeed Hiring Lab found that the number of U.S. job titles referencing AI has more than tripled since 2022, growing from 264 to 822 by the first quarter of 2026.



The research division of the global job search platform also discovered that nearly two-thirds (63%) of those AI-r...]]></description>
<link>https://tsecurity.de/de/3660370/it-security-nachrichten/ai-job-titles-expand-beyond-tech-as-it-hiring-remains-strong/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660370/it-security-nachrichten/ai-job-titles-expand-beyond-tech-as-it-hiring-remains-strong/</guid>
<pubDate>Fri, 10 Jul 2026 18:33:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>New research from <a href="https://www.hiringlab.org/2026/07/08/ai-is-no-longer-just-a-tech-occupation-story/" target="_blank" rel="noreferrer noopener">Indeed Hiring Lab</a> found that the number of U.S. job titles referencing AI has more than tripled since 2022, growing from 264 to 822 by the first quarter of 2026.</p>



<p>The research division of the global job search platform also discovered that nearly two-thirds (63%) of those AI-related job titles in the U.S. now appear in roles outside traditional technology occupations, in fields such as healthcare, education, marketing, logistics, and management.</p>



<p>“AI is no longer just a tech occupation story,” Indeed <a href="https://www.hiringlab.org/2026/07/08/ai-is-no-longer-just-a-tech-occupation-story/" target="_blank" rel="noreferrer noopener">researchers wrote</a>, noting that employers are increasingly incorporating AI skills into roles that historically had little connection to software development or data science. “The number of AI-touched jobs has risen across every market we track.”</p>



<p>Separately, according to CompTIA’s latest <a href="https://www.comptia.org/en-us/about-us/news/press-releases/Tech-hiring-momentum-continues-as-tech-occupations-and-new-job-postings-increase-CompTIA-analysis-reveals/" target="_blank" rel="noreferrer noopener">Tech Jobs Report</a>, employers posted more than <a href="http://lecbyo.files.cmp.optimizely.com/download/6b6fc8e4ff4a11efbebeaeb5c39a94d9?sfvrsn=725f3c8d_0" target="_blank" rel="noreferrer noopener">280,000 new technology job postings</a> in June, marking the sixth consecutive month of growth. Active technology job postings approached 600,000, while employment in tech occupations increased by 47,000 positions. The unemployment rate for tech occupations fell to 2.9%, compared with the national unemployment rate of 4.2%, according to CompTIA.</p>



<p>“June’s employment data suggests that employers are ramping up their technology investments and hiring the talent needed to support them,” said Seth Robinson, vice president for industry research at CompTIA, in a <a href="https://www.comptia.org/en-us/about-us/news/press-releases/Tech-hiring-momentum-continues-as-tech-occupations-and-new-job-postings-increase-CompTIA-analysis-reveals/" target="_blank" rel="noreferrer noopener">statement</a>. “Even as some tech companies announce layoffs, employers in other industries are accelerating digital transformation initiatives and moving from AI experimentation to implementation.”</p>



<p><a href="https://lecbyo.files.cmp.optimizely.com/download/6b6fc8e4ff4a11efbebeaeb5c39a94d9?sfvrsn=725f3c8d_0" target="_blank" rel="noreferrer noopener">CompTIA’s report</a> notes that new tech job postings increased for the sixth consecutive month amid what it described as a “broad-based movement toward reinvigorating digital transformation activities and clarifying AI strategies.”</p>



<p>Demand remains strongest for traditional IT roles. Software developers and engineers led all technology job postings in June with nearly 50,000 openings, followed by systems engineers, tech support specialists, data analysts, and DevOps engineers. Professional, scientific, and technical services firms generated the highest volume of technology job postings, followed by administrative services, manufacturing, information and media, and financial services organizations, according to CompTIA.</p>



<p>Employers are increasingly “writing AI into job titles for a wide range of roles—not just software and data jobs,” according to Indeed’s report. The reports show continued demand for technology workers while AI-related job titles become more common outside the traditional tech sector.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to watch Fery vs Zverev for FREE: live stream Wimbledon 2026 semi-final from anywhere]]></title>
<description><![CDATA[All the ways to watch Arthur Fery vs Alexander Zverev online and from anywhere for free as the British wildcard seeks a huge semi-final upset at Wimbledon 2026.]]></description>
<link>https://tsecurity.de/de/3659464/it-nachrichten/how-to-watch-fery-vs-zverev-for-free-live-stream-wimbledon-2026-semi-final-from-anywhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659464/it-nachrichten/how-to-watch-fery-vs-zverev-for-free-live-stream-wimbledon-2026-semi-final-from-anywhere/</guid>
<pubDate>Fri, 10 Jul 2026 13:03:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[All the ways to watch Arthur Fery vs Alexander Zverev online and from anywhere for free as the British wildcard seeks a huge semi-final upset at Wimbledon 2026.]]></content:encoded>
</item>
<item>
<title><![CDATA[Braintree NuGet Typosquat Uses XOR-Obfuscated C2 to Hide Environment Secret Theft]]></title>
<description><![CDATA[A malicious NuGet package impersonating the Braintree .NET payment library has put production payment systems at risk. The package can collect live card details during transactions, then send the data away without alerting the application or its users. It also seeks credentials that could give cr...]]></description>
<link>https://tsecurity.de/de/3659020/it-security-nachrichten/braintree-nuget-typosquat-uses-xor-obfuscated-c2-to-hide-environment-secret-theft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659020/it-security-nachrichten/braintree-nuget-typosquat-uses-xor-obfuscated-c2-to-hide-environment-secret-theft/</guid>
<pubDate>Fri, 10 Jul 2026 09:52:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A malicious NuGet package impersonating the Braintree .NET payment library has put production payment systems at risk. The package can collect live card details during transactions, then send the data away without alerting the application or its users. It also seeks credentials that could give criminals broader access to merchant systems. Typosquatting works because a […]</p>
<p>The post <a href="https://cybersecuritynews.com/braintree-nuget-typosquat-uses-xor-obfuscated-c2/">Braintree NuGet Typosquat Uses XOR-Obfuscated C2 to Hide Environment Secret Theft</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[“1~2시간 걸리던 장애 분석, 5분이면 끝”…데이터독 ‘비츠 AI’ 전면에]]></title>
<description><![CDATA[데이터독 코리아는 9일 서울에서 기자간담회를 열고 이 같은 사업 현황과 연례 컨퍼런스 ‘대시(Dash) 2026’에서 공개한 신제품 전략을 소개했다.



엄수창 데이터독 코리아 지사장은 이를 시장 변화의 신호로 해석했다.



엄 지사장은 “연초만 해도 ‘SaaS 아포칼립스’라는 말이 나올 정도로 SaaS 기업들의 미래를 부정적으로 보는 시각이 많았다”며 “하지만 데이터독은 AI와 함께 성장하면서 오히려 큰 미래 비전을 갖게 됐다”고 말했다. 이어 “글로벌 상위 AI 기업 10곳 모두 데이터독을 사용하고 있다는 사실 자체가 ...]]></description>
<link>https://tsecurity.de/de/3658717/it-nachrichten/12-5-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658717/it-nachrichten/12-5-ai/</guid>
<pubDate>Fri, 10 Jul 2026 07:02:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>데이터독 코리아는 9일 서울에서 기자간담회를 열고 이 같은 사업 현황과 연례 컨퍼런스 ‘<a href="https://dash.datadoghq.com/" target="_blank" rel="nofollow">대시</a>(Dash) 2026’에서 공개한 신제품 전략을 소개했다.</p>



<p>엄수창 데이터독 코리아 지사장은 이를 시장 변화의 신호로 해석했다.</p>



<p>엄 지사장은 “연초만 해도 ‘SaaS 아포칼립스’라는 말이 나올 정도로 SaaS 기업들의 미래를 부정적으로 보는 시각이 많았다”며 “하지만 데이터독은 AI와 함께 성장하면서 오히려 큰 미래 비전을 갖게 됐다”고 말했다. 이어 “글로벌 상위 AI 기업 10곳 모두 데이터독을 사용하고 있다는 사실 자체가 시장이 우리의 성장 가능성을 높게 평가하고 있다는 방증”이라고 강조했다.</p>



<p>이 같은 자신감의 배경에는 AI 시대 급증하는 운영 관리 수요가 있다. 과거에는 데브옵스(DevOps)와 SRE(Site Reliability Engineering) 조직이 장애 분석과 인프라 모니터링을 위해 주로 활용했다면, 이제는 AI를 활용해 운영을 자동화하는 기능과 AI 애플리케이션 자체를 관리하는 기능까지 제공하며 AI 시대에 맞춰 사업 영역을 확대하고 있다.</p>



<p>정영석 데이터독 기술총괄은 올해 대시에서 공개한 100여 개의 신기능을 ‘자율 IT 운영(Autonomous Operations)’과 ‘AI 거버넌스’라는 두 가지 축으로 설명했다.</p>



<p>자율 IT 운영 분야에서는 ‘비츠 AI(Bits AI)’가 장애 탐지부터 원인 분석, 해결까지 자동으로 수행한다. 정 총괄은 “장애가 발생하면 비츠 AI가 8가지 안팎의 가설을 세운 뒤 하나씩 검증해 근본 원인을 찾아내고, 코드 수정안까지 PR(Pull Request) 형태로 제안한다”며 “기존에는 엔지니어가 1~2시간 걸리던 분석 및 보고서 작성 작업을 빠르면 5분 이내로 단축할 수 있다”고 설명했다.</p>



<p>또 인프라 자원이 부족하면 슬랙 등을 통해 운영자 승인만 받아 메모리와 CPU를 자동으로 증설하고, 사전에 정의한 가드레일 안에서는 무인 복구도 수행한다. 코드 변경부터 스테이징 배포, 프로덕션 환경에 이르기까지 애플리케이션이 의도대로 동작하는지도 AI가 지속적으로 검증한다.</p>



<p>AI 거버넌스 분야에서는 ▲에이전트 옵저버빌리티(Agent Observability) ▲AI 게이트웨이(AI Gateway) ▲AI 가드(AI Guard) ▲LLM 비용 관리 콘솔 등의 기능 공개했다.</p>



<p>에이전트 옵저버빌리티는 AI 에이전트 내부에서 어떤 LLM과 도구를 사용했고, 토큰과 비용이 얼마나 발생했는지 시각화한다. AI 게이트웨이는 여러 LLM을 통합 관리하고 감사(Audit)를 수행하며, AI 가드는 프롬프트 인젝션과 민감정보 유출을 차단한다.</p>



<p>정 총괄은 “코파일럿, 커서(Cursor), 클로드 등 여러 AI 모델을 함께 사용하는 기업이 늘면서 비용과 보안, 신뢰성을 통제하는 것이 C레벨 경영진의 공통 과제가 됐다”며 “개발자별, 모델별 사용량과 비용을 세분화해 보여주기 때문에 임원들도 최적화 지점을 쉽게 찾을 수 있다”고 말했다.</p>



<p>최근 많은 기업이 멀티 LLM 전략을 채택하는 만큼 이러한 통합 관리 플랫폼의 필요성도 커질 것이라는 설명이다.</p>



<p>CIO 코리아가 AI 기능 추가로 관련 비용이 늘어나는 것 아니냐고 묻자 정 총괄 “데이터독이 제공하는 수백 개의 외부 서비스 연동 기능은 모두 기본 호스트 사용료에 포함돼 있어 AI 기능이 추가됐다고 모니터링 비용이 늘어나는 것은 아니다”며 “다만 로그는 저장량이 늘어나면 비용이 증가하는 구조인데 이는 어느 벤더나 비슷하다”고 답했다.</p>



<p>이어 “AI가 추가됐다고 인프라 모니터링 비용이 올라가는 것은 아니지만 AI SRE처럼 자동 분석 기능을 사용할 경우 토큰(크레딧)이 소모돼 비용이 추가될 수 있다”며 “반면 엔지니어의 업무 시간을 크게 줄일 수 있기 때문에 ROI 측면에서는 충분히 상쇄할 수 있고, UI 대신 MCP(Model Context Protocol)를 활용하면 비용을 낮출 수 있어 국내 여러 대형 고객도 MCP 기반 AI옵스를 구축하고 있다”고 덧붙였다.</p>



<p>AI가 문제 해결책까지 제시하는 것에 대한 고객사의 거부감은 없는지 묻는 질문에는 “잘못 분석할 가능성이 있는 것은 사실이지만 지금까지 고객 반응은 매우 긍정적”이라며 “AI가 잘못 탐지하더라도 사용자가 대화를 통해 추가 분석을 요청하면 계속 수정하면서 근본 원인에 더 가까운 결과를 제시한다”고 설명했다.</p>



<p>이어 “이 경험은 ‘비츠 메모리(Bits Memory)’ 기능에 축적돼 이후 유사한 장애가 발생하면 더욱 정확하게 분석하도록 학습된다”고 말했다.</p>



<p>내부 AI는 자체 모델과 업계 최신 모델을 함께 사용하는 하이브리드 구조다.</p>



<p>정 총괄은 “프론티어 모델과 자체 모델인 ‘<a href="https://www.datadoghq.com/blog/datadog-time-series-foundation-model/" target="_blank" rel="nofollow">토토</a>(Toto)’를 함께 운영하고 있으며 작업 특성에 따라 가장 적합한 모델을 선택해 사용한다”고 밝혔다. 클로드, GPT, 제미나이 등 다양한 외부 최신 모델을 활용하며, AI SRE는 내부적으로 최적 모델이 자동 선택되지만 에이전트 빌더에서는 고객이 MCP와 사용할 모델을 직접 선택할 수 있다. 또한 LLM 옵저버빌리티에서는 환각을 탐지하기 위해 교차 검증용 모델을 별도로 지정하는 기능도 제공한다.</p>



<p>데이터독은 앞으로 옵저버빌리티(Observability), 보안, 핀옵스(FinOps), 비즈니스 인텔리전스(BI)를 하나의 플랫폼에서 통합 제공하는 차별성을 앞세워 국내 시장 공략을 확대하겠다고 밝혔다.<br>jihyun.lee@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[JetBrains seeks to unify fragmented AI-based software development with governance suite]]></title>
<description><![CDATA[AI promised to make software development faster, but for many enterprises, it has also created a new management challenge: developers increasingly rely on a mix of coding assistants, AI agents, and models that operate in isolation, making it harder for engineering leaders to govern usage, share k...]]></description>
<link>https://tsecurity.de/de/3657123/ai-nachrichten/jetbrains-seeks-to-unify-fragmented-ai-based-software-development-with-governance-suite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657123/ai-nachrichten/jetbrains-seeks-to-unify-fragmented-ai-based-software-development-with-governance-suite/</guid>
<pubDate>Thu, 09 Jul 2026 15:03:58 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI promised to make software development faster, but for many enterprises, it has also created a new management challenge: developers increasingly rely on a mix of coding assistants, AI agents, and models that operate in isolation, making it harder for engineering leaders to govern usage, share knowledge, and control costs.</p>



<p>JetBrains has sought to address these challenges with a new suite of tools and capabilities named JetBrains AI for Teams and Organizations that supports nearly all coding tools, their respective CLIs, and most IDEs, such as Claude, Codex, Gemini, Junie, IntelliJ, Pycharm, and Rider, with support for VS Code to be added soon.</p>



<p>The suite, which consists of capabilities like team automations and cloud agents, JetBrains Context, JetBrains Central, and JetBrains Central CLI, will allow enterprises to manage AI-assisted software development from a single control layer while allowing developers to continue using their preferred coding assistants and IDEs, <a href="https://www.linkedin.com/in/oleg-koverznev/" target="_blank" rel="noreferrer noopener">Oleg Koverznev</a>, head of agent systems at JetBrains, wrote in a <a href="https://blog.jetbrains.com/blog/2026/07/07/jetbrains-ai-for-teams-and-organizations-from-fragmented-ai-usage-to-coordinated-software-development/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p>While team automations and cloud agents are intended to let AI agents run long-running engineering tasks in managed cloud environments and trigger workflows based on repository events or schedules, JetBrains Context is designed to provide a shared understanding of project code, documentation, and development activity across tools, Koverznev added.</p>



<p>Complementing those collaboration capabilities, JetBrains Central serves as the administrative layer for governance, access control, and usage management, with the Central CLI extending those controls to the command-line and automation workflows, Kovernznev further added.</p>



<h2 class="wp-block-heading">Tool sprawl to reduced operational friction</h2>



<p>Fragmentation of AI-assisted coding tools and development environments adds complexity for enterprises and their leaders.</p>



<p>“Fragmentation of AI coding tools is an evolving problem for enterprises. A year ago, the conversation was whether to even allow an AI assistant. Now a single team is running Copilot, Claude Code, Cursor, and a few homegrown agents at once,” said <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at FinOps services providing firm ZopDev.</p>



<p>“The pain leaders raise with us isn’t the tools themselves. It’s that nobody can answer three questions: who is using what, what is it costing us, and is it actually safe? Fragmentation became a governance and cost problem the moment agents started touching real codebases and running up real bills,” Bandta added.</p>



<p>These governance and cost issues are increasing demand for suites, such as JetBrains AI for Teams and Organizations, that can coordinate AI-assisted software development across teams.</p>



<p>For development teams specifically, such suites with a centralized context layer can reduce operational friction, according to <a href="https://www.gartner.com/en/experts/nitish-tyagi" target="_blank" rel="noreferrer noopener">Nitish Tyagi</a>, senior principal analyst at Gartner.</p>



<p>“Rather than teams manually configuring multiple AI coding tools, maintaining prompts, or repeatedly supplying context, a centralized context layer enables agents to work with a more consistent understanding of the organization’s codebase, standards, documentation, and workflows,” Tyagi said.</p>



<p>“Over time, this can help accelerate parts of the software development lifecycle by reducing time spent searching for information, understanding legacy code, onboarding developers, and reworking outputs that lack the necessary business context. The primary value is not necessarily that agents write more code, but that they produce more relevant and organization-aware outputs,” Tyagi added.</p>



<p>More so because, a shared context layer for AI agents primarily helps development teams by reducing knowledge silos, Tyagi further added.</p>



<h2 class="wp-block-heading">Governance and cost management as benefits</h2>



<p>The benefits of the suite, according to Bandta, transcend developer productivity and should help CIOs with governance and cost management.</p>



<p>“The suite will enable engineering leaders to gain greater control over what information can be accessed by different agents and teams, helping reduce security and compliance risks. For example, enterprises can prevent agents from directly accessing sensitive repositories or business-critical data,” echoed Tyagi.</p>



<p> “Secondly, as the platform is continuously refining and managing context, agents get optimized and more relevant context to deliver higher quality output at lower cost,” Tyagi added.</p>



<p>The launch of JetBrains’ new suite, analysts pointed out, also reflects a broader shift in the software development tools market, where vendors are evolving from integrated development environments.</p>



<p>“This launch signals the evolution of the IDE into an ‘agentic development environment’. A platform where developers increasingly orchestrate fleets of AI agents instead of writing every line of code themselves,” Bandta said.</p>



<p>“The segment is splitting into agents that do the work and platforms that govern them, and the platform layer is where enterprise budgets will concentrate,” Bandta noted, adding that she expects rival vendors, including Microsoft, to pursue similar strategies.</p>



<p>The new capabilities, according to JetBrains, will be rolled out gradually to business customers throughout July and August.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI-Native Disaggregated RAN: Project Sylva Reference Architecture with SUSE Telco Cloud and OCUDU RAN stack]]></title>
<description><![CDATA[Blog post authored by: Nils Fuerste, DevOps Engineer at Software Radio Systems Alberto Morgante, Principal Telco Engineer at SUSE   Introduction Communication Service Providers (CSPs) are transitioning to open, disaggregated, and AI-native network architectures to reduce costs, eliminate vendor l...]]></description>
<link>https://tsecurity.de/de/3656179/unix-server/ai-native-disaggregated-ran-project-sylva-reference-architecture-with-suse-telco-cloud-and-ocudu-ran-stack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656179/unix-server/ai-native-disaggregated-ran-project-sylva-reference-architecture-with-suse-telco-cloud-and-ocudu-ran-stack/</guid>
<pubDate>Thu, 09 Jul 2026 09:01:00 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Blog post authored by: Nils Fuerste, DevOps Engineer at Software Radio Systems Alberto Morgante, Principal Telco Engineer at SUSE   Introduction Communication Service Providers (CSPs) are transitioning to open, disaggregated, and AI-native network architectures to reduce costs, eliminate vendor lock-in, and accelerate innovation in 5G and 6G services. This shift requires tight integration between carrier-grade […]</p>
<p>The post <a href="https://www.suse.com/c/ai-native-disaggregated-ran-project-sylva-reference-architecture-with-suse-telco-cloud-and-ocudu-ran-stack/">AI-Native Disaggregated RAN: Project Sylva Reference Architecture with SUSE Telco Cloud and OCUDU RAN stack</a> appeared first on <a href="https://www.suse.com/c">SUSE Communities</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Accenture investigating breach after threat actor claims theft of Azure DevOps source code]]></title>
<description><![CDATA[Accenture has confirmed it is investigating a security incident after a threat actor claimed to have stolen data from the company's Azure DevOps environment. According to the threat actor, the data includes source code, CI/CD configuration files, internal documentation, and credentials such as Az...]]></description>
<link>https://tsecurity.de/de/3655782/it-security-nachrichten/accenture-investigating-breach-after-threat-actor-claims-theft-of-azure-devops-source-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655782/it-security-nachrichten/accenture-investigating-breach-after-threat-actor-claims-theft-of-azure-devops-source-code/</guid>
<pubDate>Thu, 09 Jul 2026 04:08:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/security/comments/1uqmvii/accenture_investigating_breach_after_threat_actor/"> <img src="https://external-preview.redd.it/a7DcEU-89p8EAiOf5nKoxNayWTkzwCOcH5kekxuY1nM.jpeg?width=640&amp;crop=smart&amp;auto=webp&amp;s=8867cdec4750629fcd350a5e7bcf63dd5e2403ff" alt="Accenture investigating breach after threat actor claims theft of Azure DevOps source code" title="Accenture investigating breach after threat actor claims theft of Azure DevOps source code"> </a> </td><td> <!-- SC_OFF --><div class="md"><p>Accenture has confirmed it is investigating a security incident after a threat actor claimed to have stolen data from the company's Azure DevOps environment. According to the threat actor, the data includes source code, CI/CD configuration files, internal documentation, and credentials such as Azure Personal Access Tokens (PATs) and SSH keys. While the incident itself has been acknowledged, the full scope of the allegedly stolen data has not been independently verified.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/NapierPalm"> /u/NapierPalm </a> <br> <span><a href="https://thecybersecguru.com/news/accenture-data-breach-888-azure-devops-source-code/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1uqmvii/accenture_investigating_breach_after_threat_actor/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub’s public APIs are becoming an enterprise reconnaissance tool]]></title>
<description><![CDATA[GitHub continues to be a scintillating target for attackers because it sits in the middle of the software supply chain and gives threat actors three things they crave: source code, secrets, and automated pipelines to run amok in.



Datadog Security Research has been tracking what it calls a “sus...]]></description>
<link>https://tsecurity.de/de/3655643/ai-nachrichten/githubs-public-apis-are-becoming-an-enterprise-reconnaissance-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655643/ai-nachrichten/githubs-public-apis-are-becoming-an-enterprise-reconnaissance-tool/</guid>
<pubDate>Thu, 09 Jul 2026 02:02:56 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>GitHub continues to be a scintillating target for attackers because it sits in the middle of the software supply chain and gives threat actors three things they crave: source code, secrets, and automated pipelines to run amok in.</p>



<p>Datadog Security Research has been tracking what it calls a “sustained pattern” of GitHub API abuse over the past several months that seeks to map organizations and their members. While individually these requests are “unremarkable,” they become dangerous when they move across environments for weeks at a time, and, worse, progress to full-out cloning. The biggest challenge is that they blend into normal API usage patterns.</p>



<p>GitHub has been a goldmine for criminals looking to breach organizations because many development lifecycles are insecure, said <a href="https://www.beauceronsecurity.com/blog/tag/David+Shipley" target="_blank" rel="noreferrer noopener">David Shipley</a> of Beauceron Security. Typically, threat actors are after API keys and cloud secrets.</p>



<p><br>“Now with everyone being pushed to do more, faster, with AI agents coding, the treasure trove of secrets is likely even bigger,” he said. “In short, to steal a line from a previous gold rush of the analog era, ‘there’s gold in them thar hills.'”</p>



<p><a href="https://www.linkedin.com/in/scottmiserendino" target="_blank" rel="noreferrer noopener">Scott Miserendino,</a> CTO at security and compliance company DataBee, agreed. “Github is the most popular source code repository for both open-source and enterprise projects,” he said. “Its sheer volume of projects, along with being home to some of the most popular and widely used software, make it a target.”</p>



<p>He noted that intellectual property theft such as the unauthorized cloning of private repositories can be used to gain use of proprietary software or find vulnerabilities that can be exploited.</p>



<p>A second popular attack involves searching for repositories containing default credentials to popular software. Using them, attackers may develop and test assaults on accounts that are present in production environments or come installed by default on certain appliances.</p>



<p>And, Datadog senior security engineer <a href="https://www.rsaconference.com/experts/julie-sparks" target="_blank" rel="noreferrer noopener">Julie Agnes Sparks</a> wrote in a <a href="https://securitylabs.datadoghq.com/articles/coordinated-github-api-enumeration/" target="_blank" rel="noreferrer noopener">blog post</a>, “the activity is not a single actor. Rather, it’s a blend of custom automated scanner tools, opportunistic abuse of leaked credentials, and coordinated networks of burner (ghost) accounts.”</p>



<h2 class="wp-block-heading">A simple but effective way to map GitHub users</h2>



<p>Sparks explained that a “large share” of GitHub’s API surface can be reached without authentication; it is public by design. Requests against APIs typically produce standard HTTP 200 responses.</p>



<p>This means a threat actor can build detailed maps of organizations, their public repositories, their members, who they follow, their starred repos, and projects they interact with. This traffic blends into normal API usage and thus does not seem suspicious, she said.</p>



<p>Furthermore, <a href="https://www.csoonline.com/article/4194448/github-ai-agent-leaks-private-repositories-via-prompt-injection-attack.html" target="_blank">GitHub</a> only collects geolocation data when a user interacts with private repositories, recording who they are and what access token they used, not when they interact with external resources. This limits geolocation and VPN/proxy-based attribution.</p>



<p>Typically, threat actors have performed automated scraping with custom or legitimate-sounding user agents, taking advantage of GitHub “ghost” accounts, profiles created anywhere from two to five years ago and left dormant.</p>



<p>This is an attractive method because, Sparks noted, “an account with a multi-year history reads as more legitimate than one registered the same week it starts scraping.”</p>



<p>Typically, these accounts are used for a “burst” of just one to three weeks across many enterprises at once, then usage stops. The researchers identified more than 50 ghost accounts across multiple user agents, clustered into families with names like <em>user432023</em>, <em>user412023</em>, or <em>kobalt*</em>.</p>



<p>Some campaigns did use the legitimate accounts of GitHub users who had inadvertently posted their OAuth tokens or personal access tokens (PATs), or have had their endpoints compromised or exposed in other ways.</p>



<p>Attackers use a mix of data exfiltration agents with names like <em>GitHub-Company-Scraper,</em> <em>GitHub-Scraper-Tool/1.0., </em>and<em> GitHubAnalytics/1.5</em>,designed to blend into normal data analysis traffic. The bulk of requests target the open source query language <em>/graphql</em>, which is “well suited” for bulk queries across enterprises, users, and repositories, Sparks noted. Normal REST endpoints are used for org-mapping.</p>



<p>The focus of the campaigns was “narrow and consistent,” and the concern “lies in the aggregate,” Sparks said. In isolation, requests target public repositories without authentication and return successful responses. This rarely produces “meaningful access” into an enterprise’s repositories. </p>



<p>But a group of accounts moving in sync across shared GitHub accounts with versioned, custom tooling over a period of weeks represents more troubling and systematic behavior. She cited one event in which dozens of distinct, legitimate, but compromised GitHub user accounts made API requests to a single organization within a window of only a few minutes, although in that case the attack failed, because they targeted private repository commit paths.</p>



<h2 class="wp-block-heading">How enterprises can protect their GitHub environments</h2>



<p>Sparks pointed out that these behaviors can be <a href="https://www.csoonline.com/article/3847510/rising-attack-exposure-threat-sophistication-spur-interest-in-detection-engineering.html" target="_blank">hunted for and detected</a> “if you are watching the right fields,” such as those identifying the user agent, token type, autonomous system number (ASN), or attempted action.</p>



<p>“User agents, event activity, and actor names are vital clues to unauthorized activity in your environment,” Sparks emphasized. She suggested reviewing unusual user agent behavior across GitHub audit logs, particularly for those that extend to private repositories where the platform also captures the IP address, actor name, and programmatic access type.</p>



<p>Enterprises should also enable GitHub audit log streaming, baseline user agents, and perform proactive threat hunting. Most importantly, she said, they should develop detections unique to their GitHub organization, noting, “It’s important to know what normal looks like in your environment.”</p>



<p>Simply put, added Miserendino, enterprises should be following security best practices, including enabling multi-factor authentication (MFA) on all accounts, performing periodic user access reviews, removing any unused or unneeded accounts, and scanning repositories for credentials stored in plaintext rather than in a secret store.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub’s public APIs are becoming an enterprise reconnaissance tool]]></title>
<description><![CDATA[GitHub continues to be a scintillating target for attackers because it sits in the middle of the software supply chain and gives threat actors three things they crave: source code, secrets, and automated pipelines to run amok in.



Datadog Security Research has been tracking what it calls a “sus...]]></description>
<link>https://tsecurity.de/de/3655622/it-security-nachrichten/githubs-public-apis-are-becoming-an-enterprise-reconnaissance-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655622/it-security-nachrichten/githubs-public-apis-are-becoming-an-enterprise-reconnaissance-tool/</guid>
<pubDate>Thu, 09 Jul 2026 01:37:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>GitHub continues to be a scintillating target for attackers because it sits in the middle of the software supply chain and gives threat actors three things they crave: source code, secrets, and automated pipelines to run amok in.</p>



<p>Datadog Security Research has been tracking what it calls a “sustained pattern” of GitHub API abuse over the past several months that seeks to map organizations and their members. While individually these requests are “unremarkable,” they become dangerous when they move across environments for weeks at a time, and, worse, progress to full-out cloning. The biggest challenge is that they blend into normal API usage patterns.</p>



<p>GitHub has been a goldmine for criminals looking to breach organizations because many development lifecycles are insecure, said <a href="https://www.beauceronsecurity.com/blog/tag/David+Shipley" target="_blank" rel="noreferrer noopener">David Shipley</a> of Beauceron Security. Typically, threat actors are after API keys and cloud secrets.</p>



<p><br>“Now with everyone being pushed to do more, faster, with AI agents coding, the treasure trove of secrets is likely even bigger,” he said. “In short, to steal a line from a previous gold rush of the analog era, ‘there’s gold in them thar hills.'”</p>



<p><a href="https://www.linkedin.com/in/scottmiserendino" target="_blank" rel="noreferrer noopener">Scott Miserendino,</a> CTO at security and compliance company DataBee, agreed. “Github is the most popular source code repository for both open-source and enterprise projects,” he said. “Its sheer volume of projects, along with being home to some of the most popular and widely used software, make it a target.”</p>



<p>He noted that intellectual property theft such as the unauthorized cloning of private repositories can be used to gain use of proprietary software or find vulnerabilities that can be exploited.</p>



<p>A second popular attack involves searching for repositories containing default credentials to popular software. Using them, attackers may develop and test assaults on accounts that are present in production environments or come installed by default on certain appliances.</p>



<p>And, Datadog senior security engineer <a href="https://www.rsaconference.com/experts/julie-sparks" target="_blank" rel="noreferrer noopener">Julie Agnes Sparks</a> wrote in a <a href="https://securitylabs.datadoghq.com/articles/coordinated-github-api-enumeration/" target="_blank" rel="noreferrer noopener">blog post</a>, “the activity is not a single actor. Rather, it’s a blend of custom automated scanner tools, opportunistic abuse of leaked credentials, and coordinated networks of burner (ghost) accounts.”</p>



<h2 class="wp-block-heading">A simple but effective way to map GitHub users</h2>



<p>Sparks explained that a “large share” of GitHub’s API surface can be reached without authentication; it is public by design. Requests against APIs typically produce standard HTTP 200 responses.</p>



<p>This means a threat actor can build detailed maps of organizations, their public repositories, their members, who they follow, their starred repos, and projects they interact with. This traffic blends into normal API usage and thus does not seem suspicious, she said.</p>



<p>Furthermore, <a href="https://www.csoonline.com/article/4194448/github-ai-agent-leaks-private-repositories-via-prompt-injection-attack.html" target="_blank">GitHub</a> only collects geolocation data when a user interacts with private repositories, recording who they are and what access token they used, not when they interact with external resources. This limits geolocation and VPN/proxy-based attribution.</p>



<p>Typically, threat actors have performed automated scraping with custom or legitimate-sounding user agents, taking advantage of GitHub “ghost” accounts, profiles created anywhere from two to five years ago and left dormant.</p>



<p>This is an attractive method because, Sparks noted, “an account with a multi-year history reads as more legitimate than one registered the same week it starts scraping.”</p>



<p>Typically, these accounts are used for a “burst” of just one to three weeks across many enterprises at once, then usage stops. The researchers identified more than 50 ghost accounts across multiple user agents, clustered into families with names like <em>user432023</em>, <em>user412023</em>, or <em>kobalt*</em>.</p>



<p>Some campaigns did use the legitimate accounts of GitHub users who had inadvertently posted their OAuth tokens or personal access tokens (PATs), or have had their endpoints compromised or exposed in other ways.</p>



<p>Attackers use a mix of data exfiltration agents with names like <em>GitHub-Company-Scraper,</em> <em>GitHub-Scraper-Tool/1.0., </em>and<em> GitHubAnalytics/1.5</em>,designed to blend into normal data analysis traffic. The bulk of requests target the open source query language <em>/graphql</em>, which is “well suited” for bulk queries across enterprises, users, and repositories, Sparks noted. Normal REST endpoints are used for org-mapping.</p>



<p>The focus of the campaigns was “narrow and consistent,” and the concern “lies in the aggregate,” Sparks said. In isolation, requests target public repositories without authentication and return successful responses. This rarely produces “meaningful access” into an enterprise’s repositories. </p>



<p>But a group of accounts moving in sync across shared GitHub accounts with versioned, custom tooling over a period of weeks represents more troubling and systematic behavior. She cited one event in which dozens of distinct, legitimate, but compromised GitHub user accounts made API requests to a single organization within a window of only a few minutes, although in that case the attack failed, because they targeted private repository commit paths.</p>



<h2 class="wp-block-heading">How enterprises can protect their GitHub environments</h2>



<p>Sparks pointed out that these behaviors can be <a href="https://www.csoonline.com/article/3847510/rising-attack-exposure-threat-sophistication-spur-interest-in-detection-engineering.html" target="_blank">hunted for and detected</a> “if you are watching the right fields,” such as those identifying the user agent, token type, autonomous system number (ASN), or attempted action.</p>



<p>“User agents, event activity, and actor names are vital clues to unauthorized activity in your environment,” Sparks emphasized. She suggested reviewing unusual user agent behavior across GitHub audit logs, particularly for those that extend to private repositories where the platform also captures the IP address, actor name, and programmatic access type.</p>



<p>Enterprises should also enable GitHub audit log streaming, baseline user agents, and perform proactive threat hunting. Most importantly, she said, they should develop detections unique to their GitHub organization, noting, “It’s important to know what normal looks like in your environment.”</p>



<p>Simply put, added Miserendino, enterprises should be following security best practices, including enabling multi-factor authentication (MFA) on all accounts, performing periodic user access reviews, removing any unused or unneeded accounts, and scanning repositories for credentials stored in plaintext rather than in a secret store.</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4194627/githubs-public-apis-are-becoming-an-enterprise-reconnaissance-tool.html" target="_blank">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Paris Startup UMA Unveils Humanoid Robot for Europe’s Physical AI Push]]></title>
<description><![CDATA[Paris-based UMA unveiled its first humanoid robot design as Europe seeks a greater role in physical AI and industrial automation.]]></description>
<link>https://tsecurity.de/de/3655110/it-nachrichten/paris-startup-uma-unveils-humanoid-robot-for-europes-physical-ai-push/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655110/it-nachrichten/paris-startup-uma-unveils-humanoid-robot-for-europes-physical-ai-push/</guid>
<pubDate>Wed, 08 Jul 2026 20:02:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Paris-based UMA unveiled its first humanoid robot design as Europe seeks a greater role in physical AI and industrial automation.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic expands Claude Cowork to web and mobile as enterprise use broadens]]></title>
<description><![CDATA[Anthropic is bringing its Claude Cowork AI agent to web and mobile platforms, a move aimed at helping enterprise users monitor and manage long-running AI-driven tasks from anywhere as organizations increasingly adopt agents for operational and knowledge work.



The rollout, according to the comp...]]></description>
<link>https://tsecurity.de/de/3654335/ai-nachrichten/anthropic-expands-claude-cowork-to-web-and-mobile-as-enterprise-use-broadens/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654335/ai-nachrichten/anthropic-expands-claude-cowork-to-web-and-mobile-as-enterprise-use-broadens/</guid>
<pubDate>Wed, 08 Jul 2026 14:48:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Anthropic is bringing its Claude Cowork AI agent to web and mobile platforms, a move aimed at helping enterprise users monitor and manage long-running AI-driven tasks from anywhere as organizations increasingly adopt agents for operational and knowledge work.</p>



<p>The rollout, according to the company, is based on an analysis of 1.2 million anonymized and aggregated <a href="https://www.infoworld.com/article/4116598/anthropic-expands-claude-code-beyond-developer-tasks-with-cowork.html" target="_blank">Claude Cowork</a> sessions conducted between May 11 and May 31 that showed that business process and operations accounted for the largest share of the AI agent’s usage at 33.4%, followed by content creation and copywriting at 16.4%, the company wrote in a <a href="https://claude.com/blog/%20how-people-are-using-claude-cowork" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p>Software development represented only 8.7% of sessions, ahead of DevOps and infrastructure at 7%, along with research and intelligence at 6.4%, and data analysis and business intelligence (5.8%).</p>



<p>Cowork’s expansion, which is currently in beta, will allow users to start and manage Claude Cowork sessions directly from the Claude interface on the web and mobile, while enabling the AI agent to continue executing long-running tasks in the cloud, the company wrote in a separate <a href="https://claude.com/blog/cowork-web-mobile" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p>That cloud functionality would allow users to check progress, respond to approval requests, and resume conversations across devices without returning to their desktop, it added.</p>



<h2 class="wp-block-heading">More employee productivity</h2>



<p>For CIOs and their enterprises, Cowork’s expansion is likely to unlock productivity gains, according to <a href="https://www.linkedin.com/in/pareekhjain/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal at Pareekh Consulting.</p>



<p>“Teams can monitor long-running tasks, respond to exceptions, and keep business processes moving even when away from their desks, reducing operational delays, while also improving AI adoption,” Jain said.  </p>



<p>Beyond productivity gains, the expansion could reshape how CIOs staff and manage operational support functions, according to <a href="https://www.linkedin.com/in/bhupendrachopra/" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, chief revenue officer at IT consulting firm Kanerika.</p>



<p>“As AI agents take on routine knowledge work such as preparing reports, processing documents, and reconciling data, employees would increasingly shift from executing those tasks to supervising AI-generated outputs, reviewing exceptions, and applying business judgment. That would allow CIOs to redeploy knowledge workers toward higher-value activities while reducing the manual effort required across operational support teams,” Chopra said.</p>



<p>For developers, Cowork’s expansion will help shorten development cycles as it makes AI-assisted software engineering more continuous instead of being tied to a desktop IDE, Jain said.  </p>



<h2 class="wp-block-heading">Background agents bring governance challenges</h2>



<p>However, analysts cautioned that the rise and enterprise adoption of Claude Cowork-like tools, which represent a growing class of AI agents that operate in the background, executing long-running tasks with periodic human oversight, would also require CIOs to strengthen governance, security, and oversight.</p>



<p>“Always-on or persistent agents expand the attack surface because they continuously access enterprise systems and data. CIOs will need stronger identity controls, least-privilege permissions, audit trails, approval workflows, policy enforcement, and continuous monitoring to ensure these agents remain secure, compliant, and accountable,” Jain said.</p>



<p>Citing research from <a href="https://www.gravitee.io/blog/88-of-companies-have-already-seen-ai-agent-security-failures">Gravitee</a> that surveyed 445 IT and security leaders across multiple industries, Chopra pointed out that 88% of the surveyed leaders said that deploying AI agents reported confirmed or suspected security incidents over the past year, while only about 14% said their agents were deployed with full security and IT approval.</p>



<p>“The deployment velocity is dramatically outpacing governance. A background agent reading email, files, and calendars while the user is offline requires very precise scoping of what it can access and what it can act on,” Chopra said.</p>



<p>“Anthropic has kept human approval in the loop for consequential actions — that’s sensible product design. But enterprises need to build the same discipline on their side before they extend broad access to any agent,” Chopra added. </p>



<p>The web and mobile experience are currently available only for Max subscribers, Anthropic said, adding that support for Pro, Team, and Enterprise plans will follow in the coming weeks.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft bets that enterprise AI needs engineers, not bigger sales teams]]></title>
<description><![CDATA[The number of tech layoffs continues to tick upwards as AI investments increase, with Microsoft alone cutting around 4,800 employees, or roughly 2.1% of its workforce, this week.



The latest cutbacks are mostly in the company’s commercial sales and Xbox divisions. They follow two others in 2025...]]></description>
<link>https://tsecurity.de/de/3653518/it-nachrichten/microsoft-bets-that-enterprise-ai-needs-engineers-not-bigger-sales-teams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653518/it-nachrichten/microsoft-bets-that-enterprise-ai-needs-engineers-not-bigger-sales-teams/</guid>
<pubDate>Wed, 08 Jul 2026 09:18:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The number of tech layoffs continues to tick upwards as AI investments increase, with Microsoft alone cutting around 4,800 employees, or roughly 2.1% of its workforce, this week.</p>



<p>The latest cutbacks are mostly in the company’s commercial sales and Xbox divisions. They follow two others in 2025 that impacted around 15,000 workers, or roughly 4% of the company’s workforce. Prior to the latest cuts, Microsoft had 220,000-plus employees.</p>



<p>The headcount reduction also comes just days after the announcement of <a href="https://www.cio.com/article/4192504/microsoft-and-amazon-devote-billions-of-dollars-to-thousands-of-fdes.html" target="_blank">Microsoft Frontier Company</a>, an initiative that will provide embedded support for customers deploying AI projects, similar to traditional offerings from systems integrators (SIs).</p>



<p>Taken together, these moves seem to indicate that Microsoft is betting on its engineering expertise, rather than traditional account management, as the path to <a href="https://www.cio.com/article/411198/how-to-launch-your-ai-projects-from-pilot-to-production-and-ensure-success.html" target="_blank">AI success</a>.</p>



<p>“Microsoft had already reorganized its commercial business around AI,” said <a href="https://www.infotech.com/profiles/thomas-randall" target="_blank" rel="noreferrer noopener">Thomas Randall</a>, a research director at Info-Tech Research Group. “Recent layoffs are part of that ongoing context.”</p>



<h2 class="wp-block-heading">Microsoft’s memo to employees</h2>



<p>In a <a href="https://www.businessinsider.com/microsoft-jobs-cuts-across-sales-and-xbox-read-the-memo-2026-7" target="_blank" rel="noreferrer noopener">memo obtained by Business Insider</a>, Microsoft EVP and chief people officer Amy Coleman said the cuts effectively reflect the tectonic shift being brought about by AI.</p>



<p>“The ‘why’ is this: Our business is changing because the world around it is changing,” she said. “Companies don’t get to choose whether their industry changes; they only get to choose whether they change with it.”</p>



<p>Customer needs, and the business models that serve them, are shifting, meaning vendors must “adjust resources and roles” so they can operate in a way that best serves their customers. However, Coleman emphasized: “Whenever possible, our priority is to place people into new roles aligned to the company’s highest priorities and greatest areas of opportunity.”</p>



<p>Which, today, is AI.</p>



<p>Seemingly contradictorily, Coleman said the cuts “build on” the Frontier Company announcement, which is “reshaping how we work and embedding our engineering experts alongside customers so we can help them accelerate their technology deployments.”</p>



<p>While she emphasized that the roles eliminated this week are <a href="https://www.infoworld.com/article/4113574/forecast-ai-wont-replace-human-devs-for-at-least-5-years.html" target="_blank">not being replaced by AI</a>, the technology is fundamentally changing work. Many everyday tasks are being automated, meaning “we all need to keep learning, keep building new skills, and keep adapting as the work evolves.” </p>



<p>Customers are undergoing the same shift and are looking to Microsoft for guidance, she noted. “We can’t do that well unless we’re doing it ourselves.”</p>



<p>Finally, she said the tech giant will evolve structure and priorities across the company “thoughtfully.”</p>



<p>“We are working on alternative solutions to job eliminations and … we will continue to invest in equipping employees with new skills, including in AI.”</p>



<h2 class="wp-block-heading">What customers might expect</h2>



<p>Redmond isn’t the only big tech company taking scalpels to staff as the industry adjusts to, and seeks to capitalize on, AI. Companies are spending billions and inking strategic partnerships with top AI labs, and these investments in some cases need to be offset with cuts because some have yet to provide tangible ROI.</p>



<p>For instance, Amazon has laid off <a href="https://finance.yahoo.com/markets/stocks/articles/amazon-cutting-even-more-jobs-215000751.html?guccounter=1&amp;guce_referrer=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS8&amp;guce_referrer_sig=AQAAABApQepSEbQ_dc1TGRGI6UlyX5mFPpTY5zoGKqYKNDv3jt19X8whfI9ZKnzpE0RdmD4BMAlgVjxfGRT0IfHy34G8e78MqJIbW1QWvQb00AC9dor6nzVfTgWuv7bxYVZ3fEBKKwXi-cfiKOObM-csOMADd4byfnnAiiFfzJ8pa48f" target="_blank" rel="noreferrer noopener">30,000 workers</a> since last fall, while Google is rumored to be <a href="https://www.businessinsider.com/google-clouds-quiet-layoffs-hit-cybersecurity-teams-2026-6" target="_blank" rel="noreferrer noopener">cutting employees</a> in its cloud division. Meta, for its part, eliminated 8,000 employees, or about 10% of its total headcount, in May alone, while Oracle <a href="https://www.bbc.com/news/articles/c4gy0x0j5deo" target="_blank" rel="noreferrer noopener">recently slashed 21,000</a>.</p>



<p>For customers, there is a price to pay, however. In the case of Microsoft, Info-Tech’s Randall said that, with the cuts, some customers can now expect slower response times on “non-strategic asks,” particularly as accounts are consolidated under fewer reps.</p>



<p>That said, given its Frontier Company investments, top accounts with large AI, data, security, and cloud commitments may get “deeper technical engagement,” while ordinary licensing/support workflows may become leaner.</p>



<p>Further, customers can expect more hand-offs to partner-led engagements, given that Microsoft is already pushing customers toward its partners for FY27 (which began July 1, 2026) when it comes to AI, security, cloud modernization, Copilot, agents, and managed services, Randall said. The company is also offering partners higher margins for growth in certain AI workloads.</p>



<p>“To prepare for these shifts, customers should reflect and document their Microsoft account and support teams,” Randall advised.</p>



<p>By that he meant enumerating things like the support contacts, the partner contacts, and the escalation paths for issues. This information should be well-documented and shared internally, he said. The same goes for Microsoft-involved conversations having to do with any kind of commitment, such as those involve pricing assumptions, roadmap dependencies, or deployment milestones.</p>



<p>“This can ensure a smoother transition with a new account rep on what has already been set out for the organization,” Randall said.</p>



<h2 class="wp-block-heading">Closing the gap between AI investment and ROI</h2>



<p>Last week, Microsoft launched the $2.5 billion Frontier Company, which it said “goes beyond” SIs and Forward Deployed Engineers (FDE). The initiative will integrate thousands of the company’s own engineers directly into customer environments to help them build AI tools, and to also help customers learn essential skills so they can eventually handle projects on their own.</p>



<p>But customers shouldn’t think of this as what he described as “consulting-heavy, McKinsey-style engagements,” noted Info-Tech’s Randall. Pre-sales will likely become more focused on qualifying an organization’s specific processes for ongoing AI implementations, rather than on system-wide change management. As with other hyperscalers such as AWS, Microsoft is leaning into this more white-glove model to help “prevent the gap between AI investments and AI ROI from widening.”</p>



<p>“As such, Microsoft will likely reserve its best technical talent for accounts with strong production intent, credible budget, usable data, and clear executive sponsorship,” Randall predicted.</p>



<p><em>This article originally appeared on <a href="https://www.cio.com/article/4193510/microsoft-betting-that-enterprise-ai-needs-engineers-not-bigger-sales-teams.html" target="_blank">CIO.com</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Accenture Data Breach Exposes 35GB Source Code and Azure DevOps Credentials]]></title>
<description><![CDATA[Accenture is currently investigating a potential data breach after a threat actor using the alias “888” claimed to be selling approximately 35GB of stolen data, including source code and sensitive credentials, on a cybercrime forum. This listing, posted on July…
Read more →
The post Accenture Dat...]]></description>
<link>https://tsecurity.de/de/3653212/it-security-nachrichten/accenture-data-breach-exposes-35gb-source-code-and-azure-devops-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653212/it-security-nachrichten/accenture-data-breach-exposes-35gb-source-code-and-azure-devops-credentials/</guid>
<pubDate>Wed, 08 Jul 2026 06:24:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Accenture is currently investigating a potential data breach after a threat actor using the alias “888” claimed to be selling approximately 35GB of stolen data, including source code and sensitive credentials, on a cybercrime forum. This listing, posted on July…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/accenture-data-breach-exposes-35gb-source-code-and-azure-devops-credentials/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/accenture-data-breach-exposes-35gb-source-code-and-azure-devops-credentials/">Accenture Data Breach Exposes 35GB Source Code and Azure DevOps Credentials</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Accenture Data Breach Exposes 35GB Source Code and Azure DevOps Credentials]]></title>
<description><![CDATA[Accenture is currently investigating a potential data breach after a threat actor using the alias “888” claimed to be selling approximately 35GB of stolen data, including source code and sensitive credentials, on a cybercrime forum. This listing, posted on July 6, 2026, alleges that the breach re...]]></description>
<link>https://tsecurity.de/de/3653201/it-security-nachrichten/accenture-data-breach-exposes-35gb-source-code-and-azure-devops-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653201/it-security-nachrichten/accenture-data-breach-exposes-35gb-source-code-and-azure-devops-credentials/</guid>
<pubDate>Wed, 08 Jul 2026 06:07:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Accenture is currently investigating a potential data breach after a threat actor using the alias “888” claimed to be selling approximately 35GB of stolen data, including source code and sensitive credentials, on a cybercrime forum. This listing, posted on July 6, 2026, alleges that the breach resulted in the exfiltration of proprietary assets, including source […]</p>
<p>The post <a href="https://gbhackers.com/accenture-data-breach-exposes-35gb-source-code/">Accenture Data Breach Exposes 35GB Source Code and Azure DevOps Credentials</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-31991 | HCL DevOps Velocity up to 5.1.6 excessive authentication (KB0130138)]]></title>
<description><![CDATA[A vulnerability was found in HCL DevOps Velocity up to 5.1.6. It has been rated as problematic. Impacted is an unknown function. This manipulation causes improper restriction of excessive authentication attempts.

This vulnerability is registered as CVE-2025-31991. Remote exploitation of the atta...]]></description>
<link>https://tsecurity.de/de/3653185/sicherheitsluecken/cve-2025-31991-hcl-devops-velocity-up-to-516-excessive-authentication-kb0130138/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653185/sicherheitsluecken/cve-2025-31991-hcl-devops-velocity-up-to-516-excessive-authentication-kb0130138/</guid>
<pubDate>Wed, 08 Jul 2026 05:54:25 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/hcl:devops_velocity">HCL DevOps Velocity up to 5.1.6</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. Impacted is an unknown function. This manipulation causes improper restriction of excessive authentication attempts.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2025-31991">CVE-2025-31991</a>. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[Tucson, Ariz., Seeks AI Agent to Support Service Delivery]]></title>
<description><![CDATA[In the city’s first venture into agentic AI solutions, officials are looking for a vendor to help create an AI agent to support service delivery for residents. It will function as a chatbot and agent.]]></description>
<link>https://tsecurity.de/de/3652802/ai-nachrichten/tucson-ariz-seeks-ai-agent-to-support-service-delivery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652802/ai-nachrichten/tucson-ariz-seeks-ai-agent-to-support-service-delivery/</guid>
<pubDate>Tue, 07 Jul 2026 23:32:52 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In the city’s first venture into agentic AI solutions, officials are looking for a vendor to help create an AI agent to support service delivery for residents. It will function as a chatbot and agent.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic brings Claude Cowork to mobile and web as usage data shows most users aren’t coding]]></title>
<description><![CDATA[Anthropic on Tuesday launched Claude Cowork on mobile and web, expanding a tool that has quietly become the company's bridge between the developer-centric world of AI coding agents and the far larger market of knowledge workers who never open a terminal.The rollout, which begins in beta with Max ...]]></description>
<link>https://tsecurity.de/de/3652421/it-nachrichten/anthropic-brings-claude-cowork-to-mobile-and-web-as-usage-data-shows-most-users-arent-coding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652421/it-nachrichten/anthropic-brings-claude-cowork-to-mobile-and-web-as-usage-data-shows-most-users-arent-coding/</guid>
<pubDate>Tue, 07 Jul 2026 20:03:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.anthropic.com/">Anthropic</a> on Tuesday launched <a href="https://claude.com/blog/cowork-web-mobile/">Claude Cowork on mobile and web</a>, expanding a tool that has quietly become the company's bridge between the developer-centric world of AI coding agents and the far larger market of knowledge workers who never open a terminal.</p><p>The rollout, which begins in beta with <a href="https://support.claude.com/en/articles/11049741-what-is-the-max-plan">Max subscribers</a> before expanding to additional plans, marks a strategic inflection for Anthropic. It transforms Cowork from a desktop-only agent into a cross-device platform where tasks can start on a laptop, continue autonomously in the background, and be reviewed from a phone — even after the user closes the app entirely.</p><p>"Your work goes everywhere with you, and keeps going without you," Anthropic writes in its announcement.</p><p>The timing is deliberate. Alongside the mobile launch, Anthropic published usage data from 1.2 million anonymized Claude Cowork sessions sampled between May 11 and May 31, drawn from more than 600,000 organizations. The data paints a striking picture: the overwhelming majority of what people do with Cowork has nothing to do with writing software.</p><div></div><h2><b>The biggest AI story nobody's talking about</b></h2><p>The numbers tell a story that cuts against the dominant narrative in enterprise AI, which has fixated on coding assistants and developer productivity as the primary use case for large language models.</p><p>Business process and operations — tasks like pulling scattered updates into a single report, building onboarding checklists, and reconciling spreadsheets — accounted for 33.4% of all sampled Cowork sessions, making it the single largest category by a wide margin. Content creation and copywriting — producing drafts, slide decks, posts, and proposals — came in second at 16.4%.</p><p>Together, those two categories make up roughly half of all Claude Cowork usage. Software development, by contrast, accounted for just 8.7%. DevOps and infrastructure followed at 7%, with research and intelligence at 6.4%, data analysis and business intelligence at 5.8%, document processing and extraction at 4.1%, and sales and revenue operations at 4%.</p><p>The remaining 12 categories each represented less than 4% of usage, including personal assistance at 3.8%, education at 2.4%, and meeting intelligence at 1.8%.</p><p>Anthropic describes these dominant use cases as "the work around the work" — tasks that span nearly every role in an organization but rarely appear in anyone's core job description. "People are using it for a variety of tasks that aren't necessarily the hallmark of a specific role, but instead represent the connective work around a role that moves projects forward and keeps businesses running," the company writes. "That means tasks like drafting a status update, building a slide deck, or condensing reams of research into a single report."</p><p>That phrase — "the work around the work" — is Anthropic's attempt to define and claim an entirely new category of AI productivity. It's a calculated reframing: rather than positioning AI as a tool that replaces what professionals do, Anthropic is arguing that the most valuable current application is handling everything professionals do around their actual expertise.</p><h2><b>What mobile access changes — and what it doesn't</b></h2><p>The <a href="https://claude.com/blog/cowork-web-mobile/">expansion to mobile and web</a> introduces three concrete capabilities that reflect how Anthropic envisions Cowork fitting into daily workflows.</p><p>First, sessions now sync across devices. A user can start a task at their desk, check on its progress from a phone, and retrieve the finished output from any device. Second — and arguably more significant — Cowork can now run tasks in the background with no device online at all. Users can schedule work for a specific time, and Claude will execute it autonomously. Anthropic offers the example of setting Monday morning client prep for 6 a.m.: "Claude works through the email threads, transcripts, and recent news, builds the briefing doc, and leaves the follow-up email drafted but unsent. Review it over coffee."</p><p>Third, when Claude encounters a decision that requires human judgment, it surfaces the question to the user's phone. "Nothing ships until you've reviewed and approved it," Anthropic states.</p><p>Desktop remains the most fully featured surface, with access to local files and the browser. But the web version also opens Cowork to users who cannot install a desktop application — a meaningful expansion in enterprise environments where IT departments control software installation.</p><p>The company also unified its interface: on web and desktop, chat and Cowork now share a single home screen, and projects and artifacts persist across both modes.</p><p>To encourage adoption, Anthropic is extending doubled Cowork usage limits through August 5.</p><h2><b>The strategic logic: why Anthropic is chasing the non-developer</b></h2><p>The usage data and the mobile launch together reveal a company executing a two-track strategy. <a href="https://www.anthropic.com/product/claude-code">Claude Code</a>, its terminal-based coding agent, dominates among software developers. But Cowork is designed to capture the vastly larger population of professionals whose work involves creating, organizing, and communicating information rather than writing code.</p><p>The contrast between the two products is instructive. As Anthropic notes, Claude Code "is most often used by software developers for the key parts of their role: building, debugging, and shipping code." When developers do use <a href="https://www.anthropic.com/product/claude-cowork">Cowork</a>, they tend to use it not for programming but for the communications-focused work that surrounds every role — status updates, documentation, and coordination.</p><p>This pattern — where AI handles the connective tissue of work rather than its core substance — aligns with what Anthropic describes as people using "Claude Cowork to assemble and structure the information they can use to act on their expertise." The company illustrates this with three examples: a lawyer using Cowork for document formatting and filing while reserving legal judgment for themselves, a hiring manager synthesizing interview feedback while spending more time on candidate conversations, and a team lead producing a slide deck that explains a decision while focusing on actually making that decision.</p><p>The implications for Anthropic's business model are significant. Developer-focused tools, while high-profile, serve a relatively narrow market. The <a href="https://ramp.com/data/ai-index">Ramp AI Index</a> published in May showed Anthropic pulling ahead of OpenAI in business adoption for the first time — with 34.4% of firms paying for Anthropic's services compared to OpenAI's 32.3% — and suggests the company's enterprise push is gaining traction. Claude Code was identified as the primary driver of that shift. But Cowork targets an addressable market that is orders of magnitude larger: every knowledge worker with a laptop, a pile of spreadsheets, and a slide deck due by Friday.</p><h2><b>A crowded field gets more competitive</b></h2><p>The mobile launch arrives during one of Anthropic's busiest — and most turbulent — stretches in its history. </p><p>Just last week, Anthropic launched <a href="https://www.anthropic.com/news/claude-sonnet-5">Claude Sonnet 5</a>, a new model that narrows the performance gap with its more expensive Opus-class models while maintaining lower pricing. The model is available at introductory pricing of $2 per million input tokens through August 31 before rising to $3 per million input tokens. Sonnet 5 serves as the engine underneath Cowork, and its improved agentic capabilities — better reasoning, tool use, and sustained task completion — directly enhance Cowork's ability to handle complex, multi-step workflows.</p><p>Two weeks before that, Anthropic released <a href="https://venturebeat.com/technology/anthropic-launches-claude-tag-replacing-its-slack-app-with-a-persistent-ai-teammate-that-learns-monitors-and-works-autonomously">Claude Tag</a>, a Slack-native AI agent designed for team collaboration. Where Cowork focuses on individual task delegation, Claude Tag operates as a multiplayer tool — a single Claude identity that everyone in a Slack channel can interact with, building context from conversations over time. </p><p>According to Anthropic's announcement, 65% of the company's own product team's code is created by its internal version of Claude Tag. <a href="https://fortune.com/2026/06/23/anthropic-claude-tag-virtual-employee-tool-slack/">Fortune reported</a> that Anthropic's head of product for Claude Code and Cowork, Cat Wu, described the distinction: "Claude Code, Cowork, and chat are very single-player, whereas Claude Tag is built to be interactive and multiplayer."</p><p>Together, <a href="https://www.anthropic.com/product/claude-cowork">Cowork</a> and <a href="https://www.anthropic.com/news/introducing-claude-tag">Claude Tag</a> represent a pincer strategy: Cowork captures individual productivity workflows across devices, while Claude Tag embeds AI into team communication channels. Both are designed to push Anthropic deeper into enterprise operations, beyond the developer seat.</p><h2><b>The security question looms</b></h2><p>The expansion also arrives against a backdrop of unresolved security concerns. On July 1, security firm Armadin — led by Mandiant founder Kevin Mandia — published research detailing what it described as a full sandbox escape in Claude Cowork on Windows, as reported by <a href="https://siliconangle.com/2026/07/01/armadin-details-full-sandbox-escape-claude-cowork-anthropic-disputes-risk/">SiliconANGLE</a>. The attack chain involved DLL sideloading against the Claude desktop executable to gain trusted access to Cowork's virtual machine service, then exploiting undocumented parameters to achieve root access and bypass network restrictions.</p><p>Anthropic responded that the vulnerability did not qualify as a security issue because exploiting it requires an attacker to already have local code execution on the host machine. Armadin, however, raised a broader concern: that deploying local virtual machines on nontechnical users' systems creates visibility gaps that endpoint security products struggle to monitor.</p><p>This tension takes on new dimensions as Cowork moves to mobile and web. The web and mobile versions run tasks server-side rather than in a local virtual machine, which eliminates the specific attack surface Armadin identified but introduces different questions about data handling, especially for scheduled background tasks that process email threads, calendar data, and documents without real-time user oversight.</p><p>Anthropic's announcement states that "<a href="https://claude.com/blog/cowork-web-mobile/">the decisions still come to you</a>" and that nothing ships without review and approval. But as Cowork takes on increasingly complex autonomous workflows — processing contract folders, building client briefings from multiple data sources, drafting emails — the surface area for prompt injection and data exposure grows correspondingly. </p><p>When Cowork first launched in January, TechCrunch reported that Anthropic <a href="https://techcrunch.com/2026/01/12/anthropics-new-cowork-tool-offers-claude-code-without-the-code/">explicitly warned</a> about prompt injection risks, noting in its blog post: "These risks aren't new with Cowork, but it might be the first time you're using a more advanced tool that moves beyond a simple conversation."</p><h2><b>As Anthropic courts enterprises, geopolitics complicates the pitch</b></h2><p>Anthropic's enterprise push is also colliding with geopolitical reality. CNBC reported Monday that <a href="https://www.cnbc.com/2026/07/06/alibaba-anthropic-ai-ban-claude-china.html#:~:text=Alibaba%20will%20ban%20employees%20from%20using%20Anthropic%20's%20artificial%20intelligence,risks%2C%20CNBC%20confirmed%20on%20Monday.">Alibaba will ban employees from using Anthropic's AI tools</a> starting July 10, placing Claude Code on a high-risk software list. The move followed Anthropic's June letter to the U.S. Senate accusing Alibaba of carrying out what it called "<a href="https://www.reuters.com/world/china/anthropic-says-alibaba-illicitly-extracted-claude-ai-model-capabilities-2026-06-24/">the largest known distillation attack</a>" against its models.</p><p>The Alibaba ban, combined with reports that Anthropic is closing loopholes that allowed Chinese companies to access Claude through third-country entities, underscores the increasingly fraught environment for AI companies attempting to serve global enterprise customers while navigating U.S. export and security restrictions.</p><p>At the same time, Anthropic is investing massively in infrastructure. Reuters reported Monday that <a href="https://www.reuters.com/business/terawulf-jumps-19-billion-data-center-lease-deal-with-anthropic-2026-07-06/">Anthropic signed a $19 billion, 20-year lease with TeraWulf for a data center</a> being built in Hawesville, Kentucky, with 401 megawatts of computing power expected to become fully operational in 2028.</p><p>That kind of capital commitment only makes sense if the company expects enterprise demand — not just from developers, but from the millions of knowledge workers that Cowork targets — to grow dramatically.</p><h2><b>Anthropic's own usage report comes with notable blind spots</b></h2><p>Anthropic is transparent about the limitations of its usage analysis. The taxonomy classifies sessions by the type of work being performed, not by the job title of the person doing it. </p><p>There are no standalone categories for marketing, finance, or HR — functions that are likely absorbed into the dominant "business process and operations" bucket, which may partly explain why that category commands a third of all usage.</p><p>The sample is also rate-capped rather than proportional to traffic, meaning the numbers are shares of sampled sessions, not absolute volumes. Usage during peak hours is somewhat underrepresented. And roughly 5% of sampled sessions involved personal, non-work use — hobbies, personal assistance, and companionship-style conversations — meaning the data doesn't purely reflect workplace activity.</p><p>The company also acknowledged that its labeling pipeline changed around May 11, which is why the analysis window begins on that date rather than covering a longer period.</p><h2><b>What Cowork's rise says about the future of enterprise AI</b></h2><p>Anthropic's <a href="https://claude.com/blog/cowork-web-mobile/">mobile launch</a> and usage data arrive at a moment when the enterprise AI market is shifting from proof of concept to proof of value. The question facing every company deploying AI tools is no longer whether the technology works — but whether it delivers measurable productivity gains across an organization, not just within engineering teams.</p><p>The usage data suggests that the answer, at least for Cowork, is emerging in an unexpected place. It's not in the glamorous work of building software or conducting research. It's in the unglamorous, universal labor of turning messy information into structured outputs that move organizations forward — the status reports, the onboarding checklists, the variance memos, the client decks.</p><p>By untethering that capability from the desktop and making it available on every device, Anthropic is betting that the most valuable AI agent isn't the one that writes code. It's the one that handles everything else.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple intros permission popup for AI features sending data to Google Cloud in iOS 27 and iOS 26]]></title>
<description><![CDATA[Apple is enhancing transparency by adding a new user permission popup that notifies and seeks consent before sending data to Google Cloud…
The post Apple intros permission popup for AI features sending data to Google Cloud in iOS 27 and iOS 26 appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3652213/ios-mac-os/apple-intros-permission-popup-for-ai-features-sending-data-to-google-cloud-in-ios-27-and-ios-26/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652213/ios-mac-os/apple-intros-permission-popup-for-ai-features-sending-data-to-google-cloud-in-ios-27-and-ios-26/</guid>
<pubDate>Tue, 07 Jul 2026 18:40:02 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple is enhancing transparency by adding a new user permission popup that notifies and seeks consent before sending data to Google Cloud…</p>
<p>The post <a href="https://macdailynews.com/2026/07/07/apple-intros-permission-popup-for-ai-features-sending-data-to-google-cloud-in-ios-27-and-ios-26/">Apple intros permission popup for AI features sending data to Google Cloud in iOS 27 and iOS 26</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chicago software company plants flag in Seattle area as new leadership team seeks AI talent]]></title>
<description><![CDATA[Governance, risk and compliance software company LogicGate recently signed a lease in Bellevue with space for up to 25 employees and expects to have about 20 people working there by the end of the year. Read More]]></description>
<link>https://tsecurity.de/de/3651993/it-nachrichten/chicago-software-company-plants-flag-in-seattle-area-as-new-leadership-team-seeks-ai-talent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651993/it-nachrichten/chicago-software-company-plants-flag-in-seattle-area-as-new-leadership-team-seeks-ai-talent/</guid>
<pubDate>Tue, 07 Jul 2026 17:18:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="400" height="400" src="https://cdn.geekwire.com/wp-content/uploads/2026/05/Diego-Panama.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/05/Diego-Panama.jpg 400w, https://cdn.geekwire.com/wp-content/uploads/2026/05/Diego-Panama-300x300.jpg 300w, https://cdn.geekwire.com/wp-content/uploads/2026/05/Diego-Panama-150x150.jpg 150w, https://cdn.geekwire.com/wp-content/uploads/2026/05/Diego-Panama-100x100.jpg 100w, https://cdn.geekwire.com/wp-content/uploads/2026/05/Diego-Panama-200x200.jpg 200w" sizes="(max-width: 400px) 100vw, 400px"><br>Governance, risk and compliance software company LogicGate recently signed a lease in Bellevue with space for up to 25 employees and expects to have about 20 people working there by the end of the year. <a href="https://www.geekwire.com/2026/chicago-software-company-plants-flag-in-seattle-area-as-new-leadership-team-seeks-ai-talent/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Five tips for developing data products]]></title>
<description><![CDATA[Data products help standardize how raw data sets, data warehouse views, and data lake logical views are combined and used to deliver analytics and AI capabilities. By developing data products, teams can streamline much of the upfront data pipelines, governance, and management needed to deliver tr...]]></description>
<link>https://tsecurity.de/de/3650966/ai-nachrichten/five-tips-for-developing-data-products/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650966/ai-nachrichten/five-tips-for-developing-data-products/</guid>
<pubDate>Tue, 07 Jul 2026 11:04:19 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Data products help standardize how raw data sets, data warehouse views, and <a href="https://www.infoworld.com/article/2335103/what-is-a-data-lake-massively-scalable-storage-for-big-data-analytics.html">data lake</a> logical views are combined and used to deliver analytics and AI capabilities. By developing data products, teams can streamline much of the upfront <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">data pipelines</a>, <a href="https://www.infoworld.com/article/3956251/measuring-success-in-dataops-data-governance-and-data-security.html">governance</a>, and <a href="https://drive.starcio.com/2025/06/data-management-cios-genai-era/">management</a> needed to deliver trusted data assets that people, tools, and AI can then use for different purposes.</p>



<p>The way you cook a meal can serve as a helpful analogy. You can choose to purchase only raw ingredients like tomatoes, wheat flour, eggs, and fresh herbs to make a favorite pasta dish. The approach works well when you have the time and skills to cook from scratch or want to prepare a nice meal for a small family. Otherwise, you may want to buy canned tomatoes, your favorite box of pasta, and a spice mix to cook the same meal, especially if you are time-constrained, are cooking for many people, or want a consistent finished product.  </p>



<p>Like the not-from-scratch pasta meal, data products provide a similar level of time-saving effort, so that analytics and AI capabilities start with consistent, streamlined ingredients. Here are five questions teams should consider as they develop data products and their standards.</p>



<h2 class="wp-block-heading">When to build a data product?</h2>



<p>Most organizations can’t afford to develop data products as intermediaries for every data visualization, machine learning model, or <a href="https://www.infoworld.com/article/4105884/10-essential-release-criteria-for-launching-ai-agents.html">AI agent</a>. There’s cost and time to develop data products, and once they’re deployed or “on the shelves,” their <a href="https://www.infoworld.com/article/3479075/5-things-great-data-science-product-managers-do.html">product managers</a> must oversee their ongoing support and life-cycle management. So when should <a href="https://drive.starcio.com/2020/08/data-science-dataops-agile/">agile data teams</a> develop data products, and how should they prioritize which ones are more important? One starting point is to consider data products built from a single data set and what it means to productize them.</p>



<p>“A data set should really become a data product when multiple teams start relying on it to make decisions or to power applications,” says Danielle Ben-Gera, vice president of engineering at <a href="https://www.crunchbase.com/">Crunchbase</a>. “Developing proper governance, clear ownership, versioning, and a managed life cycle for changes becomes important, or you’ll just be shipping fragile pipelines that break downstream work.”</p>



<p>A second consideration is treating the use of ungoverned data sets as a form of <a href="https://www.infoworld.com/article/3691789/6-ways-to-avoid-and-reduce-data-debt.html">data debt</a>. Establishing a data product can be a tactical approach to standardize usage and address risks.</p>



<p>“Organizations should build a data product when data sets are being used across teams without strong governance, well-defined processes, or clear ownership,” says Yaad Oren, managing director at SAP Labs US and global head of research and innovation at <a href="https://www.sap.com/index.html">SAP</a>. “When anchored in a unified data foundation, data products eliminate silos, create shared understanding, and establish secure, standardized access that enables teams to leverage the same assets with confidence.”</p>



<p>A third consideration is to apply manufacturing principles by building data products for defined customers, driving reuse, and creating efficiencies. Drafting the data product’s vision statement and <a href="https://drive.starcio.com/2026/02/why-chaotic-ai-experiments-arent-producing-business-value/">qualifying its business value</a> is particularly important when a data product requires combining multiple data sources. It raises the question of how standardization delivers efficiencies, improves quality, reduces data security risks, and provides other benefits.</p>



<p>Christopher Zangrilli, vice president of technology strategy at <a href="https://www.vertexinc.com/">Vertex</a>, says, “Leaders should ask whether the data will reduce cycle time, improve decision accuracy, or mitigate compliance risk as a lens on the business impact. When governance, change management for adoption, quality, and value measurement are embedded from the start, data products transform from experimental tools to strategic assets.”</p>



<h2 class="wp-block-heading">Why define standards for data products?</h2>



<p>The products at the grocery store have packaging with a detailed list of ingredients, an expiration date, and a price. Data governance leaders should also standardize how data products are defined, cataloged, and managed. </p>



<p>“Any modern data product should answer four questions clearly: where the data originates, how it transforms across systems, who or what is consuming it, and what governance obligations apply at every step,” says Abhi Sharma, cofounder and CEO at <a href="https://www.relyance.ai/">Relyance AI</a>. “Without that end-to-end context, teams are building features on top of data they don’t fully understand.”</p>



<p>Although food products publish their ingredients and label them for dietary restrictions, few document the sourcing of raw ingredients and the logistics of the path from farm to grocer. But when building data products, <a href="https://www.infoworld.com/article/3613592/data-lineage-what-it-is-and-why-its-important.html">capturing data lineage</a> may be required in regulated industries and is particularly important when standardizing data sources for AI applications. </p>



<p>“Without lineage, teams operate blind, and governance becomes reactive cleanup,” says Carter Page, executive vice president of research and development at <a href="https://www.astronomer.io/">Astronomer</a>. “When teams can see where data originated, how it was transformed, and every system that relies on it, updates become predictable, the right pipelines get tested, the target stakeholders are notified, and breaking changes are documented before they cause incidents.”</p>



<h2 class="wp-block-heading">What is a data product’s life cycle?</h2>



<p>Life-cycle management of an API, application, or AI model requires defining a release schedule for delivering improvements, fixes, and other required upgrades. Data product life-cycle management involves several similar disciplines. Ulf Viney, executive vice president of engineering, support, and operations at <a href="https://www.precisely.com/">Precisely</a>, says, “Life-cycle management must include versioning, testing, structured deployment, and stakeholder communication.”</p>



<p>One fundamental difference with data products is that their life-cycle management is closely linked to how their underlying data sets grow or undergo structural changes. Having a data product that works today but isn’t resilient to changes or doesn’t generate alerts when fixes are necessary can break downstream use cases and erode stakeholders’ and users’ trust in the data.     </p>



<p>“Managing data as a product means that data consumers can trust the data from the outset, which requires a sustainable and scalable governance framework that ensures data is easy to find, understand, and use,” says Bethany Sehon, senior director of enterprise data at <a href="https://www.capitalone.com/tech/">Capital One</a>. “By embedding observability, quality checks, and interoperability from day one, you can manage the full data life cycle from versioning and testing to measuring adoption and performance.”</p>



<p>Teams managing mission-critical, real-time data products that feed multiple downstream analytics and AI use cases should consider the following devops and data governance practices.</p>



<ul class="wp-block-list">
<li>Establish <a href="https://drive.starcio.com/2024/10/6-important-ai-and-data-governance-non-negotiables/">data governance non-negotiables</a>, especially on setting data quality benchmarks, qualifying any data biases, and adhering to <a href="https://drive.starcio.com/2026/02/data-privacy-week-leadership-accountability/">data privacy policies</a>.</li>



<li>Support <a href="https://www.infoworld.com/article/2337516/advanced-cicd-6-steps-to-better-cicd-pipelines.html">advanced continuous integration/continuous delivery (CI/CD</a>) and <a href="https://www.infoworld.com/article/3663055/are-you-ready-to-automate-continuous-deployment-in-cicd.html">continuous deployment</a>, with <a href="https://www.infoworld.com/article/3705049/3-ways-to-upgrade-continuous-testing-for-generative-ai.html">continuous testing</a> and production deployments fully automated.</li>



<li>Ensure all data integrations have <a href="https://www.infoworld.com/article/3687135/why-observability-in-dataops.html">observable dataops</a> with monitoring for data quality issues and alerting when pipelines stop running. IT services should be defined to address requests and incidents. </li>



<li>Align with data management technology platform strategies, including <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">data fabrics</a>, <a href="https://www.infoworld.com/article/3826186/3-reasons-to-consider-a-data-security-posture-management-platform.html">data security posture management</a> (DSPM), <a href="https://www.infoworld.com/article/3833936/why-genai-powered-intelligent-document-processing-is-a-big-deal.html">document processing</a>, and <a href="https://www.infoworld.com/article/3709912/vector-databases-in-llms-and-search.html">vector databases</a>.</li>
</ul>



<h2 class="wp-block-heading">How to encourage adoption?</h2>



<p>Unfortunately, building a data product doesn’t guarantee adoption. Think back to the challenges of getting code reuse, API adoption, or standardizing in-house-developed devops tools. These are all examples of intermediary products aimed at reducing developer toil and improving quality, yet many teams adopted “not-invented-here” postures and do-it-yourself practices rather than learning and adopting standards developed by other teams.</p>



<p>Data products face even greater challenges, especially when they aim to consolidate data silos or eliminate spreadsheets. Product managers overseeing data products must develop a <a href="https://blogs.starcio.com/2024/02/change-management-digital-transformation.html">change management program</a> to grow adoption and gather feedback.</p>



<p>“A data product earns its place when it drives a real business decision and can be trusted at scale,” says Quais Taraki, CTO at <a href="https://www.enterprisedb.com/">EnterpriseDB</a>. “Treat data products like software, with versioning, testing, and controlled releases, not one-off pipelines. That discipline securely delivers the right data to the right place and turns data into measurable value through adoption, speed, and risk reduction.”</p>



<p>Product managers can accelerate adoption by communicating how a data product aligns with the business’s AI strategy and culture transformation. For example, show how the data product improves AI literacy, <a href="https://www.cio.com/article/4136302/how-to-get-ai-democratization-right.html">democratizes AI</a> through the right business use cases, or<a href="https://www.cio.com/article/4082282/preparing-your-workforce-for-ai-agents-a-change-management-guide.html"> prepares the workforce to use AI agents</a>.</p>



<h2 class="wp-block-heading">How to measure business value?</h2>



<p>The value delivered by a customer-facing product is often measured through revenue impact, usage metrics, and customer satisfaction (CSat). Internal, employee-facing products can be measured in terms of workflow efficiency, productivity improvement, and employee satisfaction (ESat). Data products are intermediaries, so quantifying their value can be more challenging.   </p>



<p>“Too many organizations still treat data products as technical outputs instead of strategic assets,” says Daniel Ziv, global vice president of AI and analytics at <a href="https://www.verint.com/">Verint</a>. “Their true value becomes clear when assessing how uniquely the data is generated, how much measurable impact it can drive across decisions, and how you can safely extract insight while managing risk. When every organization has access to the same AI models, competitive advantage comes from your unique data and how quickly you turn it into action.”</p>



<p>Sunil Kalra, head of the Databricks center of excellence at <a href="https://www.latentview.com/">LatentView Analytics</a>, adds, “Value should be measured through adoption, usage, and outcomes such as faster insights, reduced manual work, and improved revenue or cost performance.”</p>



<p>A best practice is to use <a href="https://www.cio.com/article/1296705/digital-kpis-the-secret-to-measuring-transformational-success.html">digital transformation velocity metrics</a> such as time to data, time to decision, time to innovation, and time to value. As more organizations seek to deliver business value from AI agents, creating data products will be seen as a path to accelerate delivery, reuse data assets, reduce risks, and manage costs.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft betting that enterprise AI needs engineers, not bigger sales teams]]></title>
<description><![CDATA[The number of tech layoffs continues to tick upwards as AI investments increase, with Microsoft alone cutting around 4,800 employees, or roughly 2.1% of its workforce, this week.



The latest cutbacks are mostly in the company’s commercial sales and Xbox divisions. They follow two others in 2025...]]></description>
<link>https://tsecurity.de/de/3650292/it-nachrichten/microsoft-betting-that-enterprise-ai-needs-engineers-not-bigger-sales-teams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650292/it-nachrichten/microsoft-betting-that-enterprise-ai-needs-engineers-not-bigger-sales-teams/</guid>
<pubDate>Tue, 07 Jul 2026 04:18:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The number of tech layoffs continues to tick upwards as AI investments increase, with Microsoft alone cutting around 4,800 employees, or roughly 2.1% of its workforce, this week.</p>



<p>The latest cutbacks are mostly in the company’s commercial sales and Xbox divisions. They follow two others in 2025 that impacted around 15,000 workers, or roughly 4% of the company’s workforce. Prior to the latest cuts, Microsoft had 220,000-plus employees.</p>



<p>The headcount reduction also comes just days after the announcement of <a href="https://www.cio.com/article/4192504/microsoft-and-amazon-devote-billions-of-dollars-to-thousands-of-fdes.html" target="_blank">Microsoft Frontier Company</a>, an initiative that will provide embedded support for customers deploying AI projects, similar to traditional offerings from systems integrators (SIs).</p>



<p>Taken together, these moves seem to indicate that Microsoft is betting on its engineering expertise, rather than traditional account management, as the path to <a href="https://www.cio.com/article/411198/how-to-launch-your-ai-projects-from-pilot-to-production-and-ensure-success.html" target="_blank">AI success</a>.</p>



<p>“Microsoft had already reorganized its commercial business around AI,” said <a href="https://www.infotech.com/profiles/thomas-randall" target="_blank" rel="nofollow">Thomas Randall</a>, a research director at Info-Tech Research Group. “Recent layoffs are part of that ongoing context.”</p>



<h2 class="wp-block-heading">Microsoft’s memo to employees</h2>



<p>In a <a href="https://www.businessinsider.com/microsoft-jobs-cuts-across-sales-and-xbox-read-the-memo-2026-7" target="_blank" rel="nofollow">memo obtained by Business Insider</a>, Microsoft EVP and chief people officer Amy Coleman said the cuts effectively reflect the tectonic shift being brought about by AI.</p>



<p>“The ‘why’ is this: Our business is changing because the world around it is changing,” she said. “Companies don’t get to choose whether their industry changes; they only get to choose whether they change with it.”</p>



<p>Customer needs, and the business models that serve them, are shifting, meaning vendors must “adjust resources and roles” so they can operate in a way that best serves their customers. However, Coleman emphasized: “Whenever possible, our priority is to place people into new roles aligned to the company’s highest priorities and greatest areas of opportunity.”</p>



<p>Which, today, is AI.</p>



<p>Seemingly contradictorily, Coleman said the cuts “build on” the Frontier Company announcement, which is “reshaping how we work and embedding our engineering experts alongside customers so we can help them accelerate their technology deployments.”</p>



<p>While she emphasized that the roles eliminated this week are <a href="https://www.infoworld.com/article/4113574/forecast-ai-wont-replace-human-devs-for-at-least-5-years.html" target="_blank">not being replaced by AI</a>, the technology is fundamentally changing work. Many everyday tasks are being automated, meaning “we all need to keep learning, keep building new skills, and keep adapting as the work evolves.” </p>



<p>Customers are undergoing the same shift and are looking to Microsoft for guidance, she noted. “We can’t do that well unless we’re doing it ourselves.”</p>



<p>Finally, she said the tech giant will evolve structure and priorities across the company “thoughtfully.”</p>



<p>“We are working on alternative solutions to job eliminations and … we will continue to invest in equipping employees with new skills, including in AI.”</p>



<h2 class="wp-block-heading">What customers might expect</h2>



<p>Redmond isn’t the only big tech company taking scalpels to staff as the industry adjusts to, and seeks to capitalize on, AI. Companies are spending billions and inking strategic partnerships with top AI labs, and these investments in some cases need to be offset with cuts because some have yet to provide tangible ROI.</p>



<p>For instance, Amazon has laid off <a href="https://finance.yahoo.com/markets/stocks/articles/amazon-cutting-even-more-jobs-215000751.html?guccounter=1&amp;guce_referrer=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS8&amp;guce_referrer_sig=AQAAABApQepSEbQ_dc1TGRGI6UlyX5mFPpTY5zoGKqYKNDv3jt19X8whfI9ZKnzpE0RdmD4BMAlgVjxfGRT0IfHy34G8e78MqJIbW1QWvQb00AC9dor6nzVfTgWuv7bxYVZ3fEBKKwXi-cfiKOObM-csOMADd4byfnnAiiFfzJ8pa48f" target="_blank" rel="nofollow">30,000 workers</a> since last fall, while Google is rumored to be <a href="https://www.businessinsider.com/google-clouds-quiet-layoffs-hit-cybersecurity-teams-2026-6" target="_blank" rel="nofollow">cutting employees</a> in its cloud division. Meta, for its part, eliminated 8,000 employees, or about 10% of its total headcount, in May alone, while Oracle <a href="https://www.bbc.com/news/articles/c4gy0x0j5deo" target="_blank" rel="nofollow">recently slashed 21,000</a>.</p>



<p>For customers, there is a price to pay, however. In the case of Microsoft, Info-Tech’s Randall said that, with the cuts, some customers can now expect slower response times on “non-strategic asks,” particularly as accounts are consolidated under fewer reps.</p>



<p>That said, given its Frontier Company investments, top accounts with large AI, data, security, and cloud commitments may get “deeper technical engagement,” while ordinary licensing/support workflows may become leaner.</p>



<p>Further, customers can expect more hand-offs to partner-led engagements, given that Microsoft is already pushing customers toward its partners for FY27 (which began July 1, 2026) when it comes to AI, security, cloud modernization, Copilot, agents, and managed services, Randall said. The company is also offering partners higher margins for growth in certain AI workloads.</p>



<p>“To prepare for these shifts, customers should reflect and document their Microsoft account and support teams,” Randall advised.</p>



<p>By that he meant enumerating things like the support contacts, the partner contacts, and the escalation paths for issues. This information should be well-documented and shared internally, he said. The same goes for Microsoft-involved conversations having to do with any kind of commitment, such as those involve pricing assumptions, roadmap dependencies, or deployment milestones.</p>



<p>“This can ensure a smoother transition with a new account rep on what has already been set out for the organization,” Randall said.</p>



<h2 class="wp-block-heading">Closing the gap between AI investment and ROI</h2>



<p>Last week, Microsoft launched the $2.5 billion Frontier Company, which it said “goes beyond” SIs and Forward Deployed Engineers (FDE). The initiative will integrate thousands of the company’s own engineers directly into customer environments to help them build AI tools, and to also help customers learn essential skills so they can eventually handle projects on their own.</p>



<p>But customers shouldn’t think of this as what he described as “consulting-heavy, McKinsey-style engagements,” noted Info-Tech’s Randall. Pre-sales will likely become more focused on qualifying an organization’s specific processes for ongoing AI implementations, rather than on system-wide change management. As with other hyperscalers such as AWS, Microsoft is leaning into this more white-glove model to help “prevent the gap between AI investments and AI ROI from widening.”</p>



<p>“As such, Microsoft will likely reserve its best technical talent for accounts with strong production intent, credible budget, usable data, and clear executive sponsorship,” Randall predicted.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft betting that enterprise AI needs engineers, not bigger sales teams]]></title>
<description><![CDATA[The number of tech layoffs continues to tick upwards as AI investments increase, with Microsoft alone cutting around 4,800 employees, or roughly 2.1% of its workforce, this week.



The latest cutbacks are mostly in the company’s commercial sales and Xbox divisions. They follow two others in 2025...]]></description>
<link>https://tsecurity.de/de/3650291/it-nachrichten/microsoft-betting-that-enterprise-ai-needs-engineers-not-bigger-sales-teams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650291/it-nachrichten/microsoft-betting-that-enterprise-ai-needs-engineers-not-bigger-sales-teams/</guid>
<pubDate>Tue, 07 Jul 2026 04:18:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The number of tech layoffs continues to tick upwards as AI investments increase, with Microsoft alone cutting around 4,800 employees, or roughly 2.1% of its workforce, this week.</p>



<p>The latest cutbacks are mostly in the company’s commercial sales and Xbox divisions. They follow two others in 2025 that impacted around 15,000 workers, or roughly 4% of the company’s workforce. Prior to the latest cuts, Microsoft had 220,000-plus employees.</p>



<p>The headcount reduction also comes just days after the announcement of <a href="https://www.cio.com/article/4192504/microsoft-and-amazon-devote-billions-of-dollars-to-thousands-of-fdes.html" target="_blank">Microsoft Frontier Company</a>, an initiative that will provide embedded support for customers deploying AI projects, similar to traditional offerings from systems integrators (SIs).</p>



<p>Taken together, these moves seem to indicate that Microsoft is betting on its engineering expertise, rather than traditional account management, as the path to <a href="https://www.cio.com/article/411198/how-to-launch-your-ai-projects-from-pilot-to-production-and-ensure-success.html" target="_blank">AI success</a>.</p>



<p>“Microsoft had already reorganized its commercial business around AI,” said <a href="https://www.infotech.com/profiles/thomas-randall" target="_blank" rel="noreferrer noopener">Thomas Randall</a>, a research director at Info-Tech Research Group. “Recent layoffs are part of that ongoing context.”</p>



<h2 class="wp-block-heading">Microsoft’s memo to employees</h2>



<p>In a <a href="https://www.businessinsider.com/microsoft-jobs-cuts-across-sales-and-xbox-read-the-memo-2026-7" target="_blank" rel="noreferrer noopener">memo obtained by Business Insider</a>, Microsoft EVP and chief people officer Amy Coleman said the cuts effectively reflect the tectonic shift being brought about by AI.</p>



<p>“The ‘why’ is this: Our business is changing because the world around it is changing,” she said. “Companies don’t get to choose whether their industry changes; they only get to choose whether they change with it.”</p>



<p>Customer needs, and the business models that serve them, are shifting, meaning vendors must “adjust resources and roles” so they can operate in a way that best serves their customers. However, Coleman emphasized: “Whenever possible, our priority is to place people into new roles aligned to the company’s highest priorities and greatest areas of opportunity.”</p>



<p>Which, today, is AI.</p>



<p>Seemingly contradictorily, Coleman said the cuts “build on” the Frontier Company announcement, which is “reshaping how we work and embedding our engineering experts alongside customers so we can help them accelerate their technology deployments.”</p>



<p>While she emphasized that the roles eliminated this week are <a href="https://www.infoworld.com/article/4113574/forecast-ai-wont-replace-human-devs-for-at-least-5-years.html" target="_blank">not being replaced by AI</a>, the technology is fundamentally changing work. Many everyday tasks are being automated, meaning “we all need to keep learning, keep building new skills, and keep adapting as the work evolves.” </p>



<p>Customers are undergoing the same shift and are looking to Microsoft for guidance, she noted. “We can’t do that well unless we’re doing it ourselves.”</p>



<p>Finally, she said the tech giant will evolve structure and priorities across the company “thoughtfully.”</p>



<p>“We are working on alternative solutions to job eliminations and … we will continue to invest in equipping employees with new skills, including in AI.”</p>



<h2 class="wp-block-heading">What customers might expect</h2>



<p>Redmond isn’t the only big tech company taking scalpels to staff as the industry adjusts to, and seeks to capitalize on, AI. Companies are spending billions and inking strategic partnerships with top AI labs, and these investments in some cases need to be offset with cuts because some have yet to provide tangible ROI.</p>



<p>For instance, Amazon has laid off <a href="https://finance.yahoo.com/markets/stocks/articles/amazon-cutting-even-more-jobs-215000751.html?guccounter=1&amp;guce_referrer=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS8&amp;guce_referrer_sig=AQAAABApQepSEbQ_dc1TGRGI6UlyX5mFPpTY5zoGKqYKNDv3jt19X8whfI9ZKnzpE0RdmD4BMAlgVjxfGRT0IfHy34G8e78MqJIbW1QWvQb00AC9dor6nzVfTgWuv7bxYVZ3fEBKKwXi-cfiKOObM-csOMADd4byfnnAiiFfzJ8pa48f" target="_blank" rel="noreferrer noopener">30,000 workers</a> since last fall, while Google is rumored to be <a href="https://www.businessinsider.com/google-clouds-quiet-layoffs-hit-cybersecurity-teams-2026-6" target="_blank" rel="noreferrer noopener">cutting employees</a> in its cloud division. Meta, for its part, eliminated 8,000 employees, or about 10% of its total headcount, in May alone, while Oracle <a href="https://www.bbc.com/news/articles/c4gy0x0j5deo" target="_blank" rel="noreferrer noopener">recently slashed 21,000</a>.</p>



<p>For customers, there is a price to pay, however. In the case of Microsoft, Info-Tech’s Randall said that, with the cuts, some customers can now expect slower response times on “non-strategic asks,” particularly as accounts are consolidated under fewer reps.</p>



<p>That said, given its Frontier Company investments, top accounts with large AI, data, security, and cloud commitments may get “deeper technical engagement,” while ordinary licensing/support workflows may become leaner.</p>



<p>Further, customers can expect more hand-offs to partner-led engagements, given that Microsoft is already pushing customers toward its partners for FY27 (which began July 1, 2026) when it comes to AI, security, cloud modernization, Copilot, agents, and managed services, Randall said. The company is also offering partners higher margins for growth in certain AI workloads.</p>



<p>“To prepare for these shifts, customers should reflect and document their Microsoft account and support teams,” Randall advised.</p>



<p>By that he meant enumerating things like the support contacts, the partner contacts, and the escalation paths for issues. This information should be well-documented and shared internally, he said. The same goes for Microsoft-involved conversations having to do with any kind of commitment, such as those involve pricing assumptions, roadmap dependencies, or deployment milestones.</p>



<p>“This can ensure a smoother transition with a new account rep on what has already been set out for the organization,” Randall said.</p>



<h2 class="wp-block-heading">Closing the gap between AI investment and ROI</h2>



<p>Last week, Microsoft launched the $2.5 billion Frontier Company, which it said “goes beyond” SIs and Forward Deployed Engineers (FDE). The initiative will integrate thousands of the company’s own engineers directly into customer environments to help them build AI tools, and to also help customers learn essential skills so they can eventually handle projects on their own.</p>



<p>But customers shouldn’t think of this as what he described as “consulting-heavy, McKinsey-style engagements,” noted Info-Tech’s Randall. Pre-sales will likely become more focused on qualifying an organization’s specific processes for ongoing AI implementations, rather than on system-wide change management. As with other hyperscalers such as AWS, Microsoft is leaning into this more white-glove model to help “prevent the gap between AI investments and AI ROI from widening.”</p>



<p>“As such, Microsoft will likely reserve its best technical talent for accounts with strong production intent, credible budget, usable data, and clear executive sponsorship,” Randall predicted.</p>



<p><em>This article originally appeared on <a href="https://www.cio.com/article/4193510/microsoft-betting-that-enterprise-ai-needs-engineers-not-bigger-sales-teams.html" target="_blank">CIO.com</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure]]></title>
<description><![CDATA[Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerability that stems from the DevOps platform trusting the…
Read more →
The post T...]]></description>
<link>https://tsecurity.de/de/3649521/it-security-nachrichten/threat-actors-probe-gitea-docker-flaw-cve-2026-20896-13-days-after-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649521/it-security-nachrichten/threat-actors-probe-gitea-docker-flaw-cve-2026-20896-13-days-after-disclosure/</guid>
<pubDate>Mon, 06 Jul 2026 19:53:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerability that stems from the DevOps platform trusting the…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/threat-actors-probe-gitea-docker-flaw-cve-2026-20896-13-days-after-disclosure/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/threat-actors-probe-gitea-docker-flaw-cve-2026-20896-13-days-after-disclosure/">Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure]]></title>
<description><![CDATA[Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig.

The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerability that stems from the DevOps platform trusting the "X-WEBAUTH-USER" heade...]]></description>
<link>https://tsecurity.de/de/3649499/it-security-nachrichten/threat-actors-probe-gitea-docker-flaw-cve-2026-20896-13-days-after-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649499/it-security-nachrichten/threat-actors-probe-gitea-docker-flaw-cve-2026-20896-13-days-after-disclosure/</guid>
<pubDate>Mon, 06 Jul 2026 19:23:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig.

The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerability that stems from the DevOps platform trusting the "X-WEBAUTH-USER" header from any source IP address, effectively allowing an unauthenticated internet client to get elevated]]></content:encoded>
</item>
<item>
<title><![CDATA[Unpacking Workday’s agentic AI pricing model]]></title>
<description><![CDATA[Only 35% of CIOs have full visibility into their AI operating costs, according to a recent KPMG survey. That makes it difficult for them to control spend on software-as-a-service offerings from vendors who, like Workday, have incorporated pay-as-you-go agentic AI into their offerings. Workday is ...]]></description>
<link>https://tsecurity.de/de/3644080/it-nachrichten/unpacking-workdays-agentic-ai-pricing-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644080/it-nachrichten/unpacking-workdays-agentic-ai-pricing-model/</guid>
<pubDate>Fri, 03 Jul 2026 19:04:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Only 35% of CIOs have full visibility into their AI operating costs, according to a recent KPMG survey. That makes it difficult for them to control spend on software-as-a-service offerings from vendors who, like Workday, have incorporated pay-as-you-go agentic AI into their offerings. Workday is one of several vendors that have shifted to a <a href="https://www.cio.com/article/4057792/workday-unveils-new-agents-a-new-cloud-and-a-developer-platform.html">hybrid subscription/consumption pricing model</a>.</p>



<p>“Fundamentally, with AI we are shifting the value of what enterprise software as a service is delivering in the industry,” Workday CTO Gabe Monroy explained in a recent interview. “The key, though, is that the value is no longer derived by a fixed factor, like how many employees you have working for you. It’s now going to be derived by how much use are you getting out of the system, hence the consumption.”</p>



<p>However, “It’s going to be in some cases disruptive to our customers, and it’s incumbent on us to provide them with tools to forecast and navigate that transition effectively,” he said.</p>



<p>That will be welcome news for the 40% of organizations that <a href="https://assets.kpmg.com/content/dam/kpmgsites/xx/pdf/2026/06/global-ai-pulse-q2.pdf.coredownload.inline.pdf" target="_blank" rel="nofollow">KPMG found</a> have usage or token budgets in place.</p>



<p>The changes Monroy described are part of an industry trend, according to <a href="https://www.infotech.com/profiles/terra-higginson" target="_blank" rel="nofollow">Terra Higginson</a>, principal research director at Info-Tech Research Group. “What we are seeing in the market is that basic seat pricing and seat counts are not going away. Customers are still paying for the core subscription footprint. AI is being layered on top as an incremental cost,” she said. “The practical message is simple: expect to pay more. The pricing model may shift from seats to credits or consumption, but the direction of spend is still up.”</p>



<p>And because each vendor’s program has its own twists and its own ways of measuring and charging for usage, every new model adds a layer of complexity to the budgeting headaches CIOs already face thanks to the ongoing move to consumption-based services, which began with the cloud.</p>



<h2 class="wp-block-heading">Two parts to the model</h2>



<p>Workday’s AI pricing model is in two parts. First, customers subscribe to the services they want, as they always have. With that subscription, they receive a pool of Flex Credits that can be used to enable AI agents and other “applicable platform capabilities” including Agent-Ready Tools, Workday Data Cloud, and high-volume use of <a href="https://www.cio.com/article/4146511/workday-integrates-sana-to-turn-its-enterprise-apps-into-agentic-execution-engines.html">Sana through its conversational AI interface</a>. The number of credits included varies by company size. But on top of that, they also purchase a subscription for additional Flex Credits that can be applied to any product they subscribe to.</p>



<p>Flex Credit usage is monitored through the Platform Consumption Console, which generates alerts when consumption hits 80%, 90% and 100% of subscribed credits. Use is metered when a task is completed.</p>



<p>However, one Flex Credit doesn’t necessarily equal one action. Workday’s <a href="https://www.workday.com/content/dam/web/en-us/documents/legal/flex-credits-rate-card.pdf" target="_blank" rel="nofollow">rate card</a> lists the number of credits per activity; for example, as of May 21, in the Recruiting Agent, it currently costs six credits to screen and grade each candidate’s resumé against a job opening, and 750 credits per requisition to identify relevant leads in existing talent pools and rediscover candidates for recruiters, recommending jobs for those candidates to apply for. In the Contract Negotiation Agent, the review and redlining of a contract, based on a playbook, costs 500 credits.</p>



<p>The company also provides a <a href="https://www.workday.com/content/dam/web/en-us/documents/legal/sana-platform-self-service-reference.pdf" target="_blank" rel="nofollow">reference guide</a> listing the credits used by actions performed by the Sana platform and by self-service agents.</p>



<p>The good news is that, though Workday’s console counts credits used in both production and pre-production environments, only those used in production are charged for, offering an early budgeting reality check and a chance to tweak processes before they land in production. Pre-production usage count is only in aggregate, however, so if a customer wants to size a specific agent, the best approach is to run it in a defined window or dedicated test tenant and compare usage before and after the test<em>.</em></p>



<h2 class="wp-block-heading">Use them or lose them</h2>



<p>The bad news is that Flex Credits expire after one year, and any left in a subscription do not roll over to the next; it’s a use them or lose them situation.</p>



<p>If, on the other hand, a customer exceeds their Flex Credit balance during the year, Workday said it does not just turn off their agents or other access to services. Instead, Workday’s account teams “partner with them to reconcile usage and help them purchase additional credits.”</p>



<p>Analysts agree that there are pros and cons to this new market reality.</p>



<p>“Workday’s Flex Credits are part of a broader shift we’re seeing across SaaS,” said <a href="https://moorinsightsstrategy.com/team/melody-brue/" target="_blank" rel="nofollow">Melody Brue</a>, principal analyst at Moor Insights &amp; Strategy. “Vendors are defining their own proprietary units for AI consumption so they can meter usage on top of existing subscriptions.”</p>



<p>Workday’s model, she said, is more flexible than a static AI add-on because customers can use Flex Credits for whichever agents drive the most value at a given time and get access to new AI capabilities as they launch.</p>



<p>The trade-off, however, is predictability. “Credit burn rates vary widely by task,” she said. A pilot can quietly consume a year’s worth of Flex Credits within weeks without strong telemetry and governance. And that, she said is what worries technology and finance leaders: apparently successful AI adoption that shows up as a budget surprise.</p>



<p>But, said <a href="https://www.infotech.com/profiles/scott-bickley" target="_blank" rel="nofollow">Scott Bickley</a>, advisory fellow at Info-Tech Research Group, “The Workday Flex Credits Rate Card seeks to quantify consumption of Flex Credits to specific value-added actions that are AI agent-driven. Many other vendors in the ERP space have created incredibly complex, multi-layered consumption models, leaving their customers’ heads spinning as they seek to decipher how capacity will be consumed, much less if it can add value.”</p>



<p>Brue, too, approved of Workday’s model, although she said that a core issue with AI pricing today is that <a href="https://www.cio.com/article/4138622/awu-by-salesforce-a-shiny-new-metric-that-tells-cios-little-of-value.html">vendors are each defining their own units</a>, with no common measurement across platforms. This gives vendors pricing flexibility, but makes customers do extra work to create meaningful metrics like cost per resolution or cost per process run, just to keep budgets and ROI under control.</p>



<p>“Workday’s Flex Credits are a smart move for Workday because they align revenue with AI usage, but from the buyer’s side, they raise the bar on FinOps and governance,” she said. “You need clear dashboards, guardrails, and forecasting, or that flexibility can quickly turn into a budget black hole.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ohne gutes Datenbank-Change-Management droht das Chaos]]></title>
<description><![CDATA[Künstliche Intelligenz hilft Unternehmen unter anderem, mangelnde Mitarbeiter- und Finanzressourcen auszugleichen. 

Tags: #Change Management | #Datenbank]]></description>
<link>https://tsecurity.de/de/3642657/it-security-nachrichten/ohne-gutes-datenbank-change-management-droht-das-chaos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642657/it-security-nachrichten/ohne-gutes-datenbank-change-management-droht-das-chaos/</guid>
<pubDate>Fri, 03 Jul 2026 05:53:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2025/07/Datenbank_Shutterstock_2533276269_1920.jpg" class="attachment-full size-full wp-post-image" alt="Datenbankmanagement, Technische Schulden Datenbank, Datenbank Compliance, Datenbank, DevOps" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2025/07/Datenbank_Shutterstock_2533276269_1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2025/07/Datenbank_Shutterstock_2533276269_1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2025/07/Datenbank_Shutterstock_2533276269_1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2025/07/Datenbank_Shutterstock_2533276269_1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2025/07/Datenbank_Shutterstock_2533276269_1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Ohne gutes Datenbank-Change-Management droht das Chaos 1"></p>
    Künstliche Intelligenz hilft Unternehmen unter anderem, mangelnde Mitarbeiter- und Finanzressourcen auszugleichen. 

<p>Tags: <a href="https://www.it-daily.net/thema/change-management">#Change Management</a> | <a href="https://www.it-daily.net/thema/datenbank">#Datenbank</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple says public YouTube videos can be used in AI lawsuit defense]]></title>
<description><![CDATA[Apple is asking a federal court to dismiss the YouTuber AI training lawsuit, on the grounds that publicly available YouTube videos are lawfully accessible under both the DMCA and YouTube's Terms of Service.Apple seeks dismissal of YouTube AI training lawsuitIn April 2026, a collection of YouTube ...]]></description>
<link>https://tsecurity.de/de/3642651/ios-mac-os/apple-says-public-youtube-videos-can-be-used-in-ai-lawsuit-defense/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642651/ios-mac-os/apple-says-public-youtube-videos-can-be-used-in-ai-lawsuit-defense/</guid>
<pubDate>Fri, 03 Jul 2026 05:36:05 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is asking a federal court to dismiss the YouTuber AI training lawsuit, on the grounds that publicly available YouTube videos are lawfully accessible under both the DMCA and YouTube's Terms of Service.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68149-143655-AI-glass-xl.jpg" alt="Glowing silver Apple logo centered on a black background, surrounded by a neon multicolored looping outline forming a stylized star or atom shape" height="738"><br><span>Apple seeks dismissal of YouTube AI training lawsuit</span></div><br>In April 2026, a collection of YouTube channels <a href="https://appleinsider.com/articles/26/04/06/apple-may-have-scraped-youtube-videos-without-permission-for-ai-training">sued Apple</a>,  claiming the company had scraped videos from YouTube to train internal AI models.<br><br>The class-action lawsuit was headed up by Ted Entertainment, owners of the h3h3Productions channels and podcast. Two golf channels, MrShortGameGolf and Golfholics, were also involved.<br><br><br> <a href="https://appleinsider.com/articles/26/07/03/apple-says-public-youtube-videos-can-be-used-in-ai-lawsuit-defense?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244861?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[7/2/2026]]></title>
<description><![CDATA[Germany Seeks Powers for Spies To Hack and Disrupt Attackers Launch of UK’s National Cyber Action Plan Delayed Amid Labour Leadership CrisisSupreme Court Decision Threatens EU-U.S. Data Transfer AgreementSpaceX Showed Investors Prototype of Elon Musk’s New AI Device…Musk Denies Report That SpaceX...]]></description>
<link>https://tsecurity.de/de/3642531/it-security-nachrichten/722026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642531/it-security-nachrichten/722026/</guid>
<pubDate>Fri, 03 Jul 2026 03:08:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Germany Seeks Powers for Spies To Hack and Disrupt Attackers Launch of UK’s National Cyber Action Plan Delayed Amid Labour Leadership CrisisSupreme Court Decision Threatens EU-U.S. Data Transfer AgreementSpaceX Showed Investors Prototype of Elon Musk’s New AI Device…Musk Denies Report That SpaceX Showed AI Handset Prototype Before IPODev Says Google Warned Him About Account Hijack … <a href="https://thecyberbeat.com/2026/07/03/7-2-2026/" class="more-link">Continue reading <span class="screen-reader-text">7/2/2026</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[NTLM-Abschaltung in Git: Folgen für Azure DevOps Server - All About Security]]></title>
<description><![CDATA[Azure DevOps Server akzeptiert über die integrierte Windows-Authentifizierung sowohl Kerberos als auch NTLM. Die dabei verwendete Negotiate ...]]></description>
<link>https://tsecurity.de/de/3641890/windows-server/ntlm-abschaltung-in-git-folgen-fuer-azure-devops-server-all-about-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641890/windows-server/ntlm-abschaltung-in-git-folgen-fuer-azure-devops-server-all-about-security/</guid>
<pubDate>Thu, 02 Jul 2026 19:16:58 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Azure DevOps <b>Server</b> akzeptiert über die integrierte <b>Windows</b>-Authentifizierung sowohl Kerberos als auch NTLM. Die dabei verwendete Negotiate ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Cheap Chinese chips could offer way out of RAM price crisis, Apple suggests]]></title>
<description><![CDATA[The RAM price crisis is pushing hardware manufacturers to pursue deals with Chinese companies, against the wishes of the US government. Apple is one of those reportedly exploring such deals.



“Apple is in negotiations to purchase chips from Chinese semiconductor makers ChangXin Memory Technolog...]]></description>
<link>https://tsecurity.de/de/3641855/it-security-nachrichten/cheap-chinese-chips-could-offer-way-out-of-ram-price-crisis-apple-suggests/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641855/it-security-nachrichten/cheap-chinese-chips-could-offer-way-out-of-ram-price-crisis-apple-suggests/</guid>
<pubDate>Thu, 02 Jul 2026 19:09:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The RAM price crisis is pushing hardware manufacturers to pursue deals with Chinese companies, against the wishes of the US government. Apple is one of those reportedly exploring such deals.</p>



<p>“Apple is in negotiations to purchase chips from Chinese semiconductor makers ChangXin Memory Technologies Inc. (CMTI) and Yangtze Memory Technologies Co. (YMTC) to help reduce the impact of a global memory shortage,” <a href="https://www.bloomberg.com/news/articles/2026-07-01/apple-seeks-to-buy-chinese-made-memory-chips-with-lobbying-push" target="_blank" rel="noreferrer noopener">Bloomberg reported</a>. “The companies are on a Pentagon blacklist of Chinese entities believed to support Beijing’s military, and Apple’s effort to buy chips from them has included appeals to Trump administration officials to help soften the political fallout,” it said.</p>



<p>Rumors surrounding Apple talking with CMTI and YMTC have been going on for months, with analyst Ming-Chi Kuo pointing to Apple CEO Tim Cook being “<a href="https://www.computerworld.com/article/4190611/apples-memory-problem-is-your-problem-too.html">one of the few tech leaders who can still navigate both Washington and Beijing</a>, so this is better handled before he steps down as CEO.”</p>



<p>Beyond the potential political ramifications, any deal would have immediate implications for enterprise IT buyers.</p>



<p>“CIOs should focus on the risk that this strategy could introduce. Will Apple be able to thoroughly assess those chips to completely rule out the possibility of trojan horses, backdoors, and hidden functionality such as dead man switches?” asked <a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group. “If Apple says that they will do, to what degree of certainty? There have been rumors about hidden backdoors in chips before, such as <a href="https://www.csoonline.com/article/567717/insecure-virtual-usb-feature-in-supermicro-bmcs-exposes-servers-to-attack.html">Supermicro</a> in 2018, <a href="https://www.hackster.io/news/hacknect-a-wireless-automation-platform-inside-a-usb-cable-15e3384fae59" target="_blank" rel="noreferrer noopener">ESP32 microcontroller</a> hidden functionality in 2025, and <a href="https://www.csoonline.com/article/536082/security-awareness-china-not-to-blame-for-backdoor-in-us-military-chip.html">Microsemi backdoor</a> in 2012, to name a few.”</p>



<h2 class="wp-block-heading">On the naughty list?</h2>



<p>This issue gets complicated based on what the US government ultimately does. The two Chinese manufacturers figure on the Pentagon’s so-called <a href="https://media.defense.gov/2026/Jun/08/2003945537/-1/-1/1/ENTITIES-IDENTIFIED-AS-CHINESE-MILITARY-COMPANIES-OPERATING-IN-THE-UNITED-STATES-IN-ACCORDANCE-WITH-SECTION-1260H.PDF" target="_blank" rel="noreferrer noopener">1260H list</a> of “entities identified as Chinese Military Companies,” which also includes Chinese internet giants Alibaba, Baidu, and Tencent; router maker TP-Link Technologies; and drone maker DJI. Being on that list has no real consequences for the companies concerned, but the government could move them to the <a href="https://www.cisa.gov/resources-tools/resources/entity-list" target="_blank" rel="noreferrer noopener">Department of Commerce’s Entity List</a>, subjecting them to export licensing requirements, or make them the subject of a <a href="https://www.acquisition.gov/Section-889-Policies" target="_blank" rel="noreferrer noopener">Section 889 clause</a>, barring them from government procurement deals. That could sharply change the dynamics for Apple and other technology vendors seeking cheaper RAM supplies — and for their customers.</p>



<p><a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant for Digital 520, said, “Currently, CXMT is only on the Pentagon’s 1260H list, which doesn’t legally bar transactions. Inclusion in the Commerce Department Entity List placement would, which is what Apple is seeking to prevent here.”</p>



<p>He suggested Apple might try to limit blowback by only using the Chinese chips in Apple devices sold in China.</p>



<p>If the government does intensify restrictions and if components from YMTC or CXMT “show up in a customer contract you already signed, a standard-issue device becomes a procurement compliance question. Fleet inventory in MDM will need to track memory sourcing, not just device model. That is a capability most enterprises do not have today,” Kenney said. “The real question for a CIO is not whether Washington pushes back on Apple, but whether their customers will push back for shipping Apple.”</p>



<h2 class="wp-block-heading">Other vendors use Chinese RAM already</h2>



<p>“Lenovo has sourced from Chinese memory makers for years,” as have other manufacturers, Kenney said. “The difference is that they are not lobbying the Treasury Secretary about it.”</p>



<p>Geopolitical analyst <a href="https://www.linkedin.com/in/irina-tsukerman-4b04595/" target="_blank" rel="noreferrer noopener">Irina Tsukerman</a> said Apple could clear the way for more vendors to use cheaper RAM.</p>



<p>“If Apple absorbs the political criticism and keeps enterprise buyers comfortable, competitors would gain room to consider Chinese memory for selected markets or less sensitive product channels,” Tsukerman said. “If Washington turns Apple into an example, other manufacturers would become more careful around government-facing sales and reserve this kind of sourcing for places where US procurement pressure has less impact.”</p>



<p>Tsukerman agreed with Kenney that IT departments will need to improve component visibility.</p>



<p>“Enterprise CIOs should take this seriously because Apple’s reported sourcing discussions turn a normally invisible component decision into something that can affect procurement credibility, especially for buyers whose technology choices are reviewed through government or regulated-sector requirements,” Tsukerman said.</p>



<p>The lack of a clear product quality issue is what will make this a delicate IT dance, Tsukerman said.</p>



<p>“Engineers could see limited practical danger from memory sourcing alone, and procurement reviewers could still see a serious issue because the supplier has already been placed in a national-security category,” she said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cheap Chinese chips could offer way out of RAM price crisis, Apple suggests]]></title>
<description><![CDATA[The RAM price crisis is pushing hardware manufacturers to pursue deals with Chinese companies, against the wishes of the US government. Apple is one of those reportedly exploring such deals.



“Apple is in negotiations to purchase chips from Chinese semiconductor makers ChangXin Memory Technolog...]]></description>
<link>https://tsecurity.de/de/3641832/it-nachrichten/cheap-chinese-chips-could-offer-way-out-of-ram-price-crisis-apple-suggests/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641832/it-nachrichten/cheap-chinese-chips-could-offer-way-out-of-ram-price-crisis-apple-suggests/</guid>
<pubDate>Thu, 02 Jul 2026 19:03:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The RAM price crisis is pushing hardware manufacturers to pursue deals with Chinese companies, against the wishes of the US government. Apple is one of those reportedly exploring such deals.</p>



<p>“Apple is in negotiations to purchase chips from Chinese semiconductor makers ChangXin Memory Technologies Inc. (CMTI) and Yangtze Memory Technologies Co. (YMTC) to help reduce the impact of a global memory shortage,” <a href="https://www.bloomberg.com/news/articles/2026-07-01/apple-seeks-to-buy-chinese-made-memory-chips-with-lobbying-push" target="_blank" rel="noreferrer noopener">Bloomberg reported</a>. “The companies are on a Pentagon blacklist of Chinese entities believed to support Beijing’s military, and Apple’s effort to buy chips from them has included appeals to Trump administration officials to help soften the political fallout,” it said.</p>



<p>Rumors surrounding Apple talking with CMTI and YMTC have been going on for months, with analyst Ming-Chi Kuo pointing to Apple CEO Tim Cook being “<a href="https://www.computerworld.com/article/4190611/apples-memory-problem-is-your-problem-too.html">one of the few tech leaders who can still navigate both Washington and Beijing</a>, so this is better handled before he steps down as CEO.”</p>



<p>Beyond the potential political ramifications, any deal would have immediate implications for enterprise IT buyers.</p>



<p>“CIOs should focus on the risk that this strategy could introduce. Will Apple be able to thoroughly assess those chips to completely rule out the possibility of trojan horses, backdoors, and hidden functionality such as dead man switches?” asked <a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group. “If Apple says that they will do, to what degree of certainty? There have been rumors about hidden backdoors in chips before, such as <a href="https://www.csoonline.com/article/567717/insecure-virtual-usb-feature-in-supermicro-bmcs-exposes-servers-to-attack.html">Supermicro</a> in 2018, <a href="https://www.hackster.io/news/hacknect-a-wireless-automation-platform-inside-a-usb-cable-15e3384fae59" target="_blank" rel="noreferrer noopener">ESP32 microcontroller</a> hidden functionality in 2025, and <a href="https://www.csoonline.com/article/536082/security-awareness-china-not-to-blame-for-backdoor-in-us-military-chip.html">Microsemi backdoor</a> in 2012, to name a few.”</p>



<h2 class="wp-block-heading">On the naughty list?</h2>



<p>This issue gets complicated based on what the US government ultimately does. The two Chinese manufacturers figure on the Pentagon’s so-called <a href="https://media.defense.gov/2026/Jun/08/2003945537/-1/-1/1/ENTITIES-IDENTIFIED-AS-CHINESE-MILITARY-COMPANIES-OPERATING-IN-THE-UNITED-STATES-IN-ACCORDANCE-WITH-SECTION-1260H.PDF" target="_blank" rel="noreferrer noopener">1260H list</a> of “entities identified as Chinese Military Companies,” which also includes Chinese internet giants Alibaba, Baidu, and Tencent; router maker TP-Link Technologies; and drone maker DJI. Being on that list has no real consequences for the companies concerned, but the government could move them to the <a href="https://www.cisa.gov/resources-tools/resources/entity-list" target="_blank" rel="noreferrer noopener">Department of Commerce’s Entity List</a>, subjecting them to export licensing requirements, or make them the subject of a <a href="https://www.acquisition.gov/Section-889-Policies" target="_blank" rel="noreferrer noopener">Section 889 clause</a>, barring them from government procurement deals. That could sharply change the dynamics for Apple and other technology vendors seeking cheaper RAM supplies — and for their customers.</p>



<p><a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant for Digital 520, said, “Currently, CXMT is only on the Pentagon’s 1260H list, which doesn’t legally bar transactions. Inclusion in the Commerce Department Entity List placement would, which is what Apple is seeking to prevent here.”</p>



<p>He suggested Apple might try to limit blowback by only using the Chinese chips in Apple devices sold in China.</p>



<p>If the government does intensify restrictions and if components from YMTC or CXMT “show up in a customer contract you already signed, a standard-issue device becomes a procurement compliance question. Fleet inventory in MDM will need to track memory sourcing, not just device model. That is a capability most enterprises do not have today,” Kenney said. “The real question for a CIO is not whether Washington pushes back on Apple, but whether their customers will push back for shipping Apple.”</p>



<h2 class="wp-block-heading">Other vendors use Chinese RAM already</h2>



<p>“Lenovo has sourced from Chinese memory makers for years,” as have other manufacturers, Kenney said. “The difference is that they are not lobbying the Treasury Secretary about it.”</p>



<p>Geopolitical analyst <a href="https://www.linkedin.com/in/irina-tsukerman-4b04595/" target="_blank" rel="noreferrer noopener">Irina Tsukerman</a> said Apple could clear the way for more vendors to use cheaper RAM.</p>



<p>“If Apple absorbs the political criticism and keeps enterprise buyers comfortable, competitors would gain room to consider Chinese memory for selected markets or less sensitive product channels,” Tsukerman said. “If Washington turns Apple into an example, other manufacturers would become more careful around government-facing sales and reserve this kind of sourcing for places where US procurement pressure has less impact.”</p>



<p>Tsukerman agreed with Kenney that IT departments will need to improve component visibility.</p>



<p>“Enterprise CIOs should take this seriously because Apple’s reported sourcing discussions turn a normally invisible component decision into something that can affect procurement credibility, especially for buyers whose technology choices are reviewed through government or regulated-sector requirements,” Tsukerman said.</p>



<p>The lack of a clear product quality issue is what will make this a delicate IT dance, Tsukerman said.</p>



<p>“Engineers could see limited practical danger from memory sourcing alone, and procurement reviewers could still see a serious issue because the supplier has already been placed in a national-security category,” she said.</p>



<p><em>This article first appeared on <a href="https://www.networkworld.com/article/4192382/cheap-chinese-chips-could-offer-way-out-of-ram-price-crisis-apple-suggests.html">Network World</a>.</em> </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Will Trump Take the Win at NATO’s Ankara Summit?]]></title>
<description><![CDATA[It is an open question whether the Trump administration seeks to rebalance NATO or disengage the U.S. from European security.
The post Will Trump Take the Win at NATO’s Ankara Summit? appeared first on Just Security.]]></description>
<link>https://tsecurity.de/de/3641299/it-security-nachrichten/will-trump-take-the-win-at-natos-ankara-summit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641299/it-security-nachrichten/will-trump-take-the-win-at-natos-ankara-summit/</guid>
<pubDate>Thu, 02 Jul 2026 15:23:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>It is an open question whether the Trump administration seeks to rebalance NATO or disengage the U.S. from European security.</p>
<p>The post <a href="https://www.justsecurity.org/144465/will-trump-take-the-win-at-natos-ankara-summit/">Will Trump Take the Win at NATO’s Ankara Summit?</a> appeared first on <a href="https://www.justsecurity.org/">Just Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building a browser-based sandbox for quantum-safe migration]]></title>
<description><![CDATA[Author: PQShield - Bewertung: 0x - Views:3 Eric Amador from Thales joins the show to discuss pqctoday.com, an open initiative designed to simplify quantum-safe migration. Discover how browser-based cryptographic tools and AI help organizations understand upcoming global timelines, test new algori...]]></description>
<link>https://tsecurity.de/de/3641164/videos/building-a-browser-based-sandbox-for-quantum-safe-migration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641164/videos/building-a-browser-based-sandbox-for-quantum-safe-migration/</guid>
<pubDate>Thu, 02 Jul 2026 14:33:57 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: PQShield - Bewertung: 0x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/xzwIRHO6jEI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Eric Amador from Thales joins the show to discuss pqctoday.com, an open initiative designed to simplify quantum-safe migration. Discover how browser-based cryptographic tools and AI help organizations understand upcoming global timelines, test new algorithms such as ML-KEM without friction, and prepare for the quantum threat.<br />
<br />
YouTube chapters<br />
00:00: Introduction to Eric Amador and PQC Today <br />
01:24: Combining AI with cryptography to solve migration challenges <br />
03:46: Testing ML-KEM and ML-DSA in the browser using WebAssembly <br />
05:07: Shifting landscapes: Blockchain, 5G, and broken elliptic curves <br />
07:58: Simplifying tracking for global standards bodies like IETF and NIST <br />
10:50: Collaborating across industry lines at NCCoE and ICMC 2026 <br />
13:51: Amplifying vendor impact through open-source education <br />
16:20: Tailoring migration strategies to developer, DevOps, and executive personas <br />
21:14: Accelerating momentum and the reality of modern cryptographic threats <br />
24:50: Actionable first steps for building true cryptographic governance<br />
<br />
Guest bio<br />
Eric Amador serves as a Product Manager at Thales and is the creator of pqctoday.com. He focuses on making applied cryptography actionable across multiple industries by bridging the gap between technical teams and executives.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS raises AgentCore runtime quotas by up to 5x to help enterprises scale AI agents]]></title>
<description><![CDATA[AWS has increased key Amazon Bedrock AgentCore runtime quotas by up to fivefold, enabling enterprises to support more concurrent AI agents and user interactions without going through the quota-increase process that often slows production deployments.



While quota increase service requests are f...]]></description>
<link>https://tsecurity.de/de/3640959/ai-nachrichten/aws-raises-agentcore-runtime-quotas-by-up-to-5x-to-help-enterprises-scale-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640959/ai-nachrichten/aws-raises-agentcore-runtime-quotas-by-up-to-5x-to-help-enterprises-scale-ai-agents/</guid>
<pubDate>Thu, 02 Jul 2026 13:33:23 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AWS has increased key Amazon Bedrock AgentCore runtime quotas by up to fivefold, enabling enterprises to support more concurrent AI agents and user interactions without going through the quota-increase process that often slows production deployments.</p>



<p>While quota increase service requests are free themselves, the added capacity is more likely to translate into higher underlying compute and runtime consumption as enterprises expand AI deployments.</p>



<p>“The new default limits support up to 5,000 active concurrent sessions in US East (N. Virginia) and US West (Oregon), and 2,500 in all other supported Regions (previously 1,000 and 500 respectively),” AWS wrote in its <a href="https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.html" target="_blank" rel="noreferrer noopener">release notes</a>.</p>



<p>The hyperscaler has also increased the number of interactions each AI agent can handle from 25 tokens per second to 200 tokens per second across <a href="https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/agentcore-regions.html" target="_blank" rel="noreferrer noopener">all supported regions</a>, which it says will enable enterprises to support more simultaneous user requests.</p>



<p>Further, to help enterprises scale AI applications faster during periods of peak demand, the hyperscaler also quadrupled the rate at which new AI agent sessions can be created for container deployments, increasing the limit from 100 TPM to 400 TPM.</p>



<h2 class="wp-block-heading">Why the higher quotas matter for enterprise AI deployments</h2>



<p>The change in <a href="https://www.infoworld.com/article/4024311/aws-previews-agentcore-services-to-ease-ai-agent-deployment.html">AgentCore Runtime</a> quotas, according to <a href="https://www.forrester.com/analyst-bio/charlie-dai/BIO5344" target="_blank" rel="noreferrer noopener">Charlie Dai</a>, principal analyst at Forrester, is the hyperscaler’s response to enterprises rapidly shifting AI-agent experiments to production deployments: “In our client conversations, the bigger change is not the number of agents but the move from single-task copilots to multiple production-grade agents serving larger user populations.”</p>



<p>That means that AWS is seeing higher concurrency, longer-running agents, and more complex orchestration patterns that exceed earlier default assumptions, Dai said.</p>



<p>For enterprises making that transition, the higher default quotas, according to <a href="https://www.gartner.com/en/experts/ashish-banerjee" target="_blank" rel="noreferrer noopener">Ashish Banerjee</a>, senior principal analyst at Gartner, will help reduce the operational friction of scaling AI agents from pilot projects to production deployments.</p>



<p>Large-scale AI deployments, especially multi-agent systems, are becoming an operational consideration as they outgrow default runtime quotas quickly, requiring enterprises to seek quota increases, echoed <a href="https://www.linkedin.com/in/amitchandak78/" target="_blank" rel="noreferrer noopener">Amit Chandak</a>, chief analytics officer at IT Consulting firm Kanerika.</p>



<p>“That quota increase request in an enterprise environment means a support ticket, a business justification, and a review cycle. That’s days or weeks of overhead on something that shouldn’t block a deployment,” Chandak said.</p>



<p>“A quota beyond the process cost, teams design architectures around whatever the default ceiling is. Higher defaults change what teams are willing to attempt without triggering an exceptions process, and that shapes architectural decisions, not just day-to-day operations,” Chandak added.</p>



<p>The benefits extend beyond reducing administrative overhead, Chandak further added, as exhausting runtime quotas in production can interrupt customer-facing applications and multi-agent workflows.</p>



<p>“Agent sessions are stateful. When a session gets throttled mid-task, the agent can lose intermediate context, and reconstructing that state is significantly harder than retrying a stateless <a href="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html">API</a> call,” Chandak pointed out.</p>



<p>“In multi-agent pipelines, one rejected session stalls the entire workflow. You get orphaned sessions, incomplete tool calls, and gaps in monitoring that are hard to diagnose after the fact,” Chandak added.</p>



<p>These gains, however, are unlikely to be uniform across enterprises. Enterprises running high-concurrency, transaction-intensive AI workloads, according to <a href="https://www.linkedin.com/in/gaurav-dewan-pmp-8644a19/" target="_blank" rel="noreferrer noopener">Gaurav Dewan</a>, research director at Avasant, stand to benefit the most from the higher default quotas.</p>



<p>These include customer service and contact centers, software engineering and <a href="https://www.infoworld.com/article/2255028/what-is-devops-bringing-dev-and-ops-together-for-better-software.html">DevOps</a> automation, IT operations, financial services process automation, healthcare administration, supply chain coordination, and security operations, where AI agents often operate simultaneously at scale, Dewan added.</p>



<h2 class="wp-block-heading">Hyperscalers are taking different paths to production AI</h2>



<p>AWS, however, is not alone in adapting its infrastructure for helping enterprises scale AI agents in production, and rival hyperscalers, such as Microsoft and Google, are approaching the challenge in different ways.</p>



<p>Microsoft’s approach with the Azure Foundry Agent Service, according to Chandak, differs from AWS: “Many of its agent runtime limits are fixed by design; they cannot be increased even on request.”</p>



<p>“Instead, Microsoft puts the scaling flexibility at the model deployment layer, where quotas are adjustable, rather than at the agent runtime layer. That’s a deliberate architectural difference from what AWS is doing with AgentCore: raising the floor on concurrent sessions at the runtime level,” Chandak pointed out.</p>



<p>The updated quota limits for Bedrock AgentCore will automatically apply to all enterprise accounts, AWS said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Newport News, Va.’s, First CIO Tackles Security, Upskilling]]></title>
<description><![CDATA[The city's inaugural CIO Hassan Janjua started in February, bringing IT leadership expertise from Los Angeles County to the new role as he seeks to build a future-ready government workforce.]]></description>
<link>https://tsecurity.de/de/3639843/ai-nachrichten/newport-news-vas-first-cio-tackles-security-upskilling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639843/ai-nachrichten/newport-news-vas-first-cio-tackles-security-upskilling/</guid>
<pubDate>Thu, 02 Jul 2026 00:17:17 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The city's inaugural CIO Hassan Janjua started in February, bringing IT leadership expertise from Los Angeles County to the new role as he seeks to build a future-ready government workforce.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple weighs buying RAM from two blacklisted Chinese suppliers to curb rising costs]]></title>
<description><![CDATA[A global memory shortage is pushing Apple to consider alternate RAM suppliers. In all likelihood, this will draw scrutiny from U.S. lawmakers.Memory is in short supply globally — Image credit: SK HynixThe companies in question are ChangXin Memory Technologies Inc. and Yangtze Memory Technologies ...]]></description>
<link>https://tsecurity.de/de/3639732/ios-mac-os/apple-weighs-buying-ram-from-two-blacklisted-chinese-suppliers-to-curb-rising-costs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639732/ios-mac-os/apple-weighs-buying-ram-from-two-blacklisted-chinese-suppliers-to-curb-rising-costs/</guid>
<pubDate>Wed, 01 Jul 2026 23:39:01 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A global memory shortage is pushing Apple to consider alternate RAM suppliers. In all likelihood, this will draw scrutiny from U.S. lawmakers.<br><br><div><img src="https://photos5.appleinsider.com/gallery/66858-140268-Untitled-4-xl.jpg" alt="Two small SK hynix memory chips resting on a colorful, grid-patterned silicon wafer background with vertical rows in gradients of red, orange, yellow, green, and blue"><br><span>Memory is in short supply globally — Image credit: SK Hynix</span></div><br>The companies in question are ChangXin Memory Technologies Inc. and Yangtze Memory Technologies Co. The companies are on a Department of Defense list of Chinese companies believed to support Beijing's military.<br><br><a href="https://www.bloomberg.com/news/articles/2026-07-01/apple-seeks-to-buy-chinese-made-memory-chips-with-lobbying-push">According to</a> <em>Bloomberg</em>, talks are still ongoing and nothing is final yet. However, Apple's goal is to reduce the impact of a global memory shortage, which recently caused the company to <a href="https://appleinsider.com/articles/26/06/25/apple-confirms-price-nikes-across-macs-ipads-and-more">increase prices across</a> its hardware lineup.<br><br><br> <a href="https://appleinsider.com/articles/26/07/01/apple-weighs-buying-ram-from-two-blacklisted-chinese-suppliers-to-curb-rising-costs?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244850?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Intruder offers Free security plan for lean IT and security teams]]></title>
<description><![CDATA[Intruder has announced the launch of its Free plan, providing security, IT, and DevOps teams ongoing access to professional-grade vulnerability management, cloud security, and attack surface management at no cost. Smaller organizations face the same threats as Fortune 500 companies, but without t...]]></description>
<link>https://tsecurity.de/de/3638360/it-security-nachrichten/intruder-offers-free-security-plan-for-lean-it-and-security-teams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638360/it-security-nachrichten/intruder-offers-free-security-plan-for-lean-it-and-security-teams/</guid>
<pubDate>Wed, 01 Jul 2026 13:38:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Intruder has announced the launch of its Free plan, providing security, IT, and DevOps teams ongoing access to professional-grade vulnerability management, cloud security, and attack surface management at no cost. Smaller organizations face the same threats as Fortune 500 companies, but without the budgets and headcount to match. Mid-sized businesses appear in breach headlines week after week, yet many still lack access to the tooling that would help them stay ahead. Compounding the problem, lean … <a href="https://www.helpnetsecurity.com/2026/07/01/intruder-offers-free-security-plan-for-lean-it-and-security-teams/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/01/intruder-offers-free-security-plan-for-lean-it-and-security-teams/">Intruder offers Free security plan for lean IT and security teams</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Intruder offers Free security plan for lean IT and security teams]]></title>
<description><![CDATA[Intruder has announced the launch of its Free plan, providing security, IT, and DevOps teams ongoing access to professional-grade vulnerability management, cloud security, and attack surface management at no cost. Smaller organizations face the same threats as Fortune 500 companies,…
Read more →
...]]></description>
<link>https://tsecurity.de/de/3638352/it-security-nachrichten/intruder-offers-free-security-plan-for-lean-it-and-security-teams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638352/it-security-nachrichten/intruder-offers-free-security-plan-for-lean-it-and-security-teams/</guid>
<pubDate>Wed, 01 Jul 2026 13:38:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Intruder has announced the launch of its Free plan, providing security, IT, and DevOps teams ongoing access to professional-grade vulnerability management, cloud security, and attack surface management at no cost. Smaller organizations face the same threats as Fortune 500 companies,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/intruder-offers-free-security-plan-for-lean-it-and-security-teams/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/intruder-offers-free-security-plan-for-lean-it-and-security-teams/">Intruder offers Free security plan for lean IT and security teams</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shadow agents: How IT leaders must govern ‘headless’ AI before it breaks the enterprise]]></title>
<description><![CDATA[Earlier this year, I was running my own local AI agent, a system I built called LaptopAI-Agent, which uses a LangGraph reasoning loop, a local Ollama model and a set of tools that can read files, query my git repositories and monitor system processes, all running entirely on my laptop with no clo...]]></description>
<link>https://tsecurity.de/de/3638078/it-security-nachrichten/shadow-agents-how-it-leaders-must-govern-headless-ai-before-it-breaks-the-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638078/it-security-nachrichten/shadow-agents-how-it-leaders-must-govern-headless-ai-before-it-breaks-the-enterprise/</guid>
<pubDate>Wed, 01 Jul 2026 12:08:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Earlier this year, I was running my own local AI agent, a system I built called LaptopAI-Agent, which uses a LangGraph reasoning loop, a local Ollama model and a set of tools that can read files, query my git repositories and monitor system processes, all running entirely on my laptop with no cloud calls. I had given it a broad task and walked away. When I came back, it had completed the work. Every file it touched was within its allowed paths. Every action was technically correct.</p>



<p>What unsettled me was not what the agent had done. It was that I could not reconstruct the sequence of decisions that led to it. Without the SHA-256 chained audit log I had deliberately built in, I would have had no record of why the agent made each choice, only what it produced. That gap between visible outcomes and invisible reasoning is what I had to engineer around for a single-user personal tool. Enterprises face the same problem at the scale of thousands of agents, with far less instrumentation.</p>



<p>This is what I mean by shadow agents: autonomous AI processes that operate at the API layer, chain tools together and complete multi-step workflows without logging in, generating session records, or waiting for a human to approve. They already run inside enterprise systems today. The governance infrastructure to manage them is, in most cases, far behind.</p>



<p>The question is no longer whether your organization will run these autonomous processes. It already does. The question is whether you can see what they are doing.</p>



<h2 class="wp-block-heading">The economics that opened the door</h2>



<p>The immediate catalyst for this shift is financial. Enterprise teams that embedded frontier AI models from providers like OpenAI and Anthropic into everyday workflows quickly discovered that per-token cloud inference costs compound fast once agents run autonomously, making hundreds of API calls per task rather than one.</p>



<p>The industry response has been a push toward local AI processing. <a href="https://blog.google/innovation-and-ai/technology/developers-tools/introducing-gemma-4-12b/" rel="nofollow">Google’s Gemma 4 12B</a>, released in June 2026, is the clearest signal yet. Designed to run on consumer-grade hardware with just 16GB of VRAM, it brings multimodal AI, covering text, audio and visual processing, fully local to enterprise laptops without any cloud API dependency. Apache 2.0 licensing means any organization can deploy it without per-token fees.</p>



<p>For finance teams, this is cost relief. For IT governance teams, it is a new category of exposure. When inference moves onto thousands of distributed laptops, centralized telemetry disappears. The natural network choke points that monitoring tools rely on vanish with it. Without visibility infrastructure built before rollout, IT has no reliable way to know what those agents are accessing or deciding in the organization’s name.</p>



<h2 class="wp-block-heading">The visibility gap is structural</h2>



<p>Every monitoring tool, security scanner and compliance platform most enterprises rely on was designed to track human behavior: logins, session durations and file accesses triggered by a person at a keyboard. The implicit assumption in all of it is that a human is somewhere in the loop, generating observable signals.</p>



<p>Agentic AI generates none of those signals. It operates at the API layer, bypasses the user interface entirely, retrieves context from data stores, reasons over it and takes action. It does not log in. It produces no session record.</p>



<p>Box’s <a href="https://www.businesswire.com/news/home/20260402112577/en/Box-Unveils-the-Box-Agent-to-Transform-How-Enterprises-Work-With-Content" rel="nofollow">April 2026 launch of the Box Agent</a> shows exactly how fast enterprise software is moving in this direction. The Box Agent works natively on the enterprise content layer, respecting existing permissions and compliance controls while it autonomously searches, summarizes and routes documents. That is solid engineering for business teams. It also means that contract reviews, approval chains and regulatory filings can now be executed by an agent that leaves no login trace in the monitoring systems IT manages.</p>



<p>The compliance consequence is real. An agent can chain tools in ways that move sensitive data from a secured internal store to an external processing endpoint because the agent found the connection useful, all within valid permissions, with no single step appearing suspicious and no record in any system IT is watching. The violation happens in the reasoning layer.</p>



<h2 class="wp-block-heading">A new role: The forward-deployed AI engineer</h2>



<p>Closing the governance gap requires a type of technical talent that most enterprise IT teams have not hired for. I have been calling this the forward-deployed AI engineer, a distinct role from DevOps.</p>



<p>A DevOps engineer asks whether the system is up. A forward-deployed AI engineer asks whether the agent is doing what was intended and only that. Their work covers three areas.</p>



<p>The first is prompt governance. The instructions that drive agent behavior function as code. They need version control, hardening against prompt injection attacks and rigorous re-testing after every model update. A prompt producing correct output in January can behave differently after a model version change in March, with no external indication that anything shifted.</p>



<p>The second is guardrail design: defining in technical terms what each agent is permitted to access, which external systems it may contact and which categories of action, financial transactions, credential access, outbound data transfers require human authorization before the agent can proceed.</p>



<p>The third is RAG pipeline governance. Enterprise agents typically access corporate knowledge through Retrieval-Augmented Generation pipelines. Scoping those pipelines correctly and auditing them on a consistent schedule is one of the most underestimated security responsibilities in agentic deployment. Overly permissive retrieval creates data exposure paths that are hard to detect until something has already gone wrong.</p>



<h2 class="wp-block-heading">Runtime isolation: The right security model for agents</h2>



<p>The architectural shift required here is from perimeter defense to runtime isolation. Perimeter defense assumes you control what enters the environment. When agents run locally, call external APIs dynamically and chain tools based on autonomous reasoning, the perimeter boundary is no longer a meaningful control surface.</p>



<p>Microsoft’s <a href="https://learn.microsoft.com/en-us/agent-framework/workflows/advanced/agent-executor" rel="nofollow">Agent Executor</a>, part of the Microsoft Agent Framework, provides a practical model here. The Agent Executor wraps an agent in a sandboxed runtime that manages session state, conversation context and tool permission boundaries within a controlled envelope. An agent inside a properly configured executor cannot reach unauthorized systems or take unapproved actions regardless of what the model decides to do. The security guarantee shifts from trusting the model’s output to controlling what it is allowed to execute. For any organization under compliance mandates, that distinction between trust and control is not a nuance; it is the design requirement.</p>



<h2 class="wp-block-heading">Governing at scale: The multi-agent challenge</h2>



<p>One sandboxed agent with clear guardrails is manageable. A fleet of coordinating agents with distinct permissions, running simultaneously across cloud, desktop and on-premises environments, is a qualitatively different problem that requires dedicated infrastructure.</p>



<p>Automation Anywhere’s <a href="https://www.prnewswire.com/news-releases/automation-anywhere-collaborates-with-cisco-nvidia-okta-and-openai-launching-enterpriseclaw-to-run-next-generation-ai-agents-inside-enterprise-systems-302775670.html" rel="nofollow">EnterpriseClaw</a>, launched in May 2026 with Cisco, NVIDIA, Okta and OpenAI as partners, is the most comprehensive platform I have seen address this. NVIDIA contributes OpenShell, an open-source runtime for deploying autonomous agents safely, plus NIM microservices with Nemotron models for on-premises customers. Okta handles cross-agent identity management and policy enforcement across the entire agent fleet. Cisco AI Defense provides an agent-specific threat detection layer that conventional network monitoring cannot replicate. OpenAI enables production workflows on its latest models, including GPT-5.5.</p>



<p>The platform gives IT a single governance surface: centralized policy, behavioral monitoring and auditable observability across every agent regardless of where it runs. The core principle is that no agent, cloud-hosted or running locally on a laptop, operates outside a defined policy boundary. EnterpriseClaw is currently in preview, with general availability expected later in 2026.</p>



<h2 class="wp-block-heading">Accountability cannot be an afterthought</h2>



<p>Building governance into LaptopAI-Agent took deliberate effort: a permission guard with path allowlists, blocked commands, manual approval triggers and a chained audit log. That overhead for a personal tool on a single laptop previews what enterprises face at an orders-of-magnitude larger scale, across systems they did not build and agents they did not deploy themselves.</p>



<p>The tools are available. The architectural patterns are documented. What is missing in most organizations is the deliberate decision to build governance in parallel with deployment, not as remediation after the first incident.</p>



<p>Every shadow agent in your environment was approved somewhere, by someone, for a specific purpose. The question is whether you still have a current, verifiable line from that approval to what the agent is doing right now. If the answer is no, or we are not sure, that is exactly where the work needs to start.</p>



<p>Shadow agents are not a future problem. They are in production today, summarizing documents, routing decisions and interacting with systems your monitoring tools cannot observe. IT leaders who build real accountability infrastructure around them will be positioned to harness autonomous AI with confidence. The ones who wait will spend their time explaining, after the fact, how something happened that nobody could see.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Preventing agent-generated infrastructure bloat through spec-driven governance]]></title>
<description><![CDATA[Autonomous AI engineer agents can deliver software at a scale in multiples of what a human engineering team can do, and that productivity is genuinely valuable. But without proper guardrails at the specification level, these agents can industrialise inefficient infrastructure patterns at the same...]]></description>
<link>https://tsecurity.de/de/3637960/ai-nachrichten/preventing-agent-generated-infrastructure-bloat-through-spec-driven-governance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637960/ai-nachrichten/preventing-agent-generated-infrastructure-bloat-through-spec-driven-governance/</guid>
<pubDate>Wed, 01 Jul 2026 11:19:17 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Autonomous AI engineer agents can deliver software at a scale in multiples of what a human engineering team can do, and that productivity is genuinely valuable. But without proper guardrails at the specification level, these agents can industrialise inefficient infrastructure patterns at the same pace, consistently and at a scale that makes post-deploy remediation impractical. When an agent provisions a three-node GKE cluster using n2-standard-16 machines for a workload a single e2-medium node could handle, or generates a Kubernetes pod spec with 4-CPU and 8GB memory requests for a service that peaks at 200 milli-cores and 256MB, or writes a Dockerfile that pulls a full Ubuntu base image where a distro-less container would serve, infrastructure runs that decision continuously, for the lifetime of the service. The agent will reproduce these patterns across every environment it touches, because the specification never instructed it otherwise. When agentic pipelines are generating infrastructure at scale, operational remediation after the fact becomes impractical.</p>



<p>The scale of what is now being generated autonomously is significant. <a href="https://www.infoworld.com/article/3999607/how-to-succeed-or-fail-with-ai-driven-development.html">InfoWorld’s reporting on AI-driven development</a> shows the pace of AI-generated output is accelerating sharply, and <a href="https://www.infoworld.com/article/3993479/what-we-know-now-about-generative-ai-for-software-development.html">projections suggest more than a quarter of new production code and configuration is already AI-generated</a>. What those projections do not yet capture is the shift from AI-assisted to fully agentic pipelines, where agents generate Terraform, Kubernetes manifests, Helm charts and Docker configurations end-to-end, commit them and trigger deployment, with no human in the loop or little oversight that concentrates on functional capabilities. When that pipeline runs without sustainability constraints, it systematically reproduces that infrastructure inefficiency across every environment it touches.</p>



<p>Green software has traditionally been an operational problem: Right-size the containers retrospectively, tune the cluster after the fact, schedule workloads in low-carbon windows. That approach was already struggling before agentic pipelines arrived. <a href="https://www.gartner.com/en/newsroom/press-releases/2024-05-16-gartner-identifies-the-top-five-strategic-technology-trends-in-software-engineering-for-2024">Gartner projects</a> that by 2027, just 30% of large enterprises will have software sustainability embedded in their non-functional requirements. That statistic carries a consequence most engineering leaders have not yet confronted: If 70% of enterprise code has been written without sustainability intent, then the training data autonomous AI engineer agents learned from is dominated by potentially unsustainable patterns. An agent defaults to the majority pattern in its training distribution, which is the inefficient one. This makes the specification constraint not just a governance need, but a corrective instruction that the agent’s training data never provided.</p>



<h2 class="wp-block-heading">Sustainable specification as a reliable intervention point</h2>



<p>In a fully agentic development pipeline, the specification is not a document an engineer reads before writing code. It is the instruction set the agent executes. It determines which machine types get provisioned, which container base images get selected, how pod resource requests are sized, how storage is allocated and how networking is configured. Every infrastructure decision the agent makes downstream is a function of what the specification permitted or left undefined.</p>



<p>If the specification contains no sustainability constraints, the agent will make infrastructure decisions based on defaults, conventions and training data patterns, none of which are optimised for energy efficiency. An agent prompted to scaffold a GKE-based microservice will, by default, select machine types that ensure availability headroom rather than efficiency. It will size pod resource requests conservatively to avoid out-of-memory conditions from potentially inefficient application code, but not to minimise node utilization. It will pull familiar base images rather than minimal ones. These are not failures of the agent. They are the predictable output of an instruction set that never asked for sustainability.</p>



<p>The fix is to make sustainability a first-class constraint in the specification itself. A constraint such as GS-INFRA-001 (select the smallest GKE machine type that satisfies the workload’s measured resource ceiling, defaulting to e2-medium or smaller) or GS-K8S-001 (set pod CPU requests to measured p95 consumption with a 20% ceiling, not to arbitrary safe values) is a structured policy the agent reads before it generates a single line of Terraform or YAML. The agent does not override it. It executes it. That is the mechanism that makes sustainability structural and automated rather than aspirational.</p>



<h2 class="wp-block-heading">The infrastructure patterns that matter most</h2>



<p>Three infrastructure domains represent the highest-impact targets for sustainability constraints, precisely because autonomous AI engineer agents generate them prolifically and the consequences compound continuously at runtime rather than only when code executes.</p>



<p>The first is IaC and cloud resource provisioning. An agent generating a Terraform configuration for a GKE cluster defaults to instance families and node counts calibrated for resilience, not efficiency. A three-node cluster of n2-standard-16 machines (64 vCPUs, 192GB RAM) provisioned for a service that runs comfortably on a single e2-medium (2 vCPUs, 4GB RAM) represents a 32x over-provisioning of compute. That gap does not show up in staging. It runs in production, is billed continuously, emitting continuously. A sustainability constraint in the Terraform specification that enforces machine type selection against a measured workload profile eliminates this class of error before the agent writes its first resource block.</p>



<p>The second is the Kubernetes pod resource configuration. Pod resource requests are the input the Kubernetes scheduler uses to place workloads on nodes. When an autonomous AI engineer agent generates a pod spec with generous CPU and memory requests, the scheduler reserves that capacity whether the pod uses it or not. Nodes that could host eight efficiently-sized pods instead host two or three over-specified ones, leaving the remaining capacity stranded and the underlying VM running at low utilization. A pod spec with a 4-CPU, 8GB memory request for a service that observably consumes 200 millicores and 256MB at peak is not cautious engineering. It is a scheduler instruction to waste three and a half CPUs and 7.75GB of memory per pod, per node, per hour, across every replica in every environment. A sustainability constraint specifying that pod resource requests must be derived from measured p95 consumption data, not from defaults or intuition, changes this systematically.</p>



<p>The third is the container base image selection. When an agent generates a Dockerfile, it gravitates toward familiar, full-featured base images: Ubuntu, Debian, Python, Node.js. These images are large, carry a significant attack surface and consume more storage, memory and transfer bandwidth than their minimal equivalents. A distroless or Alpine-based image for the same workload can be an order of magnitude smaller. At the scale at which an autonomous AI engineer agent operates, pulling, storing and running bloated base images across hundreds of services is a significant and entirely avoidable infrastructure cost. A constraint specifying distroless or minimal base images as the default, with justification required for exceptions, eliminates the pattern without slowing generation.</p>



<h2 class="wp-block-heading">4 pipeline stages where constraints are enforced</h2>



<p>Embedding constraints in the specification is the intervention. Enforcing them through the pipeline is what makes the intervention reliable. Four stages create the enforcement architecture.</p>



<p>The first stage is generation itself. When sustainability constraints are part of the specification the autonomous AI engineer agent operates from, those constraints shape every artifact the agent produces: Terraform resource blocks, Kubernetes manifests, Helm chart defaults, Dockerfile base image selections. The agent does not reason about sustainability independently. It executes the specification. A well-constrained specification produces sustainable infrastructure by construction, not by review.</p>



<p>The second stage is static analysis. Tools including Checkov, tfsec, KICS and Trivy analyze Terraform, Kubernetes YAML and Dockerfiles against configurable policy rules without modifying the agent or the pipeline architecture. A Checkov policy enforcing the GKE machine type constraint, or a tfsec rule flagging over-provisioned node pools, runs against every artifact the agent generates before it reaches a deployment gate. The violation surfaces as structured CI output the gate acts on. The agent’s output is checked the same way a human engineer’s output would be, consistently, at every commit.</p>



<p>The third stage is the quality gate. Sustainability violations fail the build. They do not generate warnings that an agent pipeline has no mechanism to act on. A gate that blocks deployment on policy violations is the enforcement layer that makes constraints binding rather than advisory. Because the gate operates on artifact output rather than on the agent itself, it is fully autonomous AI engineer agent-agnostic: It does not matter whether the Terraform was generated by Copilot, a custom LLM pipeline, an internal scaffolding agent or a human engineer. The gate evaluates the artifact against the policy. That is the only thing that matters.</p>



<p>The fourth stage is runtime telemetry feeding back into constraint refinement. Actual resource utilization, node efficiency metrics and carbon intensity data from production inform constraint updates at the specification level. A constraint calibrated on design-time estimates tightens over time as empirical data replaces assumptions. The governance model improves continuously rather than stagnating at its initial calibration.</p>



<h2 class="wp-block-heading">3 steps to start this week</h2>



<p>Most engineering organizations already have everything they need to begin. The static analysis toolchain is there: Checkov, tfsec, KICS, Trivy and OPA Conftest all support configurable sustainability policies against Terraform, Kubernetes YAML and Dockerfile artifacts without pipeline replacement. The CI/CD pipeline is there: GitHub Actions, GitLab CI, Jenkins, Tekton and Azure DevOps Pipelines all support blocking quality gates against policy tool outputs. The specification layer is there: Terraform modules, Helm chart value schemas, Kubernetes admission controllers and architectural decision records are already version-controlled in most mature engineering organizations. And critically, this approach is a fully autonomous AI engineer agent-agnostic. The governance layer does not inspect which agent or model generated the infrastructure artifact. It enforces the policy against the output. Whether the Terraform came from a custom agentic pipeline, a Copilot suggestion or a human engineer, the gate applies identically. The only things genuinely missing are the sustainability constraint definitions authored into the specification and the policy rules wired into the CI/CD pipeline to enforce them. Three steps close that gap.</p>



<ol class="wp-block-list">
<li><strong>Audit your IaC specifications for sustainability constraints.</strong> Open an active Terraform module or Helm chart and locate the machine type defaults, pod resource request defaults and base image defaults. For most organizations, these are set to safe, familiar values with no sustainability rationale. Define three constraints: A maximum machine type ceiling for each workload tier, a pod resource request ceiling derived from measured utilization, and a base image policy requiring distro-less or Alpine equivalents. Version control these constraints alongside the specifications they govern.</li>



<li><strong>Add one Checkov or tfsec policy to your CI pipeline.</strong> A policy flagging GKE node pools configured above the e2-standard-4 threshold without a documented justification is implementable in under an hour using Checkov’s custom check API. Wire it as a blocking gate, not a warning. This single addition creates immediate, agent-agnostic enforcement across every Terraform commit in your repository.</li>



<li><strong>Embed sustainability constraints before you scale your agentic pipelines.</strong> The highest-leverage moment is now, before autonomous AI engineer agents are generating infrastructure at full organizational scale. Every agentic pipeline that goes into production without sustainability constraints in its specification becomes a systematic source of over-provisioned, carbon-intensive infrastructure that compounds daily. Retrofitting governance after hundreds of agent-generated services are running is an order of magnitude harder than constraining generation at the specification source.</li>
</ol>



<h2 class="wp-block-heading">What lies ahead</h2>



<p>The sustainability challenge discussed here is not the energy consumed by the AI engineer agent itself, but the long-lived infrastructure decisions encoded into the artifacts it generates. Sustainable infrastructure engineering is no longer an operational discipline. It is an architectural necessity, and the specification layer is where that necessity must be addressed. When autonomous AI engineer agents are generating Terraform, Kubernetes manifests and Docker configurations at scale, the organizations that embed sustainability constraints into the specifications those agents execute will build efficient, cost-controlled, regulation-ready infrastructure by construction. Those that do not will build a remediation programme instead, which at scale will become impractical.</p>



<p>The urgency is not speculative. <a href="https://spectrum.ieee.org/green-software/particle-2">IEEE Spectrum reports</a> that Microsoft’s emissions have risen 23% since its 2020 baseline and Google’s have climbed 51% since 2019, with AI infrastructure as the primary driver. <a href="https://spectrum.ieee.org/firms-bet-climate-tech">Global data centres are on track to consume more electricity than Japan by 2030.</a> A significant fraction of that load is over-provisioned infrastructure that an autonomous AI engineer agent generated from a specification that never asked for efficiency. The constraint cost is low. The compounding cost of the alternative is not.</p>



<p>The governance imperative is converging from three directions simultaneously. Cloud cost: Over-provisioned AI-generated infrastructure compounds spend at a rate that makes early specification-layer control orders of magnitude cheaper than post-deployment rightsizing programmes. Technical debt: Every agentic sprint that ships infrastructure without sustainability constraints adds configuration debt that grows faster than any platform team can retrospectively correct. Regulatory pressure: Sustainability reporting requirements, already mandatory in the EU and accelerating in other jurisdictions, will reach infrastructure efficiency metrics. Engineering organizations that have operationalised sustainability governance at the specification layer will meet those requirements as a natural output of their existing pipeline. Those who have not will discover that compliance is a crisis programme when the deadline arrives. These are not abstract architectural concerns. The organizations that govern agentic generation upstream, at the specification, will compound efficiency gains with every agent run, not just sustainability but cost, too. Those who govern only in production will spend a lot of time remediating what they should have prevented before the first line of Terraform was written.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want </a><a href="https://www.infoworld.com/expert-contributor-network/">to</a><a href="https://www.cio.com/expert-contributor-network/"> join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Five tools to bolster your AI coding stack]]></title>
<description><![CDATA[Whether you are using an AI code generator, vibe coding, or applying spec-driven development methodologies, your job doesn’t end with AI writing the code. Whether you’re using AI to develop applications, APIs, data pipelines, AI agents, or other automations, writing the code is just one part of t...]]></description>
<link>https://tsecurity.de/de/3635032/ai-nachrichten/five-tools-to-bolster-your-ai-coding-stack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635032/ai-nachrichten/five-tools-to-bolster-your-ai-coding-stack/</guid>
<pubDate>Tue, 30 Jun 2026 11:18:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Whether you are using an <a href="https://www.infoworld.com/article/4032989/a-developers-guide-to-code-generation.html">AI code generator</a>, <a href="https://www.infoworld.com/article/4058076/vibe-coding-and-the-future-of-software-development.html">vibe coding</a>, or applying <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development.html">spec-driven development</a> methodologies, your job doesn’t end with AI writing the code. Whether you’re using AI to develop applications, APIs, <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">data pipelines</a>, <a href="https://www.infoworld.com/article/4105884/10-essential-release-criteria-for-launching-ai-agents.html">AI agents</a>, or other automations, writing the code is just one part of the job. Developers must still perform code validation, test applications, automate deployment, and configure infrastructure.</p>



<p>According to <a href="https://www.infoworld.com/article/3831759/developers-spend-most-of-their-time-not-coding-idc-report.html">one survey</a>, only 16% of a developer’s time is spent writing code. The remaining 84% is spent on <a href="https://www.atlassian.com/blog/ai-at-work/beyond-the-jira-board-how-autonomous-workflows-unlock-engineering-velocity">other activities</a> including defining requirements, triaging bugs, and addressing vulnerabilities.</p>



<p>Additionally, while AI code generation speeds up development, it can come at the cost of quality and collaboration. In Atlassian’s <a href="https://www.atlassian.com/blog/state-of-teams-2026">State of Teams 2026</a> survey, nearly 50% of respondents say their AI outputs aren’t reliably high quality and admit that using AI is a compromise between speed and quality. Knowledge workers say the pressure to execute is also problematic, with 87% saying they lack time to coordinate and 70% saying their processes aren’t well-optimized for AI.</p>



<p>So, although AI capabilities have changed drastically in the past few years, code-generation tools are not the only ways <a href="https://www.infoworld.com/article/3993479/what-we-know-now-about-generative-ai-for-software-development.html">AI can improve software development</a>. In fact, developers should seek additional AI capabilities to support the full software development life cycle (SDLC). Here are five recommendations for the AI coding stack. </p>



<h2 class="wp-block-heading">Scale up testing environments</h2>



<p>If coding is faster, development teams should have suitably configured environments that they can use to quickly and easily test changes against real APIs and databases. Testing apps and AI agents against environments that don’t mimic production can slow down development. </p>



<p><a href="https://metalbear.com/mirrord/docs/use-cases/local-development" data-type="link" data-id="https://metalbear.com/mirrord/docs/use-cases/local-development">“Remote + local” development environments</a> (local execution with remote context) are one option to accelerate testing. Developers can code locally on their own physical or virtual machine, but build and deploy to remote instances. Additionally, when developing AI agents, developers need an execution environment, such as secure sandboxes or ephemeral virtual machines.</p>



<p>“GenAI has been a step-change for developer productivity, absorbing the repetitive work of writing boilerplate, tests, and refactors so engineers can focus on intent and design,” says Aviram Hassan, CEO and cofounder at <a href="https://metalbear.com/">MetalBear</a>. “But by compressing the time it takes to produce all of this, genAI has also exposed what’s always been the real bottleneck in the SDLC: the feedback loop against the real world. Validating code and configurations against a realistic cloud environment still depends on the same slow build-and-deploy cycles teams have tolerated for years.”</p>



<p>The goal should be to remove the friction and delays from where developers code to a complete, real-world infrastructure they can use to validate changes. Three tools to review are <a href="https://metalbear.com/mirrord/">mirrord</a>, <a href="https://www.signadot.com/">Signadot</a>, and <a href="https://telepresence.io/">Telepresence</a>.</p>



<h2 class="wp-block-heading">Validate the AI-generated code</h2>



<p>At a recent <a href="https://drive.starcio.com/coffee-with-digital-trailblazers/">Coffee With Digital Trailblazers</a> LinkedIn Live event that I hosted on <a href="https://drive.starcio.com/podcast/ai-coding-competencies-hype-realities-and-the-future/">AI coding competencies</a>, one speaker shared how he quickly went from a short spec to more than 10,000 lines of AI-generated code. He admitted he didn’t have the time, expertise, or tools to validate the code. He’s not alone. In Sonar’s <a href="https://www.sonarsource.com/resources/developer-survey-report/">State of Code Developer Survey</a>, 96% of developers don’t fully trust AI’s output, but only 48% always verify it before committing.</p>



<p>“Agentic software development is generating code faster than any team can manually review it, but speed without confidence only results in technical debt,” says Scott Sanders, corporate vice president of engineering at <a href="https://www.sonarsource.com/">Sonar</a>. “What’s needed to avoid this is an automated independent verification layer embedded directly into the development workflow—one that unifies code quality and code security into a single, deterministic platform to deliver actionable intelligence before code ever reaches the repository.”</p>



<p>A big concern is that AI-generated code can produce 1.4 times as many critical issues as code created by developers, according to CodeRabbit’s <a href="https://www.coderabbit.ai/blog/state-of-ai-vs-human-code-generation-report">State of AI Versus Human Code Generation Report</a>. Top issues include code readability, cross-site scripting, code formatting errors, and incorrect concurrency control.</p>



<p>Another challenge is that 82.4% of AI tools originate from third-party packages, according to Snyk’s <a href="https://snyk.io/lp/state-of-agentic-ai-adoption/">2026 State of Agentic AI Adoption</a>. The implication is that development teams have much more code to validate than they develop themselves, whether by humans or AI code generators.</p>



<p>“When tools like Cursor are installing dependencies and running actions on a developer’s behalf, they can unintentionally pull in malicious or unvetted packages,” says Randall Degges, vice president of AI engineering and developer relations at <a href="https://snyk.io/">Snyk</a>. “That’s why techniques like intercepting tool calls, validating inputs and outputs, enforcing least-privilege access, and isolating credentials are becoming foundational to how AI-driven development systems operate. Without security embedded directly into the agent loop, teams risk shipping faster into more exposure, not less.”</p>



<p>According to Qodo’s report on <a href="https://www.qodo.ai/resources/the-ai-coding-paradox/">The AI Coding Paradox</a>, 89% of enterprise engineering teams have experienced an AI-generated code incident and have had a production outage caused by AI-generated code. Development teams building a large portfolio of AI agents or heavily relying on AI code-generation capabilities may want to look at AI code-review tools that provide more contextual analysis than basic static code review tools.</p>



<p>“Current AI coding assistants suffer from a severe amnesia problem, and each session starts without memory of an organization’s unique context, subjective standards, and business logic,” says Itamar Friedman, CEO and cofounder at <a href="https://qodo.ai/">Qodo</a>. “To safely scale AI, it requires integrating stateful systems equipped with persistent organizational memory that continuously learn from past pull requests and automatically enforce enterprise-specific governance. Ultimately, developers need tools that ensure code is guided by continuously learning organizational experience rather than just raw machine-generated code.”</p>



<p>Tools to review include static application security testing (SAST), software composition analysis (SCA), software bill of materials (SBOM), and AI code review tools.</p>



<h2 class="wp-block-heading">Security and end-to-end testing</h2>



<p>Even when AI-generated code passes all the tests, how can devops teams validate whether it meets business and <a href="https://www.infoworld.com/article/4061123/how-to-write-nonfunctional-requirements-for-ai-agents.html">non-functional technical requirements</a>? Many devops teams have invested in <a href="https://www.infoworld.com/article/3705049/3-ways-to-upgrade-continuous-testing-for-generative-ai.html">continuous testing</a>, and some support <a href="https://www.infoworld.com/article/3663055/are-you-ready-to-automate-continuous-deployment-in-cicd.html">continuous deployment</a>, but the underlying assumptions behind those practices are being challenged now by who is coding and how much code is being generated. </p>



<p>Some spec-driven development platforms aim to bridge the gap. Tools like <a href="https://docs.appian.com/suite/help/26.4/plan-view.html">Appian Composer</a> and <a href="https://www.sap.com/products/artificial-intelligence/joule-studio.html">SAP Joule Studio 2.0</a> generate product requirements documents (PRDs) before coding, enabling the introduction of business acceptance criteria. These tools create knowledge graphs from the business processes implemented on their platforms and provide environments for validating AI agents before deployment.</p>



<p>“For most organizations, the AI code-generation methodology question matters less than the verification question,” says Gal Vered, CEO and cofounder at <a href="https://checksum.ai/">Checksum.ai</a>.  “Whether your team is prompting from intent or working from specs, AI-generated code still needs to be validated against a production environment before it ships.”</p>



<p>Beyond functional testing, developers must look at new security concerns, especially as AI agents integrate with <a href="https://www.infoworld.com/article/4124612/5-requirements-for-using-mcp-servers-to-connect-ai-agents.html">Model Context Protocol servers</a>. “Most teams are stacking generation tools on top of review tools and on top of testing tools, but without security validation embedded at every stage, you’re just automating the path to your next breach,” says Harshit Agarwal, CEO at <a href="https://www.appknox.com/">Appknox</a>. “Mature teams treat security feedback as a non-negotiable part of the build loop, running automated checks continuously rather than catching issues after the fact.”</p>



<h2 class="wp-block-heading">Add observability tools </h2>



<p>Developers save an average of 3.6 hours per week with AI coding tools, <a href="https://getdx.com/blog/ai-assisted-engineering-q4-impact-report-2025/#developers-save-an-average-of-36-hours-per-week-with-ai-coding-tools">according to one report</a>, and the more experienced engineers achieve the largest productivity gains.</p>



<p>What’s one way to blow these savings? When defects get pushed to production, it’s often the <a href="https://www.infoworld.com/article/3689881/career-paths-for-devops-engineers-and-sres.html">site reliability engineers</a> and senior developers who are left to triage and resolve the issue. Establishing <a href="https://www.infoworld.com/article/3686056/best-practices-for-devops-observability.html">observability practices</a> as a <a href="https://drive.starcio.com/2025/01/important-devsecops-non-negotiables/">devops non-negotiable</a> is a development investment that pays off significantly to help diagnose issues, resolve errors, and improve performance.</p>



<p>“In data and AI systems, even small changes like model updates, tool decisions, or shifts in data flow can silently cascade into issues no one anticipated, and the AI agent has no way to know that,” says Barr Moses, cofounder and CEO at <a href="https://www.montecarlodata.com/">Monte Carlo</a>. “Leading teams are addressing this by embedding observability across the entire agentic stack, particularly at precommit checkpoints, so agents can surface the true impact of changes before they go live.”</p>



<p>While many devops teams have mature observability practices for APIs, applications, and data integrations, <a href="https://www.infoworld.com/article/4140832/7-safeguards-for-observable-ai-agents.html">observability practices for AI agents</a> are relatively new. One technique to consider is <a href="https://www.montecarlodata.com/blog-best-ai-observability-tools/">AI tracing platforms</a> with notation queues for human review and <a href="https://www.evidentlyai.com/llm-guide/llm-as-a-judge">LLM-as-judge</a> evals. A second option is to implement an <a href="https://startupstash.com/top-ai-gateways/">AI gateway</a> with observability, caching, routing, and cost-tracking capabilities.</p>



<h2 class="wp-block-heading">Develop reusable agent skills</h2>



<p>One last element of the AI stack, especially for organizations heavily investing in AI agent development, is to adopt best practices for developing reusable skills embedded in code-generating tools.</p>



<p>“A key emerging pattern is purpose-built AI skills: reusable, scoped instructions that give agents deep context for specific tasks, rather than relying on general-purpose prompting alongside antagonist agents that challenge other agents’ outputs,” says Phillip Goericke, CTO of <a href="https://www.nmi.com/">NMI</a>. “The defining shift is that developers are no longer writing code with AI assistance—they’re architecting the systems that produce and validate it.”</p>



<p>Development organizations that leverage code-generation tools are recognizing that coding is just one part of delivering <a href="https://drive.starcio.com/2026/02/why-chaotic-ai-experiments-arent-producing-business-value/">business value from AI</a> and <a href="https://www.infoworld.com/article/4105884/10-essential-release-criteria-for-launching-ai-agents.html">resilient AI agents</a>. Developing AI skills and establishing an AI stack are steps toward scaling to a dependable AI software development life cycle.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple's $502M payment to Optis over patent infringement goes to UK Supreme Court]]></title>
<description><![CDATA[Apple is contesting a ruling that would force it to pay Optis $502 million for LTE patent infringement, but the UK Supreme Court has yet to reach a verdict.Apple seeks to avoid paying Optis $502 million over alleged patent infringement.The legal battle between Apple and Optis goes back to Februar...]]></description>
<link>https://tsecurity.de/de/3634209/ios-mac-os/apples-502m-payment-to-optis-over-patent-infringement-goes-to-uk-supreme-court/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634209/ios-mac-os/apples-502m-payment-to-optis-over-patent-infringement-goes-to-uk-supreme-court/</guid>
<pubDate>Tue, 30 Jun 2026 01:08:51 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is contesting a ruling that would force it to pay Optis $502 million for LTE patent infringement, but the UK Supreme Court has yet to reach a verdict.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68112-143567-iPhone-Air-xl.jpg" alt="Back of a white iPhone with a single rear camera and flash on a raised module, Apple logo centered, against a soft blue blurred background" height="738"><br><span>Apple seeks to avoid paying Optis $502 million over alleged patent infringement.</span></div><br>The legal battle between Apple and Optis goes back to <a href="https://appleinsider.com/articles/19/02/26/apples-iphone-ipad-more-targeted-in-new-lawsuit-over-lte-patents">February 2019</a>, and there's still no end in sight all these years later. Apple was accused of infringing upon Optis' LTE patents, which ultimately led to lawsuits in both the United Kingdom and the United States.<br><br>The latter case resulted in Apple's victory, as it avoided paying Optis $300M in damages in <a href="https://appleinsider.com/articles/26/02/13/third-optis-jury-trial-results-in-a-victory-for-apple-in-the-us">February 2026</a>. The outcome of the UK lawsuit, however, isn't quite as clear-cut.<br><br><br> <a href="https://appleinsider.com/articles/26/06/29/apples-502m-payment-to-optis-over-patent-infringement-goes-to-uk-supreme-court?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244824?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[EU seeks AI independence as Austria proposes luring Anthropic to Europe]]></title>
<description><![CDATA[Austria's State Secretary for Digitalization, Alexander Pröll, is calling on the European Commission to explore bringing Anthropic to Europe. He's responding to the U.S. ban on advanced AI models from OpenAI and Anthropic for foreign users. The initiative is likely unrealistic, though. And the al...]]></description>
<link>https://tsecurity.de/de/3633705/ai-nachrichten/eu-seeks-ai-independence-as-austria-proposes-luring-anthropic-to-europe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633705/ai-nachrichten/eu-seeks-ai-independence-as-austria-proposes-luring-anthropic-to-europe/</guid>
<pubDate>Mon, 29 Jun 2026 19:48:39 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1376" height="768" src="https://the-decoder.com/wp-content/uploads/2026/06/usa_china_eu.png" class="attachment-full size-full wp-post-image" alt="" decoding="async"></p>
<p>        Austria's State Secretary for Digitalization, Alexander Pröll, is calling on the European Commission to explore bringing Anthropic to Europe. He's responding to the U.S. ban on advanced AI models from OpenAI and Anthropic for foreign users. The initiative is likely unrealistic, though. And the alternative floating in the background, Chinese AI models, would just trade one dependency for another.</p>
<p>The article <a href="https://the-decoder.com/eu-seeks-ai-independence-as-austria-proposes-luring-anthropic-to-europe/">EU seeks AI independence as Austria proposes luring Anthropic to Europe</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Der Übergang von der Theorie zur Praxis: So richten Sie Ihre eigene Serverumgebung ein]]></title>
<description><![CDATA[Viele Menschen müssen sich zunächst mithilfe von Kursen oder technischen
The post Der Übergang von der Theorie zur Praxis: So richten Sie Ihre eigene Serverumgebung ein first appeared on IT-LEARNER.]]></description>
<link>https://tsecurity.de/de/3633697/it-nachrichten/der-uebergang-von-der-theorie-zur-praxis-so-richten-sie-ihre-eigene-serverumgebung-ein/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633697/it-nachrichten/der-uebergang-von-der-theorie-zur-praxis-so-richten-sie-ihre-eigene-serverumgebung-ein/</guid>
<pubDate>Mon, 29 Jun 2026 19:47:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Viele Menschen müssen sich zunächst mithilfe von Kursen oder technischen</p>
<p>The post <a rel="nofollow" href="https://it-learner.de/der-uebergang-von-der-theorie-zur-praxis-so-richten-sie-ihre-eigene-serverumgebung-ein/">Der Übergang von der Theorie zur Praxis: So richten Sie Ihre eigene Serverumgebung ein</a> first appeared on <a rel="nofollow" href="https://it-learner.de/">IT-LEARNER</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to watch Germany vs Paraguay: Free Streams, TV Channels & Kick-Off time for FIFA World Cup 2026 as Julian Nagelsmann seeks improvement]]></title>
<description><![CDATA[Here's how to watch Germany vs Paraguay for free online and from anywhere at the FIFA World Cup 2026, with a place in the last-16 at stake in Boston.]]></description>
<link>https://tsecurity.de/de/3633693/it-nachrichten/how-to-watch-germany-vs-paraguay-free-streams-tv-channels-kick-off-time-for-fifa-world-cup-2026-as-julian-nagelsmann-seeks-improvement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633693/it-nachrichten/how-to-watch-germany-vs-paraguay-free-streams-tv-channels-kick-off-time-for-fifa-world-cup-2026-as-julian-nagelsmann-seeks-improvement/</guid>
<pubDate>Mon, 29 Jun 2026 19:47:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Here's how to watch Germany vs Paraguay for free online and from anywhere at the FIFA World Cup 2026, with a place in the last-16 at stake in Boston.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple accuses India of ‘copy-pasting’ rivals’ claims in antitrust probe, seeks to quash findings]]></title>
<description><![CDATA[Apple has sharply criticized Indian antitrust investigators, accusing them of "copy-pasting" allegations from its competitors rather than…
The post Apple accuses India of ‘copy-pasting’ rivals’ claims in antitrust probe, seeks to quash findings appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3633459/ios-mac-os/apple-accuses-india-of-copy-pasting-rivals-claims-in-antitrust-probe-seeks-to-quash-findings/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633459/ios-mac-os/apple-accuses-india-of-copy-pasting-rivals-claims-in-antitrust-probe-seeks-to-quash-findings/</guid>
<pubDate>Mon, 29 Jun 2026 18:09:34 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple has sharply criticized Indian antitrust investigators, accusing them of "copy-pasting" allegations from its competitors rather than…</p>
<p>The post <a href="https://macdailynews.com/2026/06/29/apple-accuses-india-of-copy-pasting-rivals-claims-in-antitrust-probe-seeks-to-quash-findings/">Apple accuses India of ‘copy-pasting’ rivals’ claims in antitrust probe, seeks to quash findings</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple seeks Trump admin approval to buy memory chips from blacklisted Chinese company]]></title>
<description><![CDATA[Apple is lobbying the Trump administration for permission to purchase memory chips from ChangXin Memory Technologies Inc. (CXMT), a Chinese…
The post Apple seeks Trump admin approval to buy memory chips from blacklisted Chinese company appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3633128/ios-mac-os/apple-seeks-trump-admin-approval-to-buy-memory-chips-from-blacklisted-chinese-company/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633128/ios-mac-os/apple-seeks-trump-admin-approval-to-buy-memory-chips-from-blacklisted-chinese-company/</guid>
<pubDate>Mon, 29 Jun 2026 16:09:06 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple is lobbying the Trump administration for permission to purchase memory chips from ChangXin Memory Technologies Inc. (CXMT), a Chinese…</p>
<p>The post <a href="https://macdailynews.com/2026/06/29/apple-seeks-trump-admin-approval-to-buy-memory-chips-from-blacklisted-chinese-company/">Apple seeks Trump admin approval to buy memory chips from blacklisted Chinese company</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem]]></title>
<description><![CDATA[Written by: James Sadowski, Alden Wahlstrom

Introduction
Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we hav...]]></description>
<link>https://tsecurity.de/de/3633127/it-security-nachrichten/the-bear-necessities-a-look-at-the-drivers-dynamics-and-applications-of-the-pro-russia-influence-ecosystem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633127/it-security-nachrichten/the-bear-necessities-a-look-at-the-drivers-dynamics-and-applications-of-the-pro-russia-influence-ecosystem/</guid>
<pubDate>Mon, 29 Jun 2026 16:07:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: James Sadowski, Alden Wahlstrom</p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction</span></h3>
<p><span>Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we have witnessed the expedited development of new influence assets linked to multiple, expansive, covert information operations (IO) campaigns and a </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/global-revival-of-hacktivism"><span>revitalization</span></a><span> of pro-Russia hacktivism at an unprecedented scale. While this threat activity initially adapted to encompass Ukraine-related priorities, it is gradually pivoting back to established Russian influence objectives for which the ecosystem was originally honed. This shift is significant because it likely signals increased focus outside of Ukraine, warning that pro-Russia influence activity targeting the European Union (EU), North Atlantic Treaty Organization (NATO), and other top targeting priorities may intensify. </span></p>
<p><span>Ultimately, the war in Ukraine has provided a critical feedback loop for Russia to refine its influence activity, lessons that we anticipate will be applied as the ecosystem continues to reorient toward global strategic objectives while maintaining focus on Ukraine. Further, recent pro-Russia IO indicates the continued expansion of already diverse tactics, and the increasing use of </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai"><span>generative AI tooling</span></a><span> for planning, research, and content creation marks a forward trend in pro-Russia IO. Meanwhile, new and different actors have adopted IO tactics to meet an increasingly diverse set of challenges, signaling growing Russian reliance on influence tactics. Together, these trends likely demonstrate the Kremlin's perception of these tactics as cost effective and successful. The interconnected nature of the ecosystem's disparate components makes it resilient to limited scope disruptions, which defenders must consider to effectively mitigate pro-Russia influence threats. </span></p>
<h3><span>The Ecosystem at a Glance: Objectives, Targeting, and Tactics</span></h3>
<p><span>Russia's modern approach to information operations is built on the conceptual foundation of Soviet-era "</span><a href="https://www.marshallcenter.org/en/publications/security-insights/active-measures-russias-covert-geopolitical-operations-0" rel="noopener" target="_blank"><span>active measures</span></a><span>" adapted for the digital age. Alongside disruptive cyberattacks dating back to the early 2000s, the Kremlin has increasingly harnessed internet-based platforms for espionage and information operations. Russia's approach has evolved from rudimentary, singular operations into a complex, self-sustaining environment intentionally curated by the Russian Government that blends overt, covert, and independent elements to advance Kremlin interests both at home and abroad.</span></p>
<h4><span>Core Influence Objectives </span></h4>
<p><span>GTIG’s observations suggest the primary strategic motivations driving the pro-Russia influence ecosystem fall into five categories, each aiming to achieve military and/or political objectives through psychological manipulation of the target audience (Figure 1). Collectively, these objectives informally depict a global influence strategy: through the furthest reach of its influence, the Kremlin seeks to diminish Western primacy and advance Russia's global position; within its surrounding region, it strives to retain and return Moscow's dominance; and at home, it works to ensure the stability of the political regime.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig1.max-1000x1000.png" alt="Core objectives of the pro-Russia influence ecosystem">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="sfic5">Figure 1: Core objectives of the pro-Russia influence ecosystem</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h5><span>Targeting</span><span> </span></h5>
<p><span>Pro-Russia influence operations are pivoting from the </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/information-operations-surrounding-ukraine"><span>near singular focus on Ukraine</span></a><span> that dominated the ecosystem since 2022. We expect influence operations advancing Russia's war-specific interests to continue. However, as Russia seeks to reemerge from international isolation, we have increasingly observed a concurrent focus on pre-war pro-Russia influence objectives. </span></p>
<p><span>The current and historical targeting scope of each ecosystem component exposes both the Kremlin's global ambitions and the realistic limitations of its power projection. State-owned media organizations produce content intended to serve populations across six continents, but in recent years, sanctions and other factors have limited its production and distribution. Meanwhile, covert operations have appeared more limited in scope, primarily targeting the West and countries surrounding Russia, with intermittent operations targeting the Middle East and Africa, indicating that finite resources necessarily limit these operations (Figure 2).</span></p>
<h5><span>Top Regional Targets</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><strong>The United States and Europe:</strong><span> The Kremlin has long viewed the West as a top adversary of Russia. Accordingly, the US and Europe are top targets of covert pro-Russia information operations, especially aimed at undermining political stability within these countries and the unity between them. </span><span>NATO and the EU embody the collective "West" and are Russia's perceived top adversaries</span><span>, second only to the US independently.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Russia's "Near Abroad":</strong><span> Since the dissolution of the Soviet Union, Moscow has asserted that the countries that formerly comprised part of the USSR now reside in Russia's so-called "sphere of influence." Covert influence targeting this region directly reflects Moscow's assertion that Russia is a world power entitled to special privileges within its neighborhood. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>The Middle East and Africa:</strong><span> Over the past decade, Russian efforts to reassert itself as a global power have included high-profile investments in cultivating Russia's standing in the Middle East and </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/io-campaigns-russian-prigozhin-persist"><span>Africa</span></a><span>. Covert pro-Russia influence activity is likely deployed in tandem as intended support for other Russian initiatives in these regions.  </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Russia Domestic:</strong><span> Internally targeted covert IO is a well-established component of pro-Russia influence activity, deployed by regime-aligned actors to promote Kremlin policies and repress opposition voices. </span></p>
</li>
</ul>
<h5><span>Targeted Entities and Global Events</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><strong>The Olympics:</strong><span> Russia has long viewed Olympic participation as a point of national prestige, and GTIG has observed notable Russian influence activity targeting the </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/cyber-threats-2024-paris-olympics"><span>Olympics</span></a><span> in the face of Russian participation bans. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>War in Ukraine:</strong><span> The </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/information-operations-surrounding-ukraine"><span>war in Ukraine</span></a><span> has been a key driver of Russia's influence activity, including attempts to influence events on the ground as well as influence activity intended to advance Moscow's interests elsewhere vis-a-vis the war. GTIG expects that Ukraine will remain a priority in Russia's targeting calculus during the post-conflict phase following any future peace agreements.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Elections:</strong><span> Election targeting aligns with multiple Russian influence objectives, including attempting to undermine confidence in democratic institutions as well as internally weakening perceived Western adversaries. These operations regularly target elections in countries that are already prioritized by ongoing pro-Russia influence activity. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Ad Hoc Geopolitical Flashpoints and Global Events:</strong><span> Russian influence actors have a history of pivoting activity to engage with emerging geopolitical developments and events, such as the </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/limited-shifts-cyber-threat-landscape-driven-covid-19?e=48754805"><span>COVID-19 </span></a><span>pandemic or the</span><a href="https://apnews.com/article/iran-war-images-misinformation-russia-israel-9e495017dc5c4bf24a0b6152863dbfb1" rel="noopener" target="_blank"><span> 2026 Middle East </span></a><span>conflict. This flexible target selection often overlaps or is aligned with other Russian priorities, making previously observed Russian influence activity helpful in anticipating which events may be appropriated.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig2.max-1000x1000.png" alt="Priority targets of the ecosystem">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="7460p">Figure 2: Priority targets of the ecosystem</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h5><span>Tactics</span><span> </span></h5>
<p><span>Converging geopolitical and technological developments make the evolution of pro-Russia influence tactics a particularly important space to monitor right now. The pro-Russia influence ecosystem expanded to support the war effort, bringing change across the spectrum of activity and providing operators the opportunity to hone their tactics, techniques, and procedures (TTPs) in the rapid feedback loop of war. Meanwhile, the emergence and increased democratization of </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use"><span>generative AI</span></a><span> tooling has brought both promised and already realized opportunities to support all phases of the IO lifecycle. The following are a sample of key tactics that illustrate how pro-Russia actors currently blend well-tested methods with new technological developments to reach audiences through diverse means:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Generative AI: </strong><span>GTIG </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai"><span>has observed</span></a><span> pro-Russia influence actors increasingly leverage AI tooling to support different stages of their operations, including support for planning and general research as well as content creation.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Google Threat Intelligence Group (GTIG) is closely tracking the transition from nascent AI-enabled operations to the maturing, industrial-scale application of generative models within adversarial workflows across threats ranging from espionage and crime to IO. Please see our latest </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access"><span>AI threat tracker</span></a><span> for more information on how this threat is developing based on our insights, and what Google is doing to protect our customers. </span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><strong>Narrative Resonance:</strong><span> Hijacking existing ideological and emotional fissures within a society provides pro-Russia influence actors tailored narratives to target audiences and potentially increases potential engagement and impact. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Cyber-Enabled IO:</strong><span> Influence campaigns frequently coincide with destructive cyberattacks, such as the deployment of </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/gru-disruptive-playbook?e=48754805"><span>wiper malware</span></a><span> alongside website defacements containing false surrender messages, or the historic use of "hack and leak" campaigns in which exfiltrated data, sometimes manipulated, is then publicized through an actor-controlled false persona. In some instances, Russian actors may even leverage direct cyber espionage targeting as a way to achieve psychological effects, intending to influence victims' behavior through intimidation.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Media Mimicry:</strong><span> Pro-Russia actors have attempted to mimic legitimate media at scale and through a variety of means, including via the wholesale appropriation of legitimate media brands or developing inauthentic media brands that generally masquerade as independent news sources. These tactics are intended to add a veneer of legitimacy to the promoted narratives. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Direct Dissemination: </strong><span>Pro-Russia influence actors have used closed communication channels, such as emails, SMS text messages, and messenger apps, to disseminate various types of pro-Russia narratives as an adjunct to or outside typical social media-focused operations. </span></p>
</li>
</ul>
<h4><span>Core Ecosystem Components </span></h4>
<p><span>The current pro-Russia influence ecosystem operates across a spectrum from official government communications to deniable covert actions conducted by intelligence services and "patriotic" proxies. GTIG identified six core components that represent key activity types (Figure 3). While many elements are state-directed or state-affiliated, the ecosystem is also a cultivated, self-sustaining system: various actors, often without explicit direction, amplify Kremlin-friendly narratives and pursue actions that advance Russia's strategic interests. This fluidity provides resilience and complicates attribution, mirroring the longstanding Kremlin strategy to co-opt non-state actors, including criminal networks for </span><a href="https://www.rusi.org/explore-our-research/publications/commentary/operation-destabilise-russia-organised-crime-and-illicit-finance" rel="noopener" target="_blank"><span>finance</span></a><span> or </span><a href="https://www.bbc.com/news/articles/cz91dk0l50no" rel="noopener" target="_blank"><span>illicit logistics</span></a><span>, to achieve state objectives without direct attribution. Although each of the core ecosystem components serves as a unique lever the Russian Government can employ to achieve desired objectives, they are regularly used together. For instance, while the entire pro-Russia hacktivist landscape is not state-sponsored, the Russian intelligence services have used both genuine and fabricated hacktivist personas to launder stolen data as part of blended cyber espionage and IO hybrid operations.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig3.max-1000x1000.png" alt="Core components of the pro-Russia influence ecosystem">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="7460p">Figure 3: Core components of the pro-Russia influence ecosystem</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h5><span>An Interconnected Ecosystem Enhances Influence Utility</span></h5>
<p><span>Figure 4 illustrates the complex, interconnected nature of the pro-Russia influence ecosystem by mapping relationships between a selection of key actors and organizations across five of the core components. The ecosystem functions as a cohesive unit, not only through shared objectives, but also through direct cross-component interactions. The Russian Government functions as the sixth core ecosystem component, setting the policy and talking points that inform the ecosystem’s promoted narratives and sponsoring overt and covert assets throughout the other five components diagrammed in Figure 4. Through these levers, the Kremlin fosters the cross-component links that underpin the ecosystem, enhancing its overall utility as a versatile tool of state influence.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig4.max-1000x1000.png" alt="Subset of actors that illustrate how different components of the ecosystem interact with each other">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="df0ri">Figure 4: Subset of actors that illustrate how different components of the ecosystem interact with each other</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>10 Key Dynamics for Understanding the Pro-Russia Influence Ecosystem</span></h4>
<p><span>The scope and diversity of activity in the pro-Russia influence ecosystem challenges defenders tasked with enumerating, tracking, and countering its threats. GTIG has distilled 10 key ecosystem dynamics based on our current understanding of its components and how they each enable covert influence activity. These dynamics frame critical aspects of how activity manifests within the ecosystem, providing a high-level guide to understand and track these threats.</span></p>
<p><strong>Large-scale IO campaigns are an integral element of the pro-Russia influence ecosystem. </strong><span>Major pro-Russia IO campaigns have been an enduring feature of the pro-Russia ecosystem, with new campaigns emerging as previous ones fall into inactivity. Maintaining extensive IO campaigns and their associated established influence infrastructure enables proactive </span><a href="https://home.treasury.gov/news/press-releases/jy0628" rel="noopener" target="_blank"><span>messaging</span></a><span> on strategic issues and underpins a capability that can be rapidly adapted for emerging domestic and global priorities.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Long-established IO campaigns, like Secondary Infektion, </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/information-operations-surrounding-ukraine"><span>pivoted to meet</span></a><span> new strategic needs as Russia’s 2022 invasion of Ukraine began. New IO campaigns, such as “Operation Overload,” subsequently emerged to support the war effort; while Secondary Infektion has become dormant, these “successor” campaigns have since been leveraged to advance other global Russian influence objectives beyond the war itself. </span></p>
</li>
</ul>
<p><strong>Pro-Russia actors often prioritize persistence </strong><span>and the range of tactics they leverage reflects this. In the face of public exposure and disruption, pro-Russia actors and their infrastructure have often remained persistent, sometimes making tactical adjustments to mitigate the effects of detection and disruption and other times continuing operations unabated. </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>These persistence tactics include the Doppelganger campaign and overt </span><a href="https://www.bloomberg.com/news/articles/2023-11-23/ukraine-war-how-kremlin-propaganda-websites-dodge-disinformation-sanctions#xj4y7vzkg" rel="noopener" target="_blank"><span>Russian media</span></a><span>’s respective cycling of domain infrastructure and/or use of mirror domains to overcome exposure, platform bans and sanctions. Influence operators also frequently continue using compromised assets, sometimes mocking their exposure, as seen with the legacy US-targeted NAEBC campaign and the APT44-affiliated hacktivist persona XakNet Team.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig5.max-1000x1000.png" alt="NAEBC-linked persona account">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="df0ri">Figure 5: NAEBC-linked persona account mocking public exposure of influence assets (left), and GRU-sponsored XakNet Team persona mocking then-Mandiant (now part of Google Threat Intelligence Group) attribution of the group’s activities to the GRU (right)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><strong>Pro-Russia and Russian cyber espionage groups leverage IO tactics to support their operations and weaponize stolen data and/or illicit access</strong><span>. While less frequent, this </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/russian-espionage-influence-ukrainian-military-recruits-anti-mobilization-narratives"><span>hybrid activity</span></a><span> is a critical dynamic within the pro-Russia influence ecosystem. GTIG has previously observed operations used to shape narratives around </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/gru-disruptive-playbook"><span>cyberattacks</span></a><span> and influence events on the ground and to conduct foreign political interference, including the repeated targeting of </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/cyber-threats-global-elections"><span>foreign elections</span></a><span>, reported in Spring 2024. We have attributed some observed instances of this to Russian government-sponsored threat actors.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Russian state sponsored or pro-Russia hacktivist groups have long relied on public advertisement of real or claimed data exfiltration to highlight their operations, intimidate targets, or sway public opinion. In 2022, UNC4057 (COLDRIVER) used data stolen from espionage targets in a high profile hack-and-leak operation seeking to exacerbate divisions in UK politics. More recently, the self-proclaimed hacktivist group </span><a href="https://cert.gov.ua/article/6287707" rel="noopener" target="_blank"><span>PalachPro</span></a><span> claimed in February 2026 to have gained unauthorized access to a Ukrainian government online portal and publicly posted </span><a href="https://caspianpost.com/regions/russian-hackers-target-ukraine-s-starlink-authorisation-service" rel="noopener" target="_blank"><span>screenshots</span></a><span> of the claimed compromise. The Ukrainian government has previously noted that the portal does not store the type of data the threat actor claimed to compromise, suggesting the public posting was likely intended as influence activity, attempting to create the illusion of a more serious threat.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig6.max-1000x1000.png" alt="UNC4057 leak website attempting to inflame public debate">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="df0ri">Figure 6: UNC4057 leak website attempting to inflame public debate</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><strong>Pro-Russia hacktivists serve a direct influence function. </strong><span>Modern pro-Russia hacktivism has evolved into an important component of the influence </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/global-revival-of-hacktivism"><span>ecosystem</span></a><span> that blends </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/apt44-unearthing-sandworm"><span>state-backed actors</span></a><span> leveraging </span><a href="https://www.justice.gov/opa/pr/justice-department-announces-actions-combat-two-russian-state-sponsored-cyber-criminal" rel="noopener" target="_blank"><span>hacktivist tactics</span></a><span> with an evolving cohort of likely third-party hacktivist actors that support Russia's geopolitical interests. Pro-Russia hacktivist groups gain domestic and foreign attention for strategic messaging via their </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/killnet-new-capabilities-older-tactics"><span>claimed threat activity</span></a><span>, amplify narratives directly seeded in overt ecosystem segments, and at times also support traditional IO activity or create a means of plausible deniability for state-sponsored espionage actors. </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>The self-proclaimed hacktivist group NoName057(16) emerged following the Russian invasion of Ukraine in 2022, primarily targeting Ukraine and its partners and allies with DDoS attacks and various network intrusions. It has targeted high profile events, such as the Milano Cortina Winter Olympics, institutions like the French National Assembly, and critical infrastructure and transportation targets in Germany. Often their messaging cites grievances with overt acts of Western support for Kyiv, suggesting the group advances Russian interests not only through the targeting of perceived Russian adversaries but also in gaining attention for its pro-Russia messaging. </span></p>
</li>
</ul>
<p><strong>Established ecosystem components facilitate the cultivation of new assets and activity. </strong><span>Inter-ecosystem cross-promotion helps overcome challenges of audience building by directing traffic toward </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/information-operations-2022-midterm-elections/"><span>new assets</span></a><span>, operations, and narratives, enabling rapid deployment of new and existing IO capabilities. This directly supports a self-sustaining cycle that maintains and expands the ecosystem. </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>The hacktivist persona JokerDNR played a significant role in amplifying the APT44-linked persona Solntsepek when its doxxing-focused Telegram channel first launched and then again as it began claiming cyber espionage activity. </span></p>
</li>
</ul>
<p><strong>Domestic Russian audiences are a longstanding target of the pro-Russia influence ecosystem. </strong><span>Internally directed </span><a href="https://blog.google/threat-analysis-group/prigozhin-interests-and-russian-information-operations/" rel="noopener" target="_blank"><span>influence activity</span></a><span> has often involved the promotion of Kremlin policies and talking points and the denigration of opposition voices and ideas, conducted by both overt and covert segments of the ecosystem.</span><strong> </strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Ahead of Russia’s March 2024 presidential election, GTIG identified the hybrid espionage and influence actor UNC5101 register domains and conduct associated influence operations attempting to deceive Russian opposition voters about the timing of an anti-Putin protest.</span></p>
</li>
</ul>
<p><strong>Ecosystem actors respond to the same set of internal shifting circumstances and external geopolitical developments</strong><span>, often leading to seemingly similar, but ultimately distinct, activity. </span><span>These shared drivers and general motivational alignments encourage actors to "spontaneously" coalesce around a particular topic or narrative. While this can appear superficially similar, this phenomenon is distinct from instances of actor coordination and campaign linkages, which is less common. </span></p>
<p><strong>Systemic flexibility is a central feature, </strong><span>with influence assets able to mobilize both incrementally and at scale to advance Russian interests. The Russian Government is able to </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/information-operations-surrounding-ukraine"><span>mobilize assets</span></a><span> across the ecosystem to respond to strategic events. Meanwhile, individual or aligned actors can separately mobilize to address </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/pro-russia-information-operations-drone-incursions"><span>tactical needs</span></a><span>, allowing the ecosystem to concurrently message on multiple issues across different geographies (Figure 7). </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Russia demonstrated its ability to focus the ecosystem on a single strategic issue like the Russian invasion of Ukraine. Simultaneously, discrete assets have addressed tactical events, such as when Portal Kombat briefly </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/pro-russia-information-operations-drone-incursions"><span>promoted</span></a><span> narratives about a Russian drone incursion into Poland concurrently with other covert pro-Russia influence activity.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig7.max-1000x1000.png" alt="Tactical responses are executed by individual or coordinated/aligned clusters of actors to address emerging developments">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="pcu6e">Figure 7: Tactical responses are executed by individual or coordinated/aligned clusters of actors to address emerging developments</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><strong>Overt Russian media contributes to, and is connected with, multiple covert influence components. </strong><span>The overt components of Russia's influence infrastructure play a critical role within the broader Russian influence ecosystem beyond the commonly understood function of providing a public platform for government-aligned narratives and official talking points; overt media helps to drive (inform targeting) and amplify covert pro-Russia influence activity, seeding desirable narratives within the ecosystem and providing an indirect conduit between the Kremlin and a disparate array of influence actors. Overt media outlets have directly </span><a href="https://home.treasury.gov/news/press-releases/jy2559" rel="noopener" target="_blank"><span>coordinated</span></a><span> their activity with covert actors and have increasingly employed IO tactics to disseminate their own content in the face of sanctions and platform bans (Figure 8). </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>US Government </span><a href="https://home.treasury.gov/news/press-releases/jy2559" rel="noopener" target="_blank"><span>sanctions</span></a><span> in late 2024 indicated that Russian state media company Russia Today (RT) directly conducted covert influence operations, including on behalf of the Russian intelligence services. Further, RT employees reportedly interacted with members of the self-proclaimed hacktivist group RaHDit, which has claimed to collaborate with multiple other pro-Russia hacktivist groups, illustrating the layered connections between overt media, Russian intelligence services, and hacktivist groups.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig8.max-1000x1000.png" alt="Overt Russian media maintains multiple links with the covert segments of the ecosystem">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="pcu6e">Figure 8: Overt Russian media maintains multiple links with the covert segments of the ecosystem</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><strong>Outsourcing IO capability development and campaign execution to third-party organizations and proxies enables scaling and obfuscation. </strong><span>Outsourcing is used for developing </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/cyber-operations-russian-vulkan"><span>custom tooling</span></a><span> and bolstering both human and </span><a href="https://home.treasury.gov/news/press-releases/jy2559" rel="noopener" target="_blank"><span>organizational</span></a><span> </span><a href="https://home.treasury.gov/news/press-releases/jy2195" rel="noopener" target="_blank"><span>capacity</span></a><span>. While </span><a href="https://www.justice.gov/opa/pr/justice-department-announces-actions-combat-two-russian-state-sponsored-cyber-criminal" rel="noopener" target="_blank"><span>custom tool</span></a><span> development facilitates operators in all phases of the IO lifecycle, Russian government actors can flexibly leverage different models for outsourcing campaign execution based on their specific needs. Proxy actors can also generate plausible deniability (Figure 9). </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>GTIG </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/cyber-operations-russian-vulkan"><span>reported</span></a><span> how Russian IT contractor NTC Vulkan (Russian: НТЦ Вулкан) worked with the Russian intelligence services, including providing tooling and support for the GRU unit that sponsors APT44 activity. Separately, US government </span><a href="https://home.treasury.gov/news/press-releases/jy2195" rel="noopener" target="_blank"><span>sanctions</span></a><span> detailed how the Doppelganger campaign is supported by multiple Russian contractors under the sponsorship of the Russian Presidential Administration.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig9.max-1000x1000.png" alt="Outsourcing and proxies support capability development and campaign execution for covert influence activity">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="6mos1">Figure 9: Outsourcing and proxies support capability development and campaign execution for covert influence activity</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Conclusion</span></h3>
<p><span>Multiple factors are propelling the evolution of the pro-Russia influence ecosystem we have observed since Moscow’s full scale invasion of Ukraine four years ago. The Kremlin mobilized the entire ecosystem to support the ongoing conflict, which has provided rapid feedback and driven significant investment in new and established overt and covert influence assets. At the same time, pro-Russia actors are increasingly experimenting with generative AI to enhance their workflows. This condensed period of adaptation, alongside signals suggesting Russia's growing reliance on IO tactics to navigate new challenges, raises concerns regarding how a potentially diversifying pool of actors will leverage advancements in tradecraft and scalability. As Russia seeks to emerge from international isolation and reorients its influence ecosystem back toward global objectives, it is critical for defenders to understand how this ecosystem provides the Kremlin with a durable influence capability in order to better anticipate future Russian influence threats.</span></p>
<h3><span>Additional Tools and Resources</span></h3>
<p><span>For mitigation and hardening recommendations, please review the following:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span><a href="https://cloud.google.com/blog/topics/threat-intelligence/understand-action-intelligence-information-operations">How to Understand and Action Mandiant's Intelligence on Information Operations</a></span></p>
</li>
<li aria-level="1">
<p role="presentation"><span><a href="https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks">Proactive Preparation and Hardening to Protect Against Destructive Attacks</a></span></p>
</li>
<li aria-level="1">
<p role="presentation"><span><a href="https://services.google.com/fh/files/misc/linux-endpoint-hardening-wp-en.pdf" rel="noopener" target="_blank">Linux Endpoint Hardening to Protect Against Malware and Destructive Attacks</a></span></p>
</li>
<li aria-level="1">
<p role="presentation"><span><a href="https://services.google.com/fh/files/misc/ddos-protection-recommendations-wp-en.pdf" rel="noopener" target="_blank">Distributed Denial of Service (DDoS) Protection Recommendations</a></span></p>
</li>
</ul>
<p><span>Google offers a suite of free of cost tools to help protect high-risk users from the most pervasive digital attacks, to which politicians, journalists, and campaigns are often most vulnerable. Examples include protecting accounts from targeted attacks with </span><a href="https://landing.google.com/advancedprotection/" rel="noopener" target="_blank"><span>Advanced Protection Program</span></a><span> and safeguarding campaign websites from DDoS attacks with </span><a href="https://projectshield.withgoogle.com/landing" rel="noopener" target="_blank"><span>Project Shield</span></a><span>.</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to keep your IT talent pipeline from collapsing]]></title>
<description><![CDATA[The transformative lure of AI is rapidly pushing IT leaders’ talent pipelines toward more of a crossroads than many may fully want to admit.



The traditional approach of growing IT expertise in-house from entry-level positions is being challenged by a combination of skills-demand shifts toward ...]]></description>
<link>https://tsecurity.de/de/3632581/it-security-nachrichten/how-to-keep-your-it-talent-pipeline-from-collapsing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632581/it-security-nachrichten/how-to-keep-your-it-talent-pipeline-from-collapsing/</guid>
<pubDate>Mon, 29 Jun 2026 12:09:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The transformative lure of AI is rapidly pushing IT leaders’ talent pipelines toward more of a crossroads than many may fully want to admit.</p>



<p>The traditional approach of growing IT expertise in-house from entry-level positions is being challenged by a combination of skills-demand shifts toward AI experience and the replacement of entry-level roles in favor of AI automation.</p>



<p>Employment among early-career workers, ages 22 to 25, in the most AI-exposed occupations has fallen 16% since the introduction of ChatGPT in late 2022, according to a widely cited <a href="https://digitaleconomy.stanford.edu/publication/canaries-in-the-coal-mine-six-facts-about-the-recent-employment-effects-of-artificial-intelligence/" rel="nofollow">study from Stanford’s Digital Economy Lab</a>. For entry-level software developers, the drop was nearly 20%. As the pool of talent with early-career IT pros with hands-on experience shrinks, IT leaders are likely to face stiffer challenges filling more vital midlevel roles down the road.</p>



<p>Looking forward, some IT leaders believe replacing junior engineers and other entry-level IT roles with AI to cut costs will eventually backfire, leaving companies short of experienced staff who can tackle difficult problems and design scalable solutions.<br><br></p>



<p>According to a recent <a href="https://www.gartner.com/en/newsroom/press-releases/2026-05-05-gartner-says-autonomous-business-and-artificial-intelligence-layoffs-may-create-budget-room-but-do-not-deliver-returns" rel="nofollow">Gartner survey of global business executives</a>, organizations that automated aspects of their businesses and reduced their workforces aren’t seeing returns from those supposed efficiencies. What has improved the bottom line? Investing in new roles, upskilling, and systems that amplify the capabilities of staff so they can supervise and grow autonomous work.</p>



<p>Moreover, the Gartner report forecasts that autonomous business practices will require more staff, not less, over the next two to three years, leading to a net positive in job growth as people are hired to manage those efforts.</p>



<p>Yet, in the short term, investors are rewarding companies that make AI-related workforce reductions. And many executives are pushing for the same. So how are CIOs and other leaders planning to build the necessary skills for future success by creating a pathway for middle- and senior-level IT talent?</p>



<h2 class="wp-block-heading">‘Early in context’</h2>



<p>In response to this downward trend in early career hiring, Microsoft’s Mark Russinovich and Scott Hanselman penned an <a href="https://dl.acm.org/doi/10.1145/3779312">article</a> that pushes back on this trend. They propose bringing in early-career programming talent and pairing them with experienced mentors on product teams, where they can help new hires identify — and solve — real-world problems that AI might miss.</p>



<p>In the article, the Microsoft execs noted that experienced programmers found dozens of problems in AI-generated code that appeared to work correctly. They also pointed to the risk of “cognitive debt,” citing MIT research that found reduced brain activity among people relying heavily on AI for writing tasks.</p>



<p>“While agents can speed up workflows and reduce manual effort, they lack the intuition to anticipate edge cases and build robust solutions,” the authors wrote. “Relying too much on AI risks missing subtle bugs, architectural flaws, and vulnerabilities that only skilled engineers can catch. Human oversight, critical thinking, and domain knowledge are indispensable for both correcting errors and driving innovation as technology progresses.”</p>



<p>Hanselman, vice president and member of technical staff at Microsoft, argues that software development isn’t simply a matter of writing code. Senior engineers, he notes, have experience in what works, what fails, what can break in production, and what elegant design looks like — and how to scale it. AI can increase output, but it does not help a new developer learn this sort of judgment.</p>



<p>“When you say early in career, it’s actually early in context — junior devs are missing context,” he says. “The way that we develop good taste is through failing in a safe place. And right now, companies hire juniors, throw them at a problem, chew them up and spit them out — and that’s the wrong way to do it.”</p>



<h2 class="wp-block-heading">A new mentorship model</h2>



<p>Hanselman suggests, instead of slashing roles for junior programmers, companies should be creating systems that help them develop the skills necessary to become valued senior contributors in the future.</p>



<p>He proposes adopting a mentorship approach called a “preceptorship,” borrowed from the medical field, where senior engineers are explicitly responsible for helping juniors gain experience and develop good judgment. Hanselman’s wife is a nurse and preceptor, and her experience helped spur the idea.</p>



<p>“The preceptorship acknowledges that a nurse has passed the board,” he explains. “They’ve joined the company. It’s their first day on the job. They are qualified to be there. They are supposed to be there — but they’re missing context.”</p>



<p>Technology companies need a similar model, he argues, where programmers are allowed to learn, not just produce, from experienced mentors: “We need high communicators, with high agency — kind individuals who will invest in the future.”</p>



<p>He contrasts this practical, real-world mentoring approach with a coding boot camp.</p>



<p>“What do people do in boot camps? They wash out,” he says. “You couldn’t hack it. A preceptorship is a relationship between a senior engineer, who has your best interest at heart and is going to help you become a better AI-augmented software engineer — not a vibe coder. We’re not vibing into production. We are using the powerful tools that have been developed to create high-quality software with good taste and with good discernment at scale.”</p>



<h2 class="wp-block-heading"><a></a>A talent gap in the making</h2>



<p>Companies that eliminate junior roles because AI can do some entry-level tasks may see improved short-term output while weakening their future technical capabilities. Tech executives say a lack of investment in early career hiring will show up in the future as a dearth of leadership and institutional knowledge, as well as a reduction in product quality and the ability to effectively manage and oversee code or other work created with AI.</p>



<p>“Senior engineers are built through exposure to real systems, not just writing code,” says Craig Miller, former CIO of fast-food chain Sonic, now a consultant, board advisor, and author. “They need to understand how things scale, how they break, and how decisions impact the business. That experience cannot be automated.”</p>



<p>Reducing junior developer roles should be seen as a long-term capability risk instead of a budget efficiency, says Macaire Montini, vice president of people and culture at cloud-based HR software company HiBob.</p>



<p>“The decline in junior developer roles isn’t just an employment trend,” Montini says. “It’s a long-term pipeline problem that technology leaders should treat with the same urgency as any infrastructure risk. If you stop bringing in early-career talent, you don’t just have a gap today — you have a leadership drought in five years.”</p>



<p>Zsolt Kerecsen, CTO at Graphisoft, argues that replacing early-career staff with AI hurts staff growth and undercuts an organization’s ability to manage autonomous capabilities. CIOs should treat early-career hiring as an investment in future delivery quality, system oversight, and AI governance, he says.</p>



<p>“Experienced developers are needed to train AI and validate its outputs,” he says. “That’s why trying to substitute juniors with AI is a fundamentally flawed approach. Instead, AI should be used — guided by seniors — to support junior developers and help them become seniors more quickly.”</p>



<p>Miller says the reduction in early career hiring is just one sign of a broader issue of “slow decay,” where current tech staff aren’t training their replacements. He points to other indications of a future talent crisis: “Decline in CS enrollments as prospective students respond to deteriorating job market signals, which could produce a senior engineer shortage in 5 to 10 years even as AI reduces demand for entry-level workers today. The real risk is not that AI will eliminate the need for developers. It’s that companies will eliminate the early learning ground that has always produced great ones.”</p>



<h2 class="wp-block-heading">Filling the pipeline</h2>



<p>With early-career roles evolving quickly, experts advise CIOs to take a more intentional approach to hiring and training IT talent, programmers in particular — one that uses AI to help junior staff become better, faster, instead of replacing them.</p>



<p>AI may enable junior developers to take on more advanced tasks earlier, Montini says, but they still need mentoring and structured guidance to become experienced contributors.</p>



<p>“We believe the answer isn’t just hiring,” Montini says. “It’s how you onboard and develop early-career talent once they’re through the door. Structured training, clear skill development pathways, and meaningful mentorship are what actually close the gap between potential and performance. Without that scaffolding, junior hires churn before they become the midlevel talent you need.”</p>



<p>Paul DeMott, CTO at Helium SEO, says organizations should rethink talent development from a new hire’s first day.</p>



<p>“Before a junior developer on our team writes a single line of code on any new feature, they have to propose the full architecture for it, present it in a 15-minute review with the senior team, and explain every tradeoff they considered,” he says. “The junior does not implement anything until they defend those decisions. This process forces systems thinking before syntax thinking, which is exactly what separates a developer who grows into senior roles from one who stays at the execution layer indefinitely.”</p>



<p>In the past year and a half, DeMott says, that process has helped junior hires rise more quickly through the ranks, with two junior developers promoted to midlevel roles.</p>



<p>Kerecsen says his company actively seeks out junior talent at the university level, works with them for several years, then brings them on as junior or potentially midlevel engineers.</p>



<p>“There is a concerning misunderstanding about AI’s potential, especially regarding its ability to replace junior developers,” Kerecsen says. “It is actually disastrous for delivery quality and long-term sustainability. Junior developers are an investment in our future.”</p>



<p>Liz Eversoll, CEO of upskilling and recruitment company Career Highways, says organizations should move from informal apprenticeship to a more intentional model for skills-based growth.</p>



<p>“The next generation of senior programmers will be developed differently,” Eversoll says. “Junior engineers can now contribute to higher-complexity work earlier by using AI as a copilot, but that only works if organizations provide pathways that connect real work, learning, and continuous assessment.”</p>



<h2 class="wp-block-heading"><a></a>Building judgment, not just output</h2>



<p>The goal is to help junior developers gain the kind of experience that allows them to understand systems, weigh tradeoffs, and eventually guide technical decisions.</p>



<p>Former Sonic CIO Miller says that kind of experience cannot be automated.</p>



<p>“The organizations that get this right will balance AI-driven efficiency with structured mentorship and real-world exposure, treating talent development as a long-term priority,” Miller says. “The next generation of senior engineers will not emerge accidentally. They will have to be built through structured apprenticeship, guided use of AI, real exposure to production environments, and deliberate development of judgment, architecture thinking, debugging discipline, and business context.”</p>



<p>Rema Lolas, founder of team-building platform Groziac, says AI may make technical skills more accessible, but it will also put more pressure on how people work together.</p>



<p>“AI may level the technical playing field, but it will amplify the differences in human performance,” Lolas says. “The organizations that recognize this early will stop treating development as a training problem, and start treating it as a system design challenge — where people are intentionally developed not just in skill, but in how they operate and perform together.”</p>



<p>Microsoft’s Hanselman says the skills that matter most today are not just AI prompt fluency or the ability to generate code quickly, but systems thinking and communication.</p>



<p>“So for the young person who’s coming into this, you can’t have blinders on,” he says. “Making large, interesting systems that help people and make their lives better — that is not being commoditized. You need big-picture thinking, taste, discernment, good judgment, good communication skills, and a rock-solid understanding of the basics. Just because I’m riding around in an Uber doesn’t mean that I don’t know how to change a tire.”</p>



<p>Tech leaders say organizations need to make early-career growth a core part of engineering work. That means giving junior staff real programming work, in-the-moment senior guidance and AI support that accelerates learning without replacing it.</p>



<p>“Ultimately, developing senior talent is no longer a byproduct of hiring, it’s the result of deliberate infrastructure,” Eversoll says. “Organizations that invest in skills-based progression systems will not only sustain their pipeline, but accelerate it.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Reportedly Seeks Trump Approval to Buy CXMT Memory for iPhone 18 Pro]]></title>
<description><![CDATA[Apple is reportedly asking the Trump administration for permission to buy DRAM chips from China’s CXMT, as rising memory prices create new pressure around the…
The post Apple Reportedly Seeks Trump Approval to Buy CXMT Memory for iPhone 18 Pro appeared first on OnMSFT.]]></description>
<link>https://tsecurity.de/de/3631866/windows-tipps/apple-reportedly-seeks-trump-approval-to-buy-cxmt-memory-for-iphone-18-pro/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631866/windows-tipps/apple-reportedly-seeks-trump-approval-to-buy-cxmt-memory-for-iphone-18-pro/</guid>
<pubDate>Mon, 29 Jun 2026 05:38:14 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple is reportedly asking the Trump administration for permission to buy DRAM chips from China’s CXMT, as rising memory prices create new pressure around the…</p>
<p>The post <a href="https://onmsft.com/news/apple-reportedly-seeks-trump-approval-to-buy-cxmt-memory-for-iphone-18-pro/">Apple Reportedly Seeks Trump Approval to Buy CXMT Memory for iPhone 18 Pro</a> appeared first on <a href="https://onmsft.com/">OnMSFT</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Slammed for Building Copyright-Infringing Supercomputer for OpenAI in New Court Filing]]></title>
<description><![CDATA[The New York Times alleges Microsoft actively encouraged OpenAI to steal its copyrighted work, reports Ars Technica, citing a new (and heavily redacted) court filing Thursday:

NYT's motion comes after the [U.S.] Supreme Court sided with Cox Communications in a case where Sony tried and failed to...]]></description>
<link>https://tsecurity.de/de/3631686/it-security-nachrichten/microsoft-slammed-for-building-copyright-infringing-supercomputer-for-openai-in-new-court-filing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631686/it-security-nachrichten/microsoft-slammed-for-building-copyright-infringing-supercomputer-for-openai-in-new-court-filing/</guid>
<pubDate>Mon, 29 Jun 2026 01:52:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The New York Times alleges Microsoft actively encouraged OpenAI to steal its copyrighted work, reports Ars Technica, citing a new (and heavily redacted) court filing Thursday:

NYT's motion comes after the [U.S.] Supreme Court sided with Cox Communications in a case where Sony tried and failed to claim that Cox was contributing to music piracy as an Internet service provider, which set a new standard for contributory infringement. Moving forward, plaintiffs will have to prove that parties intentionally acted to induce illegal conduct. Recognizing that the legal precedent has changed, the NYT now wants to amend its complaint to align its contributory infringement claim against Microsoft with that new standard... A Microsoft spokesperson told Ars that the company views the amended complaint as "a last-ditch effort by the plaintiff to save its claim from unfavorable precedent set in other recent rulings..." 

The updated complaint seeks to specify that [Microsoft's] supercomputer was tailor-made to help OpenAI infringe and allege that it was built for the explicit purpose of training AI on copyrighted works without permission. And as the NYT alleged, its articles were more heavily weighted by this system, as both firms hoped to train models on the highest-quality journalism possible, so that level of writing could be confidently mimicked in outputs. By building this "unusually complex" machine, Microsoft not only helped select the works that were infringed but also provided a means to seize copyrighted works without permission, the NYT alleged. "Microsoft specifically designed it for the purpose of using essentially the whole Internet — curated to disproportionately feature Times Works — to train the most capable LLM in history," the NYT alleged... Similarly as problematic for the NYT are hallucinations where Microsoft and OpenAI models falsely cite the NYT for content that they never published... "Users who ask a search engine what The Times has written on a subject should be provided with neither an unauthorized copy nor an inaccurate forgery of a Times article, but a link to the article itself," the NYT alleged... 

In a statement provided to Ars, OpenAI spokesperson Drew Pusateri reiterated the AI firm's often-repeated claims that AI training on copyrighted works is indisputably fair use... OpenAI has argued that "ChatGPT is not a substitute for a Times subscription," the NYT reported, partly because "they transformed the material for a different use." 

An OpenAI spokesperson told Ars Technica that OpenAI's models "empower innovation," while a New York Times spokesperson insisted that Microsoft "actively encouraged OpenAI to steal our copyrighted works... [O]ur core claims remain the same from the day we filed this lawsuit — that Microsoft and OpenAI stole millions of The Times's copyrighted works to compete with our products and illegally enrich themselves." 

The article speculates that the case's most extreme outcome "could require OpenAI and Microsoft to wipe models and start over. The NYT has also asked for permanent injunctive relief to prevent future infringement, as well as extensive damages..."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Microsoft+Slammed+for+Building+Copyright-Infringing+Supercomputer+for+OpenAI+in+New+Court+Filing%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F28%2F2256226%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F28%2F2256226%2Fmicrosoft-slammed-for-building-copyright-infringing-supercomputer-for-openai-in-new-court-filing%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/06/28/2256226/microsoft-slammed-for-building-copyright-infringing-supercomputer-for-openai-in-new-court-filing?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[2026年に採用が最も難しいIT職種11選——何が変わったか]]></title>
<description><![CDATA[専門家の採用はむしろ容易になった。SOCアナリスト、ML研究者、クラウドアーキテクト——こうした職種は数週間で採用が決まる。一方、採用に6〜9カ月かかるのはハイブリッドな職種だ。AIに精通しながらコードにも深く入り込め、ビジネスも理解できるエンジニア。「3つのスキル、1人の人物、少ない候補者プール」とBest BuyのCDTOであるNeal Sample氏は言う。「これらのハイブリッド人材がITの未来だ——現時点でこのようなハイブリッド人材は見つけるのがとても難しい」。



AIがサイバーセキュリティを抜いて採用最難関スキルになって2年が経過する。2026年のState of the ...]]></description>
<link>https://tsecurity.de/de/3631649/it-nachrichten/2026it11/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631649/it-nachrichten/2026it11/</guid>
<pubDate>Mon, 29 Jun 2026 01:02:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>専門家の採用はむしろ容易になった。SOCアナリスト、ML研究者、クラウドアーキテクト——こうした職種は数週間で採用が決まる。一方、採用に6〜9カ月かかるのはハイブリッドな職種だ。AIに精通しながらコードにも深く入り込め、ビジネスも理解できるエンジニア。「3つのスキル、1人の人物、少ない候補者プール」とBest BuyのCDTOであるNeal Sample氏は言う。「これらのハイブリッド人材がITの未来だ——現時点でこのようなハイブリッド人材は見つけるのがとても難しい」。</p>



<p>AIがサイバーセキュリティを抜いて採用最難関スキルになって2年が経過する。2026年のState of the CIO調査では、AI/機械学習とサイバーセキュリティが同率1位となり、データサイエンス・分析が僅差で続く、という結果になった。ランキングは似ているが、人材難の性質は変わった。LLMエンジニアやプロンプトスペシャリストへの需要は、AIをスケールで実用化し、リスクを管理し、盲目的に信頼せずに使いこなせる人材への需要に変わった。</p>



<p>リスク管理は初めてトップ5入りし、ビジネス・IT自動化は上位を維持している。一方で数年前まで注目されていた職種への需要は緩んでいる。その1つがクラウドアーキテクチャだが、今年は順位を落とし、アプリケーション開発もリストから外れた。「採用が最も難しいのは、AIとの組み合わせが求められる職種すべてだ」とValcom TechnologiesのITアドバイザー、Niel Nickolaisen氏は言う。</p>



<p><br>採用困難なIT職種：2026年 vs. 2024年</p>



<figure class="wp-block-table is-style-stripes"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td>スキル</td><td><strong>2026</strong>年</td><td><strong>2024</strong>年</td><td>変化</td></tr><tr><td>AI/機械学習</td><td>1位（同率）</td><td>1位</td><td>横ばい</td></tr><tr><td>サイバーセキュリティ</td><td>1位（同率）</td><td>2位</td><td>上昇</td></tr><tr><td>データサイエンス・分析</td><td>3位</td><td>3位</td><td>横ばい</td></tr><tr><td>ビジネス・IT自動化</td><td>4位</td><td>4位（同率）</td><td>横ばい</td></tr><tr><td>リスク管理</td><td>5位</td><td>8位（同率）</td><td>上昇</td></tr><tr><td>ソフトウェアエンジニアリング</td><td>6位（同率）</td><td>6位（同率）</td><td>横ばい</td></tr><tr><td>DevOps/DevSecOps</td><td>6位（同率）</td><td>11位（同率）</td><td>上昇</td></tr><tr><td>エンタープライズアーキテクチャ</td><td>8位（同率）</td><td>10位（同率）</td><td>上昇</td></tr><tr><td>クラウドサービス・統合</td><td>8位（同率）</td><td>12位（同率）</td><td>上昇</td></tr><tr><td>クラウドアーキテクチャ</td><td>8位（同率）</td><td>6位（同率）</td><td>低下</td></tr><tr><td>デザイン思考・UX</td><td>8位（同率）</td><td>15位（同率）</td><td>上昇</td></tr></tbody></table> </div></figure>



<p>出典：Foundry/CIO.com State of the CIO Survey、2024年および2026年</p>



<h2 class="wp-block-heading"><br>AI採用の成熟</h2>



<p>「プロンプトエンジニアリングは単独の職種としては短命だった。現在はベースラインのスキルになっている」とSample氏は言う。多くの組織が求めるのは別のものだ——エージェントを立ち上げ、テストフレームワークを構築し、コスト・レイテンシ・品質のトレードオフを管理し、AIをスケールで展開できるAIプロダクトエンジニアだ。3年前は存在しなかったガバナンスやレッドチームの役割も生まれている。「モデルを作る人からモデルを使いこなす人へ、重力の中心が移った」とSample氏は言う。</p>



<p>このように、求められるスキルは、プロンプトエンジニアリングよりもエージェンティックAIの活用へとシフトしている。「ワークフロー、プロセスの簡略化を理解し、エージェントプラットフォームで業務を自動化できる人材が必要だ」とNickolaisen氏は言う。課題は、AIが急速に進化しているため、ある企業での経験が別の企業で通用しない可能性があること、また6カ月前に学んだことがすでに時代遅れになっている可能性があることだ。</p>



<h2 class="wp-block-heading">サイバーセキュリティ——人数の問題ではなく、スキルの問題</h2>



<p>サイバーセキュリティがAIと同率1位になったのは、単なる需要の増加だけでなく、課題の質的変化を反映している。SANS/GIACの2026年サイバーセキュリティ人材レポートによれば、6割の組織がスタッフ不足よりスキルギャップを主な課題として挙げており、1年前から20ポイント増加した。サイバーセキュリティリーダーの27%がスキルギャップと直接結びついた侵害を報告し、61%がチームのストレスが過去2年で増加したと言う。</p>



<p>スキル不足はエントリーレベルではなく、シニアアーキテクトの層にある。「本当に必要なのは、ダッシュボードを読むだけでなく、実際の制約の中でセキュリティの判断を下せる人だ。そういう人材は引く手あまたで、高い報酬を要求できる」とSample氏は言う。</p>



<p>SANSの調査では、74%の組織がAIがすでにサイバーセキュリティチームの規模と役割に影響を与えていると回答。SOCアナリストなどのエントリーレベルの職種が削減される一方、AI/MLセキュリティスペシャリストやAIガバナンスアナリストなど新しい役割が生まれている。</p>



<h2 class="wp-block-heading">「二次的なAIスキル」の台頭</h2>



<p>自動化とリスク管理スキルが両方ともトップ5入りを果たした。理由は同じだ。「AIがサーフェスエリアを拡大した。展開するエージェントはすべて新たな自動化であり新たなリスクだ。多くのGRC（ガバナンス・リスク・コンプライアンス）や業務部門はそのペースに対応できるよう設計されていない」とSample氏は言う。</p>



<p>自動化の需要はRPA開発者ではない——そこはコモディティ化した。必要なのはプロセスを見て何を自動化し、何を廃止し、何を再設計するかを判断できる人だ。「それは3つの仕事を一つにしたものだ。ビジネスアナリスト、プロセスエンジニア、テクノロジスト。3つすべてをうまくこなせる人は希少で、高額だ」とSample氏は言う。</p>



<p>リスク管理も同様だ。SOXやPCIコンプライアンスのために作られたGRC機能は、モデルリスク、プロンプトインジェクション、サードパーティのAIリスクに最適化されていない。「20年前の職務記述書に基づいて5年程度の新しい規律の採用をしている。そのギャップが問題だ」とSample氏は言う。</p>



<h2 class="wp-block-heading">中堅層のジレンマ</h2>



<p>AIコーディングツールはソフトウェアエンジニアへの需要を減らしてはいないが、その性質を変えた。優秀なエンジニアとAIツールの組み合わせで、数年前の3人分の成果が出る。「プレッシャーがかかっているのは中間層——APIをつなぎ合わせることが日常業務だった人たち」とSample氏は言う。</p>



<p>採用は二極化している。判断力とオーナーシップを持つ経験豊富なリーダーと、最初からAIネイティブなジュニア人材への需要は高い。「中堅で惰性的に仕事をしてきた人たちは、自分が採用市場で不利な立場にいることに気づき始めている」とLarridinのCTO、Ameya Kanitkar氏は言う。</p>



<h2 class="wp-block-heading"><strong>クラウド職種の採用は安定</strong></h2>



<p>クラウド職種の採用は容易になった。多くの組織はクラウドの安定期に達し、パブリック、プライベート、オンプレのワークロードが確立している。ただし一部の専門領域——FinOps、規制業界の移行、逆移行（クラウドからオンプレへ）——は依然として人材が少ない。「特にAI推論は、クラウドのユニットエコノミクスがスケールで厳しくなる。それがスキルの組み合わせを再び変えている」とSample氏は言う。</p>



<h2 class="wp-block-heading">ギャップを埋めるために有効な手段</h2>



<p>ITリーダーの間で一致しているのは、社内でのスキルアップと異動が外部採用よりスピード、コスト、定着率の面で効果的だということだ。「2025年に最も生産性が高かったAIエンジニアは、AIエンジニアとして採用された人ではない。優秀なソフトウェアエンジニアを社内トレーニングと実際のプロジェクトを通じてAIに対応させた人たちだ」とSample氏は言う。</p>



<p>Best BuyのSample氏は、AIの採用を別のパイプラインとして扱うのをやめたことで、才能のプールが10倍以上広がったと言う。「まずエンジニアとして採用し、AIの使い方は後から教える。この考え方に変えるだけで、候補者のプールが10倍以上広がり、成果も上がった」。</p>



<p>CompTIAのJames Stanger氏は「最も進んでいる組織は、『どの大学を出たか』ではなく、『どんなスキルを持っていて、それで何を実現してくれるか』を問うようになっている」と言う。</p>



<p>「「2023年のプロンプトエンジニア採用ブームは18カ月で終わり、その役割に就いた人たちは今スキルを磨き直している。同じ過ちを、今度はエージェンティックAIで繰り返している組織がある。職種名ではなく、ケイパビリティで採用しなければ、同じ結果になる」とSample氏は言う。</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anzeige: IT-Jobs in Administration, DevOps und Konfigurationsmanagement]]></title>
<description><![CDATA[Ob Netzwerkadministration bei der Polizei Berlin, DevOps in der Umweltforschung oder IAM-Einstieg beim DRK - diese Stellen verbinden IT mit gesellschaftlichem Mehrwert. (Golem Karrierewelt, Betriebssysteme)]]></description>
<link>https://tsecurity.de/de/3630533/it-nachrichten/anzeige-it-jobs-in-administration-devops-und-konfigurationsmanagement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630533/it-nachrichten/anzeige-it-jobs-in-administration-devops-und-konfigurationsmanagement/</guid>
<pubDate>Sun, 28 Jun 2026 07:02:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ob Netzwerkadministration bei der Polizei Berlin, DevOps in der Umweltforschung oder IAM-Einstieg beim DRK - diese Stellen verbinden IT mit gesellschaftlichem Mehrwert. (<a href="https://www.golem.de/specials/golemakademie/">Golem Karrierewelt</a>, <a href="https://www.golem.de/specials/betriebssystem/">Betriebssysteme</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=210194&amp;page=1&amp;ts=1782622801" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[How to watch Jordan vs Argentina: Free Streams & TV Channels for FIFA World Cup 2026 as Lionel Messi seeks to add to his haul]]></title>
<description><![CDATA[Here's how to watch Jordan vs Argentina for free online and from anywhere as Lionel Messi and Co. wrap up their Group J campaign at World Cup 2026.]]></description>
<link>https://tsecurity.de/de/3630336/it-nachrichten/how-to-watch-jordan-vs-argentina-free-streams-tv-channels-for-fifa-world-cup-2026-as-lionel-messi-seeks-to-add-to-his-haul/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630336/it-nachrichten/how-to-watch-jordan-vs-argentina-free-streams-tv-channels-for-fifa-world-cup-2026-as-lionel-messi-seeks-to-add-to-his-haul/</guid>
<pubDate>Sun, 28 Jun 2026 01:17:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Here's how to watch Jordan vs Argentina for free online and from anywhere as Lionel Messi and Co. wrap up their Group J campaign at World Cup 2026.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Seeks White House Approval for Banned Chinese Memory Chips]]></title>
<description><![CDATA[Apple is asking the Trump administration for special permission to buy memory chips from a restricted Chinese company, reports The Financial Times. The tech giant wants this approval to deal with a massive global memory shortage that is driving up the cost of building its devices. After recently ...]]></description>
<link>https://tsecurity.de/de/3629523/ios-mac-os/apple-seeks-white-house-approval-for-banned-chinese-memory-chips/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629523/ios-mac-os/apple-seeks-white-house-approval-for-banned-chinese-memory-chips/</guid>
<pubDate>Sat, 27 Jun 2026 13:52:56 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is asking the Trump administration for special permission to buy memory chips from a restricted Chinese company, reports The Financial Times. The tech giant wants this approval to deal with a massive global memory shortage that is driving up the cost of building its devices. After recently hiking the prices on several of its popular gadgets, the brand hopes this move will eventually help lower the financial pressure on its buyers.



The company wants to buy parts from a restricted Chinese supplier



The tech giant reached out to the Department of Commerce to ask if it could buy parts from a Chinese manufacturer named CXMT. The problem is that the Pentagon placed CXMT on a blacklist. This list restricts American businesses from working with these groups because of suspected ties to the Chinese military.



While it is technically possible for the brand to buy from these suppliers, dealing with blacklisted companies brings heavy scrutiny from the government. Lawmakers have strongly opposed similar ideas in the past. Still, the company wants to explore every option to secure enough parts.



Surging memory prices force the brand to make tough hardware decisions



This push for new suppliers comes right after a wave of price hikes. The brand just raised the cost of its laptops and tablets because the price of computer memory has jumped so high. This crunch is happening because tech companies are buying massive amounts of chips for artificial intelligence servers, leaving less supply for everyday gadgets.



The market reacted poorly to these changes, as we saw how Apple's stock dropped after higher prices rolled out across Macs and iPads recently. Before this shift, we also watched as Apple raised the Mac mini M4 Pro price by $200 amid rising component costs.



Experts believe the phone lineup might be next to see higher price tags if the company cannot find cheaper parts. Reports even suggest that Apple's next CEO may approve iPhone price hikes of $100 or more due to RAM shortage later this year.



If the government approves this request, it could help the brand lock down the memory chips it needs. For now, the company has to wait and see if it gets the green light or if it will have to keep passing high costs along to shoppers.]]></content:encoded>
</item>
<item>
<title><![CDATA[Akrites: The Latest Attempt to Protect Open-Source From AI Attacks Has Arrived]]></title>
<description><![CDATA[submitted by    /u/CackleRooster   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3628765/linux-tipps/akrites-the-latest-attempt-to-protect-open-source-from-ai-attacks-has-arrived/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628765/linux-tipps/akrites-the-latest-attempt-to-protect-open-source-from-ai-attacks-has-arrived/</guid>
<pubDate>Sat, 27 Jun 2026 02:10:21 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/CackleRooster"> /u/CackleRooster </a> <br> <span><a href="https://devops.com/akrites-the-latest-attempt-to-protect-open-source-from-ai-attacks-has-arrived/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uggexy/akrites_the_latest_attempt_to_protect_opensource/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Setze auf effektive SEO-Techniken für mehr Sichtbarkeit!]]></title>
<description><![CDATA[Auch 2026 zählt Suchmaschinenoptimierung zu den wirksamsten Mitteln, um Webseiten
The post Setze auf effektive SEO-Techniken für mehr Sichtbarkeit! first appeared on IT-LEARNER.]]></description>
<link>https://tsecurity.de/de/3626777/it-nachrichten/setze-auf-effektive-seo-techniken-fuer-mehr-sichtbarkeit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626777/it-nachrichten/setze-auf-effektive-seo-techniken-fuer-mehr-sichtbarkeit/</guid>
<pubDate>Fri, 26 Jun 2026 10:33:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Auch 2026 zählt Suchmaschinenoptimierung zu den wirksamsten Mitteln, um Webseiten</p>
<p>The post <a rel="nofollow" href="https://it-learner.de/setze-auf-effektive-seo-techniken-fuer-mehr-sichtbarkeit/">Setze auf effektive SEO-Techniken für mehr Sichtbarkeit!</a> first appeared on <a rel="nofollow" href="https://it-learner.de/">IT-LEARNER</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Linux Foundation project aims to bring DNS-style trust to AI agents]]></title>
<description><![CDATA[As enterprises deploy increasing numbers of AI agents across applications and organizations, the Linux Foundation on Wednesday announced plans to launch a new Agent Name Service framework designed to establish identity, ownership, and trust for these systems.



The ANS framework, which is expect...]]></description>
<link>https://tsecurity.de/de/3624299/ai-nachrichten/new-linux-foundation-project-aims-to-bring-dns-style-trust-to-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624299/ai-nachrichten/new-linux-foundation-project-aims-to-bring-dns-style-trust-to-ai-agents/</guid>
<pubDate>Thu, 25 Jun 2026 13:33:51 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As enterprises deploy increasing numbers of AI agents across applications and organizations, the Linux Foundation on Wednesday announced plans to launch a new Agent Name Service framework designed to establish identity, ownership, and trust for these systems.</p>



<p>The <a href="https://github.com/agentnameservice" target="_blank" rel="noreferrer noopener">ANS framework</a>, which is expected to allow systems and users to verify who an agent represents, what permissions it has, and whether its code and operational history remain authentic and unchanged, will be based on the existing <a href="https://www.networkworld.com/article/965540/what-is-dns-and-how-does-it-work.html" target="_blank">Domain Name System (DNS)</a>, the Foundation said in a statement.</p>



<p>Just like DNS translates human-readable website names into internet addresses, ANS aims to create a standardized naming and discovery layer for AI agents, with the ability for enterprises to publish agent identities through domains they already control, enabling other agents and systems to verify who an agent represents and discover information about its capabilities and ownership before interacting with it, it added.</p>



<p>This, the Foundation further added, creates a federated mechanism for agent discovery and verification without any reliance on any proprietary registry or centralized control.</p>



<h2 class="wp-block-heading">Growing demand for an agent identity framework </h2>



<p>ANS solves an emerging problem for enterprises, especially in scaling AI deployments, said <a href="https://www.forrester.com/analyst-bio/charlie-dai/BIO5344" target="_blank" rel="noreferrer noopener">Charlie Dai</a>, principal analyst at Forrester, too. “The agent identity problem is already emerging in early production deployments, particularly where multiple agents interact across tools, APIs, and organizational boundaries without consistent authentication and accountability models,” he said.</p>



<p>“We have seen growing concerns around provenance, authorization scoping, and auditability in agent-to-agent interactions, especially in regulated industries and multi-vendor environments,” Dai said.</p>



<p>Agent identity has become a more critical concern for enterprises, pointed out <a href="https://www.gartner.com/en/experts/jaishiv-prakash" target="_blank" rel="noreferrer noopener">Jaishiv Prakash</a>, director analyst at Gartner: “Agent identity has moved from an architectural consideration to an operational control-plane gap.”</p>



<p>“The evidence we see from enterprise clients is consistent: they need to know which agent acted, who it represented, what authority it had, and whether its runtime behavior matched its intended design,” Prakash said.</p>



<p>Beyond the problem ANS seeks to solve, analysts also said the framework’s architecture could prove equally important for enterprise adoption.</p>



<p>“For enterprises, one of ANS’s biggest advantages may be its reliance on DNS, especially since they already use it to manage domains and trust. It avoids creating a new registry and lets companies publish and verify agent identities using existing internet infrastructure, making adoption easier and cheaper,” said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<p>More so because enterprises don’t have to build anything new, according to <a href="https://www.linkedin.com/in/znamit?originalSubdomain=in" target="_blank" rel="noreferrer noopener">Amit Jena</a>, AI development manager at IT consulting firm Kanerika.</p>



<p>However, there are downsides to being built on DNS, especially on the security front, Dai cautioned.</p>



<p>“DNS was not originally designed for high-assurance identity. This will make it susceptible to spoofing, hijacking, and latency or propagation inconsistencies that can undermine trust guarantees,” Dai said.</p>



<p>To bypass these security concerns, enterprises should complement ANS with <a href="https://www.csoonline.com/article/518296/what-is-iam-identity-and-access-management-explained.html">IAM</a>, workload identity, AI gateways, and API security controls, according to Prakash.</p>



<p>The Foundation, though, argues that DNS alone is not intended to serve as the sole trust mechanism inside ANS and the framework supports Decentralized Identifiers (DIDs) and Legal Entity Identifiers (LEIs), allowing enterprises to tie agents to existing digital and organizational identity systems as part of the broader identity verification model.</p>



<h2 class="wp-block-heading">Battle of the standards</h2>



<p>Even so, ANS is entering an increasingly crowded ecosystem of standards and frameworks that enable and govern enterprise AI agents.</p>



<p>While protocols such as <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP</a> and <a href="https://www.infoworld.com/article/4088217/what-is-a2a-how-the-agent-to-agent-protocol-enables-autonomous-collaboration.html">A2A</a> focus on connecting agents to tools and facilitating communication between each other, the Foundation itself hosts two standards that touch on agent identity, discovery, and trust.</p>



<p>One of them is <a href="https://www.infoworld.com/article/4178820/dns-aid-will-make-ai-agents-easier-to-discover-says-linux-foundation.html">DNS-AI Discovery (DNS-AID)</a>, a proposed framework that uses DNS records to help agents advertise their capabilities and make themselves discoverable across networks. Another is <a href="https://www.networkworld.com/article/4029803/cisco-donates-ai-agent-tech-to-linux-foundation.html">AGNTCY</a>, a Cisco-led project that aims to provide a broader infrastructure stack for multi-agent systems, including capabilities for agent discovery, identity, messaging, and observability.</p>



<p>That raises the possibility of fragmentation if competing approaches evolve in parallel.</p>



<p>However, Prakash pointed out that the presence of multiple similar frameworks that touch on agent trust, identity, and discovery shows that the agent infrastructure market has entered its standards discovery phase, not its standards consolidation phase.</p>



<p>“Overlap in discovery, identity, messaging, and observability is expected at this stage,” Prakash said.</p>



<p>Enterprises, thus, the analyst added, should wait for “clarity and clearer interoperability guidance” before they treat any one initiative as strategic infrastructure.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Linux Foundation project aims to bring DNS-style trust to AI agents]]></title>
<description><![CDATA[As enterprises deploy increasing numbers of AI agents across applications and organizations, the Linux Foundation on Wednesday announced plans to launch a new Agent Name Service framework designed to establish identity, ownership, and trust for these systems.



The ANS framework, which is expect...]]></description>
<link>https://tsecurity.de/de/3624291/it-nachrichten/new-linux-foundation-project-aims-to-bring-dns-style-trust-to-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624291/it-nachrichten/new-linux-foundation-project-aims-to-bring-dns-style-trust-to-ai-agents/</guid>
<pubDate>Thu, 25 Jun 2026 13:32:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As enterprises deploy increasing numbers of AI agents across applications and organizations, the Linux Foundation on Wednesday announced plans to launch a new Agent Name Service framework designed to establish identity, ownership, and trust for these systems.</p>



<p>The <a href="https://github.com/agentnameservice" target="_blank" rel="noreferrer noopener">ANS framework</a>, which is expected to allow systems and users to verify who an agent represents, what permissions it has, and whether its code and operational history remain authentic and unchanged, will be based on the existing <a href="https://www.networkworld.com/article/965540/what-is-dns-and-how-does-it-work.html" target="_blank">Domain Name System (DNS)</a>, the Foundation said in a statement.</p>



<p>Just like DNS translates human-readable website names into internet addresses, ANS aims to create a standardized naming and discovery layer for AI agents, with the ability for enterprises to publish agent identities through domains they already control, enabling other agents and systems to verify who an agent represents and discover information about its capabilities and ownership before interacting with it, it added.</p>



<p>This, the Foundation further added, creates a federated mechanism for agent discovery and verification without any reliance on any proprietary registry or centralized control.</p>



<h2 class="wp-block-heading">Growing demand for an agent identity framework</h2>



<p>ANS solves an emerging problem for enterprises, especially in scaling AI deployments, said <a href="https://www.forrester.com/analyst-bio/charlie-dai/BIO5344" target="_blank" rel="noreferrer noopener">Charlie Dai</a>, principal analyst at Forrester, too. “The agent identity problem is already emerging in early production deployments, particularly where multiple agents interact across tools, APIs, and organizational boundaries without consistent authentication and accountability models,” he said.</p>



<p>“We have seen growing concerns around provenance, authorization scoping, and auditability in agent-to-agent interactions, especially in regulated industries and multi-vendor environments,” Dai said.</p>



<p>Agent identity has become a more critical concern for enterprises, pointed out <a href="https://www.gartner.com/en/experts/jaishiv-prakash" target="_blank" rel="noreferrer noopener">Jaishiv Prakash</a>, director analyst at Gartner: “Agent identity has moved from an architectural consideration to an operational control-plane gap.”</p>



<p>“The evidence we see from enterprise clients is consistent: they need to know which agent acted, who it represented, what authority it had, and whether its runtime behavior matched its intended design,” Prakash said.</p>



<p>Beyond the problem ANS seeks to solve, analysts also said the framework’s architecture could prove equally important for enterprise adoption.</p>



<p>“For enterprises, one of ANS’s biggest advantages may be its reliance on DNS, especially since they already use it to manage domains and trust. It avoids creating a new registry and lets companies publish and verify agent identities using existing internet infrastructure, making adoption easier and cheaper,” said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<p>More so because enterprises don’t have to build anything new, according to <a href="https://www.linkedin.com/in/znamit?originalSubdomain=in" target="_blank" rel="noreferrer noopener">Amit Jena</a>, AI development manager at IT consulting firm Kanerika.</p>



<p>However, there are downsides to being built on DNS, especially on the security front, Dai cautioned.</p>



<p>“DNS was not originally designed for high-assurance identity. This will make it susceptible to spoofing, hijacking, and latency or propagation inconsistencies that can undermine trust guarantees,” Dai said.</p>



<p>To bypass these security concerns, enterprises should complement ANS with <a href="https://www.csoonline.com/article/518296/what-is-iam-identity-and-access-management-explained.html">IAM</a>, workload identity, AI gateways, and API security controls, according to Prakash.</p>



<p>The Foundation, though, argues that DNS alone is not intended to serve as the sole trust mechanism inside ANS and the framework supports Decentralized Identifiers (DIDs) and Legal Entity Identifiers (LEIs), allowing enterprises to tie agents to existing digital and organizational identity systems as part of the broader identity verification model.</p>



<h2 class="wp-block-heading">Battle of the standards</h2>



<p>Even so, ANS is entering an increasingly crowded ecosystem of standards and frameworks that enable and govern enterprise AI agents.</p>



<p>While protocols such as <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP</a> and <a href="https://www.infoworld.com/article/4088217/what-is-a2a-how-the-agent-to-agent-protocol-enables-autonomous-collaboration.html">A2A</a> focus on connecting agents to tools and facilitating communication between each other, the Foundation itself hosts two standards that touch on agent identity, discovery, and trust.</p>



<p>One of them is <a href="https://www.infoworld.com/article/4178820/dns-aid-will-make-ai-agents-easier-to-discover-says-linux-foundation.html">DNS-AI Discovery (DNS-AID)</a>, a proposed framework that uses DNS records to help agents advertise their capabilities and make themselves discoverable across networks. Another is <a href="https://www.networkworld.com/article/4029803/cisco-donates-ai-agent-tech-to-linux-foundation.html">AGNTCY</a>, a Cisco-led project that aims to provide a broader infrastructure stack for multi-agent systems, including capabilities for agent discovery, identity, messaging, and observability.</p>



<p>That raises the possibility of fragmentation if competing approaches evolve in parallel.</p>



<p>However, Prakash pointed out that the presence of multiple similar frameworks that touch on agent trust, identity, and discovery shows that the agent infrastructure market has entered its standards discovery phase, not its standards consolidation phase.</p>



<p>“Overlap in discovery, identity, messaging, and observability is expected at this stage,” Prakash said.</p>



<p>Enterprises, thus, the analyst added, should wait for “clarity and clearer interoperability guidance” before they treat any one initiative as strategic infrastructure.</p>



<p><em>The article originally appeared on <a href="https://www.infoworld.com/article/4189361/new-linux-foundation-project-aims-to-bring-dns-style-trust-to-ai-agents.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How France’s education ministry built an open-source file-share platform for 400K users]]></title>
<description><![CDATA[As France seeks to reduce its dependence on non-European technology suppliers across the public sector, open-source software is playing an increasingly prominent role.



Among the projects that reflect this trend is Nuage, a file-sharing and storage platform developed by the Ministry of National...]]></description>
<link>https://tsecurity.de/de/3624257/it-nachrichten/how-frances-education-ministry-built-an-open-source-file-share-platform-for-400k-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624257/it-nachrichten/how-frances-education-ministry-built-an-open-source-file-share-platform-for-400k-users/</guid>
<pubDate>Thu, 25 Jun 2026 13:18:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As France seeks to reduce its dependence on non-European technology suppliers across the public sector, open-source software is playing an increasingly prominent role.</p>



<p>Among the projects that reflect this trend is Nuage, a file-sharing and storage platform developed by the Ministry of National Education for teachers, administrators and other staff. Aimed at its 1.2 million employees within the Ministry, there are now 400,000 active accounts, with around two-thirds of users accessing the service each week. </p>



<p>Each person is allocated 100GB in storage for documents, PDFs, videos, and images, though the average usage level is around 3GB. Workers can also use the platform to share and co-edit documents with colleagues.</p>



<h2 class="wp-block-heading">Open source as a model for others</h2>



<p>The Ministry’s project is an example of how open-source software used at scale and could serve as a model for other organizations looking to embrace digital sovereignty. Interest in that approach has risen in recent months <a href="https://www.computerworld.com/article/4127546/how-the-eus-trade-bazooka-could-hit-the-us-tech-sector.html">amid geopolitical and trade tensions</a>, with <a href="https://www.computerworld.com/article/4109029/global-uncertainty-is-reshaping-cloud-strategies-in-europe.html">heightened concerns in Europe</a> that the Trump Administration could suddenly access to certain technologies.</p>



<p>For the French agency, Nuage allows the ministry to retain control over sensitive student-related data stored by teachers, said <a href="https://fr.linkedin.com/in/beno%C3%AEt-pi%C3%A9dallu-075a065" target="_blank" rel="noreferrer noopener">Benoît Piédallu</a>, national project manager for digital services at the French Ministry of National Education. “We didn’t want this data to go to the US, to Microsoft, to other systems like that. It was important to us to be on premise,” said Piédallu. </p>



<p>Cost is another factor. The Ministry of Education can allocate around 10 euros per user each year for the project, said Piédallu. “My budget for the platform is less than two million [euros] a year, so price is, of course, a big issue in this matter,” he said.</p>



<p>The Ministry for Education’s digital services team is responsible for design and delivery of the Nuage platform, with the work taking place between the initial deployment in 2020 to the final version release in 2022. </p>



<p>“The major challenge about deploying an open-source platform is that we have to do everything [internally],” he said, such as running virtual machines, and installing and configuring Linux Debian. “We need to manage everything on this virtual machine, and, of course, to install and configure Nextcloud on it.” </p>



<p>The Ministry has two dedicated staff members managing the file-storage platform, while another handles the infrastructure. The Nuage platform is hosted at two state-owned data centers: one near Paris, the other in the south of the country near the Pyrenees.</p>



<p>Nuage’s file storage and synchronization features are built on Nextcloud Files, open-source software developed by German vendor Nextcloud. Nuage also includes a document editor app built on Nextcloud Office, which uses Collabora’s open-source software.</p>



<h2 class="wp-block-heading">User uptake on the upswing</h2>



<p>Piédallu said user uptake of the file-storage service is a sign of its success. (A smaller proportion of that 400,000-strong group — 80,000 workers— use the Nuage file sync client on their desktop. Nuage stores 570 million documents with 1.2 petabytes of data.)</p>



<p>This level of adoption has been achieved largely without \ efforts to encourage use internally, said Piédallu. “We didn’t do any major, national communication for our users to start using the service, to make them know they have the opportunity to use 100 gigabyte of backup on this file system,” he said. Even so, adoption continues to rise, with around 40 terabytes more storage required each month to meet demand.</p>



<p>“We have a very linear increase. It is incredible to see that,” said Piédallu.</p>



<p>But with <a href="https://www.idc.com/resource-center/press-releases/worldwide-external-enterprise-storage-systems-market-accelerates-to-22-7-growth-in-the-first-quarter-of-2026-driven-by-ai-infrastructure-demand-and-deferred-refresh-spending-according-to-idc/" target="_blank">rising storage hardware costs,</a> the Ministry actually hopes to slow the pace of adoption to avoid added infrastructure costs, said Piédallu. “If I do a communication tomorrow it will accelerate usage, and I know that I have a limit in my data center.” </p>



<p>Even without an adoption push, the Ministry forecasts uptake will increase to 600,000 users by the end of this year. </p>



<p>Although the digital services team doesn’t have full visibility into how Nuage has been received, Piédallu said feedback is positive, with the file storage and sync system largely invisible to users and operating well — aside from some bugs around synchronization at times. “They are very happy to use it. They don’t make a comparison to Google Drive or OneDrive…, it’s just working,” he said. </p>



<p>The Collabora-based office application suite has been less well-received, in part because its interface is unfamiliar to many users. “When they want to edit documents, work on a [spreadsheet] or something like that, they want it to be exactly like they are used to — if they have Microsoft Office, they want [it] to work the same, to have the same options,” he said. </p>



<p>Local administrations and school districts are not required to use Nuage; they can choose whether to deploy the platform or rely on proprietary software. Microsoft SharePoint and Office tools are still in use, for instance, though there are no figures available for how many people are using the software. The Ministry pays around 2.5 million euros a year for Windows licenses, for instance, across 50,000 devices for Ministry staff.</p>



<h2 class="wp-block-heading">Looking toward tech independence</h2>



<p>Digital sovereignty has become a growing priority for the Ministry in recent years, and across the French public sector more broadly, said Piédallu. </p>



<p>“A few years ago, free software and digital commons were very important; now, it is sovereignty…, to deploy some tools that are sovereign, and that we can deploy on our side with no ‘kill switch,’ et cetera,” he said. “It is something that in the administration, the French administration, we push, and politicians are pushing.”</p>



<p>Nuage is just one of numerous open-source initiatives under way within the French public sector. Other examples include the introduction of LaSuite, an open-source productivity and collaboration suite developed by France’s Interministerial Directorate for Digital Affairs (DINUM). It includes services such as messaging app Tchap and Visio, a <a href="https://www.computerworld.com/article/4122979/french-authorities-ban-teams-and-zoom.html">video meeting platform.</a> The French government has also set out plans to <a href="https://www.computerworld.com/article/4158085/the-french-government-is-testing-alternatives-to-windows.html">replace Windows with Linux</a> in parts of the public sector.</p>



<p>Piédallu said other public sector organizations considering open-source software should look to peers that have completed similar projects for guidance. He added that many senior decision-makers overestimate the difficulty of moving away from established technologies.</p>



<p>“Most of the decision people in the hierarchy think that it will be very hard to do. Of course, there is work to do to embrace the change, to help people, to be sure that everything that has been thought about,” said Piédallu. “But at the end, it is possible, it is something that we can do.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stryker Cyberattack Lawsuit Faces Challenge as Company Seeks Dismissal]]></title>
<description><![CDATA[The legal fallout from the Stryker cyberattack continues to unfold, as the medical technology manufacturer has asked a federal court to dismiss a proposed class action lawsuit brought by current and former employees. The plaintiffs allege that their personal information was compromised during the...]]></description>
<link>https://tsecurity.de/de/3623999/it-security-nachrichten/stryker-cyberattack-lawsuit-faces-challenge-as-company-seeks-dismissal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623999/it-security-nachrichten/stryker-cyberattack-lawsuit-faces-challenge-as-company-seeks-dismissal/</guid>
<pubDate>Thu, 25 Jun 2026 11:52:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="801" height="496" src="https://thecyberexpress.com/wp-content/uploads/Stryker-cyberattack.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Stryker cyberattack" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Stryker-cyberattack.webp 801w, https://thecyberexpress.com/wp-content/uploads/Stryker-cyberattack-300x186.webp 300w, https://thecyberexpress.com/wp-content/uploads/Stryker-cyberattack-768x476.webp 768w, https://thecyberexpress.com/wp-content/uploads/Stryker-cyberattack-600x372.webp 600w, https://thecyberexpress.com/wp-content/uploads/Stryker-cyberattack-150x93.webp 150w, https://thecyberexpress.com/wp-content/uploads/Stryker-cyberattack-750x464.webp 750w, https://thecyberexpress.com/wp-content/uploads/Stryker-cyberattack.webp 801w, https://thecyberexpress.com/wp-content/uploads/Stryker-cyberattack-300x186.webp 300w, https://thecyberexpress.com/wp-content/uploads/Stryker-cyberattack-768x476.webp 768w, https://thecyberexpress.com/wp-content/uploads/Stryker-cyberattack-600x372.webp 600w, https://thecyberexpress.com/wp-content/uploads/Stryker-cyberattack-150x93.webp 150w, https://thecyberexpress.com/wp-content/uploads/Stryker-cyberattack-750x464.webp 750w" sizes="(max-width: 801px) 100vw, 801px" title="Stryker Cyberattack Lawsuit Faces Challenge as Company Seeks Dismissal 3"></p><span data-contrast="auto">The legal fallout from the Stryker cyberattack continues to unfold, as the medical technology manufacturer has asked a federal court to dismiss a proposed class action lawsuit brought by current and former employees. The plaintiffs allege that their personal information was compromised during the cyberattack on Stryker, but the company argues that its investigation found no evidence supporting those claims.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Employee Data Was Not Accessed During the Stryker Cyberattack</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">In a <a href="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/asset_files/external/memoranduminsupportofmotiontodismisslackof.pdf" target="_blank" rel="nofollow noopener">court filing</a> submitted Monday, Michigan-based Stryker said an internal review conducted with independent experts found that none of the eight named plaintiffs had personally identifiable information (PII) accessed during the incident. According to a statement from Chief Information Security Officer Juan Pablo Calderon, investigators examined files and data that the <a href="https://thecyberexpress.com/irhythm-data-breach/" target="_blank" rel="noopener">threat actor</a> may have accessed during the attack.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">“Those files and <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28820">data</a> were searched for plaintiffs' PII, and Stryker determined as a purely factual matter that none of the plaintiffs' PII exists in those files and data,” Calderon stated. He added that business email addresses belonging to two plaintiffs were found, but no sensitive personal information was identified.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Iranian Hacktivists Claimed Massive Data Theft and Destruction</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">The Stryker <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-a-cyber-attack/" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="28819">cyberattack</a> was claimed by Handala, a group widely suspected of acting as a front for Iran’s Ministry of Intelligence. The Iranian hacktivists alleged in March that they had stolen 50 terabytes of critical company data. They further claimed to have erased 200,000 devices and 12 petabytes of data “in just a few hours,” describing the information as assets that had taken years to collect and billions of dollars to protect.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The cyberattack on Stryker <a href="https://thecyberexpress.com/stryker-cyberattack-disrupted-supply-chain/" target="_blank" rel="noopener">occurred nearly two weeks</a> after the United States and Israel launched major military operations against Iran on February 28. While Stryker maintained that customer-connected devices and systems were not affected, the incident disrupted electronic ordering and related services used by clients. Those systems remained unavailable for several weeks before being fully restored in early April.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Legal Experts Weigh In on the Cyberattack on Stryker</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">Stryker also argued that the plaintiffs rushed to court, filing lawsuits “merely 48 hours” after the company disclosed the cyberattack on March 11. According to the company, the lawsuits relied on speculation that names, Social <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Security" data-wpil-keyword-link="linked" data-wpil-monitor-id="28821">Security</a> numbers, and other personal information had been exposed.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The company further contends that each plaintiff’s PII had already been exposed in previous breaches involving other organizations, making it difficult to connect any alleged harm, including identity theft, directly to the cyberattack on Stryker. None of the named plaintiffs received breach notifications from the company, yet they seek to represent all U.S. individuals whose information was allegedly compromised.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Legal experts say the case highlights broader questions surrounding data breach litigation. <a href="https://www.bankinfosecurity.com/stryker-seeks-to-dismiss-class-action-lawsuit-in-cyberattack-a-32063" target="_blank" rel="nofollow noopener">Steven Teppler</a> of Mandelbaum Barrett noted that “the complaint may outrun the facts” when lawsuits are filed immediately after a cyberattack. He added that courts increasingly require plaintiffs to show “more than speculation” that their information was affected.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building a state-of-the-art development platform with Backstage]]></title>
<description><![CDATA[Key takeaways




Backstage solved the portal problem, not the platform problem. A portal organizes catalogs, documentation, and templates. A platform owns deployments, environments, policies, and runtime operations. Backstage assumes that the execution layer exists beneath it.



Point-to-point ...]]></description>
<link>https://tsecurity.de/de/3623951/ai-nachrichten/building-a-state-of-the-art-development-platform-with-backstage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623951/ai-nachrichten/building-a-state-of-the-art-development-platform-with-backstage/</guid>
<pubDate>Thu, 25 Jun 2026 11:34:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">Key takeaways</h2>



<ul class="wp-block-list">
<li>Backstage solved the portal problem, not the platform problem. A portal organizes catalogs, documentation, and templates. A platform owns deployments, environments, policies, and runtime operations. Backstage assumes that the execution layer exists beneath it.</li>



<li>Point-to-point integrations become a maintenance burden. Many organizations end up with a “messy middle” where Backstage is connected directly to <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">CI/CD</a>, <a href="https://www.infoworld.com/article/2259088/what-is-gitops-extending-devops-to-kubernetes-and-beyond.html" data-type="link" data-id="https://www.infoworld.com/article/2259088/what-is-gitops-extending-devops-to-kubernetes-and-beyond.html">GitOps</a>, <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html" data-type="link" data-id="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a>, and <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html" data-type="link" data-id="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a> tools through custom wiring that’s fragile and hard to evolve.</li>



<li>Abstractions are the interface between developers and infrastructure. Developers work with components, endpoints, and dependencies. Platform engineers work with environments, pipelines, and component types. The platform compiles both into Kubernetes resources.</li>



<li>A control plane bridges the gap. It sits between the portal and runtime, compiling abstractions into infrastructure, enforcing policies consistently, reconciling drift, and aggregating runtime state back to the portal.</li>



<li>Good abstractions enable advanced capabilities. Unified observability, automated guardrails, and AI agents that can reason about and act on your platform. All becomes possible when you have well-defined concepts and a control plane that understands both sides.</li>
</ul>



<p>…</p>



<h2 class="wp-block-heading">Start with Backstage</h2>



<p>If you’re building an <a href="https://www.infoworld.com/article/2263059/what-is-an-internal-developer-platform-paas-done-your-way.html" data-type="link" data-id="https://www.infoworld.com/article/2263059/what-is-an-internal-developer-platform-paas-done-your-way.html">internal developer platform</a>, Backstage is certainly part of your architecture. It solved the discovery problem and became the default choice for developer portals.</p>



<p>Before Backstage, developers navigated wikis, spreadsheets, and tribal knowledge just to find who owned a service or how to spin up a new one. Backstage brought structure: a unified catalog, a plugin ecosystem, and golden-path templates that actually got adopted.</p>



<p><a href="https://github.com/backstage/backstage" data-type="link" data-id="https://github.com/backstage/backstage">Backstage</a> is a Cloud Native Computing Foundation (CNCF) project with one of the most active contributor communities in the ecosystem. When organizations evaluate developer portals, Backstage is the starting point.</p>



<p>However, many teams discover something after deployment: Backstage provides a portal, not a platform. A portal organizes information. A platform owns execution: deployments, environments, policies, observability, and runtime operations.</p>



<p>Backstage assumes that the execution layer exists beneath it. That layer is where most of the complexity lives, and it’s what this article is about.</p>



<h2 class="wp-block-heading"><a></a>What a developer platform actually is</h2>



<p>A developer platform or an internal developer platform is a self-service framework you build to help developers build, deploy, and manage applications independently.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_01_developer_platform.png" alt="Image_01_developer_platform" class="wp-image-4189088" width="1024" height="307" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<p>Most organizations already have an organically grown version of this:</p>



<ul class="wp-block-list">
<li>Developer commits code</li>



<li>CI pipeline builds and pushes images to a registry</li>



<li>Pipeline updates a GitOps repo containing Helm charts or Kubernetes manifests</li>



<li>Argo CD or Flux syncs those manifests to clusters</li>
</ul>



<p>You may have this workflow running today. The question is whether it’s a pipeline stitched together with scripts and tribal knowledge, or a platform with consistent abstractions and self-service capabilities.</p>



<h2 class="wp-block-heading"><a></a>What usually happens after adopting Backstage</h2>



<p>How do you add Backstage to this setup? The common approach is for developers to maintain Backstage entity files (primarily component and API entities) alongside the source code. Then you configure the built-in entity provider in Backstage to scan source code repositories to populate the catalog. Eventually, you’ll end up with a portal with all your systems, components, APIs, and other resources. So far, so good.</p>



<p>Once developers start using the portal, you’ll be hit with a consistent flow of feature requests:</p>



<ul class="wp-block-list">
<li>“I see my component in the catalog, but is it actually running?” You configure the Kubernetes plugin and link components to their corresponding manifests. Now developers can see pod status, deployment state, and replica counts.</li>



<li>“I need logs, metrics, and traces related to my component.” You integrate your observability stack or developers context-switch to Grafana, Datadog, or whatever you’re running. Either way, more wiring.</li>



<li>“Can I create new components from here?” You build Backstage templates that scaffold repos with the right structure, Backstage entities, Helm charts, and CI pipelines, all of which encode your organization’s best practices. Now you’re maintaining golden paths in templates, separately from the runtime configuration that actually enforces them.</li>
</ul>



<p>Each request is reasonable and achievable, but they add up.</p>



<h2 class="wp-block-heading"><a></a>The messy middle</h2>



<p>Eventually, you end up with a platform held together by point-to-point connections. Every new capability requires new wiring. Every upgrade risks breaking something. You spend more time maintaining integrations than building features.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_02_messy_middle.png" alt="Image_02_messy_middle" class="wp-image-4189092" width="1024" height="893" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<p>You would never design a production system with this many point-to-point dependencies. Why accept it for your platform?</p>



<h2 class="wp-block-heading"><a></a>Treat the platform as a product, but also as a system</h2>



<p>Organically grown systems get you started, but once you commit to Backstage as your portal, you need a product mindset. Start from developer experience, understand their pain points, then design a system that addresses them coherently.</p>



<p>A platform is also a system. Approach it the way you would approach any production system you’re building. You wouldn’t design a back-end service without thinking about separation of concerns, clear interfaces, and extensibility.</p>



<p>The same principles apply here:</p>



<ul class="wp-block-list">
<li>Separation of concerns: Don’t mix developer-facing abstractions with infrastructure implementation. Keep them separate so you can evolve each independently.</li>



<li>Clear interfaces: Define explicit abstractions. Developers and platform engineers should interact with well-defined concepts rather than implementation details scattered across Helm charts and CI scripts.</li>



<li>Extensibility: Requirements keep changing. If every new capability requires custom wiring, you’ll spend more time maintaining than improving. Design for extension from the start.</li>
</ul>



<p>The difference between a pile of integrations and a platform is architecture. Get the system design right, and new capabilities slot in cleanly. Get it wrong, and every feature request becomes a maintenance burden.</p>



<h2 class="wp-block-heading">The missing layer beneath Backstage</h2>



<p>Moving from an organically grown pipeline to an actionable developer platform is a big leap. You probably have CI/CD pipelines that work, a Kubernetes cluster running workloads, and a Backstage catalog describing what exists.</p>



<p>The questions are:</p>



<ul class="wp-block-list">
<li>How do you transform an informational portal into one with a platform under the hood?</li>



<li>How do you bridge the gap between what the catalog describes and what’s actually running?</li>



<li>How do you enforce golden paths beyond initial scaffolding?</li>



<li>How do you design a platform that evolves with your organization’s needs?</li>
</ul>



<p>What’s missing is a connective layer between Backstage and your runtime, something that makes the portal operational rather than just informational. Let’s look at the key architectural elements to consider when designing that layer and the whole platform.</p>



<h2 class="wp-block-heading"><a></a>Start with abstractions</h2>



<p>One of the main goals of a developer platform is to reduce cognitive load. The platform should meet developers where they are and speak their language, not Kubernetes’.</p>



<p>Every organization has its own vocabulary, but the Backstage system model is a good starting point. It may not cover everything, but you can extend it with custom entities. The key is that developers work with high-level concepts while the platform compiles them into Kubernetes resources. Developers are abstracted away from the underlying details, but they can still see what’s happening underneath.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Concept</strong></td><td><strong>Description</strong></td><td><strong>Backstage mapping</strong></td></tr><tr><td>Project</td><td>A cloud-native application composed of multiple components. It is also a unit of isolation.</td><td>System</td></tr><tr><td>Component</td><td>A deployable unit, such as web services, APIs, workers, or scheduled tasks.</td><td>Component</td></tr><tr><td>Endpoint</td><td>A network-accessible interface exposed by a component. </td><td>API</td></tr><tr><td>Resource</td><td>External infrastructure such as databases, queues, and caches.</td><td>Resource</td></tr><tr><td>Dependency</td><td>A component’s reliance on endpoints or resources.</td><td>consumesAPI, dependsOn</td></tr></tbody></table> </div></figure>



<p>These are not just static abstractions; they also have associated runtime semantics. The following diagram illustrates runtime representations of these concepts.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_03_cell_diagram.png" alt="Image_03_cell_diagram" class="wp-image-4189100" width="1024" height="905" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<p>In the workload cluster, a project becomes an isolation boundary for all of its components. The platform translates this into Kubernetes namespaces and network policies that enforce the boundary, not just document it.</p>



<p>Endpoint visibility determines which endpoints can talk to which. A project-scoped endpoint gets network policies that block traffic from outside the project. An organization-scoped endpoint is exposed to internal traffic but remains behind the internal gateway. An external endpoint gets routed through the public gateway with appropriate authentication. Developers declare visibility; the platform generates the policies.</p>



<p>Dependencies work the same way. When a component declares a dependency on an endpoint, the platform injects the URL and other environment variables required to connect to the dependency. It configures the network policies for both directions, egress from the calling endpoint and ingress to the target endpoint. Without the declared dependency, egress is blocked by default. The dependency graph you see above reflects actual permitted traffic flow, not just intended relationships.</p>



<h2 class="wp-block-heading"><a></a>You need platform abstractions, too</h2>



<p>Developer abstractions help your developers. Platform abstractions help you.</p>



<p>While developers work with components, endpoints, and dependencies, you need a different vocabulary to design and operate the platform itself. These abstractions let you and your team define standards, enforce policies, and create structure without writing low-level configurations for every scenario.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Concept</strong></td><td><strong>Description</strong></td></tr><tr><td>Namespace</td><td>A logical grouping of users and resources, typically aligned to a company, business unit, or team. Defines ownership and access boundaries.</td></tr><tr><td>Data plane</td><td>A Kubernetes cluster that hosts one or more deployment environments. You can have multiple data planes for isolation, regional distribution, or scaling.</td></tr><tr><td>Environment</td><td>A runtime context, such as dev, test, staging, or prod, where workloads are deployed and executed. Environments carry their own policies and resource configurations.</td></tr><tr><td>Pipeline</td><td>A defined process that governs how work, such as builds, deployments, promotions, or any automated workflows, flows through the platform. Encodes your operational processes as a platform primitive.</td></tr><tr><td>Component type</td><td>Defines a category of workload—Service, Worker, Cron, Job.</td></tr><tr><td>Trait</td><td>A reusable capability that attaches to any component, such as autoscaling, resilience, observability, and security policies. Compose behaviors without duplicating configuration.</td></tr></tbody></table> </div></figure>



<p>These abstractions separate platform concerns from application concerns. Developers don’t need to know which cluster their code runs on or how environments are wired together. They deploy to “staging” or “prod,” and you define what those terms mean.</p>



<h2 class="wp-block-heading"><a></a>The missing layer is a control plane</h2>



<p>The control plane is where abstractions become real. It sits between the portal and your workload clusters, translating developer intent into infrastructure configuration.</p>



<p>You can think of it as a compiler that targets Kubernetes clusters, converting higher-level abstractions into what Kubernetes and its underlying frameworks understand. It can also apply platform-wide rules during this compilation. Resource limits, security requirements, etc., can be enforced consistently, not merely documented and hoped for.</p>



<p>But compilation is only half the job. The control plane also reconciles continuously. It monitors drift between the declared and actual states. When they diverge, it corrects. Your abstractions remain the source of truth; the control plane enforces them over time.</p>



<h2 class="wp-block-heading"><a></a>Programmability is not optional</h2>



<p>One of the key aspects of this control plane is programmability. If you want your platform to evolve, the control plane needs to be extensible. Different teams have different requirements. New capabilities emerge. You can’t anticipate everything up front.</p>



<p>This means allowing customization of how abstractions compile to Kubernetes manifests. But extensibility without guardrails is dangerous. You need programmability that preserves your invariants. The goal is constrained flexibility, open enough to evolve, structured enough to stay coherent.</p>



<h2 class="wp-block-heading"><a></a>Observable abstractions make the portal useful</h2>



<p>The control plane also aggregates runtime state and associates it with your abstractions. This is what makes the portal useful. Without this, developers piece together information from different tools: Kubernetes dashboard for pod status, Argo CD for the deployment state, Grafana for metrics, Jaeger for traces. Each tool knows part of the story; none shows the full picture.</p>



<p>With the control plane aggregating state, the portal tells a connected story. When a developer opens a component page in Backstage, they see:</p>



<ul class="wp-block-list">
<li>Deployed environments and their status</li>



<li>Current replicas and resource usage</li>



<li>Recent deployments and who triggered them</li>



<li>Logs, metrics, and traces that are scoped to that component, in each environment</li>



<li>Dependencies and their health</li>
</ul>



<p>No context-switching. No reconstructing which pod belongs to which service in which cluster. The abstraction is the anchor; everything else attaches to it.</p>



<p>This only works because the control plane understands both sides. It compiled the abstractions to Kubernetes, so it knows how to map runtime data back. Information flows in both directions. Downward: developer intent flows through the control plane and becomes running workloads. Upward: runtime state flows back through the control plane and appears in the portal.</p>



<p>This is what makes the portal actionable. It’s not just displaying information; it’s connected to a system that can act.</p>



<h2 class="wp-block-heading"><a></a>Data plane: keep it simple</h2>



<p>The data plane is where your workloads actually run. In most cases, this means one or more Kubernetes clusters. The data plane doesn’t know about your abstractions. It understands Kubernetes primitives such as pods, deployments, services, and ingresses. The control plane’s job is to compile your higher-level concepts into these primitives and apply them.</p>



<p>The data plane does one thing: it runs what the control plane tells it to run. The intelligence lives in the control plane; the execution happens in the data plane.</p>



<h2 class="wp-block-heading">Where AI fits into the platform</h2>



<p>AI is now part of every platform conversation, but the architectural question is where it actually belongs.</p>



<p>The abstractions and control plane you’ve built create the foundation. You have well-defined concepts such as components, endpoints, and dependencies. You have a runtime state aggregated and tied to those concepts. You have a connected view of your system. AI agents can definitely leverage this.</p>



<h3 class="wp-block-heading"><a></a>Agents as platform users</h3>



<p>AI agents should be able to interact with your platform as first-class participants. This requires exposing platform capabilities through interfaces that agents can use, such as <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) servers, APIs with clear semantics, user-friendly CLIs, and skills that map to platform operations.</p>



<p>These capabilities of the platform enable agents to create components, trigger builds and deployments, query environment status, and reason about dependencies. They help you and your developers become more productive.</p>



<h3 class="wp-block-heading"><a></a>Agents as platform capabilities</h3>



<p>You can also embed agents inside your platform to help your teams’ day-to-day operations. Here are some examples of agents you can develop:</p>



<ul class="wp-block-list">
<li>SRE agents: Analyze logs, metrics, and traces to surface likely root causes. Instead of developers digging through dashboards, the agent correlates signals and suggests where to look.</li>



<li>FinOps agents: Help teams understand and optimize resource costs across environments and components.</li>



<li>Architect agents: Assist with system design decisions, such as dependency analysis, capacity planning, and migration impact assessment.</li>
</ul>



<p>These agents work because they have access to the control plane’s unified view. They see abstractions, runtime state, and observability data in one place, the same connected story developers see in the portal.</p>



<p>The pattern holds. Good abstractions make everything easier, including AI.</p>



<h2 class="wp-block-heading"><a></a>OpenChoreo as a reference implementation</h2>



<p><a href="https://github.com/openchoreo/openchoreo" data-type="link" data-id="https://github.com/openchoreo/openchoreo">OpenChoreo</a> is an open-source developer platform for Kubernetes. It was recently accepted into the CNCF as a sandbox project. OpenChoreo implements the architecture described in this article: developer abstractions backed by a control plane, a Backstage-powered portal, integrated CI/CD and GitOps, and observability wired to your abstractions.</p>



<p>If you’re building this architecture yourself, OpenChoreo is worth studying as a reference, even if you don’t adopt it directly. The project demonstrates how these pieces fit together: how abstractions compile into Kubernetes resources, how runtime state flows back to the portal, and how guardrails are enforced during compilation.</p>



<p>You can use OpenChoreo as a complete platform, or install its Backstage plugins into your existing portal and use just the control plane layer. Either way, the underlying patterns are what matter. The architecture is the idea. OpenChoreo is one way to implement it.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/image_04_multi_plane_architecture.png?w=1024" alt="image_04_multi_plane_architecture" class="wp-image-4189109" width="1024" height="552" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<h2 class="wp-block-heading">A useful mental model: multi-plane architecture</h2>



<p>OpenChoreo separates concerns across five planes:</p>



<ol class="wp-block-list">
<li>Experience plane: Where developers, platform engineers, and SREs interact with the platform via the Backstage-powered portal, CLI, GitOps, or AI agents.</li>



<li>Control plane: The brain that translates high-level abstractions (components, APIs, environments, pipelines) into Kubernetes manifests. Programmable through component types and traits, so you can extend it without forking or writing low-level controllers. Continuously reconciles the runtime state back into those abstractions.</li>



<li>Data plane: Where workloads run. Enforces the semantics of your abstractions, such as project isolation, traffic policies, and security boundaries. These aren’t just configurations; the platform guarantees them.</li>



<li>Observability plane: Feeds metrics, logs, and traces back through the same abstractions developers already understand, requiring no translation.</li>



<li>Workflow plane (optional): Handles builds using Cloud Native Buildpacks and Argo Workflows by default.</li>
</ol>



<p>These planes work together but remain separate concerns. You can reason about each independently, evolve them at different rates, and deploy them flexibly: a single cluster with namespace isolation for dev/test, fully separated multi-cluster setups for production, or hybrid topologies that colocate planes like Control and CI for cost efficiency.</p>



<h2 class="wp-block-heading"><a></a>AI and OpenChoreo</h2>



<p>OpenChoreo is being built to treat AI agents as first-class participants. In OpenChoreo 1.0, external agents can interact with the platform via MCP servers, agent skills, or the CLI to generate and edit component configurations, reason about releases and environments, and more. The built-in SRE Agent is a first example of this. It analyzes logs, metrics, and traces from your deployments and uses LLMs to surface likely root causes and actionable insights.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_05_external_internal_agents_openchoreo.png?w=1024" alt="Image_05_external_internal_agents_openchoreo" class="wp-image-4189115" width="1024" height="584" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<h2 class="wp-block-heading">From portal to platform</h2>



<p>Backstage solved the portal problem. It gave you a unified interface for catalogs, documentation, and golden paths. But a portal isn’t a platform. There’s a gap between what developers see and what’s actually running, and that’s where you get stuck. You fill it with point-to-point integrations, custom plugins, and scripts that become their own maintenance burden.</p>



<p>The pattern that works is portal, control plane, data plane: </p>



<ul class="wp-block-list">
<li>A portal that gives developers ready access to catalogs, documentation, and templates.</li>



<li>A control plane that compiles platform abstractions, reconciles drift, and aggregates runtime state.</li>



<li>A data plane that runs workloads and enforces guarantees.</li>
</ul>



<p>Whether you build this yourself or you adopt something like OpenChoreo, the architecture matters more than the tools. Get the layers right, and new capabilities slot in cleanly. Get them wrong, and every feature request becomes a project.</p>



<p>Backstage gives you the front door. The real platform begins behind it.</p>



<p><em>—</em></p>



<p><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[MWC 2026 Shanghai: Huawei bets on token economy as telecoms seeks new AI revenues]]></title>
<description><![CDATA[AI-native networks, intelligent computing and token-based business models are emerging as the next frontier of digital infrastructure]]></description>
<link>https://tsecurity.de/de/3623916/it-nachrichten/mwc-2026-shanghai-huawei-bets-on-token-economy-as-telecoms-seeks-new-ai-revenues/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623916/it-nachrichten/mwc-2026-shanghai-huawei-bets-on-token-economy-as-telecoms-seeks-new-ai-revenues/</guid>
<pubDate>Thu, 25 Jun 2026 11:17:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AI-native networks, intelligent computing and token-based business models are emerging as the next frontier of digital infrastructure]]></content:encoded>
</item>
<item>
<title><![CDATA[Qualcomm Signs Up Meta For Upcoming Data Centre CPUs]]></title>
<description><![CDATA[Facebook parent Meta to use upcoming Qualcomm processors to power servers, as chipmaker seeks data centre market share This article has been indexed from Silicon UK Read the original article: Qualcomm Signs Up Meta For Upcoming Data Centre CPUs
Read more →
The post Qualcomm Signs Up Meta For Upco...]]></description>
<link>https://tsecurity.de/de/3623816/it-security-nachrichten/qualcomm-signs-up-meta-for-upcoming-data-centre-cpus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623816/it-security-nachrichten/qualcomm-signs-up-meta-for-upcoming-data-centre-cpus/</guid>
<pubDate>Thu, 25 Jun 2026 10:38:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Facebook parent Meta to use upcoming Qualcomm processors to power servers, as chipmaker seeks data centre market share This article has been indexed from Silicon UK Read the original article: Qualcomm Signs Up Meta For Upcoming Data Centre CPUs</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/qualcomm-signs-up-meta-for-upcoming-data-centre-cpus/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/qualcomm-signs-up-meta-for-upcoming-data-centre-cpus/">Qualcomm Signs Up Meta For Upcoming Data Centre CPUs</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[칼럼 | AWS에서 보낸 20년, 에이전틱 AI에 대한 깨달음]]></title>
<description><![CDATA[올해는 AWS 출범 20주년이자, 필자가 아마존에서 개발자로 일한 지 20년이 되는 해다.



필자의 커리어는 줄곧 한 가지 목표를 향해 이어져 왔다. 바로 개발자의 일을 더 쉽게 만드는 것이다. 개발자인 필자에게도 다소 이기적인 목표이긴 했다. 예를 들어 데이터베이스 운영에 많은 시간을 빼앗기자, 이를 서비스로 해결하기 위해 DynamoDB 팀에 합류했다. 개발자가 더 이상 직접 데이터베이스를 운영하지 않아도 되도록 하기 위해서였다.



이후에는 람다(Lambda)와 API 게이트웨이(API Gateway) 개발에 참여했...]]></description>
<link>https://tsecurity.de/de/3623571/it-nachrichten/aws-20-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623571/it-nachrichten/aws-20-ai/</guid>
<pubDate>Thu, 25 Jun 2026 08:47:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>올해는 AWS 출범 20주년이자, 필자가 아마존에서 개발자로 일한 지 20년이 되는 해다.</p>



<p>필자의 커리어는 줄곧 한 가지 목표를 향해 이어져 왔다. 바로 개발자의 일을 더 쉽게 만드는 것이다. 개발자인 필자에게도 다소 이기적인 목표이긴 했다. 예를 들어 데이터베이스 운영에 많은 시간을 빼앗기자, 이를 서비스로 해결하기 위해 DynamoDB 팀에 합류했다. 개발자가 더 이상 직접 데이터베이스를 운영하지 않아도 되도록 하기 위해서였다.</p>



<p>이후에는 람다(Lambda)와 API 게이트웨이(API Gateway) 개발에 참여했다. 덕분에 서버를 일일이 관리하거나 요청 라우팅을 직접 처리할 필요가 없어졌다. 이어 클라우드워치(CloudWatch) 개발에도 참여해 운영 환경에서 코드가 실제로 어떻게 동작하는지 손쉽게 확인할 수 있도록 했다. 매번 목표는 같았다. 반복적이고 번거로운 작업을 없애고, 누구나 별다른 고민 없이 사용할 수 있는 서비스로 만드는 것이었다.</p>



<p>지금도 같은 목표를 추구하고 있다. 달라진 것은 사용하는 도구뿐이다.</p>



<h2 class="wp-block-heading">바이브 코딩의 등장과 한계</h2>



<p>LLM은 자연어로 원하는 기능을 설명하면 필요한 코드를 즉시 생성할 수 있는 시대를 열었다. 초기에는 이른바 ‘바이브 코딩(vibe coding)’ 방식이 주를 이뤘다. 스크립트 수정을 요청하고, 코드를 컴파일해 실행한 뒤, 발생한 오류를 다시 입력하면서 다음 결과가 더 나아지기를 기대하는 식이었다.</p>



<p>하지만 바이브 코딩의 전체 과정을 에이전트 루프(agentic loop) 로 자동화하면서 상황은 크게 달라졌다. 이제는 사람이 오류를 일일이 전달하지 않아도 에이전트가 스스로 모델을 호출하고, 코드를 실행한 뒤 실패 원인을 확인하며, 테스트를 통과할 때까지 반복 작업을 수행할 수 있게 됐다.</p>



<p>그러나 한 가지 큰 문제가 있었다. 에이전트가 쉽게 방향을 잃는다는 점이다. 개인 프로젝트에서는 큰 문제가 아닐 수 있지만, 대규모의 핵심 코드베이스에서는 결코 용납할 수 없는 한계다.</p>



<h2 class="wp-block-heading">에이전트를 위한 명세 기반 개발</h2>



<p>필자가 에이전트가 방향을 잃지 않도록 하는 방법은 <a href="https://kiro.dev/blog/kiro-and-the-future-of-software-development/" target="_blank" rel="nofollow">명세 기반 개발</a>(spec-driven development)이다.</p>



<p>막연한 프롬프트만 입력한 채 에이전트를 코드 저장소(repo)에 투입하는 대신, 본격적인 코딩에 앞서 에이전트와 함께 세 가지 핵심 산출물을 먼저 만든다. 요구사항 명세(requirements specification), 설계 문서(design document), 작업 분해(task breakdown)이며, 모두 마크다운(Markdown) 형식으로 작성한다.</p>



<p>이 문서들은 ‘개발 완료(done)’의 기준을 정의하는 공동 계약서 역할을 한다. 사람과 에이전트 모두 읽고, 검토하고, 수정할 수 있는 형태로 관리된다.</p>



<p>실제 업무에서는 일반적인 AI에 입력할 법한 프롬프트로 시작한다. 그러면 에이전트는 이를 ‘반드시 수행해야 한다(shall)’는 요구사항과 수용 기준(acceptance criteria)을 포함한 구조화된 요구사항 문서로 확장한다. 필자는 이 문서를 검토하면서 에이전트와 대화를 이어가고, 원하는 내용과 일치할 때까지 수정한다.</p>



<p>요구사항이 정리되면 에이전트는 설계안을 제시한 뒤, 우선 실제로 동작하는 기능을 구현하는 데 초점을 맞춰 작업을 세분화한다. 이후 완성도를 높이고 포괄적인 테스트를 추가하는 방식으로 개발을 진행한다.</p>



<p>이 과정의 장점은 절차가 경직돼 있다는 데 있지 않다. 실제로는 여러 단계를 오가며 반복적으로 수정한다. 설계를 검토하다 보면 빠진 요구사항이 발견되기도 하고, 코드 예시를 본 뒤 구현 방식을 바꾸기도 한다.</p>



<p>핵심은 에이전트가 더 이상 합의한 내용을 잊지 않는다는 점이다. 요구사항과 설계, 작업 목록이 모두 명시적으로 문서화되고 버전 관리되며 언제든 확인할 수 있기 때문이다. 새로운 기능을 추가하거나 버그를 수정할 때도 변경 내용을 정확히 담은 새로운 명세부터 작성한다.</p>



<h2 class="wp-block-heading">속성 기반 테스트의 역할</h2>



<p>명세가 명확해지면 이를 불변 조건(invariant)으로 정의하고, <a href="https://kiro.dev/blog/property-based-testing-fixed-security-bug/" target="_blank" rel="nofollow">속성 기반 테스트(property-based testing)에 활용</a>해 에이전트가 명세를 벗어나지 않도록 검증할 수 있다.</p>



<p>기존처럼 ‘특정 입력에는 특정 출력이 나와야 한다’는 개별 테스트를 작성하는 대신, 다양한 입력값과 실행 순서에서도 반드시 유지돼야 하는 속성을 정의하는 방식이다.</p>



<p>명세에서 도출한 강력한 테스트가 없으면 에이전트는 코드를 수정하는 대신 테스트를 통과하도록 테스트 자체를 우회하는 경우가 있다. 예를 들어 검증(assertion)을 주석 처리하거나 조건을 느슨하게 만들어 빌드만 성공시키는 식이다.</p>



<p>속성 기반 테스트는 이러한 문제를 막는 데 효과적이다. 기대하는 동작을 한 번 정의해 두면 사람과 에이전트 모두 지속적으로 그 요구사항을 충족하는지 검증할 수 있기 때문이다.</p>



<p>이 접근 방식은 보안 측면에서도 의미가 크다. 보안팀이 데이터 처리 방식이나 권한 관리, 오류 처리에 대한 요구사항을 에이전트가 사용하는 동일한 명세 언어로 불변 조건 형태로 정의하면, 속성 기반 테스트를 통해 다양한 시나리오에서 이를 반복적으로 검증할 수 있다. 이는 모든 개발자가 촉박한 일정 속에서도 모든 보안 규칙을 빠짐없이 기억하기를 기대하는 것보다 훨씬 효과적으로 보안을 개발 초기 단계부터 내재화하는 방법이다.</p>



<h2 class="wp-block-heading">데브옵스 에이전트와 앞으로 10년의 개발 방식</h2>



<p>지난 20년 동안 얻은 가장 큰 교훈은 장애 대응의 핵심이 단순히 근본 원인(root cause)을 찾는 데 있지 않다는 점이다. 무엇이 변경됐는지, 호출하는 시스템에는 어떤 변화가 있었는지, 어떤 한계에 도달했는지, 어떤 구성 요소가 의도대로 실패했는지, 그리고 어떤 의존성이 영향을 미쳤는지를 체계적으로 확인하는 것이 더 중요하다.</p>



<p>이제 데브옵스 에이전트는 통합개발환경(IDE)만큼 중요한 도구가 되고 있다. 데브옵스 에이전트는 개발팀이 이미 사용하는 도구와 연동돼 경보가 발생하면 이러한 조사 과정을 <a href="https://aws.amazon.com/blogs/networking-and-content-delivery/automated-network-incident-response-with-aws-devops-agent/" target="_blank" rel="nofollow">자동으로 수행</a>한다. 로그와 메트릭, 분산 추적(trace), 코드까지 분석하며, 개발자가 노트북을 열기도 전에 진단 결과와 대응 계획을 제시하는 경우도 적지 않다.</p>



<p>실제로 과거에는 사람이 8시간 동안 분석해야 했던 장애를 에이전트가 15분 만에 해결한 사례도 경험했다. 에이전트는 버그의 원인을 설명하고 근거를 제시하는 것은 물론, 롤백과 후속 수정 방안까지 추천했다.</p>



<p>장애가 없는 기간에도 동일한 시스템은 과거 장애 사례와 인프라를 분석해 예방 작업을 제안한다. 코드 안정성 강화와 재시도(retry) 로직 개선, 경보 설정 최적화 등이 대표적이다. 대부분의 개발팀은 이런 작업에 우선순위를 부여할 여유가 없다. 그러나 이것이야말로 가장 중요한 부분이다. 다운타임을 줄이는 것도 중요하지만, 애초에 장애가 발생하지 않도록 만드는 것이 더 큰 목표이기 때문이다.</p>



<p>앞으로는 개발자가 운영자와 제품 관리자, 고객 지원 담당자 등 다양한 역할을 수행하게 될 것으로 본다. 반면 에이전트는 반복적이고 일상적인 업무를 맡게 될 것이다. 결국 개발자의 가장 중요한 역할은 문제를 해결하고, 시스템이 올바르게 설계돼 본래 목적에 맞게 동작하도록 만드는 일이 될 것이다.</p>



<p>물론 변하지 않는 원칙도 있다. ‘만든 사람이 운영한다(If you build it, you run it)’는 철학은 에이전트가 코드의 일부 또는 전부를 작성했더라도 그대로 유지된다. 개발자는 여전히 운영 환경을 책임지고, 장애 회고(post-incident retrospective)를 통해 재발 방지 방안을 마련해야 한다.</p>



<p>데이터 수집과 영향 분석, 근본 원인 분석 같은 작업은 에이전트 덕분에 훨씬 빨라질 수 있다. 하지만 조사 방향을 결정하고 근본적인 해결책을 선택하며, 그 경험과 교훈을 조직 전체와 공유하는 역할은 여전히 개발자의 몫이다.</p>



<p>20년 전 가장 큰 변화는 인프라를 서비스로 전환한 것이었다. 덕분에 개발자는 서버를 직접 설치하거나 데이터베이스를 일일이 관리하는 데 시간을 쏟지 않아도 됐다.</p>



<p>이제 새로운 시대에는 모범 사례와 운영 경험, 보안 요구사항을 명세(spec)와 AI 에이전트로 구현해 어떤 규모의 환경에서도 일관되게 실행하는 방향으로 변화가 진행되고 있다.</p>



<p>지난 20년의 교훈은 지금도 유효하다. 오늘 감수하는 불편은 내일 누군가가 플랫폼으로 해결하게 된다. 다만 이제는 AI 에이전트 덕분에 그 간극을 훨씬 더 빠르게 메울 수 있게 됐다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Most teams will ship AI-written infrastructure code with little review]]></title>
<description><![CDATA[AI-assisted development has settled into everyday practice across software organizations, and developers using it move from idea to working code in hours. That code does not stay with the developers who prompt it. It flows downstream to the DevOps and…
Read more →
The post Most teams will ship AI...]]></description>
<link>https://tsecurity.de/de/3623343/it-security-nachrichten/most-teams-will-ship-ai-written-infrastructure-code-with-little-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623343/it-security-nachrichten/most-teams-will-ship-ai-written-infrastructure-code-with-little-review/</guid>
<pubDate>Thu, 25 Jun 2026 06:36:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AI-assisted development has settled into everyday practice across software organizations, and developers using it move from idea to working code in hours. That code does not stay with the developers who prompt it. It flows downstream to the DevOps and…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/most-teams-will-ship-ai-written-infrastructure-code-with-little-review/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/most-teams-will-ship-ai-written-infrastructure-code-with-little-review/">Most teams will ship AI-written infrastructure code with little review</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Most teams will ship AI-written infrastructure code with little review]]></title>
<description><![CDATA[AI-assisted development has settled into everyday practice across software organizations, and developers using it move from idea to working code in hours. That code does not stay with the developers who prompt it. It flows downstream to the DevOps and platform teams who deploy and maintain it, an...]]></description>
<link>https://tsecurity.de/de/3623311/it-security-nachrichten/most-teams-will-ship-ai-written-infrastructure-code-with-little-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623311/it-security-nachrichten/most-teams-will-ship-ai-written-infrastructure-code-with-little-review/</guid>
<pubDate>Thu, 25 Jun 2026 06:08:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AI-assisted development has settled into everyday practice across software organizations, and developers using it move from idea to working code in hours. That code does not stay with the developers who prompt it. It flows downstream to the DevOps and platform teams who deploy and maintain it, and those teams are not getting the same speed boost. A Spacelift survey of 406 IT and platform leaders in North America captures what happens when one side … <a href="https://www.helpnetsecurity.com/2026/06/25/ai-infrastructure-governance-gap-report/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/25/ai-infrastructure-governance-gap-report/">Most teams will ship AI-written infrastructure code with little review</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK staff at the foundation that runs Wikipedia seeks union recognition]]></title>
<description><![CDATA[UK-based staff at the Wikimedia Foundation (WMF), the nonprofit that supports Wikipedia, are pushing forward with their unionization drive. On Wednesday, the staff sent a letter to WMF management requesting the organization voluntarily recognize the union. "The WMF has undergone a period of signi...]]></description>
<link>https://tsecurity.de/de/3622226/it-nachrichten/uk-staff-at-the-foundation-that-runs-wikipedia-seeks-union-recognition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622226/it-nachrichten/uk-staff-at-the-foundation-that-runs-wikipedia-seeks-union-recognition/</guid>
<pubDate>Wed, 24 Jun 2026 19:03:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[UK-based staff at the Wikimedia Foundation (WMF), the nonprofit that supports Wikipedia, are pushing forward with their unionization drive. On Wednesday, the staff sent a letter to WMF management requesting the organization voluntarily recognize the union. "The WMF has undergone a period of significant change in recent months, escalating workers' concerns over transparency, trust, and […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk]]></title>
<description><![CDATA[The new framework seeks to help security teams identify which software supply chain vulnerabilities pose the greatest operational, safety, and business risks in AI-driven environments. The post Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat…
Read more →
The post Exc...]]></description>
<link>https://tsecurity.de/de/3621919/it-security-nachrichten/exclusive-meet-aivex-a-new-triage-model-built-to-reduce-supply-chain-threat-and-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621919/it-security-nachrichten/exclusive-meet-aivex-a-new-triage-model-built-to-reduce-supply-chain-threat-and-risk/</guid>
<pubDate>Wed, 24 Jun 2026 17:39:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The new framework seeks to help security teams identify which software supply chain vulnerabilities pose the greatest operational, safety, and business risks in AI-driven environments. The post Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/exclusive-meet-aivex-a-new-triage-model-built-to-reduce-supply-chain-threat-and-risk/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/exclusive-meet-aivex-a-new-triage-model-built-to-reduce-supply-chain-threat-and-risk/">Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[British Home Office seeks techie to herd nearly 1,000 engineers looking after 600 systems]]></title>
<description><![CDATA[£120k ... but you must take ultimate responsibility for functionality of e-gates, passports and more]]></description>
<link>https://tsecurity.de/de/3621853/it-nachrichten/british-home-office-seeks-techie-to-herd-nearly-1000-engineers-looking-after-600-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621853/it-nachrichten/british-home-office-seeks-techie-to-herd-nearly-1000-engineers-looking-after-600-systems/</guid>
<pubDate>Wed, 24 Jun 2026 17:04:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[£120k ... but you must take ultimate responsibility for functionality of e-gates, passports and more]]></content:encoded>
</item>
<item>
<title><![CDATA[Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk]]></title>
<description><![CDATA[The new framework seeks to help security teams identify which software supply chain vulnerabilities pose the greatest operational, safety, and business risks in AI-driven environments.
The post Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk appeared first o...]]></description>
<link>https://tsecurity.de/de/3621752/it-security-nachrichten/exclusive-meet-aivex-a-new-triage-model-built-to-reduce-supply-chain-threat-and-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621752/it-security-nachrichten/exclusive-meet-aivex-a-new-triage-model-built-to-reduce-supply-chain-threat-and-risk/</guid>
<pubDate>Wed, 24 Jun 2026 16:53:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The new framework seeks to help security teams identify which software supply chain vulnerabilities pose the greatest operational, safety, and business risks in AI-driven environments.</p>
<p>The post <a href="https://www.securityweek.com/exclusive-meet-aivex-a-new-triage-model-built-to-reduce-supply-chain-threat-and-risk/">Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gogs vs. GitLab: Leichtgewicht gegen DevOps-Plattform]]></title>
<description><![CDATA[Mit Gogs und GitLab stehen Ihnen zwei leistungsfähige Git-Server zur Auswahl. Doch während Gogs bewusst minimalistisch gehalten ist, deckt GitLab den gesamten Softwareentwicklungsprozess ab. Das wirkt sich nicht nur auf die Funktionen, sondern auch auf Ressourcenbedarf und Wartung aus. Unser Verg...]]></description>
<link>https://tsecurity.de/de/3621692/server/gogs-vs-gitlab-leichtgewicht-gegen-devops-plattform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621692/server/gogs-vs-gitlab-leichtgewicht-gegen-devops-plattform/</guid>
<pubDate>Wed, 24 Jun 2026 16:30:21 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/c-plus-plus-plus-plus-t.jpg" width="1200" height="630" alt=""><br>Mit Gogs und GitLab stehen Ihnen zwei leistungsfähige Git-Server zur Auswahl. Doch während Gogs bewusst minimalistisch gehalten ist, deckt GitLab den gesamten Softwareentwicklungsprozess ab. Das wirkt sich nicht nur auf die Funktionen, sondern auch auf Ressourcenbedarf und Wartung aus. Unser Vergleichsartikel zu Gogs vs. GitLab hilft Ihnen, die Unterschiede zu verstehen und die richtige Entscheidung für Ihr Projekt zu treffen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Intelligente Testdaten für moderne Softwarequalität - Teil 2 - Informatik Aktuell]]></title>
<description><![CDATA[IT-Security · Speicher · Netzwerke · Virtualisierung · Verfügbarkeit · Management ... IT-Security · DevOps · Datenbanken · Java. ☰. Entwicklung/ ...]]></description>
<link>https://tsecurity.de/de/3620329/it-security-nachrichten/intelligente-testdaten-fuer-moderne-softwarequalitaet-teil-2-informatik-aktuell/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620329/it-security-nachrichten/intelligente-testdaten-fuer-moderne-softwarequalitaet-teil-2-informatik-aktuell/</guid>
<pubDate>Wed, 24 Jun 2026 07:52:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>IT</b>-<b>Security</b> · Speicher · Netzwerke · Virtualisierung · Verfügbarkeit · Management ... <b>IT</b>-<b>Security</b> · DevOps · Datenbanken · Java. ☰. Entwicklung/ ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Venezuela faces world’s largest debt restructuring]]></title>
<description><![CDATA[Caracas will reveal $240bn debt pile as it seeks re-entry into global markets]]></description>
<link>https://tsecurity.de/de/3620180/ai-nachrichten/venezuela-faces-worlds-largest-debt-restructuring/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620180/ai-nachrichten/venezuela-faces-worlds-largest-debt-restructuring/</guid>
<pubDate>Wed, 24 Jun 2026 06:18:51 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Caracas will reveal $240bn debt pile as it seeks re-entry into global markets]]></content:encoded>
</item>
<item>
<title><![CDATA[Why full-service partners are becoming critical to New Zealand’s cloud and AI future]]></title>
<description><![CDATA[New Zealand organisations are entering a new phase of cloud adoption – one where success is no longer measured simply by whether workloads move to the cloud, but by whether those environments are capable of supporting AI-driven innovation.



The opportunity is significant. AI adoption is expecte...]]></description>
<link>https://tsecurity.de/de/3620050/it-nachrichten/why-full-service-partners-are-becoming-critical-to-new-zealands-cloud-and-ai-future/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620050/it-nachrichten/why-full-service-partners-are-becoming-critical-to-new-zealands-cloud-and-ai-future/</guid>
<pubDate>Wed, 24 Jun 2026 04:33:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>New Zealand organisations are entering a new phase of cloud adoption – one where success is no longer measured simply by whether workloads move to the cloud, but by whether those environments are capable of supporting AI-driven innovation.</p>



<p>The opportunity is significant. AI adoption is <a href="https://news.microsoft.com/en-nz/2024/08/21/generative-ai-expected-to-more-than-double-new-zealands-productivity-report/?msockid=2813134f1e40649e000d073c1f5e6574" target="_blank" rel="sponsored">expected to add NZ$76 billion annually</a> to NZ’s economy by 2038, growing GDP by around 1 per cent every year.</p>



<p>That acceleration is also fuelling cloud investment. IDC forecasts indicate NZ’s <a href="https://my.idc.com/getdoc.jsp?containerId=AP52206825&amp;pageType" target="_blank" rel="sponsored">public cloud spend </a>will almost double from NZ$5 billion in 2024 to NZ$9.6 billion by 2028, as organisations increasingly modernise infrastructure and prepare for AI-enabled operations.</p>



<p>Increasingly, cloud is no longer viewed simply as infrastructure hosting. According to IDC, Kiwi organisations are evolving from basic “lift-and-shift” migrations toward more sophisticated cloud-native and data-driven strategies, with IT leaders now treating cloud as a platform for AI-led transformation.</p>



<p>For many organisations, however, the challenge is not whether to move – it is how to move well.</p>



<p>According to Chris Beckett, technology strategist at<a href="https://www.inde.nz/" target="_blank" rel="sponsored"> Inde Technology</a>, most NZ organisations already understand the strategic value of cloud, particularly around platforms like Microsoft Azure, but execution remains the difficult part.</p>



<p>“Cost and budget uncertainty tend to top the list,” Beckett says. “That is not because cloud is inherently expensive, but because undisciplined adoption is. Organisations that have not built proper cost governance in from day one end up with sprawl and bill shock, and that reinforces scepticism at board level.”</p>



<h2 class="wp-block-heading"><strong>Governance matters more than ever</strong></h2>



<p>One of the biggest misconceptions organisations still make is assuming cloud migration itself automatically delivers efficiency.</p>



<p>Beckett says treating cloud as a direct infrastructure replacement means organisations lose out on the opportunity to modernise architecture and operating models.</p>



<p>“The most common and costly mistake is lift and shift,” he says.</p>



<p>“When you lift and shift, you take all of your existing technical debt and put it on a meter. You are now paying cloud running costs on top of architecture decisions that were made for a different world.”</p>



<p>Instead, organisations achieving the strongest outcomes are using migration as a forcing function to modernise applications, governance and operational processes simultaneously.</p>



<p>That includes adopting Infrastructure as Code, cloud-native platform services, embedded security controls and DevOps practices from the outset.</p>



<p>According to Beckett, governance cannot be retrofitted later.</p>



<p>“Visibility and control have to be built in from day one. Retrofitting them to a running environment means you are already behind, and the bill has already arrived.”</p>



<p>This is particularly important as organisations scale AI workloads on platforms like Azure, where poorly managed environments can quickly create unpredictable consumption costs.</p>



<h2 class="wp-block-heading"><a></a><strong>The Azure advantage for NZ companies</strong></h2>



<p>The launch of Microsoft’s first New Zealand hyperscale cloud region, <a href="https://www.reseller.co.nz/article/4110758/microsofts-nz-north-datacentre-region-now-a-foundation-for-countrys-emerging-ai-economy.html" target="_blank" rel="sponsored">NZ North</a>, has also changed the conversation significantly.</p>



<p>The region already supports tenants including <a href="https://www.reseller.co.nz/article/4162332/boosting-productivity-and-skills-key-to-ai-transformation-for-spark-and-fonterra-ceos.html" target="_blank" rel="sponsored">Fonterra</a>, <a href="https://www.reseller.co.nz/article/3827902/spark-teams-with-microsoft-to-drive-cloud-transition-and-deploy-ai-company-wide.html" target="_blank" rel="sponsored">Spark</a> and <a href="https://www.reseller.co.nz/article/1296154/asb-signs-up-as-anchor-tenant-for-microsofts-nz-datacentre-region.html" target="_blank" rel="sponsored">ASB</a>, alongside smaller organisations such as Te Tumu Paeroa.</p>



<p>“For boards that have been asking, ‘where does the data actually live?’ the answer is now unambiguously here in NZ, with full Azure capability,” Beckett says. “That is a significant shift.”</p>



<p>Beyond sovereignty, Beckett says Azure is delivering measurable value across scalability for customer-facing applications, improved resilience and recovery capability, Infrastructure as Code and operational consistency, and stronger cost governance through native tooling.</p>



<p>He points to a recent engagement with a major Kiwi logistics company that migrated critical freight management systems to Azure Platform-as-a-Service infrastructure. “This was not a lift and shift, but a proper architectural rebuild. The result was scalable, always-on applications with operational visibility the team had never had before.”</p>



<h2 class="wp-block-heading"><strong>Why full-service partners are becoming more valuable</strong></h2>



<p>As cloud environments become more complex – and increasingly tied to AI initiatives, governance requirements and cybersecurity obligations – many organisations are reassessing the role of their technology partners.</p>



<p>In New Zealand, Inde works closely with Microsoft, leveraging the expertise, enablement, and partner ecosystem strength of leading IT distributor <a href="https://www.dickerdata.co.nz/" target="_blank" rel="noreferrer noopener nofollow">Dicker Data</a>.</p>



<p>Beckett argues there is a growing distinction between traditional systems integrators and full-service cloud partners.</p>



<p>“A full-service partner stays with you through the whole lifecycle: consult, create, supply and manage,” he says. “That matters in cloud, because the technology does not stop evolving once the migration is complete.”</p>



<p>The value, he says, lies not only in technical delivery, but in strategic guidance and long-term operational accountability. “A partner worth working with will tell you when you are not ready to migrate, not just help you move.”</p>



<p>He cites a healthcare engagement where Inde Technology delayed migration activity in order to first address security, identity and governance readiness through the Microsoft Cloud Adoption Framework.</p>



<p>“That was not the fastest path to a sale, but it was the right path to a good outcome,” he says.</p>



<p>This ability to assess readiness honestly is becoming increasingly important as organisations navigate growing complexity around AI, cybersecurity, compliance and operational resilience.</p>



<h2 class="wp-block-heading"><strong>Planning early creates strategic advantage</strong></h2>



<p>Beckett believes one of the biggest differentiators between successful cloud transformations and reactive migrations is timing. “The organisations that modernise well started thinking about this 18 to 36 months before the forcing function arrived.” Those forcing functions can include hardware end-of-life dates, expiring software licences or escalating operational risk.</p>



<p>“The organisations that struggle are the ones who bring a partner in at six months. At that point, options are limited, leverage is gone, and decisions are being made under pressure.”</p>



<p>“The infrastructure argument in NZ is resolved. Microsoft’s in-country datacentre means data sovereignty is no longer a reason to delay. The organisations building their roadmap today will be deploying with confidence in 18 months. The ones who wait will be reacting.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to watch England vs Ghana: Free Streams, TV Channels & Kick-Off time as Harry Kane seeks more goals at the FIFA World Cup 2026]]></title>
<description><![CDATA[Here's how to watch England vs Ghana for free online and from anywhere in the FIFA World Cup 2026, as the Three Lions look to take control of Group L.]]></description>
<link>https://tsecurity.de/de/3619040/it-nachrichten/how-to-watch-england-vs-ghana-free-streams-tv-channels-kick-off-time-as-harry-kane-seeks-more-goals-at-the-fifa-world-cup-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619040/it-nachrichten/how-to-watch-england-vs-ghana-free-streams-tv-channels-kick-off-time-as-harry-kane-seeks-more-goals-at-the-fifa-world-cup-2026/</guid>
<pubDate>Tue, 23 Jun 2026 19:02:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Here's how to watch England vs Ghana for free online and from anywhere in the FIFA World Cup 2026, as the Three Lions look to take control of Group L.]]></content:encoded>
</item>
<item>
<title><![CDATA[EU Digital Euro Plan Takes Aim at Visa, Mastercard, and Apple Pay]]></title>
<description><![CDATA[EU lawmakers are advancing digital euro rules as Brussels seeks a public payment option to reduce reliance on US-linked payment systems and wallets.
The post EU Digital Euro Plan Takes Aim at Visa, Mastercard, and Apple Pay appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3619021/it-nachrichten/eu-digital-euro-plan-takes-aim-at-visa-mastercard-and-apple-pay/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619021/it-nachrichten/eu-digital-euro-plan-takes-aim-at-visa-mastercard-and-apple-pay/</guid>
<pubDate>Tue, 23 Jun 2026 18:46:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>EU lawmakers are advancing digital euro rules as Brussels seeks a public payment option to reduce reliance on US-linked payment systems and wallets.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-digital-euro-payments-emea-eu/">EU Digital Euro Plan Takes Aim at Visa, Mastercard, and Apple Pay</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Europe’s cloud sovereignty push may backfire]]></title>
<description><![CDATA[The European Commission’s latest push to reduce dependence on foreign technology providers is not surprising. If Europe believes that critical digital services could be disrupted by foreign governments, foreign legal systems, or foreign-owned providers, it will, of course, respond. That concern i...]]></description>
<link>https://tsecurity.de/de/3618824/ai-nachrichten/europes-cloud-sovereignty-push-may-backfire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618824/ai-nachrichten/europes-cloud-sovereignty-push-may-backfire/</guid>
<pubDate>Tue, 23 Jun 2026 17:48:18 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.theguardian.com/world/2026/jun/03/eu-commission-foreign-providers-kill-switch-disrupt-tech-europe">The European Commission’s latest push to reduce dependence on foreign technology providers</a> is not surprising. If Europe believes that critical digital services could be disrupted by foreign governments, foreign legal systems, or foreign-owned providers, it will, of course, respond. That concern is now being expressed in the language of “kill switch” risk, meaning the fear that the cloud, AI, or semiconductor services that Europe depends on could be interrupted or constrained by forces beyond its control.</p>



<p>At a high level, that concern is valid. Europe is right to worry about strategic dependence. If critical public services, regulated workloads, or national-interest systems rely on infrastructure controlled elsewhere, sovereignty becomes more than a policy slogan. It becomes an architectural issue. However, I am skeptical of the leap from identifying the problem to assuming that a policy response will produce a cleaner, safer, or even more sovereign market. There is a good chance it may do the opposite.</p>



<h2 class="wp-block-heading">What Europe is trying to protect</h2>



<p>The motivation behind this effort is clear. Europe wants to reduce its dependence on <a href="https://www.infoworld.com/article/2238873/what-is-cloud-computing.html">cloud computing</a>, <a href="https://www.infoworld.com/article/4061121/a-brief-history-of-ai.html">artificial intelligence</a>, and semiconductors from providers it does not fully control. It wants to ensure that core digital services cannot be switched off, legally constrained, or strategically influenced from outside the region. That is the public policy objective, and from a government standpoint, it makes sense.</p>



<p>The problem is that cloud markets don’t often respond to political intent as policymakers hope. The public cloud market is concentrated among a few big providers because scale matters. The hyperscalers have built global infrastructure, extensive services, ecosystems, and operating models that smaller regional players can’t match. Enterprises chose them for operational advantages, not geopolitical reasons.</p>



<p>Europe now finds itself in a difficult position. It wants sovereignty, but it also wants the benefits of scale, reliability, feature depth, and cost efficiency that usually come from very large cloud providers. Those goals do not always align.</p>



<h2 class="wp-block-heading">Sowing enterprise confusion</h2>



<p>One likely outcome of this push is that European enterprises will become increasingly confused about which public clouds they should select or avoid. That is not a minor point. Most enterprises already struggle with cloud strategy when the drivers are technical, financial, and operational. Add political sovereignty requirements, and the market becomes even harder to navigate.</p>



<p>Enterprises will now need to ask a more complex set of questions. Is a US-based hyperscaler with a localized European operating model acceptable? Is a European-branded sovereign cloud built on American technology better? Is a regional provider safer simply because it is smaller and local, even if it offers fewer services, weaker security tools, less resilience, and a less certain long-term future? At what point does “sovereign enough” become a legal or political judgment rather than a technical one?</p>



<p>This is where the market gets muddy. Policy discussions often imply a binary distinction between foreign and sovereign. In reality, cloud architectures are full of hybrids, partnerships, licensing arrangements, embedded dependencies, and supply chain layers, making neat categorization difficult. Enterprises do not buy cloud services based on a political slogan. They must navigate stacks of contracts, services, support structures, compliance obligations, and technical capabilities. The more politics enters that decision process, the less clarity there may be for buyers trying to make rational platform choices.</p>



<h2 class="wp-block-heading">Sovereign clouds may not fix things</h2>



<p>There is another reality that I think policymakers underestimate. Increased investment in sovereign cloud providers does not automatically create <a href="https://www.infoworld.com/article/4175895/the-sovereign-cloud-illusion.html?utm=hybrid_search">a durable sovereign cloud sector</a>. In fact, history suggests the opposite.</p>



<p>Governments and enterprises may push investment toward smaller sovereign providers, but those providers still face the same brutal economics of the cloud market. They need capital, scale, customers, engineering depth, and ecosystem gravity. Many smaller providers will struggle to compete over time. Some will fail. Others will narrow their focus. Many will eventually be acquired, directly or indirectly, by larger players, including the very US-based cloud providers Europe is trying to reduce dependence on.</p>



<p>That’s the irony. Political pressure may spark a burst of sovereign cloud activity, but market gravity tends to reward scale. Sovereign cloud investment may create a temporary diversification, but in the long run, it could still end in concentration.</p>



<p>Sovereignty is not a bad goal, but the cloud business is structurally difficult. Running a competitive cloud platform is expensive. Matching hyperscaler capabilities is even harder. Enterprises eventually notice the gaps in services, AI tools, ecosystem support, geographic resilience, and operating maturity. When they do, they drift back toward the biggest and most capable providers.</p>



<h2 class="wp-block-heading">Fragmentation comes before security</h2>



<p>My concern is that Europe may be entering a period when cloud architecture is driven less by technical fit and more by political signaling. That rarely leads to simplicity. It usually results in fragmented strategies, duplicated platforms, inconsistent governance, and long procurement cycles.</p>



<p>Some organizations will choose a sovereign-first model for political reasons. Others will remain with hyperscalers but add contractual and architectural safeguards. Others will adopt a <a href="https://www.infoworld.com/article/3584433/are-you-ready-for-multicloud-a-checklist.html">multicloud approach</a> purely to avoid appearing overly dependent on one provider. Still others will split workloads by regulatory sensitivity, which sounds sensible until integration costs and operational complexity add up.</p>



<p>This is how confusion mounts. The question shifts from “Which platform best supports my workload?” to “Which platform is politically safest this quarter?” That is not a stable architectural framework.</p>



<h2 class="wp-block-heading">Skeptical but attentive</h2>



<p>I understand exactly why Europe is raising this issue. No responsible government wants critical digital services held hostage by external dependencies. That concern is rational, but rational concern does not guarantee rational market outcomes. My skepticism is not about whether digital sovereignty matters. It does. But can policy alone produce genuine long-term autonomy or will it create a more confusing procurement environment? At the same time, the market will quietly continue to consolidate around the largest global platforms.</p>



<p>The uncomfortable truth is that sovereignty is easier to announce than to implement. Cloud sovereignty is especially difficult because cloud markets reward scale, capital, ecosystem strength, and breadth of services. Those forces do not disappear simply because a regulator seeks more regional control. I think this issue will become more important over the next few years as cloud, AI, and geopolitical power become even more tightly linked. Europe is right to ask hard questions about dependence. But the answers are likely to be messy, and market outcomes may not look as sovereign as policymakers hope.</p>



<p>I don’t expect to see a clean break from foreign cloud providers. I do expect more <a href="https://www.networkworld.com/article/964498/what-is-hybrid-cloud-computing.html">hybrid</a> arrangements, more sovereign branding, more enterprise uncertainty, more investment in regional providers, and eventually more consolidation than many people currently anticipate. That is not a failure of the idea. It is just the reality of how cloud markets tend to work.</p>



<p>The real challenge for Europe is not identifying the risk. It is building a response that does not create more confusion than the problem it is trying to solve.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Canada Plans 'Nuclear Renaissance' With Up To 10 Reactors Built By 2040]]></title>
<description><![CDATA[Canada has unveiled a national strategy to build up to 10 new nuclear reactors over the next 15 years as it seeks to double electricity-grid capacity by 2050. Energy Minister Tim Hodgson called it a plan for a "new civilian nuclear renaissance."
 
"If our goal is to double our grid and build a lo...]]></description>
<link>https://tsecurity.de/de/3618075/it-security-nachrichten/canada-plans-nuclear-renaissance-with-up-to-10-reactors-built-by-2040/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618075/it-security-nachrichten/canada-plans-nuclear-renaissance-with-up-to-10-reactors-built-by-2040/</guid>
<pubDate>Tue, 23 Jun 2026 13:23:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Canada has unveiled a national strategy to build up to 10 new nuclear reactors over the next 15 years as it seeks to double electricity-grid capacity by 2050. Energy Minister Tim Hodgson called it a plan for a "new civilian nuclear renaissance."
 
"If our goal is to double our grid and build a low-carbon economy in less than 25 years, there is no credible plan to do that without nuclear energy and the clean, reliable baseload power it provides," Hodgson said. "There is no credible plan for Canada to become an energy superpower if we choose not to build upon one of the strongest energy advantages we have." CBC News reports: The strategy calls for construction to start on two new large-scale reactors by 2035, for five more to be planned or under development by 2040 and for at least one reactor to be under construction outside Ontario by 2035. It also calls for a Canadian-made microreactor to be finalized by 2035 and deployed to a remote community by the late 2030s. [...] Right now, Canada has four nuclear power plants -- three in Ontario and one in New Brunswick -- which generate about 15 per cent of Canada's electricity.
 
A new proposed facility at the existing nuclear plant in Darlington, Ont., would see the first small modular reactor in the G7, capable of producing up to 300 megawatts per unit. Saskatchewan is also looking at the potential to bring small nuclear reactors online by the mid 2030s. The energy deal between Ottawa and Alberta also committed to collaborating on developing a strategy to build a nuclear power plant. Officials from Natural Resources Canada told reporters in a background briefing that construction of the reactors outlined in the new national strategy could cost more than $100 billion. The strategy does not say how Canada would pay for them, though an official pointed to the Canadian Infrastructure Bank and the Canada Growth Fund as possible funding sources. Hodgson said the strategy would double the 90,000 jobs in Canada's nuclear sector "over the coming decades."
 
The plan also looks to expand sales of Candu reactors to new export markets. It says the government wants to break into at least four new international markets by 2040 and "engage six to 10 new nuclear entrant markets over a 15-year horizon, cementing Canada as their partner of choice." Thirty Candu reactors currently operate around the world, including in South Korea, China, India, Argentina, Pakistan and Romania, and there are plans to build two more. [...] "Reactor exports are not transactional. They establish multi-decade partnerships, creating durable geopolitical and commercial relationships that advance Canada's broader foreign policy interests," the strategy says. "As Canada works to diversify its trading relationships and strengthen ties with middle powers, Candu can be a central instrument of that strategy."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Canada+Plans+'Nuclear+Renaissance'+With+Up+To+10+Reactors+Built+By+2040%3A+https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F06%2F23%2F0528230%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F06%2F23%2F0528230%2Fcanada-plans-nuclear-renaissance-with-up-to-10-reactors-built-by-2040%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://hardware.slashdot.org/story/26/06/23/0528230/canada-plans-nuclear-renaissance-with-up-to-10-reactors-built-by-2040?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What 20 years of AWS taught me about agentic AI]]></title>
<description><![CDATA[This year marks the 20th anniversary of AWS — and my 20th year building at Amazon.



My entire career is for the sole purpose of making developers’ lives easier. As a developer, it is a bit of a self-serving purpose. For example, I was constantly distracted by operating databases, so I joined th...]]></description>
<link>https://tsecurity.de/de/3617835/it-nachrichten/what-20-years-of-aws-taught-me-about-agentic-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617835/it-nachrichten/what-20-years-of-aws-taught-me-about-agentic-ai/</guid>
<pubDate>Tue, 23 Jun 2026 12:02:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>This year marks the 20th anniversary of AWS — and my 20th year building at Amazon.</p>



<p>My entire career is for the sole purpose of making developers’ lives easier. As a developer, it is a bit of a self-serving purpose. For example, I was constantly distracted by operating databases, so I joined the DynamoDB team to build a service that handles that, so that other developers and I would never have to operate databases again.</p>



<p>I then went on to work on Lambda and API <a>Gateway</a>. I didn’t have to babysit servers or handle request routing, and on CloudWatch, so I could see what my code was doing in production. Each time, the goal was the same: remove the painful, repetitive work and turn it into a service that just works.</p>



<p>I’m still chasing the same goal, just with a very different set of tools.</p>



<h2 class="wp-block-heading">The rise — and limits — of vibe coding</h2>



<p>Large language models added the ability to describe what I want in natural language and have code synthesized on demand. At first, this looked like “<a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development-how-to-choose.html?utm=hybrid_search">vibe coding</a>” — ask for a change to the script, compile it, run it, copy the errors back and hope the next iteration was better.</p>



<p>Things got interesting when we wrapped the whole “vibe coding” workflow in agentic loops. Instead of me feeding back every error, an agent could call the model, run the code, see its own failures and keep iterating until tests passed. But there was a big problem: the agents wandered. That’s fine for side projects, not fine for large, critical codebases.</p>



<h2 class="wp-block-heading">Spec‑driven development for agents</h2>



<p>The way I’ve come <a href="https://kiro.dev/blog/kiro-and-the-future-of-software-development/" rel="nofollow">to keep agents focused is through spec‑driven development</a>. Instead of dropping an agent into a repo with a vague prompt, I co‑create three concrete artifacts with it before any serious coding begins: a requirements spec, a design document and a task breakdown, all in Markdown. These are a shared contract for what “done” means, written in a form that both humans and agents can read, critique and update.</p>



<p>In my day-to-day, I start with almost the same prompt I’d give any AI, but the agent expands it into a structured requirements document with clear “shall” statements and acceptance criteria. I review those requirements and chat with the agent until the document matches what I actually want. From there, the agent proposes a design, then breaks the work into tasks focused on getting something tangible running before adding polish and exhaustive tests.</p>



<p>What I like about this flow is not that it’s rigid. In practice, I bounce back and forth. I often see a design that reveals missing requirements, or I change my mind about the approach once I see code snippets. The point is that agents no longer “forget” what we agreed on. The spec, design and tasks are explicit, versioned and always visible. And when I want to tack on another feature or bugfix, I start with a fresh spec that describes exactly what I want to change.</p>



<h2 class="wp-block-heading">Property‑based testing and keeping agents honest</h2>



<p>Once the specs are explicit, you can turn them into invariants and <a href="https://kiro.dev/blog/property-based-testing-fixed-security-bug/" rel="nofollow">use property-based tests to keep agents honest</a>. Instead of writing one test for “given this exact input, expect this exact output,” I define properties that must hold across many inputs and sequences.</p>



<p>Without strong, spec-derived tests, I’ve seen agents game the system by “fixing” the tests instead of the code — commenting out assertions or weakening conditions just to get a green build. Property-based tests give me a way to encode my expectations once and have both humans and agents constantly prove we’re still meeting them.</p>



<p>This approach has clear implications for security as well. If security teams can encode expectations — about data handling, authorization and error behavior — as invariants in the same spec language the agent consumes, then property-based tests can hammer those invariants across many scenarios. That’s a much more robust way to shift security left than hoping every developer remembers every rule under deadline pressure.</p>



<h2 class="wp-block-heading">DevOps agents and the next decade of practice</h2>



<p>Over twenty years, I’ve learned that the key to incident response isn’t only about chasing the root cause — it’s systematically asking what changed, what callers changed, what limits were hit, what components failed as designed and what dependencies are involved.</p>



<p>A DevOps agent is becoming as important as any IDE. It <a href="https://aws.amazon.com/blogs/networking-and-content-delivery/automated-network-incident-response-with-aws-devops-agent/">plugs into the tooling teams already use and runs that investigation automatically whenever an alarm fires</a>. It reads logs, metrics, traces and code, and often has a diagnosis and plan ready by the time I open my laptop.</p>



<p>I’ve seen incidents that once took eight hours of human sleuthing reduced to fifteen minutes, with the agent explaining the bug, citing evidence, and recommending a rollback and follow-up fix.</p>



<p>Between incidents, the same system scans past outages and infrastructure to suggest preventative work — code hardening, better retries, alarm tuning — that teams rarely have time to prioritize on their own, and that’s the most important part. Reducing downtime is great, but avoiding it altogether is a big reason why we’re here.</p>



<p>Looking ahead, I think developers will learn to wear all sorts of other hats — the operator, product manager, customer support — while agents take on their routine tasks. The most valuable work becomes problem-solving and ensuring systems are built right and serve the right purpose.</p>



<p>Other things won’t change at all. “If you build it, you run it” still applies, even when an agent wrote part or all of the code. Developers will still own production and post‑incident retrospectives that focus on how to prevent issues. Some parts — like data collection, impact analysis, root cause analysis — get faster with agents doing the legwork, but developers still direct the investigation, decide the real fixes and share those lessons across teams.</p>



<p>Twenty years ago, the big shift was turning infrastructure into services, so developers didn’t have to think about <a>racking</a> servers or babysitting databases. In this new era, the move is turning our best practices, operational experience and security expectations into specs and agents that can execute them consistently, at any scale. The lesson from the first two decades still applies: The pain you tolerate today is the platform someone else will build tomorrow — only now, agents give us a much faster way to close that gap.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Europe’s sovereignty push may backfire]]></title>
<description><![CDATA[The European Commission’s latest push to reduce dependence on foreign technology providers is not surprising. If Europe believes that critical digital services could be disrupted by foreign governments, foreign legal systems, or foreign-owned providers, it will, of course, respond. That concern i...]]></description>
<link>https://tsecurity.de/de/3617684/ai-nachrichten/europes-sovereignty-push-may-backfire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617684/ai-nachrichten/europes-sovereignty-push-may-backfire/</guid>
<pubDate>Tue, 23 Jun 2026 11:03:59 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.theguardian.com/world/2026/jun/03/eu-commission-foreign-providers-kill-switch-disrupt-tech-europe">The European Commission’s latest push to reduce dependence on foreign technology providers</a> is not surprising. If Europe believes that critical digital services could be disrupted by foreign governments, foreign legal systems, or foreign-owned providers, it will, of course, respond. That concern is now being expressed in the language of “kill switch” risk, meaning the fear that the cloud, AI, or semiconductor services that Europe depends on could be interrupted or constrained by forces beyond its control.</p>



<p>At a high level, that concern is valid. Europe is right to worry about strategic dependence. If critical public services, regulated workloads, or national-interest systems rely on infrastructure controlled elsewhere, sovereignty becomes more than a policy slogan. It becomes an architectural issue. However, I am skeptical of the leap from identifying the problem to assuming that a policy response will produce a cleaner, safer, or even more sovereign market. There is a good chance it may do the opposite.</p>



<h2 class="wp-block-heading">What Europe is trying to protect</h2>



<p>The motivation behind this effort is clear. Europe wants to reduce its dependence on <a href="https://www.infoworld.com/article/2238873/what-is-cloud-computing.html">cloud computing</a>, <a href="https://www.infoworld.com/article/4061121/a-brief-history-of-ai.html">artificial intelligence</a>, and semiconductors from providers it does not fully control. It wants to ensure that core digital services cannot be switched off, legally constrained, or strategically influenced from outside the region. That is the public policy objective, and from a government standpoint, it makes sense.</p>



<p>The problem is that cloud markets don’t often respond to political intent as policymakers hope. The public cloud market is concentrated among a few big providers because scale matters. The hyperscalers have built global infrastructure, extensive services, ecosystems, and operating models that smaller regional players can’t match. Enterprises chose them for operational advantages, not geopolitical reasons.</p>



<p>Europe now finds itself in a difficult position. It wants sovereignty, but it also wants the benefits of scale, reliability, feature depth, and cost efficiency that usually come from very large cloud providers. Those goals do not always align.</p>



<h2 class="wp-block-heading">Sowing enterprise confusion</h2>



<p>One likely outcome of this push is that European enterprises will become increasingly confused about which public clouds they should select or avoid. That is not a minor point. Most enterprises already struggle with cloud strategy when the drivers are technical, financial, and operational. Add political sovereignty requirements, and the market becomes even harder to navigate.</p>



<p>Enterprises will now need to ask a more complex set of questions. Is a US-based hyperscaler with a localized European operating model acceptable? Is a European-branded sovereign cloud built on American technology better? Is a regional provider safer simply because it is smaller and local, even if it offers fewer services, weaker security tools, less resilience, and a less certain long-term future? At what point does “sovereign enough” become a legal or political judgment rather than a technical one?</p>



<p>This is where the market gets muddy. Policy discussions often imply a binary distinction between foreign and sovereign. In reality, cloud architectures are full of hybrids, partnerships, licensing arrangements, embedded dependencies, and supply chain layers, making neat categorization difficult. Enterprises do not buy cloud services based on a political slogan. They must navigate stacks of contracts, services, support structures, compliance obligations, and technical capabilities. The more politics enters that decision process, the less clarity there may be for buyers trying to make rational platform choices.</p>



<h2 class="wp-block-heading">Sovereign clouds may not fix things</h2>



<p>There is another reality that I think policymakers underestimate. Increased investment in sovereign cloud providers does not automatically create <a href="https://www.infoworld.com/article/4175895/the-sovereign-cloud-illusion.html?utm=hybrid_search">a durable sovereign cloud sector</a>. In fact, history suggests the opposite.</p>



<p>Governments and enterprises may push investment toward smaller sovereign providers, but those providers still face the same brutal economics of the cloud market. They need capital, scale, customers, engineering depth, and ecosystem gravity. Many smaller providers will struggle to compete over time. Some will fail. Others will narrow their focus. Many will eventually be acquired, directly or indirectly, by larger players, including the very US-based cloud providers Europe is trying to reduce dependence on.</p>



<p>That’s the irony. Political pressure may spark a burst of sovereign cloud activity, but market gravity tends to reward scale. Sovereign cloud investment may create a temporary diversification, but in the long run, it could still end in concentration.</p>



<p>Sovereignty is not a bad goal, but the cloud business is structurally difficult. Running a competitive cloud platform is expensive. Matching hyperscaler capabilities is even harder. Enterprises eventually notice the gaps in services, AI tools, ecosystem support, geographic resilience, and operating maturity. When they do, they drift back toward the biggest and most capable providers.</p>



<h2 class="wp-block-heading">Fragmentation comes before security</h2>



<p>My concern is that Europe may be entering a period when cloud architecture is driven less by technical fit and more by political signaling. That rarely leads to simplicity. It usually results in fragmented strategies, duplicated platforms, inconsistent governance, and long procurement cycles.</p>



<p>Some organizations will choose a sovereign-first model for political reasons. Others will remain with hyperscalers but add contractual and architectural safeguards. Others will adopt a <a href="https://www.infoworld.com/article/3584433/are-you-ready-for-multicloud-a-checklist.html">multicloud approach</a> purely to avoid appearing overly dependent on one provider. Still others will split workloads by regulatory sensitivity, which sounds sensible until integration costs and operational complexity add up.</p>



<p>This is how confusion mounts. The question shifts from “Which platform best supports my workload?” to “Which platform is politically safest this quarter?” That is not a stable architectural framework.</p>



<h2 class="wp-block-heading">Skeptical but attentive</h2>



<p>I understand exactly why Europe is raising this issue. No responsible government wants critical digital services held hostage by external dependencies. That concern is rational, but rational concern does not guarantee rational market outcomes. My skepticism is not about whether digital sovereignty matters. It does. But can policy alone produce genuine long-term autonomy or will it create a more confusing procurement environment? At the same time, the market will quietly continue to consolidate around the largest global platforms.</p>



<p>The uncomfortable truth is that sovereignty is easier to announce than to implement. Cloud sovereignty is especially difficult because cloud markets reward scale, capital, ecosystem strength, and breadth of services. Those forces do not disappear simply because a regulator seeks more regional control. I think this issue will become more important over the next few years as cloud, AI, and geopolitical power become even more tightly linked. Europe is right to ask hard questions about dependence. But the answers are likely to be messy, and market outcomes may not look as sovereign as policymakers hope.</p>



<p>I don’t expect to see a clean break from foreign cloud providers. I do expect more <a href="https://www.networkworld.com/article/964498/what-is-hybrid-cloud-computing.html">hybrid</a> arrangements, more sovereign branding, more enterprise uncertainty, more investment in regional providers, and eventually more consolidation than many people currently anticipate. That is not a failure of the idea. It is just the reality of how cloud markets tend to work.</p>



<p>The real challenge for Europe is not identifying the risk. It is building a response that does not create more confusion than the problem it is trying to solve.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Plans Filed For Second Major Northumberland Data Centre]]></title>
<description><![CDATA[New application seeks to build campus less than two miles from site of QTS data centre complex at former Blyth Power Station This article has been indexed from Silicon UK Read the original article: Plans Filed For Second Major Northumberland…
Read more →
The post Plans Filed For Second Major Nort...]]></description>
<link>https://tsecurity.de/de/3617480/it-security-nachrichten/plans-filed-for-second-major-northumberland-data-centre/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617480/it-security-nachrichten/plans-filed-for-second-major-northumberland-data-centre/</guid>
<pubDate>Tue, 23 Jun 2026 09:35:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>New application seeks to build campus less than two miles from site of QTS data centre complex at former Blyth Power Station This article has been indexed from Silicon UK Read the original article: Plans Filed For Second Major Northumberland…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/plans-filed-for-second-major-northumberland-data-centre/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/plans-filed-for-second-major-northumberland-data-centre/">Plans Filed For Second Major Northumberland Data Centre</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kubernetes at Home: k3s on a Single Linux Server (2026)]]></title>
<description><![CDATA[Marcus’s DevOps Brief: I run k3s on a repurposed Dell OptiPlex in my closet. It hosts my Grafana dashboards, a GitOps-managed homelab, and a few side projects. If you have a spare machine with 4GB of RAM, you can do…]]></description>
<link>https://tsecurity.de/de/3617061/linux-tipps/kubernetes-at-home-k3s-on-a-single-linux-server-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617061/linux-tipps/kubernetes-at-home-k3s-on-a-single-linux-server-2026/</guid>
<pubDate>Tue, 23 Jun 2026 04:39:16 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Marcus’s DevOps Brief: I run k3s on a repurposed Dell OptiPlex in my closet. It hosts my Grafana dashboards, a GitOps-managed homelab, and a few side projects. If you have a spare machine with 4GB of RAM, you can do…]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Supplier Bets on Robots, AI Servers in $1.1B Hong Kong Listing]]></title>
<description><![CDATA[Apple supplier Lingyi iTech seeks a US$1.1B Hong Kong IPO to fund expansion in AI hardware, robotics, smart glasses, and AI servers.
The post Apple Supplier Bets on Robots, AI Servers in $1.1B Hong Kong Listing appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3616532/it-nachrichten/apple-supplier-bets-on-robots-ai-servers-in-11b-hong-kong-listing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616532/it-nachrichten/apple-supplier-bets-on-robots-ai-servers-in-11b-hong-kong-listing/</guid>
<pubDate>Mon, 22 Jun 2026 22:03:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple supplier Lingyi iTech seeks a US$1.1B Hong Kong IPO to fund expansion in AI hardware, robotics, smart glasses, and AI servers.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-apple-supplier-lingyi-ai-robotics-apac-china/">Apple Supplier Bets on Robots, AI Servers in $1.1B Hong Kong Listing</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA['It would make 'em rich': Trump looks to secure government stake in US AI giants]]></title>
<description><![CDATA[The US government could own shares in the likes of OpenAI and Anthropic as it seeks to boost public perception of AI within the US.]]></description>
<link>https://tsecurity.de/de/3616082/it-nachrichten/it-would-make-em-rich-trump-looks-to-secure-government-stake-in-us-ai-giants/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616082/it-nachrichten/it-would-make-em-rich-trump-looks-to-secure-government-stake-in-us-ai-giants/</guid>
<pubDate>Mon, 22 Jun 2026 18:18:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The US government could own shares in the likes of OpenAI and Anthropic as it seeks to boost public perception of AI within the US.]]></content:encoded>
</item>
<item>
<title><![CDATA[Researchers introduce Self-Harness, a framework that lets AI agents rewrite their own rules, boosting performance up to 60%]]></title>
<description><![CDATA[Not every company can or should build their own frontier AI language model. However, the harness controlling the model is something that most enterprises can and should customize for their specific purposes.Of course, this is easier said than done. Agent harnesses are still largely tuned through ...]]></description>
<link>https://tsecurity.de/de/3616014/it-nachrichten/researchers-introduce-self-harness-a-framework-that-lets-ai-agents-rewrite-their-own-rules-boosting-performance-up-to-60/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616014/it-nachrichten/researchers-introduce-self-harness-a-framework-that-lets-ai-agents-rewrite-their-own-rules-boosting-performance-up-to-60/</guid>
<pubDate>Mon, 22 Jun 2026 17:48:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Not every company can or should build their own frontier AI language model. However, the <i>harness</i> controlling the model is something that most enterprises can and <i>should</i> customize for their specific purposes.</p><p>Of course, this is easier said than done. A<!-- -->gent harnesses are still largely tuned through manual, ad hoc debugging — a process that relies heavily on intuition rather than systematic feedback loops, making it difficult to keep pace with rapidly evolving LLMs.</p><p>To solve this challenge, researchers at the Shanghai Artificial Intelligence Laboratory have introduced “<a href="https://arxiv.org/abs/2606.09498">Self-Harness</a>,” a new paradigm in which an LLM-based agent systematically improves its own operating rules. By examining its own execution traces to apply edits, the system trades manual guesswork for empirical evidence.</p><p>Self-improving harnesses can enable development teams to deploy robust custom agents that continually adapt their own execution protocols to overcome model-specific weaknesses.</p><h2><b>The challenge of harness engineering</b></h2><p>An LLM-based agent's performance is not determined solely by its underlying base model, but also by its harness: the surrounding system that provides context and enables the model to interact with the environment. A harness includes components like system prompts, tools, memory, verification rules, runtime policies, orchestration logic, and failure-recovery procedures.</p><p>This layer is crucial because many common agent failures stem from the harness rather than the model. For example, an agent may report success without checking the model’s response (e.g., running the code to see if it passes the tests), or it might retry a failed action repeatedly. The harness is also responsible for preventing <a href="https://venturebeat.com/ai/mits-new-recursive-framework-lets-llms-process-10-million-tokens-without">context rot or overload</a> when the agent’s interaction history grows very large. Examples of popular harnesses include SWE-agent, Claude Code, Codex, and OpenHands.</p><p>Harness engineering remains a significant challenge, but the bottleneck isn't necessarily that humans are too slow or incapable. </p><p>In fact, Hangfan Zhang, lead author of the Self-Harness paper, told VentureBeat that "in many cases, an experienced engineer with deep domain knowledge can still propose better changes than an LLM can today."</p><p>Instead, the true bottleneck of manual engineering is that it relies heavily on ad hoc debugging rather than a verifiable, empirical feedback loop. "The deeper issue is that the current harness-engineering paradigm often lacks a systematic feedback loop," Zhang explained. "Many edits are made based on intuition, a few observed failures, or ad hoc debugging."</p><p>With new models being released at a rapid pace, depending on human intuition to manually tune model-specific harnesses becomes increasingly costly and untenable. While some approaches use stronger models to improve the harnesses of weaker target agents, this dependence on external guidance has its own challenges, as these models may be costly, unavailable for frontier models, or mismatched to the target model's failure modes.</p><h2><b>How Self-Harness works</b></h2><p>The Self-Harness paradigm enables an LLM-based agent to improve its own harness without relying on human engineers or stronger external models.</p><p>This continuous self-evolution is driven by a three-stage iterative loop that turns behavioral evidence into harness updates:</p><ul><li><p><b>Weakness mining:</b> Starting from an initial harness, the agent runs a set of tasks, producing execution traces with verifiable outcomes. The agent categorizes failed traces and tries to detect model-specific failure patterns.</p></li><li><p><b>Harness proposal:</b> Based on these failure patterns, the agent uses a “proposer” role to generate a set of diverse yet minimal harness modifications, each tied to a specific failure mechanism to avoid overly general corrections.</p></li><li><p><b>Proposal validation:</b> The system evaluates candidate modifications through regression tests. An edit is promoted only if it improves performance without causing measurable degradation on held-out tasks. If multiple candidate modifications pass the regression tests, they are merged into the next version of the harness, which then serves as the starting point for the next iteration.</p></li></ul><p>To visualize why an enterprise would need this, imagine an automated issue-fixing agent that reads internal documentation, writes patches, and opens pull requests. If the company updates its documentation style, the agent might suddenly fail, pulling the wrong context or writing bad patches. </p><p>On the surface, the agent simply looks broken. But Self-Harness turns this ambiguous failure into a solvable problem. "The failure traces expose where the agent is misusing the new documentation format; the proposer can generate a targeted harness edit... and the evaluator can decide whether that edit improves the failing cases without regressing other cases," Zhang said.</p><h2><b>Self-Harness in action</b></h2><p>The researchers evaluated Self-Harness on <a href="https://www.tbench.ai/">Terminal-Bench-2.0</a>, a benchmark that tests general tool-based execution, including artifact management, command use, verification behavior, and recovery from execution errors. They applied Self-Harness with MiniMax M2.5, Qwen3.5-35B-A3B, and GLM-5.</p><p>To isolate the impact of the self-evolving harness, they started with a minimal harness built upon the DeepAgent SDK, containing only the benchmark-facing system prompt, and the default filesystem and shell tools. The model backend, tool set, benchmark environment, and evaluator were kept unchanged while only the harness was allowed to vary.</p><p>The quantitative results show that <b>agents improved their performance through automated harness edits. </b>On held-out tasks, <b>performance jumped significantly across the board, ranging from 33 to 60 percent </b>relative improvements for different models.</p><p>Importantly, an explicit acceptance rule promotes only those edits that improve performance without introducing unacceptable regressions. What makes Self-Harness powerful for enterprise applications is that it doesn’t simply make the prompt longer or add generic instructions. Instead, it introduces targeted changes that reflect the recurring problems each model encounters during execution.</p><p>For example, under the baseline harness, MiniMax M2.5 would get stuck endlessly exploring dataset configurations until the execution environment timed out, failing to produce any deliverables. Through Self-Harness, the system identified this specific flaw and wrote a "loop breaker" into its runtime policy, forcing the agent to stop and redirect its approach after 50 tool calls. It also added a rule to create an initial version of required artifacts as early as possible.</p><p>On the other hand, Qwen-3.5 had a habit of hitting a file overwrite error and then blindly retrying the same command repeatedly, eventually deleting necessary files out of confusion before stopping. The self-harness fixed this by introducing a strict command-retry discipline (forbidding exact duplicate commands) and a mechanism that forced the agent to immediately recreate any missing artifacts if a file error occurred.</p><p>GLM-5 struggled to preserve environment changes across different commands, and would often waste time on massive downloads or finalize tasks even when sanity checks were failing. Its self-generated harness introduced rules instructing the agent to persist PATH variables across shell sessions, limit external compute, and repair any failed sanity checks before concluding its run.</p><h2><b>The hidden costs of automated harnesses</b></h2><p>While Self-Harness automates the tedious work of tracking down idiosyncratic model failures, decision-makers must be realistic about the trade-offs. Replacing human engineering with automated trial-and-error requires significant computational overhead.</p><p>"Self-Harness replaces part of the human engineering burden with repeated proposal generation, parallel candidate evaluation, and regression testing," Zhang said. "That can mean more API tokens, more latency during optimization, and more infrastructure for running evaluation tasks."</p><p>Also, this system relies on the accuracy of its evaluation pipeline. During their experiments on Terminal-Bench-2.0, the researchers relied on strict, deterministic verifiers to ensure the agent's edits were actually helpful. Without this rigorous ground truth, an automated system risks promoting bad updates. "[The] evaluation system is not an optional component; it is what lets us trade human intuition for empirical evidence," Zhang said.</p><p>This reliance on strict verifiers also dictates where Self-Harness should be deployed. "The best deployment targets today are environments where failures can be measured and where trial-and-error is relatively safe," Zhang said, pointing to coding, internal workflow automation, and DevOps data pipelines as ideal use cases.</p><p>Conversely, enterprises should avoid fully automating harnesses in high-stakes or subjective fields. "The clearest red flags are domains where evaluation is subjective, delayed, non-deterministic, or costly to get wrong, such as medical decision-making, safety-critical infrastructure, or legal decisions."</p><h2><b>From prompt tweakers to feedback architects</b></h2><p>The introduction of self-improving agents does not mean coding or enterprise workflows will suddenly become human-free. The quality of collaboration between the human engineer and the AI is still paramount and difficult to capture with automated benchmarks. </p><p>Instead, the engineering profession is moving up the abstraction layer. "The role of enterprise engineers will shift from manually patching individual prompts or tool calls toward designing the feedback systems that make agent improvement possible," Zhang predicted. Moving forward, "the engineer becomes less of a prompt tweaker and more of a feedback architect."</p><p>As foundational models grow more capable, they will naturally absorb many capabilities that currently require manual harness engineering. "But once that happens, the harness will not disappear; its scope will move outward to connect the model to richer external environments," Zhang said. "Until that boundary moves beyond what humans can evaluate, humans will remain critical providers of feedback."</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why open infrastructure will define the AI era]]></title>
<description><![CDATA[A new form of vendor lock-in is here. And it’s not proprietary languages or rigid enterprise software suites — it’s something more fundamental. It’s the very thing that writes the code.



JetBrains Research found that 74% of developers worldwide use AI tools. Claude Code, available only since Ma...]]></description>
<link>https://tsecurity.de/de/3614974/ai-nachrichten/why-open-infrastructure-will-define-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614974/ai-nachrichten/why-open-infrastructure-will-define-the-ai-era/</guid>
<pubDate>Mon, 22 Jun 2026 11:19:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A new form of vendor lock-in is here. And it’s not proprietary languages or rigid enterprise software suites — it’s something more fundamental. It’s the very thing that writes the code.</p>



<p><a href="https://blog.jetbrains.com/research/2026/04/which-ai-coding-tools-do-developers-actually-use-at-work/">JetBrains Research</a> found that 74% of developers worldwide use AI tools. <a href="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html">Claude Code</a>, available only since May 2025, is now the most popular AI coding tool, followed by <a href="https://www.infoworld.com/article/3829347/review-gemini-code-assist-is-good-at-coding.html">Gemini Code Assist</a> and <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html">GitHub Copilot</a>, according to Jellyfish’s 2026 <a href="https://jellyfish.co/resources/2026-state-of-engineering-management-report/">State of Engineering Management Report</a>.</p>



<p>The latter study also found that 91% of developers say their productivity has increased in the past 12 months. As coding output <a href="https://leaddev.com/ai/openai-says-there-are-easily-1000x-engineers-now">expectations are rewritten daily</a>, the engineering world is becoming heavily reliant on paid external AI services.</p>



<p><a href="https://www.linkedin.com/posts/markwoneill_how-to-optimize-token-consumption-for-ai-activity-7458329480994992128-AT9m?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAA-8zTABlsmtYe-zC-Uf5z3oD5nm6qXDVVo">Gartner predicts</a> that by 2028 spending on AI coding tokens could exceed developer salaries. Yet, <a href="https://www.infoworld.com/article/4183060/the-tokenmaxxing-backlash-is-coming.html">tokenmaxxing</a> while <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development-how-to-choose.html">vibe coding</a> through a vendor’s cloud-based API feels like a far cry from the open foundations of free programming languages and open models, which many of today’s AI platforms now abstract.</p>



<p>“Open infrastructure will be the backbone of the AI era,” says <a href="https://www.linkedin.com/in/farkasp/">Peter Farkas</a>, CEO of <a href="https://www.percona.com/">Percona</a>, a provider of open-source database solutions. “Right now, too many companies are building their entire AI strategy on top of proprietary platforms because the convenience is seductive.”</p>



<p>“It’s ‘three clicks’ to stand up a database or an AI service in a hyperscaler, and that convenience blinds people to the lock-in they’re signing up for,” he adds. “As AI workloads mature, organizations will realize that depending on one vendor for their data, models, runtime, and pricing is not a strategy.”</p>



<p><a href="https://www.infoworld.com/article/3973969/knowing-when-to-use-ai-coding-assistants.html">AI-assisted coding</a> is democratizing software engineering for non-engineers and <a href="https://leaddev.com/ai/ai-doesnt-create-great-developers-it-amplifies-them">accelerating top performers</a>. But if teams are always working within the confines of how one platform thinks the world should work, it could create locked-in toolsets at scale. And as <a href="https://techcrunch.com/2025/12/29/2025-was-the-year-ai-got-a-vibe-check/">AI platform costs rise</a>, a fundamental question arises: will software developers consume AI on their own terms, or on someone else’s?</p>



<p>There’s a strong case that the long-term winners in tech will be built on open-source standards and foundations, similar to the history of cloud-native computing and the internet itself.</p>



<p>“Open always wins,” says <a href="https://www.linkedin.com/in/brianalvey/">Brian Alvey</a>, CTO at <a href="https://wpvip.com/">WordPress VIP</a>, a managed WordPress hosting platform. “Not because it’s a fancy ideology, but because it gives you total freedom to adapt, evolve, and stay in control.”</p>



<p>Open infrastructure avoids a future where developers perpetually rent. “For AI to be useful to people at large, it can’t be something you’re paying rent for the rest of your life,” says <a href="https://www.linkedin.com/in/maniksurtani/">Manik Surtani</a>, CTO and co-founder of the <a href="https://aaif.io/">Agentic AI Foundation</a> (AAIF), a vendor-neutral home for open-source agentic AI technologies. “And it can’t be concentrated in one particular corporation or a small handful of corporations, because we know how that goes.”</p>



<h2 class="wp-block-heading">Pricey, closed, proprietary AI</h2>



<p>AI development today is traveling two parallel paths. On one path, <a href="https://leaddev.com/technical-direction/be-careful-open-source-ai">open-source AI</a> is thriving and fueling tremendous growth in the number and variety of AI models and tools. Just take the thousands of open-weight models on <a href="https://huggingface.co/">HuggingFace</a>, the community around the <a href="https://openclaw.ai/">OpenClaw</a> AI agent, or the many academic institutions publishing <a href="https://thenewstack.io/llms-can-now-trace-their-outputs-to-specific-training-data/">new breakthroughs</a>.</p>



<p>“Open-source models and tooling are hot on the heels of state-of-the-art, with interesting and boundary-pushing work being shared by labs and researchers across the world,” says Austin Parker, director of AI strategy at <a href="https://www.honeycomb.io/">Honeycomb</a>, an observability platform provider, citing frontier open-source models like <a href="https://mistral.ai/">Mistral</a>, <a href="https://github.com/deepseek-ai/deepseek-v3">DeepSeek</a>, and <a href="https://allenai.org/olmo2">Ai2’s OLMo</a> as examples.</p>



<p>Others agree. “There’s unprecedented openness at the model and tooling layer, with open-source models, frameworks, and orchestration advancing at remarkable speed,” says <a href="https://www.linkedin.com/in/markcollier/">Mark Collier</a>, general manager of AI and infrastructure at the <a href="https://www.linuxfoundation.org/">Linux Foundation</a>.</p>



<p>On the other path, we’re seeing heavy reliance on proprietary AI systems controlled by Anthropic, Cursor, Google, Microsoft, OpenAI, and others. As Collier says, “Many platforms are wrapping those open components in closed, opinionated interfaces that trade short-term speed for long-term constraints.”</p>



<p><a href="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html">Open source</a> and the AI tooling market don’t always mix well. LangChain’s <a href="https://github.com/langchain-ai/open-agent-platform">Open Agent Platform</a>, for instance, was open-sourced to much fanfare in 2025, but by 2026 had been deprecated, with the repository now recommending fully managed alternatives.</p>



<p>For <a href="https://www.linkedin.com/in/shaposhnik/">Roman Shaposhnik</a>, co-founder and CTO of <a href="https://nekko.ai/">Ainekko</a>, provider of an open-source, composable AI stack, the current AI platform landscape is reminiscent of <a href="https://devops.com/demystifying-the-low-code-category/">low-code and no-code platforms</a>, which promised democratization of software development but often <a href="https://www.infoworld.com/article/3958483/7-reasons-low-code-and-no-code-tools-fail-to-deliver.html">failed to deliver</a>, becoming synonymous with platform lock-in and inflexibility.</p>



<p>“Honestly, it feels familiar,” Shaposhnik says. “We have incredibly powerful AI tools right now, but most of them come bundled as tightly controlled platforms.” This is a risk for AI, he says, because the infrastructure, models, and hardware are tightly coupled. “If those layers are closed, you lose flexibility fast.”</p>



<p>Some abstractions that sit on top of models, like routing and agent frameworks, tend to be tightly coupled and optimized for certain models. Other platforms take the walled garden concept quite literally. Anthropic, for instance, has repeatedly made headlines for blocking access to its Claude models over <a href="https://www.tomshardware.com/tech-industry/artificial-intelligence/anthropic-nuked-a-companys-access-to-claude-stopping-60-employees-dead-in-their-tracks-support-via-google-form-is-the-only-recourse-for-vague-usage-policy-violation">vague policy violations</a>. The company recently shut off <a href="https://venturebeat.com/technology/anthropic-cracks-down-on-unauthorized-claude-usage-by-third-party-harnesses">competitor xAI’s use</a> and <a href="https://thenewstack.io/anthropic-agent-sdk-confusion/">stonewalled OpenCode</a>, drawing community backlash.</p>



<p>Moves toward increasingly closed systems don’t bode well for an AI economy already built on shaky economics. As <a href="https://www.linkedin.com/in/vikramsrivats/">Vikram Srivats</a>, head of product experience at <a href="https://www.wavemaker.com/">WaveMaker</a>, provider of an agentic application development platform, adds, “Given the unit economics of AI tooling and pace of accelerated change to keep up, it seems obvious that some will evolve to more of a closed system to be able to monetize and gain ROI.”</p>



<h2 class="wp-block-heading">Why openness matters in the AI era</h2>



<p>Reliance on proprietary AI platforms can create long-term operational dependencies. As systems become less interoperable, organizations may be forced to standardize on a single stack across data pipelines, models, and decision logic, says the Linux Foundation’s Collier.</p>



<p>“As infrastructure consolidates, enterprises become more exposed when platforms change direction, raise prices, or fall behind technically,” he says. “If you can’t change platforms without re-architecting your AI systems, you’ve already given up too much control.”</p>



<p>“When you build on someone else’s platform, you have to live by their rules and those rules always change,” adds WordPress VIP’s Alvey. “We’ve all seen this before, businesses wasting time and money building to serve Google, Facebook, YouTube, and the App Store, instead of building to serve their customers.”</p>



<p><a href="https://www.infoworld.com/article/2337012/get-used-to-cloud-vendor-lock-in.html">Platform lock-in</a> can also create direct business risk. As Ainekko’s Shaposhnik says, “It usually shows up as higher costs, fragile systems, and growing risk when it’s time to change direction.”</p>



<p>At Ainekko, an internal group called the <a href="https://www.eejournal.com/article/do-you-want-to-be-an-ai-plumber/">AI Plumbers</a> focuses on back-end AI infrastructure like inference, scheduling, memory, and hardware integration. “Their view is simple,” says Shaposhnik. “If those layers are closed, everything above them becomes fragile.”</p>



<p>Open standards, interfaces, and infrastructure provide a necessary hedge against closed systems to prevent this sort of fragility. “In the AI era, open infrastructure gives enterprises control, portability, and choice at exactly the time they need it most,” says Percona’s Farkas.</p>



<p>It can cost upwards of $100,000 to migrate enterprise software, <a href="https://cloudaware.com/blog/cloud-migration-costs/">according to Cloudaware</a>, making portability a major enterprise concern. From this perspective, procuring closed systems can become a costly architectural dependency.</p>



<p>Others argue that openness is a critical hedge against vendor concentration risks at large, especially if AI replaces human labor en masse. “If all of that economic value is now being concentrated in the hands of one or two companies,” says the AAIF’s Surtani, “that’s an order of magnitude bigger problem than we’ve seen in any other wave of computing.”</p>



<p>Instead, open foundations allow adaptability to evolving conditions so enterprises can swap out models, agents, data, hardware, and orchestration, as needed. “Open standards let those components change independently without breaking the system,” says Collier. </p>



<p>Openness can also help future-proof businesses against economic upheaval. “Open everything will help build a cushion for businesses and users to survive and thrive after the almost-certain correction in the current hype cycle,” says WaveMaker’s Srivats.</p>



<h2 class="wp-block-heading">Momentum toward open AI infrastructure</h2>



<p>At the industry level, momentum toward open AI infrastructure is growing. The <a href="https://www.linuxfoundation.org/press/linux-foundation-announces-the-formation-of-the-agentic-ai-foundation">establishment</a> of the <a href="https://aaif.io/author/aaif/">Agentic AI Foundation</a>, Anthropic’s donation of <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP), and Block’s donation of its <a href="https://aaif.io/projects/goose/">Goose agent</a> are significant ecosystem-wide moves toward openness. Other advances include the donation of <a href="https://thenewstack.io/llm-d-cncf-kubernetes-inference/">llm-d</a>, a <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a> framework for LLM inference, to the Cloud Native Computing Foundation (CNCF).</p>



<p>For Parker, donations like this help ensure long-term support and care. “Open standards aren’t just the foundation of the internet, they’re the foundation of the AI space,” he says. “I predict that we’ll see these practices continue, especially as enterprise adoption increases in earnest,” he adds.</p>



<p>Still, some question whether this level of stewardship is enough for a rapidly evolving ecosystem. “The internet benefited early on from groups that helped keep vendors aligned,” says Shaposhnik. “In AI infrastructure, we don’t really have that yet.”</p>



<p>“All of us open source veterans are hopeful,” he says, “but we also need to adapt to this new reality in what we do regarding AI infrastructure.”</p>



<p>Beyond industry governing bodies, companies themselves are also spearheading open AI initiatives. Warp, an agentic development environment, recently <a href="https://thenewstack.io/warp-open-source-client/">went open source</a> amid closed-source rivals. Arcade.dev, meanwhile, is pushing an open-source <a href="https://www.arcade.dev/blog/agent-library/">Agent Library</a> for agentic memory.</p>



<h2 class="wp-block-heading">Where openness matters most in the AI stack</h2>



<p>While AI infrastructure can be open in many ways, a few layers stand out as especially important. First is the openness of the model itself. “Open-source models must be the foundation of future trust and value,” says WaveMaker’s Srivats.</p>



<p>“The forms of open infrastructure that reduce integration friction and accelerate adoption stand out,” adds <a href="https://www.linkedin.com/in/neeraj-abhyankar-9040141/">Neeraj Abhyankar</a>, VP of data and AI at <a href="https://www.rsystems.com/">R Systems</a>, a global digital solutions provider. For him, open model representation formats, open orchestration and execution layers, open agentic protocols, and open governance and metadata standards are all essential for enterprise flexibility.</p>



<p>Others place more value on the connective tissue between AI components. “The most important forms of open infrastructure are the ones that connect systems together,” says Collier. “That includes open APIs, metadata standards, identity and policy frameworks, and protocols for how models and agents communicate.” </p>



<p>Arguably, <a href="https://www.infoworld.com/article/4096223/10-mcp-servers-for-devops.html">MCP</a> has become the connective tissue between AI agents and the <a href="https://thenewstack.io/how-to-prepare-your-api-for-ai-agents/">broader API ecosystem</a>. “If we get MCP right we unlock the same level of interoperability between entities on the web and models driving them as we came to enjoy during the Web 2.0 era and the API-first boom,” says Shaposhnik. “If we don’t we risk massive proprietary lock-ins.”</p>



<p>Parker agrees that open protocols will underlie future AI progress. “We’ll see continued development and progress on AI agents which will rely on protocols like MCP and ACP [<a href="https://www.infoworld.com/article/4007686/a-developers-guide-to-ai-protocols-mcp-a2a-and-acp.html">Agent Client Protocol</a>] to interoperate with various clients and each other,” he says. Yet a gap remains around API conventions for models. “It would be nice if we could get a commitment from model providers to use a standard here.”</p>



<p>For the AAIF’s Surtani, opening up the protocol layer is the most important aspect. “I think it’s really important for interoperability, for choice,” he says. “It means you can bring your own agent, you can bring your own framework, you can bring your own harness, and pick what model you want.”</p>



<p>Open standards may also play a significant role within <a href="https://www.infoworld.com/article/4117620/edge-ai-the-future-of-ai-inference-is-smarter-local-compute.html">inference architecture</a>. “As AI expands to the edge, developers need visibility into how models run, how memory is used, and how performance scales,” says Shaposhnik. Open systems could make it easier to optimize, debug, and adapt while helping enterprises avoid observability fragmentation.</p>



<p>Lastly, <a href="https://www.infoworld.com/article/3498485/the-future-of-kubernetes-and-cloud-infrastructure.html">cloud-native architectural standards</a> are a key ingredient for open AI infrastructure. “We’re seeing Kubernetes become the missing link for people who want the hyperscaler-style convenience without hyperscaler lock-in,” says Percona’s Farkas. For him, Kubernetes has become the de facto hybrid enterprise deployment option for data, workloads, and AI components.</p>



<h2 class="wp-block-heading">History repeats itself</h2>



<p>The <a href="https://opensource.org/blog/the-2026-state-of-open-source-report">2026 State of Open Source Report</a> found avoiding vendor lock-in to be the primary driver of open source adoption. But beyond being a strategic decision for a single company, open infrastructure provides a layer for entire industries to be built upon.</p>



<p>Arguably, the internet itself is evidence of this, where groups like the <a href="https://www.ietf.org/">IETF</a> and the <a href="https://www.ieee.org/">IEEE</a> were instrumental in defining the fundamental protocols. “Without open protocols we would’ve been in telco hell and without phenomenons like Google or Facebook,” says Shaposhnik.</p>



<p>Or, take the <a href="https://www.infoworld.com/article/2335646/thirty-two-years-of-linux-and-its-community.html">history of Linux</a> as a parallel. “Linux became the default operating system because it offered a common, vendor-neutral foundation that everyone could build on,” says Collier. “In the AI era, open infrastructure will define the layers that organizations rely on for long-term continuity.”</p>



<p>At the infrastructure level, open standards have repeatedly underpinned major platform shifts, from <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Docker</a> to <a href="https://www.infoworld.com/article/3812622/will-kubernetes-ever-get-easier.html">Kubernetes</a>. The question now is whether AI will develop a similarly durable standards layer.</p>



<p>For Parker, it’s too early to say, but the current growth of AI mirrors the early cloud. “Remember that it took many years before we saw the development and popularization of the open source cloud-native ecosystem,” he says. “I think it would be a mistake to extrapolate from the current trajectory towards a closed, proprietary future.”</p>



<p>Others agree the future must be rooted in openness. “I see open infrastructure becoming the foundation of enterprise AI,” says R Systems’s Abhyankar. “As systems become more distributed and agent‑driven, closed ecosystems simply won’t scale.”</p>



<p>The groundwork is being laid through open agentic protocols, open frameworks, and industry support intended to reduce fragmentation around proprietary standards.</p>



<p>“Ironically, the AI movement has mostly seemed to learn from the mistakes of the past and is starting off on a more open foot,” says Parker. “Over time, I believe we’ll see innovation and openness thrive.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Australia's social media ban shows UK child safety measures are bound to fail — and it's not because of VPNs]]></title>
<description><![CDATA[While the UK seeks to copy Australia’s world-first social media ban, evidence suggests that most teens are still using their accounts Down Under without the need to download a VPN app. So, why put every citizens' privacy at risk for an approach that’s proven to be failing?]]></description>
<link>https://tsecurity.de/de/3610929/it-nachrichten/australias-social-media-ban-shows-uk-child-safety-measures-are-bound-to-fail-and-its-not-because-of-vpns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610929/it-nachrichten/australias-social-media-ban-shows-uk-child-safety-measures-are-bound-to-fail-and-its-not-because-of-vpns/</guid>
<pubDate>Fri, 19 Jun 2026 18:31:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[While the UK seeks to copy Australia’s world-first social media ban, evidence suggests that most teens are still using their accounts Down Under without the need to download a VPN app. So, why put every citizens' privacy at risk for an approach that’s proven to be failing?]]></content:encoded>
</item>
<item>
<title><![CDATA[Phone Numbers and Emails to Hidden Subdomains: The OSINT Acquisition Pipeline That Uncovered a…]]></title>
<description><![CDATA[Phone Numbers and Emails to Hidden Subdomains: The OSINT Acquisition Pipeline That Uncovered a Critical BugA deep technical blog on using phone numbers and email addresses to discover hidden domains, subdomains, and attack surface — with real-world techniques you can use today.Phone Numbers and E...]]></description>
<link>https://tsecurity.de/de/3610154/hacking/phone-numbers-and-emails-to-hidden-subdomains-the-osint-acquisition-pipeline-that-uncovered-a/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610154/hacking/phone-numbers-and-emails-to-hidden-subdomains-the-osint-acquisition-pipeline-that-uncovered-a/</guid>
<pubDate>Fri, 19 Jun 2026 13:09:24 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Phone Numbers and Emails to Hidden Subdomains: The OSINT Acquisition Pipeline That Uncovered a Critical Bug</h3><p><em>A deep technical blog on using phone numbers and email addresses to discover hidden domains, subdomains, and attack surface — with real-world techniques you can use today.</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*szLFGSpzqAnso14K4v5vnA.png"><figcaption>Phone Numbers and Emails to Hidden Subdomains</figcaption></figure><h3>Foreword: Why I Wrote This</h3><p>In bug bounty and security research, one of the biggest challenges is not finding vulnerabilities — it’s finding the right attack surface.</p><p>Many researchers start with traditional reconnaissance: collecting subdomains, checking DNS records, and running automated tools. While these methods are valuable, they often miss assets that are not directly connected to the primary domain.</p><p>This is where OSINT becomes powerful.</p><p>A simple phone number or email address can become a starting point for discovering hidden digital assets:</p><ul><li>A company email can reveal related domains and third-party services</li><li>Public profiles can expose forgotten infrastructure</li><li>Developer footprints can reveal technology stacks and assets</li><li>Business records can connect organizations to previously unknown domains</li></ul><p>The idea behind this research is simple:</p><p><strong>Public information creates relationships, and relationships create attack surface.</strong></p><p>This blog explores an OSINT-driven acquisition workflow for connecting phone numbers and email addresses with domains, subdomains, and external assets. These techniques are useful for authorized security testing, bug bounty research, and improving reconnaissance skills.</p><p>The goal is not just to collect more assets — it is to understand how different pieces of public information connect together to reveal a larger security picture.</p><h3>Part I: The Conceptual Framework — Why This Works</h3><h3>The Problem with Traditional Subdomain Discovery</h3><p>Traditional subdomain discovery relies on one thing: the DNS namespace is enumerable. You either brute-force it (guess names) or query passive sources (CT logs, passive DNS).</p><p>Both approaches share a fundamental limitation: they only find subdomains that are publicly resolvable or historically logged.</p><p>Here’s what they miss:</p><ul><li>Private/internal domains (e.g., internal.company.com that only resolves on the corporate VPN)</li><li>Pre-production domains that were registered but never deployed to DNS</li><li>Acquired company domains that aren’t linked from the parent</li><li>Domains used for third-party services (e.g., company.slack.com, company.atlassian.net)</li><li>Personal domains used by employees for work purposes</li></ul><h3>The Email-to-Domain Bridge</h3><p>Every email address user@domain.com tells you:</p><ol><li>The domain exists (obvious, but foundational)</li><li>The domain is actively used (someone sent mail from it)</li><li>The domain has a user (potential credential, potential account)</li><li>The domain is connected to services (GitHub, Slack, Jira, AWS, etc.)</li></ol><p>When you collect thousands of email addresses associated with a company, and you extract every domain from those emails, you build a corporate domain graph that DNS brute-force can never replicate.</p><h3>The Phone-to-Domain Bridge</h3><p>Every phone number +1 (415) 555-0199 tells you:</p><ol><li>The company exists at a physical location (office, data center)</li><li>The company uses a specific VOIP provider (Twilio, RingCentral, Vonage)</li><li>The company has registered infrastructure (WHOIS records, business registries)</li><li>The company has extensions (which map to departments, which map to services)</li></ol><p>When you collect phone numbers and reverse-search them, you find domains that were registered with those same phone numbers — often from before the company had a proper security team.</p><h3>Part II: Phone Number → Domain Discovery</h3><p>Phone numbers are a persistent identifier. Companies change domains more often than they change phone numbers. A domain registered in 2005 with a phone number is still associated with that company today — even if the domain is forgotten.</p><h3>Technique 1: WHOIS Phone Number Search</h3><p>Every domain registration includes a phone number. SecurityTrails, WhoisXMLAPI, and DomainTools allow you to search by phone number to find all domains registered with it.</p><pre>#!/bin/bash<br># phone-to-domain.sh - Find domains registered with a specific phone number<br>PHONE="$1"<br><br># Using WhoisXMLAPI (paid, but worth it)<br>curl -s "https://www.whoisxmlapi.com/whoisserver/WhoisService?apiKey=$API_KEY&amp;domainName=$PHONE&amp;outputFormat=JSON" | \<br>    jq -r '.WhoisRecord.registryData.registrarName // empty'<br><br># Using DomainTools (requires API key)<br>curl -s "https://api.domaintools.com/v1/$PHONE/domains/" \<br>    -u "$DOMAINTOOLS_USER:$DOMAINTOOLS_KEY" | \<br>    jq -r '.response.domains[]'<br><br># Manual: Reverse WHOIS lookup on SecurityTrails<br># https://securitytrails.com/list/phone/$PHONE</pre><p>What this finds: Every domain that was ever registered with that phone number — including domains for subsidiaries, defunct products, and personal projects.</p><h3>Technique 2: Business Registry Phone Search</h3><p>Every corporation in the US registers with a state business registry. These registries include phone numbers. You can search by phone number to find all corporations registered under that number.</p><pre># OpenCorporates API<br>curl -s "https://api.opencorporates.com/v0.4/companies/search?q=$PHONE&amp;api_token=$TOKEN" | \<br>    jq -r '.results[].company.name'<br><br># State-specific registries (examples)<br># California: https://businesssearch.sos.ca.gov/<br># Delaware: https://icis.corp.delaware.gov/<br># Texas: https://mycpa.cpa.state.tx.us/coa/</pre><p>What this finds: Legal entities, DBAs, and subsidiaries that aren’t publicly linked to the parent company.</p><h3>Technique 3: Phone Number Reverse Lookup Services</h3><pre># Twilio Lookup API<br>curl -s "https://lookups.twilio.com/v1/PhoneNumbers/$PHONE?Type=carrier&amp;Type=caller-name" \<br>    -u "$TWILIO_SID:$TWILIO_TOKEN" | \<br>    jq '.carrier.name, .caller_name.caller_name'<br><br># Numverify<br>curl -s "https://apilayer.net/api/validate?access_key=$KEY&amp;number=$PHONE" | \<br>    jq '.carrier, .location, .line_type'<br><br># Manual: Whitepages reverse lookup</pre><p>What this finds: The carrier name (VOIP provider), which tells you what infrastructure to attack, and sometimes the registered business name.</p><h3>Technique 4: Breach Data Phone Search (Authorized Only)</h3><p>If you have authorized access to breach databases:</p><pre># Dehashed search by phone<br>curl -s "https://api.dehashed.com/v1/search?query=phone:$PHONE&amp;size=1000" \<br>    -u "$EMAIL:$API_KEY" | \<br>    jq -r '.entries[].domain' | sort -u</pre><p>What this finds: Every domain where an account was registered with that phone number — including internal systems, VPN portals, and employee benefits portals.</p><h3>Real-World Example: Phone-to-Domain Discovery</h3><p>Target: Large healthcare tech company. Scope: *.healthtech.com.</p><p>I found the company’s main phone number from their contact page: +1 (617) 555-0100.</p><p>I ran a WHOIS phone number search:</p><pre># SecurityTrails reverse WHOIS by phone<br># Result: 47 domains registered with +1.617.555.0100</pre><p>Among those 47 domains:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/734/1*9rVIeYeZHnAqzlW8RoepFg.png"><figcaption>47 domains</figcaption></figure><p>Critical find: internal-healthtech.com was registered with the same phone number but was not on any subdomain list. It resolved to a private IP range (10.x.x.x) from the outside, but it hosted an internal tool portal accessible via VPN. The VPN wasn't in scope either — until I found it through the phone number.</p><h3>Part III: Email Address → Domain Discovery</h3><p>Every email address user@domain.com is a direct pointer to a domain. When you collect thousands of emails associated with a target company, you build a comprehensive domain inventory.</p><h3>Technique 1: Cross-Company Email Analysis</h3><p>When employees from Company A and Company B communicate, email headers reveal both domains. If you find john@company-a.com and jane@company-b.com in the same email chain, they're connected.</p><pre># From breach data (authorized): find which domains appear alongside the target domain<br># From leaked email threads: extract all sender/receiver domains<br># From public mailing lists: find cross-company email patterns</pre><p>What this finds: Business relationships — partners, vendors, clients, and acquired companies.</p><h3>Technique 2: The Hunter.io API Multi-Domain Search</h3><p>Hunter.io allows you to search by domain AND by company name. The company name search returns emails from multiple domains:</p><pre># Search by company name<br>curl -s "https://api.hunter.io/v2/company/domain?company=healthtech&amp;api_key=$KEY" | \<br>    jq -r '.data.domains[]'<br><br># Result:<br># healthtech.com<br># healthtech.io<br># healthtech.dev<br># healthtech-careers.com<br># healthtech-benefits.com</pre><p>What this finds: All domains associated with a company name, including HR, benefits, and internal tool domains.</p><h3>Technique 3: Email-to-GitHub-to-Domain Chain</h3><p>This is one of the most powerful discovery chains in bug hunting:</p><ol><li>Collect employee email: alice@healthtech.com</li><li>Search GitHub for that email: finds Alice’s GitHub account</li><li>Look at Alice’s GitHub repos, commits, and organizations</li><li>Find references to other domains in code, configs, and commit messages</li></ol><pre>#!/bin/bash<br># email-to-github-to-domains.sh<br>EMAIL="$1"<br><br># Step 1: Find GitHub account<br>echo "[*] Searching GitHub for $EMAIL..."<br>curl -s "https://api.github.com/search/users?q=$EMAIL+in:email" | \<br>    jq -r '.items[].login' &gt; github_users.txt<br><br># Step 2: For each GitHub user, find their repos and orgs<br>while read USER; do<br>    echo "[*] Checking user: $USER"<br>    <br>    # Get user's repos<br>    curl -s "https://api.github.com/users/$USER/repos?per_page=100" | \<br>        jq -r '.[].full_name' &gt;&gt; repos.txt<br>    <br>    # Get organizations<br>    curl -s "https://api.github.com/users/$USER/orgs" | \<br>        jq -r '.[].login' &gt;&gt; orgs.txt<br>    <br>    sleep 2  # Rate limiting<br>done &lt; github_users.txt<br><br># Step 3: Search repo contents for domain references<br>while read REPO; do<br>    echo "[*] Searching repo: $REPO"<br>    <br>    # Search code for domain patterns<br>    curl -s "https://api.github.com/search/code?q=repo:$REPO+healthtech" | \<br>        jq -r '.items[].html_url' &gt;&gt; code_refs.txt<br>    <br>    # Search commit messages for domain references<br>    curl -s "https://api.github.com/search/commits?q=repo:$REPO+healthtech" | \<br>        jq -r '.items[].html_url' &gt;&gt; commit_refs.txt<br>    <br>    sleep 2<br>done &lt; repos.txt</pre><p>What this finds: Internal domains referenced in code comments, config files, READMEs, and commit messages.</p><h3>Technique 4: Email-to-Breach-to-Domain Correlation</h3><p>When an employee’s email appears in a breach, you can see what service they were using and what domain was involved:</p><pre># Dehashed query (authorized)<br>curl -s "@healthtech.com&amp;size=10000"&gt;https://api.dehashed.com/v1/search?query=email:@healthtech.com&amp;size=10000" \<br>    -u "$EMAIL:$API_KEY" | \<br>    jq -r '.entries[] | "\(.domain) \(.email) \(.password)"' | sort -u<br><br># Extract unique domains<br>curl -s "@healthtech.com&amp;size=10000"&gt;https://api.dehashed.com/v1/search?query=email:@healthtech.com&amp;size=10000" \<br>    -u "$EMAIL:$API_KEY" | \<br>    jq -r '.entries[].domain' | sort -u &gt; breached-domains.txt</pre><p>What this finds: Domains where employees had accounts — including personal projects, side businesses, and services they used for work purposes (sometimes on unmanaged infrastructure).</p><h3>Technique 5: Email-Specific Subdomain Discovery</h3><p>Services like Have I Been Pwned, Firefox Monitor, and custom tools can tell you which subdomains of a company have accounts registered:</p><pre># Check if a subdomain has active accounts<br># For Office 365: login.microsoftonline.com will reveal tenant info<br># For Atlassian: company-name.atlassian.net<br># For Slack: company-name.slack.com<br># For GitHub: github.com/orgs/CompanyName<br><br># Using emails to discover the company's Atlassian instance:<br>for email in $(cat emails.txt); do<br>    # Check for Atlassian account<br>    response=$(curl -s -o /dev/null -w "%{http_code}" \<br>        "https://healthtech.atlassian.net/rest/analytics/1.0/user/is-licensed?username=$email")<br>    <br>    if [ "$response" == "200" ] || [ "$response" == "401" ]; then<br>        echo "Atlassian domain found: healthtech.atlassian.net"<br>        break<br>    fi<br>done</pre><h3>Real-World Example: Email-to-Domain Discovery Chain</h3><p>Target: Financial services company finsecure.com.</p><p>I collected 2,400 emails using Hunter.io, theHarvester, and LinkedIn scraping. Among them was devops@finsecure.com.</p><p>GitHub search on <a href="mailto:devops@finsecure.com">devops@finsecure.com</a>: Found a GitHub account finsecure-devops with a private repo (misconfigured visibility).</p><p>Repo contents revealed:</p><ul><li>deploy.config with DB_HOST=mariadb.internal.finsecure.com</li><li>terraform.tf with bucket = "finsecure-terraform-state"</li><li>README.md with See internal docs at docs.internal.finsecure.com</li></ul><p>New domains discovered:</p><ul><li>internal.finsecure.com — Not in any CT log or DNS record</li><li>docs.internal.finsecure.com — Subdomain of the above</li><li>mariadb.internal.finsecure.com — Internal database hostname</li><li>finsecure-terraform-state.s3.amazonaws.com — S3 bucket with terraform state</li></ul><p>The S3 bucket was publicly listable. It contained AWS access keys. The AWS keys gave access to the production environment.</p><p>Chain: 1 email → 1 GitHub account → 1 repo → 4 new domains → 1 S3 bucket → AWS root access.</p><h3>Part IV: Phone Number + Email → Subdomain Discovery (The Real Gold)</h3><p>When you combine phone numbers and emails, you unlock subdomain discovery that no DNS tool can match.</p><h3>Technique 1: WHOIS Contact Cross-Reference</h3><p>Company domains are often registered by the same person. If you find the registrant’s name and email from one domain, you can find all other domains they’ve registered:</p><pre># Step 1: Get WHOIS info for the main domain<br>whois healthtech.com | grep -E "Registrant|Admin|Tech|Email" &gt; whois-info.txt<br><br># Step 2: Extract registrant name and email<br>NAME=$(grep "Registrant Name" whois-info.txt | awk -F: '{print $2}' | xargs)<br>EMAIL=$(grep "Registrant Email" whois-info.txt | awk -F: '{print $2}' | xargs)<br><br># Step 3: Search for other domains with same registrant<br># Using WhoisXMLAPI<br>curl -s "https://www.whoisxmlapi.com/whoisserver/WhoisService?apiKey=$API_KEY&amp;domainName=$NAME&amp;outputFormat=JSON" | \<br>    jq -r '.WhoisRecord.registryData.registrantDomains[]'<br><br># Using DomainTools Reverse WHOIS<br>curl -s "https://api.domaintools.com/v1/$NAME/domains/" \<br>    -u "$DOMAINTOOLS_USER:$DOMAINTOOLS_KEY" | \<br>    jq -r '.response.domains[]'</pre><h3>Technique 2: Social Media Profile Mining</h3><p>Employee LinkedIn profiles often list multiple domains:</p><pre>Current: Senior Engineer at HealthTech (healthtech.com)<br>Past: Lead Developer at MedData (meddata.io)<br>Education: MIT (mit.edu)</pre><p>Each of these is a domain that may or may not be in scope. If meddata.io was acquired by healthtech.com, then meddata.io infrastructure is likely part of the target's attack surface.</p><pre># LinkedIn scraper (requires authentication)<br># Extract: current company, past companies, education<br># Cross-reference with known acquisitions<br><br># For each past company found on LinkedIn profiles:<br># Check if it was acquired by the target<br># If yes: run full acquisition pipeline on that domain</pre><h3>Technique 3: Support Portal and Help Desk Domains</h3><p>Phone numbers often lead to support portals, which lead to subdomains:</p><pre># Call the company's support number<br># Listen for automated messages:<br># "Press 1 for billing" → billing.helpdesk.com<br># "Press 2 for technical support" → support.helpdesk.com<br># "Press 3 for sales" → sales.helpdesk.com<br><br># These are subdomains of the support portal domain<br># Check if they resolve, check for takeovers<br><br># Also check: support@company.com → Zendesk, Freshdesk, Helpscout<br># Zendesk: company.zendesk.com<br># Freshdesk: company.freshdesk.com<br># Helpscout: company.helpscout.net</pre><h3>Technique 4: Email Header Subdomain Discovery</h3><p>If you can obtain a legitimate email from the company (e.g., by signing up for their newsletter), the email headers reveal internal infrastructure:</p><pre>Received: from mail.healthtech.com (192.168.1.10)<br>Received: from mx1.healthtech.com (203.0.113.5)<br>Received: from smtp-in.healthtech.com (198.51.100.20)<br>DKIM-Signature: d=healthtech.com; s=selector1<br>Authentication-Results: mx.google.com;<br>       spf=pass (google.com: domain of newsletter@healthtech.com designates 203.0.113.5 as permitted sender)</pre><p>Each of these IPs and hostnames is a potential subdomain:</p><ul><li>mail.healthtech.com</li><li>mx1.healthtech.com</li><li>smtp-in.healthtech.com</li></ul><h3>Real-World Example: Phone + Email → Subdomain Discovery</h3><p>Target: SaaS company cloudserve.com.</p><p>Phone number from WHOIS: +1 (425) 555-0100 (Seattle area)</p><p>Email from WHOIS: admin@cloudserve.com</p><p>Step 1: WHOIS reverse search on phone number Found 12 domains, including:</p><ul><li>cloudserve.io (known)</li><li>cloudserve-backup.com (unknown — registered 2008)</li><li>cs-legacy.com (unknown — registered 2005)</li></ul><p>Step 2: WHOIS reverse search on email Found 8 more domains:</p><ul><li>cloudserve-status.com (status page — known but useful)</li><li>cloudserve-dev.com (development — not in scope docs)</li></ul><p>Step 3: Emails collected from Hunter.io 1,800 emails. Found devops@cloudserve.com in a GitHub commit.</p><p>Step 4: DevOps email → GitHub repos Found a repo with monitoring.cloudserve.com hardcoded in a config file.</p><p>Step 5: Subdomain enumeration on new domains</p><pre>subfinder -d cloudserve-backup.com -silent<br># Found: admin.cloudserve-backup.com<br># Found: db.cloudserve-backup.com</pre><p>Result: 14 new domains and 47 new subdomains discovered through phone and email OSINT alone. DNS brute-force against the main domain found none of these.</p><h3>Part V: Building the Phone-to-Email-to-Domain Pipeline</h3><p>Here’s a practical automated pipeline that can be used for this workflow.</p><h3>Phase 1: Phone Number Collection &amp; Analysis</h3><pre>#!/bin/bash<br># phase1-phone-collect.sh<br>TARGET="$1"<br>DOMAIN="$2"<br><br>echo "[*] Phase 1: Phone Number Collection"<br><br># 1a. WHOIS extraction<br>whois "$DOMAIN" 2&gt;/dev/null | grep -oP '(\+?\d{1,3}[-.\s]?)?\(?\d{3}\)?[-.\s]?\d{3}[-.\s]?\d{4}' &gt; phones.txt<br><br># 1b. Web scraping for phone numbers<br>katana -u "https://$DOMAIN" -d 2 -silent | \<br>    grep -oP '(\+?\d{1,3}[-.\s]?)?\(?\d{3}\)?[-.\s]?\d{3}[-.\s]?\d{4}' &gt;&gt; phones.txt<br><br># 1c. Business directories<br>curl -s "https://api.opencorporates.com/v0.4/companies/search?q=$DOMAIN" | \<br>    jq -r '.results[].company.phone_number' 2&gt;/dev/null | grep -v null &gt;&gt; phones.txt<br><br># Deduplicate<br>sort -u phones.txt -o phones.txt<br>echo "[*] Found $(wc -l &lt; phones.txt) unique phone numbers"</pre><h3>Phase 2: Phone → Domain Mapping</h3><pre>#!/bin/bash<br># phase2-phone-to-domain.sh<br>TARGET="$1"<br><br>echo "[*] Phase 2: Phone to Domain Mapping"<br><br>while read PHONE; do<br>    echo "[*] Processing phone: $PHONE"<br>    <br>    # 2a. Reverse WHOIS by phone (if you have access)<br>    # DomainTools API<br>    # curl -s "https://api.domaintools.com/v1/$PHONE/domains/" -u "$USER:$KEY" | \<br>    #     jq -r '.response.domains[]' &gt;&gt; phone-domains.txt<br>    <br>    # 2b. SecurityTrails (manual or API)<br>    # curl -s "https://api.securitytrails.com/v1/search?query=whois.phone:$PHONE" \<br>    #     -H "APIKEY: $ST_KEY" | jq -r '.records[].hostname' &gt;&gt; phone-domains.txt<br>    <br>    # 2c. Breach data (authorized)<br>    # dehashed API<br>    # curl -s "https://api.dehashed.com/v1/search?query=phone:$PHONE" \<br>    #     -u "$EMAIL:$DEHASHED_KEY" | jq -r '.entries[].domain' &gt;&gt; phone-domains.txt<br>    <br>    sleep 1<br>done &lt; phones.txt<br><br>sort -u phone-domains.txt -o phone-domains.txt<br>echo "[*] Found $(wc -l &lt; phone-domains.txt) domains from phone numbers"</pre><h3>Phase 3: Email Collection</h3><pre>#!/bin/bash<br># phase3-email-collect.sh<br>DOMAIN="$1"<br><br>echo "[*] Phase 3: Email Collection"<br><br># 3a. Hunter.io<br>curl -s "https://api.hunter.io/v2/domain-search?domain=$DOMAIN&amp;api_key=$HUNTER_KEY" | \<br>    jq -r '.data.emails[].value' &gt; emails-hunter.txt<br><br># 3b. theHarvester<br>theHarvester -d "$DOMAIN" -b google,linkedin,github -f /dev/null 2&gt;/dev/null | \<br>    grep -oP '[a-zA-Z0-9._%+-]+@'"$DOMAIN" &gt; emails-harvester.txt<br><br># 3c. Skymem<br>curl -s "https://www.skymem.info/srch?q=$DOMAIN" | \<br>    grep -oP '[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]*\.?'"$DOMAIN" &gt; emails-skymem.txt<br><br># 3d. Web page extraction<br>katana -u "https://$DOMAIN" -d 2 -silent | \<br>    grep -oP '[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]*\.?'"$DOMAIN" &gt; emails-web.txt<br><br># 3e. JS file extraction<br>katana -u "https://$DOMAIN" -jc -silent | xargs -I{} curl -s {} 2&gt;/dev/null | \<br>    grep -oP '[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]*\.?'"$DOMAIN" &gt; emails-js.txt<br><br># Combine<br>cat emails-hunter.txt emails-harvester.txt emails-skymem.txt emails-web.txt emails-js.txt | \<br>    sort -u &gt; emails.txt<br><br>echo "[*] Found $(wc -l &lt; emails.txt) unique email addresses"</pre><h3>Phase 4: Email → Domain Extraction</h3><pre>#!/bin/bash<br># phase4-email-to-domain.sh<br>DOMAIN="$1"<br><br>echo "[*] Phase 4: Email to Domain Extraction"<br><br># 4a. Extract all domains from email addresses<br>grep -oP '@[a-zA-Z0-9.-]+' emails.txt | sed 's/@//' | sort -u &gt; email-domains.txt<br><br># 4b. Remove the main domain (keep only non-obvious domains)<br>grep -v "$DOMAIN" email-domains.txt &gt; other-domains.txt<br><br>echo "[*] Found $(wc -l &lt; email-domains.txt) total domains from emails"<br>echo "[*] Found $(wc -l &lt; other-domains.txt) domains OUTSIDE the main domain"</pre><h3>Phase 5: LinkedIn → Name → Email → Domain</h3><pre>#!/bin/bash<br># phase5-linkedin-to-domains.sh<br>TARGET="$1"<br>DOMAIN="$2"<br><br>echo "[*] Phase 5: LinkedIn Name to Email to Domain"<br><br># 5a. Scrape LinkedIn for employees (manual or with tool)<br># linkedin_scraper -c "$TARGET" -o linkedin-employees.csv<br><br># 5b. Extract past companies from LinkedIn profiles<br># awk -F, '{print $3}' linkedin-employees.csv | sort -u &gt; past-companies.txt<br><br># 5c. For each past company, check if it's in scope<br>while read COMPANY; do<br>    echo "[*] Checking past company: $COMPANY"<br>    <br>    # Search for the company's domain<br>    domain_from_name=$(echo "$COMPANY" | tr '[:upper:]' '[:lower:]' | sed 's/ //g').com<br>    nslookup "$domain_from_name" &gt; /dev/null 2&gt;&amp;1 &amp;&amp; echo "$domain_from_name" &gt;&gt; past-company-domains.txt<br>    <br>done &lt; past-companies.txt<br><br># 5d. For each past company domain, check if acquired by target<br># Manual step: verify acquisition history</pre><h3>Phase 6: Cross-Reference and Subdomain Enumeration on New Domains</h3><pre>#!/bin/bash<br># phase6-subdomain-enum.sh<br>DOMAIN="$1"<br><br>echo "[*] Phase 6: Subdomain Enumeration on All Discovered Domains"<br><br># Combine all domain lists<br>cat phone-domains.txt other-domains.txt past-company-domains.txt | sort -u &gt; all-discovered-domains.txt<br><br># Run subdomain enumeration on each<br>while read DISCOVERED_DOMAIN; do<br>    echo "[*] Enumerating: $DISCOVERED_DOMAIN"<br>    <br>    # CT logs<br>    curl -s "https://crt.sh/?q=%25.$DISCOVERED_DOMAIN&amp;output=json" | \<br>        jq -r '.[].name_value' 2&gt;/dev/null &gt;&gt; all-subs.txt<br>    <br>    # Subfinder<br>    subfinder -d "$DISCOVERED_DOMAIN" -silent &gt;&gt; all-subs.txt<br>    <br>    # DNS brute-force<br>    puredns bruteforce ~/wordlists/subdomains.txt "$DISCOVERED_DOMAIN" \<br>        -r ~/resolvers.txt -q &gt;&gt; all-subs.txt<br>    <br>done &lt; all-discovered-domains.txt<br><br>sort -u all-subs.txt -o all-subs.txt<br>echo "[*] Total subdomains discovered: $(wc -l &lt; all-subs.txt)"</pre><h3>Part VI: The Complete Real-World Workflow</h3><p>To understand how this methodology works in practice, let's walk through an anonymized example of how phone numbers, emails, and public intelligence can reveal hidden assets. payflow.com</p><h3>08:00 — Phone Collection</h3><pre># WHOIS<br>whois payflow.com | grep -E "Phone|Tel"<br># +1 (415) 555-0100<br><br># Contact page<br>katana -u https://payflow.com/contact -d 1 | grep -oP '(\+?\d{1,3}[-.\s]?)?\(?\d{3}\)?[-.\s]?\d{3}[-.\s]?\d{4}'<br># +1 (415) 555-0100 (same)<br># +1 (512) 555-0200 (different — Austin)<br><br># Business registry<br>curl -s "https://api.opencorporates.com/v0.4/companies/search?q=payflow" | \<br>    jq -r '.results[].company.phone_number'<br># +1 (512) 555-0200<br># +1 (512) 555-0300 (NEW — unknown)</pre><p>Phone numbers collected:</p><ul><li>+1 (415) 555-0100 (San Francisco — HQ)</li><li>+1 (512) 555-0200 (Austin — known office)</li><li>+1 (512) 555-0300 (Austin — UNKNOWN)</li></ul><h3>08:30 — Phone → Domain</h3><pre># SecurityTrails reverse WHOIS by phone<br># +1 (512) 555-0300 → registered to:<br># payflow-holdings.com<br># payflow-ventures.com<br># pf-internal.com</pre><p>New domains discovered:</p><ul><li>payflow-holdings.com — Holding company</li><li>payflow-ventures.com — Venture arm</li><li>pf-internal.com — INTERNAL DOMAIN</li></ul><h3>09:00 — Email Collection</h3><pre># Hunter.io: 847 emails<br># theHarvester: 312 emails<br># Skymem: 1,204 emails<br># Web scraping: 89 emails<br># JS files: 34 emails<br># Total unique: 1,892 emails</pre><h3>09:30 — Email → Domain Extraction</h3><pre>grep -oP '@[a-zA-Z0-9.-]+' emails.txt | sed 's/@//' | sort -u<br><br># Unique domains found in emails (excluding payflow.com):<br># payflow.io (known)<br># payflow.co (NEW)<br># payflow-engineering.com (NEW — engineering team domain)<br># pf-payments.com (NEW — payments processing domain)<br># payflow-benefits.com (NEW — HR/benefits domain)</pre><h3>10:00 — GitHub Cross-Reference</h3><pre># Searched for devops@payflow.com on GitHub<br># Found GitHub user: payflow-devops<br># Scanned repos for domain references<br><br># Found in deploy configs:<br># monitoring.internal.payflow.com<br># logs.internal.payflow.com<br># ci.internal.payflow.com</pre><h3>10:30 — Subdomain Enumeration on New Domains</h3><pre># On pf-internal.com:<br>subfinder -d pf-internal.com -silent<br># vpn.pf-internal.com (LIVE)<br># jenkins.pf-internal.com (LIVE)<br># git.pf-internal.com (LIVE)<br><br># On payflow-engineering.com:<br>subfinder -d payflow-engineering.com -silent<br># dev.payflow-engineering.com (LIVE)<br># staging.payflow-engineering.com (LIVE)<br># api.payflow-engineering.com (LIVE)</pre><h3>11:00 — Priority Assessment</h3><p>P0:</p><ol><li>vpn.pf-internal.com — VPN portal (potential credential access)</li><li>jenkins.pf-internal.com — Jenkins (potential RCE)</li><li>pf-internal.com — Internal domain (potential for more discovery)</li></ol><p>P1: 4. payflow-engineering.com — Engineering domain (dev/staging instances) 5. payflow-holdings.com — Holding company (potential subsidiary assets) 6. monitoring.internal.payflow.com — Monitoring (potential Grafana/Prometheus)</p><h3>11:30 — Attack Phase</h3><p>Jenkins on pf-internal.com:</p><ul><li>No authentication required</li><li>Created a freestyle project with a reverse shell</li><li>Got shell access to the Jenkins server</li><li>Jenkins had AWS keys in environment variables</li><li>AWS keys had full admin access to production</li></ul><p>Chain: 1 phone number → 3 unknown phone numbers → 1 unknown domain → 3 subdomains → 1 Jenkins server → AWS root access.</p><h3>Part VII: Tool Reference Guide</h3><h4>Phone Number Tools</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/735/1*XnmWQ7exrxpOTsRHnIQ2qw.png"><figcaption>Phone Number Tools</figcaption></figure><h4>Email Collection Tools</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/738/1*z4tA68XnkqGoK0X9Ey7C3A.png"><figcaption>Email Collection Tools</figcaption></figure><h4>Cross-Reference Tools</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/716/1*IheT9-nPyVGeBaBpR9-gaQ.png"><figcaption>Cross-Reference Tools</figcaption></figure><h3>Part VIII: Common Mistakes (From Personal Experience)</h3><h3>Mistake 1: Not Checking All Phone Numbers from WHOIS</h3><p>A common mistake is finding one phone number in WHOIS and stopping too early, ran my reverse search, and stopped. There were actually three different phone numbers across different domains — I missed two.</p><p>Fix: Extract EVERY phone number from EVERY WHOIS record for EVERY domain you find.</p><h3>Mistake 2: Ignoring Email Domains That Don’t Match the Target</h3><p>What happened: I collected 2,000 emails for target.com. I filtered out everything that wasn't @target.com. I missed the 200 emails with @target-engineering.com, @target-holdings.com, and @target-benefits.com — all of which were owned by the same company.</p><p>Fix: Extract ALL unique domains from your email collection, not just the primary domain.</p><h3>Mistake 3: Not Checking LinkedIn Past Companies</h3><p>What happened: An employee’s LinkedIn profile showed they previously worked at acme-solutions.com. I ignored it. Acme Solutions had been acquired by my target three years prior. Its infrastructure was in scope but I never checked it.</p><p>Fix: Scrape past companies from LinkedIn profiles and cross-reference with acquisition history.</p><h3>Mistake 4: Not Running Subdomain Enumeration on Each New Domain</h3><p>What happened: I found pf-internal.com and added it to my list. I didn't run subfinder or CT log queries against it. vpn.pf-internal.com was sitting there the whole time.</p><p>Fix: Run full subdomain enumeration on EVERY domain you discover, no exceptions.</p><h3>Mistake 5: Stopping After One Round</h3><p>What happened: I discovered new domains, ran subfinder once, and started attacking. I didn’t recurse. Some of those new domains had their own subdomains, and those subdomains had their own CT logs.</p><p>Fix: Recursive enumeration. Every new domain → full acquisition pipeline → find more domains → repeat.</p><h3>Bug Hunter Acquisition Checklist — Phone &amp; Email Edition</h3><h3>☐ Phone Number Collection</h3><ul><li>☐ WHOIS records extracted for all discovered domains</li><li>☐ Contact/scraped pages (main site, subdomains, subsidiaries)</li><li>☐ Business registries checked (OpenCorporates, state registries)</li><li>☐ SEC filings reviewed (10-K, 10-Q, S-1)</li><li>☐ Press releases and news articles mined</li><li>☐ Social media profiles checked (LinkedIn, Twitter, Facebook)</li><li>☐ Breach data queried (with authorization)</li></ul><h3>☐ Phone Number Analysis</h3><ul><li>☐ VOIP provider identified for each number</li><li>☐ Area codes mapped to physical office locations</li><li>☐ Multi-number comparison for organizational structure</li><li>☐ Extension patterns identified</li><li>☐ Reverse WHOIS by phone number completed</li><li>☐ Business registry search by phone completed</li><li>☐ Phone number range scanning (if applicable)</li></ul><h3>☐ Phone → Domain Mapping</h3><ul><li>☐ Reverse WHOIS for every unique phone number</li><li>☐ Business registry domain mapping</li><li>☐ Carrier/VOIP provider infrastructure checked</li><li>☐ Support portal domains discovered (Zendesk, Freshdesk, etc.)</li><li>☐ VOIP admin console exposure checked</li><li>☐ Webhook endpoint testing (if Twilio/RingCentral identified)</li></ul><h3>☐ Email Collection</h3><ul><li>☐ Hunter.io domain search completed</li><li>☐ theHarvester multi-source harvest completed</li><li>☐ Skymem cross-reference completed</li><li>☐ Web page email extraction completed</li><li>☐ JavaScript file email extraction completed</li><li>☐ LinkedIn employee name scraping completed</li><li>☐ GitHub commit email extraction completed</li><li>☐ Mailing list/public forum extraction completed</li><li>☐ Breach data email extraction (with authorization)</li></ul><h3>☐ Email → Domain Extraction</h3><ul><li>☐ All unique domains extracted from email addresses</li><li>☐ Primary domain filtered out to reveal hidden domains</li><li>☐ Subsidiary/acquired company domains identified</li><li>☐ Internal/private domains identified</li><li>☐ Third-party service domains identified</li><li>☐ Employee personal domains identified</li></ul><h3>☐ Email → GitHub → Domain Chain</h3><ul><li>☐ GitHub accounts found for employee emails</li><li>☐ Repos and commits scanned for domain references</li><li>☐ Organization discovery completed</li><li>☐ Config files and environment vars checked</li><li>☐ Hardcoded endpoints extracted</li><li>☐ S3 bucket names and cloud resources extracted</li></ul><h3>☐ Email → Service → Domain Chain</h3><ul><li>☐ Atlassian (Jira/Confluence) instance discovered</li><li>☐ Slack workspace discovered</li><li>☐ Microsoft 365 tenant discovered</li><li>☐ Google Workspace tenant discovered</li><li>☐ Zendesk/Freshdesk/Helpscout portal discovered</li><li>☐ Status page hosted domain discovered</li><li>☐ Documentation/wiki hosted domain discovered</li></ul><h3>☐ Full Subdomain Enumeration on New Domains</h3><ul><li>☐ CT log queries (crt.sh, certspotter) for each new domain</li><li>☐ Passive DNS queries (SecurityTrails, VirusTotal)</li><li>☐ Subdomain brute-force (subfinder, puredns, massdns)</li><li>☐ Permutation-based discovery (alterx, gotator, dmut)</li><li>☐ Recursive enumeration (each subdomain → parent as new target)</li><li>☐ Wayback Machine historical subdomain discovery</li><li>☐ Technology fingerprinting (httpx, whatweb)</li><li>☐ HTTP response analysis (live vs. dead, redirects, error pages)</li></ul><h3>☐ Cross-Reference Validation</h3><ul><li>☐ Phone numbers matched to discovered domains</li><li>☐ Emails matched to discovered domains</li><li>☐ LinkedIn past companies cross-referenced with acquisitions</li><li>☐ GitHub profiles cross-referenced with company email domains</li><li>☐ Breach data cross-referenced (correlates emails, phones, domains)</li><li>☐ Scope validation for every newly discovered asset</li></ul><h3>☐ Continuous Monitoring</h3><ul><li>☐ Daily CT log monitoring for new subdomains on discovered domains</li><li>☐ Weekly phone number re-check (new WHOIS entries)</li><li>☐ Weekly email re-harvesting (new employees, new domains)</li><li>☐ GitHub monitoring for new employee commits</li><li>☐ Acquisition news monitoring (Google Alerts, Crunchbase)</li><li>☐ LinkedIn employee movement tracking</li><li>☐ Quarterly full pipeline re-run</li></ul><h3>Final Technical Notes</h3><h3>Why This Works at Scale</h3><p>The average Fortune 500 company has:</p><ul><li>50–200 registered domains</li><li>10–50 subsidiaries/acquired entities</li><li>2,000–20,000 employees</li><li>5–20 different phone numbers</li></ul><p>DNS brute-force will find maybe 30–50% of the subdomains on the main domain. It will find almost none of the subdomains on other domains.</p><p>Phone and email OSINT finds the other domains. Then you run DNS brute-force on those. The result is a 3–5x increase in discovered attack surface.</p><h3>The Data Flow</h3><pre>Phone Number → Reverse WHOIS → New Domains<br>Phone Number → Business Registry → Legal Entities → New Domains<br>Phone Number → VOIP Provider → Admin Console → Subdomains<br><br>Email Address → Hunter.io → Cross-Company Domains<br>Email Address → GitHub → Repos → Configs → Domains<br>Email Address → Breach Data → Service Registrations → Domains<br>Email Address → LinkedIn → Past Companies → Acquired Domains<br><br>New Domains → Subdomain Enumeration → Attack Surface</pre><h3>A Final Word on Authorization</h3><p>Everything in this blog assumes you have explicit written authorization to test the target’s assets. I do not share the names of actual targets. All examples are anonymized composites of real engagements.</p><p>If you’re new to bug bounty:</p><ol><li>Start with public programs on HackerOne/Bugcrowd that explicitly allow OSINT</li><li>Never use breach data unless the program explicitly permits it</li><li>Never use social engineering unless the program explicitly permits it</li><li>When in doubt, ask the program’s security team</li></ol><p>Disclaimer: Only for authorized bug bounty / pentesting environments.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*o-3pvh96SZd-YMZS.png"><figcaption>Follow US</figcaption></figure><p><em>GitHub: </em><a href="https://github.com/SecurityTalent"><em>SecurityTalent</em></a><em> | Medium: </em><a href="https://medium.com/@securitytalent"><em>Security Talent</em></a><em> | Twitter: </em><a href="https://twitter.com/Securi3yTalent"><em>Securi3yTalent</em></a><em> </em>| Facebook: <a href="https://www.facebook.com/Securi3ytalent/">Securi3ytalent</a> | Telegram: <a href="https://t.me/Securi3yTalent">Securi3yTalent</a></p><p>#BugBounty #OSINT #CyberSecurity #EthicalHacking #Infosec #PenetrationTesting #AttackSurface #SubdomainEnumeration #ThreatHunting #SecurityResearch #RedTeam #DigitalFootprint #CyberSecurity #BugBounty #BugBountyHunter #EthicalHacking #InfoSec #WebSecurity #ApplicationSecurity #AppSec #CloudSecurity #FrontendSecurity #WebDevelopment #JavaScript #ReactJS #Laravel #NodeJS #DevSecOps #OWASP #SecretsManagement #GitHub #GitHubDorks #SourceMaps #EnvFiles #SecurityResearch #PenetrationTesting #RedTeam #BlueTeam #CloudComputing #AWS #Azure #GoogleCloud #VibeCoding #AI #SecureCoding #DeveloperSecurity #TechBlog #Programming</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=16b1e7d533cd" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/phone-numbers-and-emails-to-hidden-subdomains-the-osint-acquisition-pipeline-that-uncovered-a-16b1e7d533cd">Phone Numbers and Emails to Hidden Subdomains: The OSINT Acquisition Pipeline That Uncovered a…</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘프롬프트 엔지니어’ 열풍은 끝났다…2026년 가장 구하기 어려운 IT 인재 11선]]></title>
<description><![CDATA[요즘은 특정 전문 인력을 채용하는 일이 비교적 수월하다. SOC 분석가, 머신러닝(ML) 연구원, 클라우드 아키텍트 등이 대표적이다. 이런 직무는 몇 주 안에 채용이 완료되는 경우가 많다. 반면 6~9개월 동안 공석으로 남는 자리는 하이브리드 직무다. AI를 능숙하게 활용하면서도 깊이 있는 개발 역량을 갖추고 비즈니스까지 이해하는 엔지니어가 이에 해당한다.



미국 유통업체 베스트바이(Best Buy)의 최고 디지털·기술 책임자(CDTO) 닐 샘플은 “세 가지 역량을 모두 갖춘 사람을 찾고 있지만 인재 풀은 매우 제한적이다”...]]></description>
<link>https://tsecurity.de/de/3609616/it-nachrichten/2026-it-11/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609616/it-nachrichten/2026-it-11/</guid>
<pubDate>Fri, 19 Jun 2026 09:32:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>요즘은 특정 전문 인력을 채용하는 일이 비교적 수월하다. SOC 분석가, 머신러닝(ML) 연구원, 클라우드 아키텍트 등이 대표적이다. 이런 직무는 몇 주 안에 채용이 완료되는 경우가 많다. 반면 6~9개월 동안 공석으로 남는 자리는 하이브리드 직무다. AI를 능숙하게 활용하면서도 깊이 있는 개발 역량을 갖추고 비즈니스까지 이해하는 엔지니어가 이에 해당한다.</p>



<p>미국 유통업체 베스트바이(Best Buy)의 최고 디지털·기술 책임자(CDTO) <a href="https://www.linkedin.com/in/nealsample/" target="_blank" rel="nofollow">닐 샘플</a>은 “세 가지 역량을 모두 갖춘 사람을 찾고 있지만 인재 풀은 매우 제한적이다”라며 “이러한 하이브리드 인재가 IT의 미래이지만 현재는 확보하기가 매우 어렵다”라고 말했다.</p>



<p>AI가 CIO.com이 펴낸 ‘<a href="https://us.resources.cio.com/resources/state-of-the-cio/" target="_blank" rel="nofollow">CIO 현황 조사</a>‘에서 사이버보안을 제치고 가장 채용하기 어려운 IT 역량으로 꼽힌 지 2년이 지났지만, 최상위권 순위는 변하지 않았다. <a href="https://us.resources.cio.com/resources/state-of-the-cio/" target="_blank" rel="nofollow">2026년 CIO 현황 조사에 따르면</a> AI·머신러닝과 사이버보안이 가장 채용하기 어려운 분야 공동 1위를 차지했으며, 데이터 과학과 분석이 그 뒤를 이었다.</p>



<p>순위는 익숙하지만 인재 부족의 양상은 달라졌다. 과거에는 대규모언어모델(LLM) 엔지니어와 프롬프트 전문가를 찾는 경쟁이 치열했다면, 이제는 AI를 대규모 환경에서 운영하고 위험을 관리하며 무조건 신뢰하기보다 효과적으로 활용할 수 있는 인재에 대한 수요가 커지고 있다.</p>



<p>한편 리스크 관리는 처음으로 상위 5위 안에 진입했으며, 비즈니스·IT 자동화는 여전히 상위권을 유지했다. 반면 몇 년 전까지 높은 수요를 보였던 일부 분야에 대한 압박은 완화됐다. 클라우드 아키텍처의 순위는 하락했고, 개발자의 업무 방식 자체를 AI 도구가 바꾸면서 애플리케이션 개발은 순위권에서 완전히 사라졌다.</p>



<p>정보기술 자문업체 발컴 테크놀로지스(Valcom Technologies)의 IT 고문 겸 필드 CTO <a href="https://www.linkedin.com/in/nielnickolaisen/" target="_blank" rel="nofollow">닐 니콜라이젠</a>은 “현재 가장 채용이 어려운 직무는 AI 역량이 결합된 모든 역할”이라고 진단했다.</p>



<p>그는 AI를 활용해 보안 태세를 강화할 수 있는 보안 분석가, AI 플랫폼을 이용해 설계·개발·배포를 수행할 수 있는 소프트웨어 엔지니어를 예로 들며 “이러한 인재는 아직 시장에 충분히 공급되지 않고 있다”라고 설명했다.</p>



<p><strong>채용이 가장 어려운 IT 직무: 2026년 vs. 2024년</strong></p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><th>역량</th><th>2026년 순위</th><th>2024년 순위</th><th>변화</th></tr></thead><tbody><tr><td>AI/머신러닝</td><td>공동 1위</td><td>1위</td><td>유지</td></tr><tr><td>사이버보안</td><td>공동 1위</td><td>2위</td><td>상승</td></tr><tr><td>데이터 과학/분석</td><td>3위</td><td>3위</td><td>유지</td></tr><tr><td>비즈니스·IT 자동화</td><td>4위</td><td>공동 4위</td><td>유지</td></tr><tr><td>리스크 관리</td><td>5위</td><td>공동 8위</td><td>상승</td></tr><tr><td>소프트웨어 엔지니어링</td><td>공동 6위</td><td>공동 6위</td><td>유지</td></tr><tr><td>DevOps/DevSecOps</td><td>공동 6위</td><td>공동 11위</td><td>상승</td></tr><tr><td>엔터프라이즈 아키텍처</td><td>공동 8위</td><td>공동 10위</td><td>상승</td></tr><tr><td>클라우드 서비스·통합</td><td>공동 8위</td><td>공동 12위</td><td>상승</td></tr><tr><td>클라우드 아키텍처</td><td>공동 8위</td><td>공동 6위</td><td>하락</td></tr><tr><td>디자인 씽킹/UX</td><td>공동 8위</td><td>공동 15위</td><td>상승</td></tr></tbody></table> </div></figure>



<p><em>자료: Foundry/CIO.com State of the CIO Survey(2024·2026)</em></p>



<h2 class="wp-block-heading">AI 채용 시장의 성숙</h2>



<p>LLM 전문 인력을 찾고 있는 IT 리더들에게는 한 가지 반가운 소식이 있다. LLM 엔지니어를 둘러싼 과열 경쟁이 다소 진정됐다는 점이다.</p>



<p>베스트바이의 샘플은 “독립적인 직무로서의 프롬프트 엔지니어링은 짧은 유행에 불과했다”라며 “이제는 기본적으로 갖춰야 할 역량이 됐다”라고 말했다.</p>



<p>하지만 현재 대부분의 기업이 찾는 인재상은 다르다. AI 에이전트를 구축하고, 테스트 프레임워크를 개발하며, 비용·지연시간·품질 간 균형을 관리하고, AI를 대규모 환경에 배포할 수 있는 AI 제품 엔지니어가 필요하다. 또한 3년 전만 해도 조직도에 존재하지 않았던 AI 거버넌스와 레드팀(red team) 관련 역할도 새롭게 채용하고 있다.</p>



<p>샘플은 “중심축이 모델을 만드는 사람에서 모델을 활용하는 사람으로 이동했다”라며 “요구되는 경력과 역량이 완전히 달라졌다”라고 설명했다.</p>



<p>생성형 AI와 LLM 도구가 충분히 직관적으로 발전하면서 기업이 요구하는 역량도 프롬프트 엔지니어링에서 에이전트 기반 AI 활용 능력 중심으로 변화하고 있다.</p>



<p>컨설팅 기업 발컴 테크놀로지스(Valcom Technologies)의 IT 고문 겸 필드 CTO 닐 니콜라이젠은 “이제는 워크플로우와 프로세스 단순화를 이해하고, 에이전트 플랫폼을 활용해 업무와 작업을 자동화할 수 있는 인재가 필요하다”라며 “향후 1~2년 내 에이전트 플랫폼이 더욱 직관적으로 발전할 것으로 예상한다. 그러면 재교육의 초점도 에이전트의 자율성을 높이는 방향으로 이동할 것”이라고 전망했다.</p>



<p>문제는 AI가 매우 빠른 속도로 발전하고 있다는 점이다. 클라우드 서비스 제공업체부터 스타트업 생태계에 이르기까지 다양한 기업이 AI에 대규모 투자를 이어가면서 한 기업에서 쌓은 경험이 다른 기업에서는 통하지 않을 수 있다. 심지어 6개월 전에 익힌 지식조차 이미 구식이 됐을 가능성이 있다.</p>



<p>사모펀드 시장 전문 기술 리더인 <a href="https://www.linkedin.com/in/scotthicar/" target="_blank" rel="nofollow">스콧 하이카</a>는 “특정 기술보다 시장 변화를 폭넓게 이해하고 지속적으로 학습할 수 있는 역량을 가진 인재를 찾는 것이 바람직하다”라고 말했다.</p>



<h2 class="wp-block-heading">사이버보안 인력난의 본질은 역량 격차</h2>



<p>사이버보안이 AI와 함께 가장 채용하기 어려운 분야로 떠오른 것은 단순히 수요 증가 때문만은 아니다. 이는 기업이 직면한 보안 과제가 근본적으로 변화하고 있음을 보여준다.</p>



<p>2026년 <a href="https://www.sans.org/white-papers/2026-cybersecurity-workforce-research-report" target="_blank" rel="nofollow">SANS/GIAC 사이버보안 인력 보고서</a>에 따르면, 전체 조직의 60%는 인력 부족보다 역량 격차를 더 큰 인력 운영 과제로 꼽았다. 이는 1년 전과 비교해 20%포인트 증가한 수치다. 그 영향도 뚜렷하게 나타나고 있다. 조사 대상 사이버보안 리더의 27%는 역량 부족이 직접적인 원인이 된 보안 침해 사고를 경험했다고 답했으며, 61%는 지난 2년 동안 팀의 업무 스트레스가 증가했다고 밝혔다.</p>



<p>부족한 것은 초급 인력이 아니라 시니어 아키텍트급 인재다.</p>



<p>베스트바이의 닐 샘플은 “단순히 대시보드를 읽는 수준이 아니라 실제 제약 조건 속에서 적절한 보안 의사결정을 내릴 수 있는 사람을 찾기 어렵다”라며 “그런 인재는 원하는 수준의 연봉을 요구할 수 있다”라고 말했다.</p>



<p>보안팀의 부담도 갈수록 커지고 있다. 새로운 SaaS 서비스가 추가되고 API와 AI 에이전트가 배포될 때마다 공격 표면은 확대된다. 사이버 공격자들도 방어 측과 동일한 AI 도구를 활용하고 있다. 그 결과 보안팀의 피로도와 소진 현상이 심화되고 있다.</p>



<p>발컴 테크놀로지스의 니콜라이젠은 이를 운영 관점에서 설명했다.</p>



<p>그는 “AI를 활용한 사이버보안 역량이 가장 시급한 이유는 그것이 가장 현실적이고 가까운 위협이기 때문”이라며 “공격자가 바이브 코딩(vibe coding)을 활용해 1시간도 안 돼 공격 도구를 만들고 몇 분 만에 수정할 수 있다면 방어 측도 거의 실시간으로 대응하고 전략을 수정할 수 있어야 한다”라고 말했다.</p>



<p>SANS 조사에 따르면 74%의 조직은 AI가 이미 사이버보안 조직 규모와 직무 구성에 영향을 미치고 있다고 답했다. AI가 보안 조직을 재편하면서 가장 먼저 축소될 가능성이 높은 직무는 SOC 분석가와 보안 분석가였다. 문제는 이들이 전통적으로 차세대 사이버보안 리더가 경험을 쌓아온 입문 단계 직무라는 점이다.</p>



<p>반면 AI·머신러닝 보안 전문가, AI 보안 엔지니어, AI 거버넌스 분석가와 같은 새로운 역할은 빠르게 등장하고 있다.</p>



<h2 class="wp-block-heading">‘2차 AI 역량’의 부상</h2>



<p>자동화와 리스크 관리 역량은 올해 처음으로 ‘CIO 현황 조사’에서 가장 채용하기 어려운 직무 상위 5위 안에 진입했다. 두 분야가 동시에 주목받는 이유는 같다.</p>



<p>샘플은 “AI가 관리해야 할 영역 자체를 크게 확장시켰다”라며 “배포하는 모든 에이전트가 새로운 자동화이자 새로운 리스크인데, 대부분의 거버넌스·리스크·컴플라이언스(GRC) 조직과 운영 조직은 이러한 속도에 맞춰 설계되지 않았다”라고 설명했다.</p>



<p>자동화 분야에서 필요한 것은 더 많은 RPA 개발자가 아니다. RPA 개발 자체는 이미 범용 기술이 됐다. 이제 기업은 프로세스를 분석해 무엇을 자동화하고, 무엇을 폐기하며, 무엇을 재설계할지 판단할 수 있는 인재를 원한다.</p>



<p>샘플은 “이는 세 가지 직무가 결합된 역할”이라며 “비즈니스 분석가, 프로세스 엔지니어, 기술 전문가 역량을 모두 갖춰야 한다. 세 가지를 모두 잘하는 사람은 드물고 비용도 많이 든다”라고 말했다.</p>



<p>자동화 인재 수요 증가의 배경에는 챗봇에서 AI 에이전트로의 전환이 있다.</p>



<p>AI 측정 플랫폼 기업 래리딘(Larridin)의 공동 설립자 겸 CTO <a href="https://www.linkedin.com/in/ameyakanitkar/" target="_blank" rel="nofollow">아메야 카니트카르</a>는 “초기 AI 에이전트는 새로운 업무를 만들어내기보다 기존 업무 수행 방식을 대체할 것”이라며 “기업들은 핵심 비즈니스 프로세스를 완전 또는 반자율 에이전트 중심으로 재설계하고 있으며, 이를 구축하고 운영할 수 있는 인재 수요가 매우 크다”라고 설명했다.</p>



<p>다만 이러한 역할에는 시스템의 작동 원리와 비즈니스 운영 방식을 모두 이해하는 드문 역량 조합이 필요하다고 카니트카르는 지적했다.</p>



<p>리스크 관리 역시 비슷한 과제를 안고 있다. SOX나 PCI 규정 준수를 위해 구축된 기존 GRC 체계는 모델 리스크, 프롬프트 인젝션, 제3자 AI 노출 위험에 최적화돼 있지 않다.</p>



<p>샘플은 “탄생한 지 5년 정도밖에 되지 않은 분야를 20년 된 직무기술서로 채용하려 하고 있다”라며 “그 간극이 문제”라고 지적했다.</p>



<p>최근 더욱 중요해진 역량 중 하나는 제3자 리스크 관리다.</p>



<p>니콜라이젠은 “AI가 우리가 구매하고 사용하는 거의 모든 제품과 서비스에 내장되고 있다”라며 “이제는 외부 공급업체의 AI를 평가하기 위해 더 많은 인력이 필요한지, 또는 더 체계적인 거버넌스 프로세스가 필요한지를 고민해야 한다”라고 말했다.</p>



<p>컴퓨팅기술산업협회(CompTIA)의 최고 기술 에벤젤리스트 <a href="https://www.linkedin.com/in/jamesstanger/" target="_blank" rel="nofollow">제임스 스탠저</a> 박사는 리스크 관리가 일반적인 기술 인력과는 다른 사고방식을 요구한다고 설명했다.</p>



<p>스탠저는 “기술 자체를 이해하는 것은 기본”이라며 “동시에 그 기술이 비즈니스에서 어떻게 활용되는지도 이해해야 한다. 그렇지 않으면 리스크가 아니라 기술만 다루게 된다”라고 말했다.</p>



<h2 class="wp-block-heading">중간급 인력의 입지 축소</h2>



<p>AI 코딩 도구와 로우코드 플랫폼은 소프트웨어 엔지니어 수요를 줄이지는 않았지만, 수요의 형태는 바꿔놓았다. 이제 뛰어난 엔지니어 한 명이 적절한 AI 도구를 활용하면 불과 몇 년 전 엔지니어 세 명이 수행하던 수준의 생산성을 낼 수 있다.</p>



<p>베스트바이의 닐 샘플은 “가장 큰 압박을 받는 계층은 중간급 인력”이라며 “주요 업무가 API를 연결하는 수준에 머물렀던 엔지니어들이 영향을 받고 있다”라고 말했다.</p>



<p>래리딘의 카니트카르는 엔지니어 채용 시장이 양극화되고 있다고 분석했다. 판단력과 책임감을 갖춘 경험 많은 리더급 인재에 대한 수요는 높고, 처음부터 AI 환경에 익숙한 주니어 인재에 대한 수요도 강하다. 반면 중간급 인력은 입지가 좁아지고 있다.</p>



<p>카니트카르는 “압박을 받는 계층은 중간 수준의 실행 역량에 의존해 온 인재”라며 “이들은 현재 채용 시장에서 불리한 위치에 놓이고 있다”라고 설명했다.</p>



<p>AI 도구는 엔지니어들에게 보다 아키텍트에 가까운 사고방식을 요구하고 있다.</p>



<p>컴퓨팅기술산업협회(CompTIA)의 스탠저 박사는 “과거에는 코드를 작성할 수 있는 IT ‘배관공’ 같은 인재를 찾았다”라며 “지금은 아키텍처 관점과 리스크, 개인정보보호 측면까지 고려할 수 있는 인재를 원한다”라고 말했다.</p>



<p>이어 “단순히 키보드로 코드를 입력하는 개발자가 아니라 AI를 활용해 잠재적인 성능 문제를 모델링하고 예측할 수 있는 능동적인 설계자가 필요하다”라고 설명했다.</p>



<p>특히 데브옵스 분야에서는 역할 통합이 진행되고 있다.</p>



<p>샘플은 “플랫폼 엔지니어링이 성장 분야로 떠오르고 있다”라며 “일반적인 데브옵스 엔지니어 직무는 플랫폼 엔지니어링이나 사이트 신뢰성 엔지니어링(SRE)에 흡수되고 있으며, 앞으로 몇 년 안에 독립적인 직무로는 사라질 가능성이 크다”라고 전망했다.</p>



<h2 class="wp-block-heading">안정기에 접어든 클라우드</h2>



<p>클라우드 관련 직무는 이전보다 인력 확보가 수월해졌다. 이러한 변화는 2024년부터 나타나기 시작했으며 현재까지 이어지고 있다.</p>



<p>발컴 테크놀로지스의 니콜라이젠은 “대부분의 조직이 클라우드 운영의 안정 단계에 도달했다”라며 “특별한 변화가 없는 한 퍼블릭 클라우드, 프라이빗 클라우드, 온프레미스 워크로드 구성이 이미 자리 잡았다”라고 말했다.</p>



<p>이어 “현재 시스템 운영팀이 보유한 역량만으로도 이를 충분히 지원할 수 있다”라고 설명했다.</p>



<p>스탠저는 클라우드 교육 프로그램이 성숙 단계에 접어들면서 인재 공급도 늘어났다고 분석했다. 다만 채용 압박이 완화된 정확한 이유를 특정하기는 어렵다고 덧붙였다.</p>



<p>샘플은 “클라우드는 이제 하나의 전문 직업 영역으로 자리 잡았다”라며 “대규모 환경에서 오랜 기간 경험을 쌓은 인재도 크게 늘었다”라고 말했다.</p>



<p>그럼에도 일부 클라우드 전문 분야는 여전히 인력 확보가 어렵다. 핀옵스, 규제 산업의 클라우드 전환 프로젝트, 클라우드 회귀(Reverse Migration) 등이 대표적이다.</p>



<p>일부 워크로드는 다시 온프레미스 환경으로 이동하는 추세도 나타나고 있다.</p>



<p>샘플은 “특히 AI 추론 워크로드는 대규모 환경에서 클라우드 비용 부담이 매우 커질 수 있다”라며 “이로 인해 필요한 역량 구성이 다시 바뀌고 있지만, ‘워크로드를 클라우드에서 효율적으로 이전할 수 있다’고 적힌 이력서는 거의 찾아보기 어렵다”라고 말했다.</p>



<h2 class="wp-block-heading">인재 격차 해소에 효과적인 방법</h2>



<p>IT 리더들이 한목소리로 동의하는 점이 있다. 속도와 비용, 인재 유지 측면에서 외부 채용보다 업스킬링과 내부 인재 이동이 훨씬 효과적이라는 것이다.</p>



<p>샘플은 “2025년 가장 생산성이 높았던 AI 엔지니어들은 처음부터 AI 엔지니어로 채용된 인재가 아니었다”라며 “우수한 소프트웨어 엔지니어들이 내부 교육과 실제 프로젝트를 통해 AI 역량을 습득한 사례였다”라고 설명했다.</p>



<p>니콜라이젠은 외부 전문가의 우위도 예전만 못하다고 평가했다.</p>



<p>그는 “AI 변화 속도가 너무 빨라 외부 컨설턴트가 내부 팀보다 반드시 앞서 있는 것은 아니다”라며 “팀이 초기 진입 장벽을 넘고 AI를 적극적으로 수용하기 시작하면 역량은 매우 빠르게 발전한다”라고 말했다.</p>



<p>성공의 핵심은 신뢰다. 니콜라이젠은 “AI를 통해 생산성이 향상되더라도 이를 인력 감축에 활용하지 않을 것이라는 확신을 팀에 심어주면 가치 창출 속도를 놀라울 정도로 높일 수 있다”라고 설명했다.</p>



<p>베스트바이는 AI 채용 방식을 바꾸면서 인재 풀을 크게 확대했다.</p>



<p>샘플은 “우리는 AI 엔지니어를 채용하는 것이 아니라 엔지니어를 채용한 뒤 우리 방식의 AI 활용법을 교육한다”라며 “이러한 관점 전환만으로도 후보자 풀이 최소 10배 이상 확대됐고 성과도 더 좋아졌다”라고 말했다.</p>



<p>스탠저는 역량 확장을 위한 방안으로 교차 교육(cross-skilling), 도제식 멘토링, 학습 경로(Pathway) 기반 교육을 제안했다. 자격증이나 학위보다 실제 역량 개발에 초점을 맞춘 접근법이다.</p>



<p>스탠저는 “이제 가장 진보적인 기업들은 ‘어느 대학을 졸업했는가’를 묻기보다 ‘어떤 역량을 갖고 있으며 그 역량으로 우리 조직을 어디까지 성장시킬 수 있는가’를 묻고 있다”라고 설명했다.</p>



<p>최신 유행 직함만 좇는 채용 전략에도 경고의 목소리가 나온다.</p>



<p>샘플은 “2023년 프롬프트 엔지니어 채용 열풍을 떠올려보면, 그 직무는 18개월 만에 사실상 수명이 다했고 당시 채용된 인력은 지금 새로운 역량을 익히고 있다”라며 “역량이 아닌 직함을 기준으로 채용하면 수명이 짧다. 일부 기업에서는 에이전트 AI 분야에서도 같은 실수가 반복되고 있다”라고 지적했다.</p>



<h2 class="wp-block-heading">침체된 시장, 그러나 어려운 과제</h2>



<p>기술 인력 채용 시장은 전반적으로 둔화된 상태다. AI에 따른 일자리 대체 우려와 경제 상황, 그리고 니콜라이젠의 표현대로 “우리 삶의 거의 모든 것”에 대한 불확실성이 영향을 미치고 있다.</p>



<p>그러나 핵심 역량을 보유한 인재를 둘러싼 경쟁은 여전히 치열하다.</p>



<p>카니트카르는 “향후 2년이 매우 중요한 시기”라며 “바로 이때 격차가 본격적으로 벌어지기 시작할 것”이라고 전망했다.</p>



<p>기술 변화의 최전선은 매일 이동하고 있다. 따라서 이러한 변화를 빠르게 수용하는 IT 조직과 변화에 저항하는 조직 간 격차는 앞으로 더욱 커질 것으로 예상된다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alibaba Cloud Bets on France as Europe Seeks More Control Over AI]]></title>
<description><![CDATA[Alibaba Cloud opened two Paris availability zones as European enterprises weigh data sovereignty, resilience, and AI infrastructure needs.
The post Alibaba Cloud Bets on France as Europe Seeks More Control Over AI appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3609290/it-security-nachrichten/alibaba-cloud-bets-on-france-as-europe-seeks-more-control-over-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609290/it-security-nachrichten/alibaba-cloud-bets-on-france-as-europe-seeks-more-control-over-ai/</guid>
<pubDate>Fri, 19 Jun 2026 04:53:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Alibaba Cloud opened two Paris availability zones as European enterprises weigh data sovereignty, resilience, and AI infrastructure needs.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-alibaba-cloud-ai-sovereignty-emea-france/">Alibaba Cloud Bets on France as Europe Seeks More Control Over AI</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alibaba Cloud Bets on France as Europe Seeks More Control Over AI]]></title>
<description><![CDATA[Alibaba Cloud opened two Paris availability zones as European enterprises weigh data sovereignty, resilience, and AI infrastructure needs. The post Alibaba Cloud Bets on France as Europe Seeks More Control Over AI appeared first on TechRepublic. This article has been…
Read more →
The post Alibaba...]]></description>
<link>https://tsecurity.de/de/3609212/it-security-nachrichten/alibaba-cloud-bets-on-france-as-europe-seeks-more-control-over-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609212/it-security-nachrichten/alibaba-cloud-bets-on-france-as-europe-seeks-more-control-over-ai/</guid>
<pubDate>Fri, 19 Jun 2026 03:59:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Alibaba Cloud opened two Paris availability zones as European enterprises weigh data sovereignty, resilience, and AI infrastructure needs. The post Alibaba Cloud Bets on France as Europe Seeks More Control Over AI appeared first on TechRepublic. This article has been…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/alibaba-cloud-bets-on-france-as-europe-seeks-more-control-over-ai/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/alibaba-cloud-bets-on-france-as-europe-seeks-more-control-over-ai/">Alibaba Cloud Bets on France as Europe Seeks More Control Over AI</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Federal Energy Regulator Seeks to Limit Conflicts Over Data Centers]]></title>
<description><![CDATA[The Federal Energy Regulatory Commission directed grid managers to make changes that protect individuals from higher electricity bills while giving data centers access to power faster.]]></description>
<link>https://tsecurity.de/de/3608738/ai-nachrichten/federal-energy-regulator-seeks-to-limit-conflicts-over-data-centers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608738/ai-nachrichten/federal-energy-regulator-seeks-to-limit-conflicts-over-data-centers/</guid>
<pubDate>Thu, 18 Jun 2026 21:03:58 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Federal Energy Regulatory Commission directed grid managers to make changes that protect individuals from higher electricity bills while giving data centers access to power faster.]]></content:encoded>
</item>
<item>
<title><![CDATA[France’s OVHcloud bets on frontier AI as Europe seeks alternatives to US models]]></title>
<description><![CDATA[France’s OVHcloud is moving beyond cloud infrastructure into frontier AI model development, a shift that could test whether Europe can produce another serious alternative to US and Chinese AI systems.



The company, one of Europe’s leading homegrown cloud providers, plans to train a family of mo...]]></description>
<link>https://tsecurity.de/de/3607421/ai-nachrichten/frances-ovhcloud-bets-on-frontier-ai-as-europe-seeks-alternatives-to-us-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607421/ai-nachrichten/frances-ovhcloud-bets-on-frontier-ai-as-europe-seeks-alternatives-to-us-models/</guid>
<pubDate>Thu, 18 Jun 2026 12:49:36 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>France’s OVHcloud is moving beyond cloud infrastructure into frontier AI model development, a shift that could test whether Europe can produce another serious alternative to US and Chinese AI systems.</p>



<p>The company, one of Europe’s leading homegrown cloud providers, plans to train a family of models from scratch and aims to <a href="https://www.computerworld.com/article/4172545/why-open-ai-models-are-gaining-ground-on-llms.html" target="_blank">open-source</a> them once they meet its performance targets, CEO Octave Klaba <a href="https://www.reuters.com/world/asia-pacific/frances-ovhcloud-plans-frontier-ai-models-become-europes-second-llm-player-2026-06-17/" target="_blank" rel="noreferrer noopener">told Reuters</a>.</p>



<p>The move would put OVHcloud in closer comparison with <a href="https://www.computerworld.com/article/4146860/mistral-launches-forge-to-help-enterprises-build-their-own-ai-models-2.html" target="_blank">Mistral AI</a>, the Paris-based model developer that has become Europe’s most visible challenger to US AI labs.</p>



<p>Klaba said the economics of building advanced AI models have changed, with improvements in chips, training methods, and synthetic data reducing the cost of a project that may once have required about $1.15 billion (€1 billion) to now cost less than $230 million (€200 million).</p>



<p>Reuters reported that OVHcloud said one of its models has completed pre-training on Jupiter, the Germany-based EuroHPC supercomputer described as Europe’s fastest and its first exascale system, though the company has not yet disclosed detailed performance benchmarks.</p>



<p>This comes as European governments and enterprises are increasingly having to assess AI infrastructure through the lens of data governance and continuity of access, rather than performance alone.</p>



<p>Those concerns were sharpened this month after Anthropic said a US government <a href="https://www.computerworld.com/article/4186538/anthropic-fable-dispute-suggests-export-no-longer-means-what-it-used-to-2.html">export-control directive</a> required it to suspend access to its Fable 5 and Mythos 5 models by foreign nationals inside and outside the US.</p>



<h2 class="wp-block-heading">Training is only the opening cost</h2>



<p>OVHcloud’s lower cost estimate does not capture the full cost of becoming a frontier AI model provider, said <a href="https://www.linkedin.com/in/meetneilshah/" target="_blank" rel="noreferrer noopener">Neil Shah</a>, vice president for research and partner at Counterpoint Research.</p>



<p>The $230 million (€200 million) figure likely refers mainly to the initial training run, Shah said. Once trained, however, models require continued investment because they can become depreciating assets if they are not improved with fresh data.</p>



<p>OVHcloud would also need to spend on fine-tuning, post-training, sovereign infrastructure, storage, security, distribution, and enterprise support. It would also need enough scale to make model serving economically viable against established AI providers such as Google and Anthropic.</p>



<p>“Model is seen as a depreciating asset if it is not consistently trained and kept fresh with the data,” Shah said.</p>



<p>That makes OVHcloud’s plan a test not only of technical capability, but also of policy support and economic viability. If the company falls short, enterprises may be reluctant to shift workloads away from more established models.</p>



<p>The lower training cost could still give OVHcloud a credible starting point, said <a href="https://www.forrester.com/analyst-bio/charlie-dai/BIO5344" target="_blank" rel="noreferrer noopener">Charlie Dai</a>, principal analyst at Forrester.</p>



<p>The budget range can be enough to produce a credible frontier model as efficiency gains reduce the cost of entry, Dai said. But enterprise competitiveness will depend on sustained capabilities beyond training, including inference efficiency, data pipelines, evaluation frameworks, and ecosystem reach.</p>



<h2 class="wp-block-heading">Buyers need proof</h2>



<p>OVHcloud’s plan remains an expression of intent rather than demonstrated capability, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, pointing to the absence of published benchmarks and other details.</p>



<p>“$200 million now buys a serious training run,” Gogia said. “It does not buy a serious enterprise AI franchise.”</p>



<p>Gogia said questions around sovereignty also extend to the infrastructure used to train the model, noting that pre-training was run on Jupiter rather than on infrastructure owned or controlled by OVHcloud.</p>



<p>The system is a publicly owned European supercomputer in Germany that runs on American silicon, Gogia said, adding that this shows how partial European AI sovereignty remains.</p>



<p>CIOs will need evidence that the models can be supported in production, governed effectively, audited when needed, and exited without major disruption.</p>



<p>Gogia said a European-owned model could reduce some dependence on US and Chinese providers, but would not remove jurisdictional risk. “Sovereignty does not abolish the off switch,” he said. “It changes whose hand rests upon it.”</p>



<p>OVHcloud’s move into model development could also alter the lock-in risks enterprises need to assess, Gogia said. Customers may be able to move cloud infrastructure later, but find it harder to shift AI workloads once applications and processes are built around a provider’s models and governance tools.</p>



<p><em>The article originally appeared on <a href="https://www.computerworld.com/article/4186752/frances-ovhcloud-bets-on-frontier-ai-as-europe-seeks-alternatives-to-us-models.html">ComputerWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[France’s OVHcloud bets on frontier AI as Europe seeks alternatives to US models]]></title>
<description><![CDATA[France’s OVHcloud is moving beyond cloud infrastructure into frontier AI model development, a shift that could test whether Europe can produce another serious alternative to US and Chinese AI systems.



The company, one of Europe’s leading homegrown cloud providers, plans to train a family of mo...]]></description>
<link>https://tsecurity.de/de/3607398/it-nachrichten/frances-ovhcloud-bets-on-frontier-ai-as-europe-seeks-alternatives-to-us-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607398/it-nachrichten/frances-ovhcloud-bets-on-frontier-ai-as-europe-seeks-alternatives-to-us-models/</guid>
<pubDate>Thu, 18 Jun 2026 12:48:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>France’s OVHcloud is moving beyond cloud infrastructure into frontier AI model development, a shift that could test whether Europe can produce another serious alternative to US and Chinese AI systems.</p>



<p>The company, one of Europe’s leading homegrown cloud providers, plans to train a family of models from scratch and aims to <a href="https://www.computerworld.com/article/4172545/why-open-ai-models-are-gaining-ground-on-llms.html" target="_blank">open-source</a> them once they meet its performance targets, CEO Octave Klaba <a href="https://www.reuters.com/world/asia-pacific/frances-ovhcloud-plans-frontier-ai-models-become-europes-second-llm-player-2026-06-17/" target="_blank" rel="noreferrer noopener">told Reuters</a>.</p>



<p>The move would put OVHcloud in closer comparison with <a href="https://www.computerworld.com/article/4146860/mistral-launches-forge-to-help-enterprises-build-their-own-ai-models-2.html" target="_blank">Mistral AI</a>, the Paris-based model developer that has become Europe’s most visible challenger to US AI labs.</p>



<p>Klaba said the economics of building advanced AI models have changed, with improvements in chips, training methods, and synthetic data reducing the cost of a project that may once have required about $1.15 billion (€1 billion) to now cost less than $230 million (€200 million).</p>



<p>Reuters reported that OVHcloud said one of its models has completed pre-training on Jupiter, the Germany-based EuroHPC supercomputer described as Europe’s fastest and its first exascale system, though the company has not yet disclosed detailed performance benchmarks.</p>



<p>This comes as European governments and enterprises are increasingly having to assess AI infrastructure through the lens of data governance and continuity of access, rather than performance alone.</p>



<p>Those concerns were sharpened this month after Anthropic said a US government <a href="https://www.computerworld.com/article/4186538/anthropic-fable-dispute-suggests-export-no-longer-means-what-it-used-to-2.html">export-control directive</a> required it to suspend access to its Fable 5 and Mythos 5 models by foreign nationals inside and outside the US.</p>



<h2 class="wp-block-heading">Training is only the opening cost</h2>



<p>OVHcloud’s lower cost estimate does not capture the full cost of becoming a frontier AI model provider, said <a href="https://www.linkedin.com/in/meetneilshah/" target="_blank" rel="noreferrer noopener">Neil Shah</a>, vice president for research and partner at Counterpoint Research.</p>



<p>The $230 million (€200 million) figure likely refers mainly to the initial training run, Shah said. Once trained, however, models require continued investment because they can become depreciating assets if they are not improved with fresh data.</p>



<p>OVHcloud would also need to spend on fine-tuning, post-training, sovereign infrastructure, storage, security, distribution, and enterprise support. It would also need enough scale to make model serving economically viable against established AI providers such as Google and Anthropic.</p>



<p>“Model is seen as a depreciating asset if it is not consistently trained and kept fresh with the data,” Shah said.</p>



<p>That makes OVHcloud’s plan a test not only of technical capability, but also of policy support and economic viability. If the company falls short, enterprises may be reluctant to shift workloads away from more established models.</p>



<p>The lower training cost could still give OVHcloud a credible starting point, said <a href="https://www.forrester.com/analyst-bio/charlie-dai/BIO5344" target="_blank" rel="noreferrer noopener">Charlie Dai</a>, principal analyst at Forrester.</p>



<p>The budget range can be enough to produce a credible frontier model as efficiency gains reduce the cost of entry, Dai said. But enterprise competitiveness will depend on sustained capabilities beyond training, including inference efficiency, data pipelines, evaluation frameworks, and ecosystem reach.</p>



<h2 class="wp-block-heading">Buyers need proof</h2>



<p>OVHcloud’s plan remains an expression of intent rather than demonstrated capability, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, pointing to the absence of published benchmarks and other details.</p>



<p>“$200 million now buys a serious training run,” Gogia said. “It does not buy a serious enterprise AI franchise.”</p>



<p>Gogia said questions around sovereignty also extend to the infrastructure used to train the model, noting that pre-training was run on Jupiter rather than on infrastructure owned or controlled by OVHcloud.</p>



<p>The system is a publicly owned European supercomputer in Germany that runs on American silicon, Gogia said, adding that this shows how partial European AI sovereignty remains.</p>



<p>CIOs will need evidence that the models can be supported in production, governed effectively, audited when needed, and exited without major disruption.</p>



<p>Gogia said a European-owned model could reduce some dependence on US and Chinese providers, but would not remove jurisdictional risk. “Sovereignty does not abolish the off switch,” he said. “It changes whose hand rests upon it.”</p>



<p>OVHcloud’s move into model development could also alter the lock-in risks enterprises need to assess, Gogia said. Customers may be able to move cloud infrastructure later, but find it harder to shift AI workloads once applications and processes are built around a provider’s models and governance tools.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS targets software release bottlenecks with DevOps Agent update]]></title>
<description><![CDATA[The problem with software development today may no longer be writing code. With AI coding assistants generating code faster than ever, the bigger challenge is reviewing, testing, and safely releasing it.



AWS is betting that software teams need help with that part of the process, adding release...]]></description>
<link>https://tsecurity.de/de/3605222/ai-nachrichten/aws-targets-software-release-bottlenecks-with-devops-agent-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605222/ai-nachrichten/aws-targets-software-release-bottlenecks-with-devops-agent-update/</guid>
<pubDate>Wed, 17 Jun 2026 17:05:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The problem with software development today may no longer be writing code. With AI coding assistants generating code faster than ever, the bigger challenge is reviewing, testing, and safely releasing it.</p>



<p>AWS is betting that software teams need help with that part of the process, adding release management features to its DevOps Agent.</p>



<p>The new features, currently in preview, automatically assess code changes against organizational standards, identify potential release risks, and generate tests tailored to individual changes before they reach production.</p>



<p>The release readiness feature, in particular, runs the code in an AWS-managed isolated environment, executing lightweight user journey tests to verify the software builds, runs, and passes basic functional checks before the change enters the pipeline, the company wrote in a blog post.</p>



<p>The findings of these tests can be viewed through the DevOps Agent console, as comments on pull requests in GitHub or GitLab, or can be invoked directly through IDEs via <a href="https://www.infoworld.com/article/4135310/aws-adds-design-first-and-bugfix-workflows-to-kiro.html">Kiro</a> or the <a href="https://www.infoworld.com/article/4116598/anthropic-expands-claude-code-beyond-developer-tasks-with-cowork.html">Claude Code</a> plugin, it added.</p>



<h2 class="wp-block-heading">Targeting AI-era software delivery bottlenecks</h2>



<p>Running code in isolated environments and delivering the results directly through developer tools helps address two longstanding challenges in software delivery, said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<p>It enables teams to validate how code changes behave before deployment, catching issues that static analysis may overlook, while reducing context switching by embedding findings into existing workflows, in turn accelerating fixes, Jain said.</p>



<p>The analyst pointed out that the release readiness capability addresses a key bottleneck in AI-driven software development: “While AI coding agents can generate code quickly, reviews, compliance checks, dependency validation, and release approvals still slow deployment.”</p>



<p>“By automatically checking code changes against internal standards, security policies, and dependency impacts, AWS helps developers, <a href="https://www.infoworld.com/article/2255028/what-is-devops-bringing-dev-and-ops-together-for-better-software.html">DevOps</a> teams, and <a href="https://www.infoworld.com/article/2257232/what-is-an-sre-the-vital-role-of-the-site-reliability-engineer.html">SREs</a> identify issues earlier, reduce manual review effort, and improve release confidence,” Jain added.</p>



<p>These gains in productivity for developers could also translate into tangible business benefits for CIOs, according to Jain.</p>



<p>“Release readiness as a feature could help enterprises capture more value from AI-generated code while reducing operational overhead by eliminating the need for additional QA and DevOps resources. This means that they can accelerate software delivery without sacrificing reliability,” the analyst noted.</p>



<h2 class="wp-block-heading">Autonomous testing before merging code</h2>



<p>While release readiness reviews focus on assessing whether a code change is safe to move through the delivery pipeline, AWS is also adding a separate feature aimed at validating how those changes behave in production-like environments.</p>



<p>Named autonomous release testing, the new capability generates and runs change-specific test plans for web and API-based applications in customer-provisioned, production-like environments before the change actually merges, the company wrote in the blog post.</p>



<p>For Jain, autonomous release testing is “even more” important for developers and SREs as it “automates one of the most time-consuming parts of software delivery.”</p>



<p>“Developers spend less time creating and maintaining tests, while SREs benefit from fewer rollbacks and improved system reliability,” Jain said.</p>



<p>These benefits stem from the feature’s ability to automatically generate tests tailored to individual code changes, covering functional correctness, behavioral regressions, and integration scenarios that might otherwise require significant manual effort, Jain added.</p>



<p>However, AWS is not alone in trying to bring AI deeper into the software delivery lifecycle.</p>



<p>Microsoft-owned GitHub has been expanding Copilot’s code review capabilities, allowing the service to automatically <a href="https://docs.github.com/en/copilot/concepts/agents/code-review" target="_blank" rel="noreferrer noopener">review pull requests</a>, suggest fixes, and provide feedback directly within developer workflows.</p>



<p>Google, meanwhile, has been steadily broadening the scope of <a href="https://docs.cloud.google.com/gemini/docs/code-review/review-repo-code" target="_blank" rel="noreferrer noopener">Gemini Code Assist</a> beyond code generation to support software development tasks such as code review and developer assistance.</p>



<p>AWS’s differentiation, though, according to Jain, lies in tying those capabilities to release management and operational workflows that span development and production environments.</p>



<h2 class="wp-block-heading">Availability and pricing</h2>



<p>For development teams interested in evaluating DevOps Agent’s new capabilities, AWS said both features are available in preview at no additional cost in the US East (N. Virginia) region.</p>



<p>AWS DevOps Agent, billed per agent-second, is included in the AWS Free Tier for new customers.</p>



<p>Additionally, new AWS DevOps Agent customers receive a 2-month free trial starting with their first operational task after general availability.</p>



<p>Each trial month includes up to 10 agent spaces, 20 hours of investigations (incident response), 15 hours of evaluations (incident prevention), and 20 hours of on-demand SRE tasks (chat), the company said.</p>



<p>Once those limits are exhausted, customers are charged based on consumption, with investigations, evaluations, and on-demand SRE tasks each priced at $0.0083 per agent-second, AWS added.</p>



<p>A prerequisite for using the new release management features includes connecting at least one GitHub or GitLab repository to an AWS DevOps Agent Space.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS hypes continuous agentic DevOps, puts Kiro in your pocket]]></title>
<description><![CDATA[Trust is the biggest barrier to AI adoption, says AI chief, claiming that new features in Bedrock AgentCore will prevent bad outcomes]]></description>
<link>https://tsecurity.de/de/3605209/it-nachrichten/aws-hypes-continuous-agentic-devops-puts-kiro-in-your-pocket/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605209/it-nachrichten/aws-hypes-continuous-agentic-devops-puts-kiro-in-your-pocket/</guid>
<pubDate>Wed, 17 Jun 2026 17:03:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Trust is the biggest barrier to AI adoption, says AI chief, claiming that new features in Bedrock AgentCore will prevent bad outcomes]]></content:encoded>
</item>
<item>
<title><![CDATA[Root Cause in unter einer Minute: Wie KI-gestützte Observability fragmentierte Cloud ...]]></title>
<description><![CDATA[IT-Security · DevOps · Datenbanken · Java. ☰. Entwicklung/Architektur · Betrieb ... Für Security- und Application-Security-Teams ist es zusätzlich ...]]></description>
<link>https://tsecurity.de/de/3604631/it-security-nachrichten/root-cause-in-unter-einer-minute-wie-ki-gestuetzte-observability-fragmentierte-cloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604631/it-security-nachrichten/root-cause-in-unter-einer-minute-wie-ki-gestuetzte-observability-fragmentierte-cloud/</guid>
<pubDate>Wed, 17 Jun 2026 13:39:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>IT</b>-<b>Security</b> · DevOps · Datenbanken · Java. ☰. Entwicklung/Architektur · Betrieb ... Für Security- und Application-Security-Teams ist es zusätzlich ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Z.ai pitches GLM-5.2 for long-running software engineering tasks]]></title>
<description><![CDATA[Z.ai has released GLM-5.2, an MIT-licensed open-source AI model designed for long-running software engineering tasks, as the Chinese company seeks to challenge proprietary coding models on cost and performance.



The company said GLM-5.2 ranked just behind Anthropic’s Claude Opus 4.8 on Frontier...]]></description>
<link>https://tsecurity.de/de/3604475/it-nachrichten/zai-pitches-glm-52-for-long-running-software-engineering-tasks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604475/it-nachrichten/zai-pitches-glm-52-for-long-running-software-engineering-tasks/</guid>
<pubDate>Wed, 17 Jun 2026 12:47:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Z.ai has released GLM-5.2, an MIT-licensed open-source AI model designed for long-running software engineering tasks, as the Chinese company seeks to challenge proprietary coding models on cost and performance.</p>



<p>The company said GLM-5.2 ranked just behind Anthropic’s Claude Opus 4.8 on FrontierSWE, a long-horizon coding benchmark, trailing it by 1%. Z.ai said the model also edged out OpenAI’s GPT-5.5 by 1%.</p>



<p>Z.ai said GLM-5.2 supports a one-million-token context window with up to 131,072 output tokens, positioning it for agentic coding workflows that require reasoning across large codebases.</p>



<p>The company is also making an efficiency argument. It said GLM-5.2 uses a technique called IndexShare, which reduces per-token compute by 2.9 times at a one-million-token context length. It also said changes to the model’s multi-token prediction layer increased the acceptance length for speculative decoding by up to 20%.</p>



<p>The changes are aimed at a practical problem for developers: long-context coding agents can be expensive to run when they are asked to work across large repositories.</p>



<h2 class="wp-block-heading">Enterprise appeal</h2>



<p>GLM-5.2’s clearest appeal is that it pairs stronger coding capabilities with the cost advantages of an open-source model. But capability alone will not be enough to make it a credible alternative.</p>



<p>“Western enterprises will want independent benchmark validation, successful deployments at global enterprises, strong security and governance controls, and long-term support commitments,” said <a href="https://pareekh.com/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, CEO of Pareekh Consulting.</p>



<p>Jain said the fastest route to enterprise credibility would be hosting by a major cloud provider like AWS. That would allow customers to use the model under standard enterprise terms, with service-level commitments and compliance certifications.</p>



<p><a href="https://www.linkedin.com/in/tulikasheel/" target="_blank" rel="noreferrer noopener">Tulika Sheel</a>, senior VP at Kadence International, said GLM-5.2 would also need to prove it can operate as a stable enterprise product.</p>



<p>“Demonstrated success in real-world deployments and transparent governance will be just as important as benchmark scores,” Sheel said.</p>



<p>The performance and cost claims will also need to hold up against established models.</p>



<p>“Enterprise leaders generally consider two major factors when evaluating new models,” said <a href="https://omdia.tech.informa.com/authors/lian-jye-su" target="_blank" rel="noreferrer noopener">Lian Jye Su</a>, chief analyst at Omdia. “First, they look at overall performance against competitors, where GLM-5.2 performs well in long-horizon agentic coding and software engineering. Second, they look at the cost of adoption. As an open-source model, GLM-5.2 has clear cost advantages.”</p>



<p>Su said the model could appeal to engineering teams under pressure to control AI costs. It may also attract open-source advocates and companies with significant operations in the Asia-Pacific.</p>



<p>But the claims still need wider validation, particularly around hallucination control and coherence during extended tasks. These are critical issues for enterprises considering AI coding agents, which may need to work across large codebases and multi-step software engineering workflows.</p>



<p>Jain said the one-million-token context window could be useful for large codebase analysis. It could also help with legacy modernization projects and complex engineering documentation.</p>



<p>He said long-context capability may also help with audit logs or legal contracts, where splitting material into smaller chunks can create errors across document boundaries. But for everyday coding tasks, effective retrieval systems may matter more than very large context windows, making some of the benefits more limited in practice.</p>



<h2 class="wp-block-heading">Governance risks</h2>



<p>The governance question depends largely on where the model runs.</p>



<p>Sheel said enterprises should evaluate GLM-5.2 as they would any strategic technology partner, rather than as a standalone model. That means looking at where data is stored and whether the model can be used in environments that customers control.</p>



<p>That deployment choice is central to the risk calculation, according to Jain. Because GLM-5.2 is available under an MIT license, companies can download the weights and run them on their own infrastructure, reducing the need to send sensitive data to Z.ai.</p>



<p>“The risk flips completely if you use Z.ai’s hosted API instead,” Jain said.</p>



<p>He said Chinese national security rules could require domestic companies to cooperate with government requests, making hosted use difficult for regulated industries or workloads involving sensitive data.</p>



<p>Su said the issue is not limited to Chinese vendors. Recent restrictions affecting access to some <a href="https://www.computerworld.com/article/4185515/anthropics-new-privacy-policy-offers-us-consumers-a-way-around-fable-ban-2.html">Anthropic models</a> have also highlighted the risk that enterprises may have limited control over the availability of AI services from foreign providers.</p>



<p>“Selecting solutions from American and Chinese AI vendors does expose non-US Western enterprises to additional risk of having zero control over the availability and uptime of these models,” Su said.</p>



<p><em>The article originally appeared on <a href="https://www.infoworld.com/article/4186136/z-ai-pitches-glm-5-2-for-long-running-software-engineering-tasks.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Z.ai pitches GLM-5.2 for long-running software engineering tasks]]></title>
<description><![CDATA[Z.ai has released GLM-5.2, an MIT-licensed open-source AI model designed for long-running software engineering tasks, as the Chinese company seeks to challenge proprietary coding models on cost and performance.



The company said GLM-5.2 ranked just behind Anthropic’s Claude Opus 4.8 on Frontier...]]></description>
<link>https://tsecurity.de/de/3604424/ai-nachrichten/zai-pitches-glm-52-for-long-running-software-engineering-tasks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604424/ai-nachrichten/zai-pitches-glm-52-for-long-running-software-engineering-tasks/</guid>
<pubDate>Wed, 17 Jun 2026 12:33:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Z.ai has released GLM-5.2, an MIT-licensed open-source AI model designed for long-running software engineering tasks, as the Chinese company seeks to challenge proprietary coding models on cost and performance.</p>



<p>The company said GLM-5.2 ranked just behind Anthropic’s Claude Opus 4.8 on FrontierSWE, a long-horizon coding benchmark, trailing it by 1%. Z.ai said the model also edged out OpenAI’s GPT-5.5 by 1%.</p>



<p>Z.ai said GLM-5.2 supports a one million-token context window with up to 131,072 output tokens, positioning it for agentic coding workflows that require reasoning across large codebases.</p>



<p>The company is also making an efficiency argument. It said GLM-5.2 uses a technique called IndexShare, which reduces per-token compute by 2.9 times at a one million-token context length. It also said changes to the model’s multi-token prediction layer increased the acceptance length for speculative decoding by up to 20%.</p>



<p>The changes are aimed at a practical problem for developers: long-context coding agents can be expensive to run when they are asked to work across large repositories.</p>



<h2 class="wp-block-heading">Enterprise appeal</h2>



<p>GLM-5.2’s clearest appeal is that it pairs stronger coding capabilities with the cost advantages of an open-source model. But capability alone will not be enough to make it a credible alternative.</p>



<p>“Western enterprises will want independent benchmark validation, successful deployments at global enterprises, strong security and governance controls, and long-term support commitments,” said <a href="https://pareekh.com/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, CEO of Pareekh Consulting.</p>



<p>Jain said the fastest route to enterprise credibility would be hosting by a major cloud provider like AWS. That would allow customers to use the model under standard enterprise terms, with service-level commitments and compliance certifications.</p>



<p><a href="https://www.linkedin.com/in/tulikasheel/" target="_blank" rel="noreferrer noopener">Tulika Sheel</a>, senior VP at Kadence International, said GLM-5.2 would also need to prove it can operate as a stable enterprise product.</p>



<p>“Demonstrated success in real-world deployments and transparent governance will be just as important as benchmark scores,” Sheel said.</p>



<p>The performance and cost claims will also need to hold up against established models.</p>



<p>“Enterprise leaders generally consider two major factors when evaluating new models,” said <a href="https://omdia.tech.informa.com/authors/lian-jye-su" target="_blank" rel="noreferrer noopener">Lian Jye Su</a>, chief analyst at Omdia. “First, they look at overall performance against competitors, where GLM-5.2 performs well in long-horizon agentic coding and software engineering. Second, they look at the cost of adoption. As an open-source model, GLM-5.2 has clear cost advantages.”</p>



<p>Su said the model could appeal to engineering teams under pressure to control AI costs. It may also attract open-source advocates and companies with significant operations in Asia-Pacific.</p>



<p>But the claims still need wider validation, particularly around hallucination control and coherence during extended tasks. These are critical issues for enterprises considering AI coding agents, which may need to work across large codebases and multi-step software engineering workflows.</p>



<p>Jain said the one million-token context window could be useful for large codebase analysis. It could also help with legacy modernization projects and complex engineering documentation.</p>



<p>He said long-context capability may also help with audit logs or legal contracts, where splitting material into smaller chunks can create errors across document boundaries. But for everyday coding tasks, effective retrieval systems may matter more than very large context windows, making some of the benefits more limited in practice.</p>



<h2 class="wp-block-heading">Governance risks</h2>



<p>The governance question depends largely on where the model runs.</p>



<p>Sheel said enterprises should evaluate GLM-5.2 as they would any strategic technology partner, rather than as a standalone model. That means looking at where data is stored and whether the model can be used in environments customers control.</p>



<p>That deployment choice is central to the risk calculation, according to Jain. Because GLM-5.2 is available under an MIT license, companies can download the weights and run them on their own infrastructure, reducing the need to send sensitive data to Z.ai.</p>



<p>“The risk flips completely if you use Z.ai’s hosted API instead,” Jain said.</p>



<p>He said Chinese national security rules could require domestic companies to cooperate with government requests, making hosted use difficult for regulated industries or workloads involving sensitive data.</p>



<p>Su said the issue is not limited to Chinese vendors. Recent restrictions affecting access to some <a href="https://www.computerworld.com/article/4185515/anthropics-new-privacy-policy-offers-us-consumers-a-way-around-fable-ban-2.html">Anthropic models</a> have also highlighted the risk that enterprises may have limited control over the availability of AI services from foreign providers.</p>



<p>“Selecting solutions from American and Chinese AI vendors does expose non-US Western enterprises to additional risk of having zero control over the availability and uptime of these models,” Su said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[(g+) Tech Asia: Japan seeks bigger role in Asia's subsea cables as AI rewires demand]]></title>
<description><![CDATA[Traders including Sumitomo, leasing firms and telecom newcomers enter critical sector (Wirtschaft, Softbank)]]></description>
<link>https://tsecurity.de/de/3604413/it-nachrichten/g-tech-asia-japan-seeks-bigger-role-in-asias-subsea-cables-as-ai-rewires-demand/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604413/it-nachrichten/g-tech-asia-japan-seeks-bigger-role-in-asias-subsea-cables-as-ai-rewires-demand/</guid>
<pubDate>Wed, 17 Jun 2026 12:32:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Traders including Sumitomo, leasing firms and telecom newcomers enter critical sector (<a href="https://www.golem.de/specials/wirtschaft/">Wirtschaft</a>, <a href="https://www.golem.de/specials/softbank/">Softbank</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=209869&amp;page=1&amp;ts=1781691906" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-4096 | IBM DevOps Plan up to 3.0.6 HTTP Header http headers for scripting syntax]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in IBM DevOps Plan up to 3.0.6. Affected by this vulnerability is an unknown functionality of the component HTTP Header Handler. The manipulation results in improper neutralization of http headers for scripting syntax.

This vulnerabilit...]]></description>
<link>https://tsecurity.de/de/3603810/sicherheitsluecken/cve-2026-4096-ibm-devops-plan-up-to-306-http-header-http-headers-for-scripting-syntax/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603810/sicherheitsluecken/cve-2026-4096-ibm-devops-plan-up-to-306-http-header-http-headers-for-scripting-syntax/</guid>
<pubDate>Wed, 17 Jun 2026 08:48:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/ibm:devops_plan">IBM DevOps Plan up to 3.0.6</a>. Affected by this vulnerability is an unknown functionality of the component <em>HTTP Header Handler</em>. The manipulation results in improper neutralization of http headers for scripting syntax.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-4096">CVE-2026-4096</a>. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[D.O.J. Seeks to Halt Pollution Lawsuit Against Elon Musk’s Data Center]]></title>
<description><![CDATA[The department cited national security concerns, saying Elon Musk’s company had played a crucial role in the Iran war. It also argued it has the authority to stop environmental lawsuits brought by citizens.]]></description>
<link>https://tsecurity.de/de/3602740/it-nachrichten/doj-seeks-to-halt-pollution-lawsuit-against-elon-musks-data-center/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602740/it-nachrichten/doj-seeks-to-halt-pollution-lawsuit-against-elon-musks-data-center/</guid>
<pubDate>Tue, 16 Jun 2026 19:32:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The department cited national security concerns, saying Elon Musk’s company had played a crucial role in the Iran war. It also argued it has the authority to stop environmental lawsuits brought by citizens.]]></content:encoded>
</item>
<item>
<title><![CDATA[Platform Engineering 2.0: The Evolution the AI Era Demands]]></title>
<description><![CDATA[A Brief Origin Platform engineering didn’t emerge from a whiteboard — it emerged from pain. The DevOps era gave us shared ownership and the cultural conviction that “you build it, you run it”. Platform Engineering 1.0 systematized that foundation into golden paths, self-service  Internal Developm...]]></description>
<link>https://tsecurity.de/de/3602699/downloads/platform-engineering-20-the-evolution-the-ai-era-demands/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602699/downloads/platform-engineering-20-the-evolution-the-ai-era-demands/</guid>
<pubDate>Tue, 16 Jun 2026 19:16:53 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img width="300" height="157" src="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/06/Platform-Engineering-2.0.png?w=300" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" srcset="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/06/Platform-Engineering-2.0.png 1200w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/06/Platform-Engineering-2.0.png?resize=300,157 300w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/06/Platform-Engineering-2.0.png?resize=768,402 768w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/06/Platform-Engineering-2.0.png?resize=1024,536 1024w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/06/Platform-Engineering-2.0.png?resize=600,314 600w" sizes="(max-width: 300px) 100vw, 300px"></div>
<p>A Brief Origin Platform engineering didn’t emerge from a whiteboard — it emerged from pain. The DevOps era gave us shared ownership and the cultural conviction that “you build it, you run it”. Platform Engineering 1.0 systematized that foundation into golden paths, self-service  Internal Development Platforms (IDPs), and platform-as-product thinking. Today, 90% of organizations have … <a href="https://blogs.vmware.com/cloud-foundation/2026/06/16/platform-engineering-2-0-the-evolution-the-ai-era-demands/">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/cloud-foundation/2026/06/16/platform-engineering-2-0-the-evolution-the-ai-era-demands/">Platform Engineering 2.0: The Evolution the AI Era Demands</a> appeared first on <a href="https://blogs.vmware.com/cloud-foundation">VMware Cloud Foundation (VCF) Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Databricks pitches LTAP as a new foundation for agentic applications]]></title>
<description><![CDATA[As enterprises rush to build AI agents that can reason over business data and take action, Databricks argues that the long-standing practice of separating operational and analytical data systems is turning into a liability.



That separation, the cloud-based data warehouse provider says, is beco...]]></description>
<link>https://tsecurity.de/de/3601890/ai-nachrichten/databricks-pitches-ltap-as-a-new-foundation-for-agentic-applications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601890/ai-nachrichten/databricks-pitches-ltap-as-a-new-foundation-for-agentic-applications/</guid>
<pubDate>Tue, 16 Jun 2026 15:04:15 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As enterprises rush to build AI agents that can reason over business data and take action, Databricks argues that the long-standing practice of separating operational and analytical data systems is turning into a liability.</p>



<p>That separation, the cloud-based data warehouse provider says, is becoming increasingly strained as AI agents require simultaneous access to live operational data and historical context to make decisions and take actions in real time, unlike humans, who traditionally can work with data that is minutes or hours old.</p>



<p>At its annual Data + AI Summit, the data warehouse provider introduced Lake Transactional and Analytical Processing (LTAP), a new architecture designed to unify transactional and analytical data on a single storage layer.</p>



<p>The new approach, according to Databricks, differs from traditional <a href="https://www.infoworld.com/article/2334535/what-is-oltp-the-backbone-of-ecommerce.html">online transaction processing (OLTP)</a> and <a href="https://www.infoworld.com/article/2334471/what-is-olap-analytical-databases.html">online analytical processing (OLAP)</a> architectures, which typically store operational and analytical data in separate systems.</p>



<p>Traditionally, OLTP databases are optimized for running day-to-day business operations such as order processing, payments, and inventory updates, while OLAP systems are designed for large-scale analytical queries and reporting.</p>



<p>As a result, enterprises often need to rely on <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">ETL pipelines</a>, data replication, and separate infrastructure to move information between the two environments.</p>



<p>LTAP, Databricks said, seeks to eliminate the reliance on ETL pipelines, replicated databases or separate data copies by storing data once in a shared <a href="https://www.infoworld.com/article/2334907/review-databricks-lakehouse-platform.html">lakehouse</a> layer while allowing dedicated compute engines to handle transactional and analytical workloads independently.</p>



<p>This approach, the company argued, provides AI-driven agents and applications access to both live operational data and historical analytical context without requiring data movement or duplicate copies.</p>



<h2 class="wp-block-heading">Developer simplicity in the agentic era</h2>



<p>Analysts, too, agree with Databricks’ contention that AI agents place new demands on enterprise data architectures.</p>



<p>“Agents don’t behave like people, or even like the apps we built for people. They read for context, loop, try things, then write something back, thousands of times over in ways you can’t fully predict. At that volume, the constant bouncing between production and analytics systems starts becoming the bottleneck. The pressure to collapse that gap is real, and LTAP is one way to approach it,” said <a href="https://moorinsightsstrategy.com/team/mike-leone/" target="_blank" rel="noreferrer noopener">Michael Leone</a>, principal analyst at Moor Insights and Strategy.</p>



<p><a href="https://www.linkedin.com/in/bhupendrachopra/" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, cofounder and CRO at IT consulting firm Kanerika, pointed out that an autonomous agent’s data access pattern makes the traditional architectures brittle: “We’re seeing this directly with clients deploying multi-agent systems, the pipeline layer becomes the ceiling almost immediately as an agent runs hundreds of times per task.”</p>



<p>The analysts also pointed out that the ability to collapse the gap between OLAP and OLTP is likely to help developers design more robust AI agents or applications that enterprises are currently targeting to deploy.</p>



<p>“The most interesting workflow or application patterns are real-time, context-aware applications that combine transactions, analytics, and AI in one flow,” said <a href="https://www.linkedin.com/in/slwalter/" target="_blank" rel="noreferrer noopener">Stephanie Walter</a>, practice leader of AI stack at HyperFRAME Research.</p>



<p>“Examples include AI agents that update customer workflows while seeing historical account context and fraud systems that act on live transactions and long-term behavioral patterns,” Walter added.</p>



<p>Designing such applications today, however, according to Leone, would require developers to pull together data from transactional systems, data warehouses, vector databases, and other sources through custom integrations, creating significant engineering complexity and maintenance overhead.</p>



<h2 class="wp-block-heading">Operational simplicity and governance gains for CIOs</h2>



<p>For CIOs,  LTAP’s ability to reduce that engineering complexity, according to <a href="https://www.hfsresearch.com/team/ashish-chaturvedi/" target="_blank" rel="noreferrer noopener">Ashish Chaturvedi</a>, leader of executive research at HFS Research, will result in operational simplicity as well as cost savings.</p>



<p>“Most prominent advantage would be fewer data pipelines and everything that cascades from eliminating them. Most enterprises don’t realize how much of their data engineering budget is pure plumbing maintenance,” Chaturvedi said.</p>



<p>Kanerika’s Chopra pointed out that a substantial portion of data engineering capacity in mid-to-large enterprises today is consumed by maintaining synchronization between transactional and analytical systems.</p>



<p>The implications, however, Chaturvedi noted, are not limited to developer productivity, architectural simplicity, or cost savings: “The strategic prize is simplified governance. When you have one copy of data under one governance model instead of the same data scattered across operational stores, replicas, warehouses, and vector databases, you’ve solved the governance fragmentation problem.”</p>



<p>That simplification, according to Chopra, will matter operationally for enterprises deploying multiple AI agents, as these workflows can amplify governance gaps at a speed and scale that no human workflow ever did.</p>



<h2 class="wp-block-heading">LTAP versus HTAP</h2>



<p>Despite all its benefits, though, LTAP isn’t the first effort to unify operational and analytical workloads under a single architecture and for years.</p>



<p>The industry has pursued a similar goal through <a href="https://www.infoworld.com/article/2260125/how-in-memory-computing-drives-digital-transformation-with-htap.html">Hybrid Transactional and Analytical Processing (HTAP)</a> architecture, which sought to combine operational and analytical workloads on tightly coupled infrastructure to serve both workload types from the same system.</p>



<p>LTAP, in contrast, separates storage from compute, allowing different engines to access a common data layer while remaining independently scalable, Databricks said.</p>



<p>That separation of compute engines is why analysts think that LTAP might be a better bet than HTAP.</p>



<p>“HTAP never took off because asking one tightly bound system to be great at transactions and great at analytics usually left it mediocre at both, so customers ended up paying a premium for that compromise,” Leone said.</p>



<p>“I think separating storage from compute is the right instinct, and it’s the same move that made the modern cloud data world work in the first place. It matters because the thing that sank HTAP was one workload starving the other, and giving each side its own dedicated engine is exactly how you keep that from happening,” Leone added.</p>



<p>Another reason for HTAP’s failure, according to <a href="https://isg-one.com/about-us/people/david-menninger">David Menninger</a>, executive director of software research at ISG, was its requirement for enterprises to replace existing data platforms with a new architecture.</p>



<p>LTAP, by contrast, builds on the now-common practice of separating compute and storage, making the addition of an operational layer less of an architectural transformation and potentially lowering the barrier to adoption, Menninger added.</p>



<h2 class="wp-block-heading">Not yet the default architecture for AI agents</h2>



<p>However, despite the enthusiasm around LTAP, analysts warned CIOs against viewing this as the inevitable successor to existing data architectures.</p>



<p>“CIOs will still need to choose their data architecture based on latency, reliability, ecosystem fit, cost, compliance, and developer experience,” Walter said.</p>



<p>Echoing Walter, Chaturvedi pointed out that for LTAP to become the de facto standard for the industry, Databricks will need more than architectural elegance: “The architecture looks sound on paper. The proof will be in the commit-to-query latency numbers under real load.”</p>



<p>LTAP, Databricks said, is expected to be released soon as part of <a href="https://www.infoworld.com/article/4007541/databricks-data-ai-summit-2025-five-takeaways-for-data-professionals-developers.html">Lakebase,</a> without providing any specific timelines.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Verizon Shine Loyalty Program Seeks to Reward Longtime Subscribers]]></title>
<description><![CDATA[Verizon is working to keep customers with weekly perks and some big giveaways.]]></description>
<link>https://tsecurity.de/de/3601643/it-nachrichten/new-verizon-shine-loyalty-program-seeks-to-reward-longtime-subscribers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601643/it-nachrichten/new-verizon-shine-loyalty-program-seeks-to-reward-longtime-subscribers/</guid>
<pubDate>Tue, 16 Jun 2026 13:33:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Verizon is working to keep customers with weekly perks and some big giveaways.]]></content:encoded>
</item>
<item>
<title><![CDATA[Zero trust isn’t broken. Most companies just do it wrong.]]></title>
<description><![CDATA[Zero trust is 15 years old, and like many teenagers, it can feel misunderstood and underappreciated.



The concept of zero trust was first defined by John Kindervag, a Forrester analyst at the time, as a strategy to replace the outmoded perimeter security model with a “never trust, always verify...]]></description>
<link>https://tsecurity.de/de/3601184/it-security-nachrichten/zero-trust-isnt-broken-most-companies-just-do-it-wrong/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601184/it-security-nachrichten/zero-trust-isnt-broken-most-companies-just-do-it-wrong/</guid>
<pubDate>Tue, 16 Jun 2026 11:08:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Zero trust is 15 years old, and like many teenagers, it can feel misunderstood and underappreciated.</p>



<p>The concept of zero trust was first defined by <a href="https://www.linkedin.com/in/john-kindervag-40572b1/">John Kindervag</a>, a Forrester analyst at the time, as a strategy to replace the outmoded perimeter security model with a “never trust, always verify” approach. But going from principle to practice isn’t easy.</p>



<p><a href="https://www.accenture.com/content/dam/accenture/final/accenture-com/document-3/State-of-Cybersecurity-report.pdf#zoom=40" target="_blank" rel="noreferrer noopener">Accenture</a> reports that 88% of organizations have encountered significant challenges implementing zero trust. In a recent <a href="https://www.gartner.com/en/newsroom/press-releases/2024-04-22-gartner-survey-reveals-63-percent-of-organizations-worldwide-have-implemented-a-zero-trust-strategy" target="_blank" rel="noreferrer noopener">Gartner</a> survey, 35% of respondents who indicated that they either attempted or partially attempted a zero-trust initiative suffered failures that adversely affected their organization. “Gartner has observed numerous instances of failed zero-trust initiatives among end users who lacked a strategic and measurable plan,” the report says.</p>



<p>At last year’s DefCon 33 conference, U.K. security researchers from AmberWolf <a href="https://www.networkworld.com/article/4039042/def-con-research-takes-aim-at-ztna-calls-it-a-bust.html" target="_blank">poked holes in zero trust</a> by identifying potential vulnerabilities in zero-trust network access (ZTNA) offerings from three vendors. “It turns out there are no magic ZTNA beans; we’ve got the same old bug classes reimagined for a new technology stack,” said AmberWolf researcher Richard Warren. “Rather than zero trust, we’re actually putting a lot of trust into these vendors to process our data securely.”  </p>



<p><a href="https://www.linkedin.com/in/mjhaber/">Morey Haber</a>, author and chief security advisor at BeyondTrust, sums up the state of zero trust in 2026 this way: “We all agree: zero trust is necessary. But it’s been hard to implement.” Haber describes the gap between intention and execution as “massive” during a <a href="https://www.computerworld.com/video/4084071/is-zero-trust-failing-or-just-misunderstood.html" target="_blank">Today in Tech episode</a> focused on whether zero trust is failing or just misunderstood. “It doesn’t matter what you read or which framework you follow,” Haber said during the podcast. “The core issue is that we have a concept with principles and tenets, but not enough guidance on how to implement it.”</p>



<p>Here are some myths and misconceptions associated with zero trust, as well as tips on how to avoid the pitfalls and successfully implement zero trust.</p>



<h2 class="wp-block-heading">Myth: Zero trust is a product</h2>



<p>Even after 15 years, there is still considerable confusion about what zero trust is. It answers to many definitions—strategy, philosophy, concept, mindset, and architecture.</p>



<p>Chase Cunningham<em>, </em>who bills himself as <a href="https://www.drzerotrust.com/" target="_blank" rel="noreferrer noopener">DrZeroTrust</a>, says,”Security is not a product, but a combination of strategy, process, and execution. Zero trust is not just an architecture—it’s a mindset. There is no zero-trust product, period.”</p>



<p>Haber agrees. “You have vendors claiming to sell “zero-trust” products, which is misleading. There’s no such thing as a zero-trust product. Products implement security controls, but they don’t embody zero-trust principles.”</p>



<p>He cautions, “If a vendor says, ‘This remote access solution achieves zero-trust principles,’ that’s great, but I have yet to see one that delivers more than 10%-15% of the required controls.”</p>



<p>Gartner adds, “The concept of zero trust is a security approach that organizations adopt to mitigate access risks associated with networks, applications, and associated data. This is frequently overshadowed by vendor marketing, which tends to promise high expectations but often delivers suboptimal results.”</p>



<h2 class="wp-block-heading">Myth: Zero trust is a technology</h2>



<p><a href="https://www.utsystem.edu/offices/information-security/chief-information-security-officer" target="_blank" rel="noreferrer noopener">George Finney</a>, CISO at the University of Texas and author of two books on zero trust, tells <em>Network World</em> that zero trust is not a technology; in other words, it’s not micro-segmentation to block lateral movement by attackers; it’s not policy-based identity to control who gets access to enterprise resources. Those are tools and tactics that help implement zero trust.</p>



<p>Zero trust at its core is a way of thinking about risk that requires breaking down silos among security teams, networking groups, business units, compliance, and risk management functions, according to Finney.</p>



<p>The first pillar of zero trust, as defined by Kindervag, is identifying the highest-priority protect surfaces in the organization. Kindervag says that unless the organization has a clear understanding of what the crown jewels are, there’s no way a zero-trust project can be successful. Kindevag adds that IT doesn’t necessarily know what those high-value protect surfaces are, but business leaders do, and that’s where a zero-trust initiative should start.</p>



<p>The second pillar of zero trust is to map transaction flows associated with those mission-critical protect surfaces. Again, this requires coordination and collaboration with teams running key enterprise applications. This is particularly important in today’s multi-cloud environments, where a specific business process can span on-prem, edge, cloud, containers, microservices, etc.</p>



<p>“It’s not a technology issue at the end of the day that makes it hard,” Finney says. It’s people issues, cultural issues, and politics. He recommends that organizations think holistically about securing sensitive data across all attack surfaces, including endpoints, remote users, IoT devices, LLMs, AI agents, etc.</p>



<p>Gartner adds, “It is not a product or technology-focused exercise but rather a methodology driven by the organization’s overall objective and priorities.”</p>



<h2 class="wp-block-heading">Myth: Zero trust is expensive  </h2>



<p>Finney says zero trust does not have to break the bank. “A lot of folks think it’s going to be too expensive, but it doesn’t have to be,” he adds. Here are key steps on the road to zero trust that don’t involve buying anything<strong>.</strong></p>



<p><strong>Identifying high-value protect surfaces. </strong>This requires thinking like an attacker and pinpointing the assets that an attacker is most likely to consider valuable. Finney adds, “In a given protect surface, you might have multiple controls that all have to be working together to remove those trust relationships.”  </p>



<p><strong>Creating a zero-trust team</strong>. Finney says most organizations already have governance, risk management, and compliance teams that can be brought into a comprehensive zero-trust task force that includes security and networking groups. Gartner adds, “A zero-trust strategy must be initiated at the executive level and integrated across all departments and teams.”</p>



<p><strong>Education. </strong>Education is critical, says Finney. “It’s helping folks see the big picture. It gets people out of their silos.”Finney adds that a major challenge is political, having to deal with a fragmented organization in which many stakeholders are dismissive of security because it’s not what they’re measured on. For example, application developers who are under the gun to get software out the door aren’t necessarily incentivized to bake security into their processes. <strong> </strong></p>



<p><strong>Creating a strategy. </strong>“When I talk to boards of directors, they understand that to be successful in any part of the business, you need to have a strategy. That resonates from the top,” says Finney. <strong></strong></p>



<p>In its analysis of why zero-trust initiatives fail, Gartner says, “The lack of a business-aligned strategic plan has led to ineffective governance, miscommunication, poor risk management, minimal budget allocation, poor execution of the organizational security objectives, and inefficient use of limited resources.”</p>



<p><strong>Defining an architecture: </strong>Every organization is different, so there is no boilerplate architecture that can be applied everywhere. Organizations need to write a specific architecture that fits their business needs, their level of risk tolerance, their specific vertical industry, and their unique technology infrastructure.</p>



<p><strong>Setting and applying policies. </strong>Again, there is no line item associated with writing access control and identity management policies.  </p>



<p><strong>Leveraging existing tools.</strong> It’s important to realize that nobody is starting from zero.</p>



<p>Most organizations already have multi-factor authentication or single sign-on in place, they already have identity management, network management, web application firewalls, etc. The key is to integrate and align existing technology and identify gaps where new tools might be needed.</p>



<p>Speaking to AmberWolf’s point that attackers can always find bugs in vendor software, zero-trust advocates counter that zero trust implies defense in depth. So, even if there’s a flaw that allows an attacker to gain end-user credentials and access the network, there will be multiple security controls in place, such as incident detection, micro-segmentation, monitoring of end-user sessions, and controls that prevent access to and exfiltration of sensitive data.</p>



<h2 class="wp-block-heading">Myth: Zero trust is difficult to implement</h2>



<p>Zero trust doesn’t have to be hard to implement if organizations follow widely disseminated guidance provided by <a href="https://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.SP.800-207.pdf" target="_blank" rel="noreferrer noopener">NIST</a>, numerous books, webinars, podcasts, experts, consultants, and more.</p>



<p>Finney recommends starting small and showing quick wins. Zero trust can’t be implemented all at once across a large organization; it requires a targeted, methodical strategy.</p>



<p>The preferred approach is to start with those high-value protect surfaces and apply tools that support the overall architecture in a coordinated, consistent, managed, and monitored fashion.  </p>



<p>“An overall strategy can deploy different tactics,” Finney says. “You want to think about what will have the biggest impact on your organization today.” He says organizations need to make informed data-driven decisions based on logs, metrics, and other data, while factoring in an analysis of what attackers are doing vs. the specific vulnerabilities and weak points in the organization’s defenses.</p>



<p>Gartner states: “Narrowing the scope of initiatives or projects within the zero-trust program is essential for attaining a zero-trust posture within practical and reasonable timeframes. Organizations define overly expansive future target states by incorporating an excessive number of systems, applications, use cases, or datasets in the initial phase—or by proposing overly intricate and granular policy sets. They will encounter scalability and cost challenges, along with extended project timelines.”</p>



<h2 class="wp-block-heading">Myth: AI breaks ZTNA</h2>



<p>Enterprises are racing to deploy generative AI and unleash semi-autonomous AI agents. This new world of black box large language models (LLM) and non-human identities (NHI) raises concerns that zero trust is an outdated strategy that’s not up to the challenge.</p>



<p>Leading zero-trust proponents are pushing back, however, arguing that the core principles still apply. “With AI, zero trust is more important than ever,” says Finney. “Zero trust is a strategy; we don’t change the strategy because AI came out. AI proves how important that strategy is.”</p>



<p>“AI is not magic,” he adds. “We secure it the same way we secure everything else. We integrate it into the tech stack and monitor it.”</p>



<p>Kindervag, currently chief evangelist at Illumio, concurs. “AI doesn’t change the fundamentals of zero trust. It reinforces them. Zero trust is the strategy that allows you to safely embrace AI. Without strict segmentation, policy enforcement, and control over data flows, AI becomes another soft and chewy center waiting to be exploited.” He adds, “You don’t need a new security strategy for AI. You just need to apply the right one. That’s zero trust.”</p>



<h2 class="wp-block-heading">Myth: There’s no way to measure success</h2>



<p>Any project that seeks support from the board and C-suite, needs to be able to justify itself through some sort of metrics. Zero trust is no exception, but how do you measure “not getting hacked?”</p>



<p>Gartner says teams should use outcome-driven metrics that link zero-trust initiatives directly to business objectives.“It’s crucial to focus on schedule adherence, cost discipline, and control effectiveness,” says Gartner. “Focus on outcomes like reduced breach incidents, improved compliance rates, and enhanced operational efficiency. Additionally, identify specific risks, such as lateral movement, data breaches, account takeovers, and insider threats, which are essential to drive value, and organizations can better justify investments and drive continuous improvement.”</p>



<h2 class="wp-block-heading">Myth: Zero-trust projects have a completion date</h2>



<p>Zero trust is more about the journey than the destination,” Finney says. He points out that organizations are constantly growing and changing. At the same time, attackers are evolving. “Zero trust is a strategy. You’re never done with a strategy,” he adds.</p>



<p>Kindervag’s final pillar of zero trust is to monitor and maintain. In other words, organizations need to be actively monitoring to make sure that access control policies are not being violated. And the zero-trust implementation needs to keep pace with changing business needs.</p>



<p>And since zero trust calls for organizations to focus on the highest value protect surfaces first, there are always additional protect surfaces that can be added under the zero-trust umbrella.</p>



<p>When Finney looks back on how things have evolved over the past 15 years, he is encouraged by the fact that tools have improved dramatically. Teams can now apply AI and machine learning to functions like anomaly detection or incident detection and response. And there are now ways to automate tasks like networking monitoring or policy enforcement.</p>



<p>“Overall, I’m feeling guardedly optimistic,” Finney says, “but the work is not done. We need to continue to make strides.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Develop smarter AI agents with data fabrics]]></title>
<description><![CDATA[Every organization has data scattered across data warehouses, data lakes, SaaS platforms, cloud drives, and data centers. Data fabrics enable organizations to centralize and control data access, making it easier for users, such as data scientists and citizen data analysts, to find and use trusted...]]></description>
<link>https://tsecurity.de/de/3601177/ai-nachrichten/develop-smarter-ai-agents-with-data-fabrics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601177/ai-nachrichten/develop-smarter-ai-agents-with-data-fabrics/</guid>
<pubDate>Tue, 16 Jun 2026 11:03:45 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Every organization has data scattered across data warehouses, data lakes, SaaS platforms, cloud drives, and data centers. Data fabrics enable organizations to centralize and control data access, making it easier for users, such as data scientists and <a href="https://drive.starcio.com/2026/03/citizen-analytics-ai-era-cios/">citizen data analysts</a>, to find and use trusted and governed data sources. </p>



<p><a href="https://www.infoworld.com/article/2338426/how-to-explain-data-meshes-fabrics-and-clouds.html">Data fabrics, data meshes, and distributed data clouds</a> are all platforms to help IT and data teams put some order to the chaos around the myriad of data sources they support. <a href="https://www.infoworld.com/article/3497094/does-your-organization-need-a-data-fabric.html">Large companies need data fabrics</a> due to the volume and variety of their data sources.</p>



<p>“A data fabric can be thought of as the connective tissue that ensures consistent accessibility, availability, and understanding of data across an organization,” says Dominic Wellington, data and AI expert at <a href="https://www.snaplogic.com/">SnapLogic</a>. “Individual siloed platforms may have their own internal data transfer systems, and particular teams or departments may adopt interchanges that work for that domain, but a data fabric operates at a higher level, ensuring that unified data policies are applied end-to-end across the entire enterprise.”</p>



<h2 class="wp-block-heading">Types of data fabrics</h2>



<p>When reviewing data fabrics, it’s important to consider their primary use cases, supported data types, data processing capabilities, data management structures, and governance functions. Below are some considerations when reviewing data fabrics as features, platforms, and stand-alone products.</p>



<ul class="wp-block-list">
<li>Some data fabrics are optimized for analytics and machine learning use cases and may have limited support for unstructured data.</li>



<li>Other data fabrics extend the functionality of data governance platforms beyond data cataloging and metadata management and now include persistent data management, data quality, and dataops capabilities.</li>



<li>Many data integration and API connectivity platforms go beyond proxying, pipelining, and transforming data to include search, governance, and other capabilities from data centralization.</li>



<li>Some SaaS platforms are extending their connectivity and data integration capabilities, enabling multicloud portability and persistent data.</li>



<li>The more advanced data fabrics support features needed for AI agents and AI model training. These platforms create a semantic context layer for structured and unstructured data sources, support <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) integrations, have real-time query capabilities, centralize policy-driven governance, and track data lineage.    </li>
</ul>



<h2 class="wp-block-heading">Why data fabrics are needed for AI</h2>



<p>Data fabrics are not just for enterprises, and today, even smaller companies need them as part of their <a href="https://www.cio.com/article/4136302/how-to-get-ai-democratization-right.html">AI democratization programs</a>. Here are a few reasons why:</p>



<ul class="wp-block-list">
<li><a href="https://drive.starcio.com/2025/10/ai-agents-definitive-guide-saas-security-titans/">AI agents in enterprise SaaS</a> solutions need access to broader data sets than those core to their workflows. Platforms such as Adobe, Appian, Oracle, Salesforce, ServiceNow, SAP, and Workday offer data fabric capabilities to bring data outside of the business processes they manage into scope for their AI agents.</li>



<li><a href="https://www.infoworld.com/article/4160979/addressing-the-challenges-of-unstructured-data-governance-for-ai.html">Unstructured data</a> is important for setting the context for AI agents, and data fabrics are now used to provide access to documents, emails, transcripts, and other media formats.</li>



<li>Data fabrics provide data access standards for the devops teams experimenting with <a href="https://www.infoworld.com/article/4032989/a-developers-guide-to-code-generation.html">AI code generators</a>, <a href="https://www.infoworld.com/article/4058076/vibe-coding-and-the-future-of-software-development.html">vibe coding</a> tools, and spec-driven development approaches to develop applications and AI agents. </li>



<li>As companies use <a href="https://www.infoworld.com/article/4124612/5-requirements-for-using-mcp-servers-to-connect-ai-agents.html">MCP servers</a> to connect AI agents, data fabrics provide a standardized way for the agents to access governed, trusted data sources.</li>
</ul>



<p>“As AI agents move from generating insights to taking action, the data fabric becomes foundational in the agentic era,” says Irfan Kahn, president and chief product officer of  <a href="https://www.sap.com/index.html">SAP Data &amp; Analytics</a>. “Most enterprises operate across scattered data sources and diverse data landscapes, and what’s needed is shared business context, governed access, and clear accountability for how data is used in decision-making. Without that context, agents can’t fully understand or coordinate across the enterprise to deliver meaningful value.”</p>



<p>Sanjay Koppikar, chief product officer and cofounder of <a href="https://evoluteiq.com/">EvoluteIQ</a>, adds, “Multi-agent architectures become untrustworthy when a unifying data fabric architecture is missing, since agents will often work against each other in the service of their own objectives.”</p>



<h2 class="wp-block-heading">Delivering context to AI agents</h2>



<p>AI agents need a combination of real-time data, user information, problem details, and historical context to guide their decision-making. Vishal Sood, president of research and development  at <a href="https://www.typeface.ai/">Typeface</a>, says, “MCP and data fabrics give agents access, but the harder problem is contextualizing data across multiple sources and ensuring the underlying content, media, and unstructured data are trustworthy.”</p>



<p>Data fabrics are the foundational elements for providing current information and long-term memory to AI agents. They simplify the many-to-many problem of connecting multiple AI models, AI agents, and MCP server integrations to multiple structured and unstructured data sources.</p>



<p>“The data fabric does a beautiful job of encompassing three concepts needed to create applications and processes: the data catalog, the data model, and data access,” says Sanat Joshi, executive vice president of product and innovations at <a href="https://www.appian.com/">Appian</a>. “But now add business rules, process models, APIs, security groups, the organizational model, and their interrelationships into one unified view of the enterprise, and that becomes your context layer.” </p>



<h2 class="wp-block-heading">Integrations with data fabrics</h2>



<p>Devops teams just getting started on an AI agent proof of concept may want to connect directly to the optimal data sources and APIs. Michel Tricot, CEO and cofounder at <a href="https://airbyte.com/">Airbyte</a>, says connecting agents to live APIs is a great start, but it creates two big problems: APIs only return data that an agent already knows to ask for, and every query is an expensive API call chain that, with overhead, can overwhelm infrastructure in production volumes.</p>



<p>Tricot says the data fabric for AI use cases must be dynamic, leveraging discovery of available information from replicated data, fetching live contextual information, and writing the data back to business applications to update records.</p>



<p>Moving data in and out of the data fabric requires an integration strategy. <a href="https://www.datacamp.com/blog/what-is-zero-etl">Zero-ETL</a> (extract, transform, load) is one low-cost, efficient approach for connecting to structured data sourced without replicating information. Once information is accessed centrally, it also enables streamlined security and governance.</p>



<p>“The promise of AI agents breaks down when they’re stuck waiting on brittle ETL, dealing with poor data quality, and lacking the right context to perform analysis,” says Preston Wood, chief security and strategy officer at <a href="https://databahn.ai/">Databahn</a>. “Generating AI-ready data within a data fabric gives agents real-time access to operational data without the latency and drift that undermine decision quality. A well-architected data fabric provides the governance and lineage controls that let you deploy agents confidently, knowing exactly what data they’re touching and why.”</p>



<h2 class="wp-block-heading">Centralizing AI-ready data</h2>



<p>Data fabrics centralize <a href="https://www.infoworld.com/article/4091422/how-to-ensure-your-enterprise-data-is-ai-ready.html">AI-ready data</a> and help data governance teams address <a href="https://www.infoworld.com/article/3667314/3-data-quality-metrics-dataops-should-prioritize.html">data quality</a> issues, <a href="https://www.nature.com/articles/s41597-022-01705-8">biased data</a> concerns, <a href="https://drive.starcio.com/2026/02/data-privacy-week-leadership-accountability/">privacy compliance</a>, and other <a href="https://drive.starcio.com/2024/10/6-important-ai-and-data-governance-non-negotiables/">data governance non-negotiables</a>. Data fabrics also help address integration issues, monitor for <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">data pipeline errors</a>, and report on performance latencies. The result is that AI agents, models, and other analytics capabilities can then connect to trusted data sources with consistency.</p>



<p>“As AI agents and MCP architectures increasingly rely on data fabrics as their golden source of truth, data quality stops being a hygiene problem and becomes a trust problem, as we all know that trust is foundational to autonomous decision-making,” says Kellyn Gorman, database and AI advocate and engineer at <a href="https://www.red-gate.com/">Redgate Software</a>. “Organizations that invest now in semantic consistency, lineage tracking, and observable data contracts across data fabrics will be the ones whose AI agents can be trusted to act without constant human correction.”</p>



<p>Data fabrics that support zero-ETL and other bidirectional integrations with sources thus become an organizational knowledge base, the data source for training AI models, and a foundation for producing data metrics.</p>



<p>“AI agents are only as reliable as the data they’re built on, and most organizations underestimate how much implicit tribal knowledge lives in their transformation logic rather than their source systems,” says Tobias Ostwald, director of analytics at <a href="https://www.nmi.com/">NMI</a>. “If you’re exposing a data fabric to agents or MCP integrations, you need lineage, testing, and metric definitions baked into the layer itself, not just documented somewhere, because the agent can’t call a colleague to gut-check a number.”</p>



<h2 class="wp-block-heading">Streamlining security and governance</h2>



<p>With a data fabric in place, governance, security, and other risk management leaders have a central location to manage data security, centralize access controls, and fulfill other governance responsibilities. Miles Ward, CTO of AI in Solution Lines at <a href="https://www.insight.com/">Insight</a>, says, “We have to move past security by isolation to a governance model where the fabric itself enforces the pavement and walls of compliance.”</p>



<p>The data fabric also governs entitlements for AI agents and their users. Centralizing these business rules can help organizations avoid creating AI debt, a risk if controls are implemented directly in data sources or consumers.</p>



<p>“The convergence of AI-generated code sprawl and autonomous MCP connectivity creates a ‘perfect storm’ of architectural drift and toxic permission combinations,” says Karen Cohen, vice president of product at <a href="https://apiiro.com/">Apiiro</a>. “Effective governance requires a security data fabric that monitors these autonomous connections in real time to enforce intent-based policies and strictly limit agent scope to its specific purpose. By integrating guardrails that align AI-assisted development with secure architecture principles, enterprises can proactively secure their expanding attack surface without sacrificing developer velocity.”</p>



<h2 class="wp-block-heading">Future considerations for data fabrics</h2>



<p>Expect vendors to expand the scope of their data fabrics beyond text and documents. Some will include <a href="https://www.infoworld.com/article/3833936/improving-intelligent-document-processing-with-generative-ai.html">specialized document processing</a> for common formats such as invoices, contracts, and product documentation. There will be skills and tools to support industry-specific documents such as health records and construction documents. Others will support multimedia file types and provide metadata extraction and search capabilities. </p>



<p>“Enterprises are asking agents to reason across contracts, images, PDFs, and video, and this is where most data fabrics break,” says Dave Shuman, chief data officer at <a href="https://www.precisely.com/">Precisely</a>. “Multimodal data must be chunked, embedded, and governed with the same rigor as structured data, including lineage and access controls.”</p>



<p>Several other emerging capabilities include:</p>



<ul class="wp-block-list">
<li>Extended support for AI agent interfaces to aid in data discovery, and with greater contextual controls on where and when AI agents can access sensitive data</li>



<li>Business ontologies, semantic layers, and knowledge graph capabilities, with management tools or integrations with third-party platforms</li>



<li>Support for data contracts, service-level agreements, centralized data observability, auditing, and other functions that will enhance explainable AI capabilities</li>



<li>Finops functions to track costs for data owners and consumers</li>
</ul>



<p>As more companies depend on AI agents in their operations, expect top data fabric platforms to release capabilities to expand scope, scale, use cases, and governance.  </p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cómo lanzar tus proyectos de IA desde piloto a producción… y asegurar el éxito]]></title>
<description><![CDATA[Este artículo te llega gracias a NVIDIA y CIO. Las opiniones expresadas en él son las del autor y no reflejan necesariamente las de NVIDIA.



Los CIO que buscan grandes logros en áreas de alto impacto empresarial donde existe un margen significativo de mejora deberían revisar sus proyectos de ci...]]></description>
<link>https://tsecurity.de/de/3601030/it-security-nachrichten/cmo-lanzar-tus-proyectos-de-ia-desde-piloto-a-produccin-y-asegurar-el-xito/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601030/it-security-nachrichten/cmo-lanzar-tus-proyectos-de-ia-desde-piloto-a-produccin-y-asegurar-el-xito/</guid>
<pubDate>Tue, 16 Jun 2026 10:08:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Este artículo te llega gracias a <a href="https://www.nvidia.com/en-us/data-center/products/ai-enterprise/?ncid=ref-inpa-477277#cid=hpc09_p14_ref-inpa_en-us?utm_source=idg&amp;utm_campaign=nvidia48011&amp;utm_medium=social" data-type="link" data-id="https://www.nvidia.com/en-us/data-center/products/ai-enterprise/?ncid=ref-inpa-477277#cid=hpc09_p14_ref-inpa_en-us?utm_source=idg&amp;utm_campaign=nvidia48011&amp;utm_medium=social" target="_blank" rel="nofollow">NVIDIA</a> y CIO. Las opiniones expresadas en él son las del autor y no reflejan necesariamente las de NVIDIA.</p>



<p>Los CIO que buscan grandes logros en áreas de alto impacto empresarial donde existe un margen significativo de mejora deberían revisar sus proyectos de ciencia de datos, aprendizaje automático (ML) e inteligencia artificial (IA).</p>



<p>Un <a href="https://www.idc.com/getdoc.jsp?containerId=AP47366221" data-type="link" data-id="https://www.idc.com/getdoc.jsp?containerId=AP47366221" target="_blank">informe reciente de IDC</a> sobre proyectos de IA en India[1] señala que entre el 30% y el 49% de los proyectos de IA fracasaron en aproximadamente un tercio de las organizaciones, y <a href="https://www2.deloitte.com/us/en/pages/consulting/articles/state-of-ai-2022.html" data-type="link" data-id="https://www2.deloitte.com/us/en/pages/consulting/articles/state-of-ai-2022.html" target="_blank" rel="nofollow">otro estudio de Deloitte</a> califica el rendimiento organizativo en IA del 50% de los encuestados como inicial o por debajo de lo esperado.</p>



<p>Ese mismo estudio indica que el 94% de los encuestados considera que la IA es crítica para el éxito en los próximos cinco años. Los ejecutivos ven en la IA una oportunidad para diferenciarse competitivamente y buscan líderes capaces de ofrecer resultados exitosos.</p>



<p>El ML y la IA siguen siendo áreas relativamente nuevas, y los líderes deben esperar un aprendizaje continuo y una curva de madurez en evolución. Pero los CIO, CDO y científicos jefe pueden desempeñar un papel activo para mejorar el número de proyectos de IA que pasan de piloto a producción.</p>



<h2 class="wp-block-heading">¿Están los equipos de ciencia de datos preparados para el éxito?</h2>



<p>Un conjunto en desarrollo de buenas prácticas para equipos de ciencia de datos abarca el proceso de desarrollo y las tecnologías necesarias para construir y probar modelos de aprendizaje automático. Desarrollar modelos no es trivial, y los científicos de datos afrontan retos como limpiar y etiquetar datos, seleccionar algoritmos, configurar modelos, preparar la infraestructura y validar los resultados.</p>



<p>Los líderes que deseen mejorar el rendimiento en la entrega de la IA deberían abordar primero esta cuestión: ¿están los científicos de datos preparados para el éxito? ¿Están trabajando en problemas que puedan generar resultados empresariales relevantes? ¿Disponen de plataformas de aprendizaje automático (como NVIDIA AI Enterprise), acceso a la infraestructura y tiempo continuo de formación para mejorar sus prácticas de ciencia de datos?</p>



<h2 class="wp-block-heading">Los CIO y los CDO deben liderar ModelOps y supervisar el ciclo de vida</h2>



<p>Los líderes pueden revisar y abordar problemas si los equipos de ciencia de datos tienen dificultades para desarrollar modelos. Sin embargo, para desplegar modelos y garantizar el éxito, los CIO y los CDO deben establecer un ciclo de vida del modelo, o ModelOps.</p>



<p>El ciclo de vida comienza antes del desarrollo del modelo y requiere formar a los líderes de negocio sobre su papel en la contribución a los proyectos de IA. También exige planificar la infraestructura a escala, implantar cumplimiento normativo y gobernanza, crear una estrategia de seguridad en el edge y colaborar con los equipos implicados para garantizar una transformación exitosa.</p>



<p>Aquí hay varios factores a considerar:</p>



<p>· Educar a los líderes de negocio sobre su papel en los proyectos de ML. ¿Han definido criterios de éxito realistas y áreas de experimentación de bajo riesgo? ¿Participan en los pilotos y aportan <em>feedback</em>? ¿Están preparados para transformar procesos empresariales con capacidades de aprendizaje automático o frenarán las inversiones ante el primer obstáculo?</p>



<p>· Adoptar un enfoque de construir, comprar o asociarse al desarrollar modelos. En algunos casos tiene sentido desarrollar modelos propios, pero también conviene evaluar <em>frameworks</em> como motores de recomendación o SDKs de IA de voz.</p>



<p>· Pensar con antelación en los requisitos de infraestructura en producción. La infraestructura de laboratorio utilizada para desarrollar modelos, así como la escala reducida de un piloto, puede no ser óptima para producción. Por ejemplo, la IA en sanidad, edificios inteligentes o aplicaciones industriales que afectan a la seguridad humana puede requerir soluciones de edge o computación embebida para garantizar fiabilidad y rendimiento.</p>



<p>· Planificar aplicaciones de IA a gran escala en el edge. Cuando existen miles de dispositivos IoT, hay oportunidades para desplegar aplicaciones de IA directamente en ellos. Por ejemplo, flotas de vehículos —como camiones de reparto, maquinaria de construcción o equipos agrícolas— pueden usar aplicaciones de IA desplegadas en el dispositivo para ofrecer información en tiempo real a los operadores, mejorando la productividad y la seguridad. <a href="https://www.nvidia.com/en-us/data-center/products/fleet-command/" data-type="link" data-id="https://www.nvidia.com/en-us/data-center/products/fleet-command/" target="_blank" rel="nofollow">Una solución de gestión del <em>edge</em></a> que despliegue aplicaciones, facilite las comunicaciones y proporcione capacidades de monitorización es fundamental.</p>



<p>· Establecer capacidades de MLOps, ModelOps y monitorización de infraestructura. Los equipos de ciencia de datos <a href="https://www.nvidia.com/en-us/data-center/solutions/mlops/" data-type="link" data-id="https://www.nvidia.com/en-us/data-center/solutions/mlops/" target="_blank" rel="nofollow">necesitarán MLOps</a> para automatizar el paso a producción, mientras que el cumplimiento requerirá ModelOps y actualizaciones de modelos para abordar el “model drift”. Los equipos de infraestructura y operaciones necesitarán monitorización para revisar costes, rendimiento y fiabilidad en la nube.</p>



<p>Los equipos de TI no sólo despliegan aplicaciones. También participan en la planificación para lograr resultados de negocio y, posteriormente, implantan DevOps para garantizar la entrega y la mejora continua. Aplicar prácticas similares a la ciencia de datos, el aprendizaje automático y la IA mejorará el éxito tanto en pilotos como en entornos de producción.</p>



<p>[1] IDC FutureScape: Worldwide Artificial Intelligence 2021 Predictions — India Implications</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Q&A: A look at forward-deployed engineers, AWS style]]></title>
<description><![CDATA[Hot AI companies can’t stop talking about forward-deployed engineers (FDEs), which are now very much in vogue. 



FDEs, in case you haven’t heard, are hired by companies looking (hoping?) to successfully deploy AI tools and services. It’s one of the hotter professions in a world still trying to ...]]></description>
<link>https://tsecurity.de/de/3600932/ai-nachrichten/qa-a-look-at-forward-deployed-engineers-aws-style/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600932/ai-nachrichten/qa-a-look-at-forward-deployed-engineers-aws-style/</guid>
<pubDate>Tue, 16 Jun 2026 09:18:29 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Hot AI companies <a href="https://www.computerworld.com/article/4180088/ai-vendor-fdes-key-considerations-and-concerns.html" data-type="link" data-id="https://www.computerworld.com/article/4180088/ai-vendor-fdes-key-considerations-and-concerns.html">can’t stop talking about forward-deployed engineers</a> (FDEs), which are now very much in vogue. </p>



<p>FDEs, in case you haven’t heard, are hired by companies looking (hoping?) to successfully deploy AI tools and services. It’s <a href="https://www.computerworld.com/article/4171867/heres-one-career-emerging-from-the-ai-shift-forward-deployed-engineers.html" data-type="link" data-id="https://www.computerworld.com/article/4171867/heres-one-career-emerging-from-the-ai-shift-forward-deployed-engineers.html">one of the hotter professions</a> in a world still trying to understand the impact of AI on careers.</p>



<p>So, what exactly are FDEs — are they techy lone rangers like the ones OpenAI, Google and Microsoft are hiring? Turns out it’s not so much about individual engineers who swoop in to design and roll out AI deployments; it’s more about a team of engineers working together at customer sites.</p>



<p>At least, that’s the view at Amazon Web Services (AWS).</p>



<p>In fact, according to <a href="https://www.linkedin.com/in/taimurrashid" data-type="link" data-id="https://www.linkedin.com/in/taimurrashid" target="_blank" rel="noreferrer noopener">Taimur Rashid</a>, managing director of the AWS Generative AI Innovation Center, the FDE concept pre-dates the current generative AI (genAI) gold rush. The same kinds of engineering teams were needed for the earlier machine-learning and cloud eras to help companies with deployments.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Taimur-Rashid-Director-GenAI-Innov-Delivery.jpg?quality=50&amp;strip=all&amp;w=1024" alt="AWS's Taimur Rashid" class="wp-image-4185215" width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p><a href="https://www.linkedin.com/in/taimurrashid" rel="noreferrer noopener" target="_blank">Taimur Rashid</a>, managing director of the AWS Generative AI Innovation Center,</p>
</figcaption></figure><p class="imageCredit">AWS</p></div>



<p>Rashid recently talked about how AWS sees FDEs as a profession in a conversation with <em>Computerworld</em>. And he weighed in on the desired job skills the company seeks in this increasingly AI-centric era.</p>



<p><strong>What is an FDE? </strong>“We view it as a team. It’s a cross-functional team that has engineers, scientists, strategists, and folks that can piece technology and business together. In some cases, we do have to have security engineers in there, too. </p>



<p>“I see them as anesthesiologists. They have to prep so many things, monitor things throughout. We see ourselves as a frontier deployment team helping customers adopt all forms of AI, whether it’s genAI, agentic AI, even emerging trends like physical AI. We’re helping these companies become frontier themselves.”</p>



<p><strong>How does an FDE engagement begin, and how is it structured? “</strong>Where we see the forward deployed model is when customers come in — for example, we have our executive briefing center in Seattle and in Arlington, VA. When customers share what they’re trying to do, very quickly a customer’s like, “What’s the quickest way I can go and build something with you?” </p>



<p>“We’ll forward deploy our people in, we’ll embed them in your business and we’ll go through these 45-day sprints that we typically design. Through those successive sprints, we’re building stuff together, we’re proving value, and then they can expand that to a much broader engagement.</p>



<p><strong>Where do FDEs actually sit? Client side, internally, or in-between? </strong>“It’s mixed, and it largely depends on what the customer’s preference is. We’ve seen models where the customer has been very adamant that, ‘We want your teams with us in our business.’  In those cases, we forward deploy the majority of the teams on site. </p>



<p>“We have models where customers are fine with you being wherever you’re based, as long as you’re still embedded virtually. And then there’s a hybrid. We deploy anywhere from five to seven people. Sometimes, the baseline is actually three.”</p>



<p><strong>Will cost savings be the job of an FDE, or someone else on the team? “</strong>I expect these teams to be able to architect systems that have those cost requirements in mind, whether it’s use a different model for a different use case that doesn’t increase the per-token cost…or think about ways where you can use semantic caching. I personally think you may have a high spend in token consumption, but if you’re generating revenue, as long as the economics work out, then you’re at peace.”</p>



<p><strong>What challenges have you gone through deploying FDEs in the real world? </strong>“One of the challenges worth highlighting is when customers get really excited about us forward deploying resources, what they end up realizing is [that] they’re not set up to absorb that right away. They realize they have to go through … process-related things, security access — all those operational things. </p>



<p>“One very good example is the Commonwealth Bank of Australia. They said: “Prioritization’s a big thing, and if you forward deploy and you’re 100% dedicated, how do we ensure that our teams are also equally 100% dedicated?’ When you’re sitting in your office, you’re distracted by your day-to-day. So they said, ‘Why don’t we create a neutral ground in Seattle? You fly your people, we’ll fly our people. We’ll give them three weeks of dedicated time so they have no distractions.’”</p>



<p><strong>Have you gone into projects where they want AI but have no security or governance ready? “</strong>I’ve been through this before, certainly. We do see customers that have security processes and capabilities, but it’s not as tight as it should be in the age of AI. Governance is the biggest area where customers right now have the biggest gap. I’m talking governance around agents. In the past two months, almost 100% of the conversation around agents is not about capability. It’s all about governance. </p>



<p>“That is a big area right now where forward deploy teams are helping with governance education, and building the scaffolding for that.”</p>



<p><strong>How does software engineering fit into the FDE model? </strong>“One of the greatest learnings is that as we forward deploy resources and get customers to take AI and integrate it into their systems, the knowledge of software engineering is so important. Today, a customer can use one of the Claude models and scan their code base and look at vulnerabilities. </p>



<p>“The tough part is not assessing those vulnerabilities, it’s remediating [them]. Remediating [them] requires software engineering experience, because you have got to merge code, test it, deploy it. We largely see that the frontier software development teams are smaller and they’re managing agents that are doing various tasks across the software development lifecycle.”</p>



<p><strong>AWS has many models at your scale, open source, closed — it’s more complex than what other AI vendors offer.  How do you nail down the talent? </strong>“It’s massive, and when you look at not only scale, it’s the complexity of the stack. We take an approach where we fundamentally do three important things: No. 1, we want to ensure people understand concepts; they have to understand pre-training, post-training, reinforcement, fine-tuning. </p>



<p>“Secondly, we make sure that our teams are well versed in their first-party services. The third thing is that by design, AWS has always been about choice. We say, ‘Let’s do 80-20 here. What is 20% of those specialties that we need to have, which can cover 80% of what most customers are trying to do?’”</p>



<p><strong>What skills should software developers learn to move into FDE work — the top three or four things? “</strong>We look at three categories. First category is entirely functional. Are they more engineering specific? Are they science specific? Are they security specific? Our litmus test is not only knowledge of the function, but the actual hands-on work that they can do with it. Secondly is around domain. I focus on what is their domain understanding across the whole AI lifecycle? The third thing is cultural. We are looking for folks that are okay at dealing with ambiguity, being good at stakeholder management, and having that startup mindset. </p>



<p>“This AI transformation’s not for the faint of heart.”</p>



<p><strong>There’s a rush for FDEs from OpenAI, Google, and others. What’s different about what you look for? “</strong>I don’t know entirely what the others are looking for, but I’ll tell you what we have been looking for in the past. When we hired solution architects, it was about systems level understanding. But what I see more and more is hands-on experience, cultural mindset, all these things are very important. If I had to pick one thing that is going to be very important in the talent that we either upskill or future talent that we hire, it has to be the application of AI towards software engineering and system integration tasks.</p>



<p><strong>You’re upskilling AWS talent as well? “</strong>We do. You will see some publications coming out in the next couple of weeks around how do we do this across our software teams and how does that translate to customer-facing roles.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DocLang aims to make documents readable by AI, not humans]]></title>
<description><![CDATA[AIs struggle to understand documents designed for humans; the DocLang working group seeks to flip that imbalance with its specification for machine-readable business documents “built from the ground up for LLM tokenizers.”



The working group, founded by IBM, Nvidia, and Red Hat and hosted by th...]]></description>
<link>https://tsecurity.de/de/3600883/ai-nachrichten/doclang-aims-to-make-documents-readable-by-ai-not-humans/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600883/ai-nachrichten/doclang-aims-to-make-documents-readable-by-ai-not-humans/</guid>
<pubDate>Tue, 16 Jun 2026 09:04:00 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AIs struggle to understand documents designed for humans; the DocLang working group seeks to flip that imbalance with its specification for machine-readable business documents “built from the ground up for LLM tokenizers.”</p>



<p>The working group, founded by IBM, Nvidia, and Red Hat and hosted by the Linux Foundation’s LF AI &amp; Data project, aims to create an open, universal, AI-native document format designed to improve how enterprises prepare, exchange, and govern document data for AI systems. ABBYY and Human Signal will also be involved in its development, and other contributors are welcome.</p>



<p>“Enterprises today work across a fragmented landscape of document formats, including PDFs, JPEGs, and other file types built primarily for human consumption rather than AI interpretation,” the group said in its launch <a href="https://www.linuxfoundation.org/press/lf-ai-data-foundation-launches-doclang-specification-working-group-to-advance-an-open-standard-for-ai-native-documents" target="_blank" rel="noreferrer noopener">announcement</a>.</p>



<p>“This disconnect can introduce complexity, raise costs, and reduce reliability when extracting meaning from business documents,” as organizations increasingly rely on generative AI and agentic systems, it said.</p>



<p><a href="https://www.linkedin.com/in/markcollier/" target="_blank" rel="noreferrer noopener">Mark Collier</a>, executive director of LF AI &amp; Data, said the goal of the <a href="https://doclang.ai/">DocLang Specification</a> Working Group is to “develop a vendor-neutral, interoperable standard that helps organizations prepare document data for AI more reliably, transparently, and at scale.”</p>



<p>DocLang defines a structured, machine-readable format for documents of any type, like JSON for data, that any tool can implement and any pipeline can consume. It builds on <a href="https://www.infoworld.com/article/3997240/docling-an-open-source-tool-kit-for-advanced-document-processing.html">DocLing</a>, a document processing toolkit hosted by LF AI &amp; Data that can transform human-readable PDFs, word processor documents or spreadsheets into structured data.</p>



<h2 class="wp-block-heading">Standards must evolve for AI</h2>



<p>Something like DocLang is needed, said independent technology analyst <a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>. “Existing document standards have done an admirable job allowing global stakeholders to confidently collaborate for decades, but it’s becoming increasingly clear that they are in desperate need of an update as AI reshapes the rules around how work gets done,” he explained.</p>



<p>Largely static document types, he said, “can be somewhat limiting when AI is redefining the very word, ‘document.’ In many ways. AI-age documents are far more iterative and dynamic than what they once were, and the definitions need to evolve with the times. The documents we currently live with simply weren’t designed for the AI age.”</p>



<p>Within that context, Levy said, “DocLang represents an early, best hope of achieving some kind of foundational baseline for document standards, one that will hopefully allow more intelligent, more efficient, lower-risk workflows than is currently the case.”</p>



<p>Taking an open-source, vendor-agnostic approach to the process ensures the collective will take precedence over the needs of specific vendors, he said, adding, “earlier standards-setting efforts around networking, documentation, the web, and the cloud powered the free-flowing digital landscape that defines modern life.”</p>



<p>An AI-centric documentation standard will carry that reality into the next generation of technology, said Levy.</p>



<h2 class="wp-block-heading">A question of governance</h2>



<p>The entire concept of LLMs, <a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy said, “involves using natural human languages. The computer is supposed to understand us without us changing our syntax or language. Forcing a syntax on users is exactly what we have today with SEO and more advanced programming languages.”</p>



<p>With something like DocLang, where the standard can be applied to content ingestion, he said, “I would be OK with that being automated, which seems to be the intent. The use case I envision is that when I upload a document to an agent, a skill can be run to preprocess the document into the DocLang standard format, saving tokens.”</p>



<p>That makes sense, he said, adding that he thinks it’s good “if it can help generate outputs, like a visualization, that can be shared outside an AI tool. On that front, that is also why I am liking Web MCP, since you are just adding some code to the page, like CSS or JavaScript, and the consumer, in this case, an AI browser or skill, is better equipped to handle the site.”</p>



<p>The point, he said, is, “these standards need to preserve the fact that humans can still do what they want, and do not need to know any coding to be proficient. In terms of governance, I am not sure if it matters.”</p>



<p>But one analyst did foresee governance problems arising from DocLang’s use.</p>



<p><a href="https://www.infotech.com/profiles/yaz-palanichamy" target="_blank" rel="noreferrer noopener">Yaz Palanichamy</a>, senior research analyst at Info-Tech Research Group, said DocLang adoption will require organizations to implement and review controls in order to scale its use accountably and securely.</p>



<p><em>This article first appeared <em>on <a href="https://www.cio.com/article/4183187/doclang-aims-to-make-documents-readable-by-ai-not-humans.html">CIO</a></em>, <em>on June 10, 2026</em>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Migrate from Terraform to OpenTofu on Rocky Linux 9 (2026 Guide)]]></title>
<description><![CDATA[Marcus’s DevOps Brief: I have been running Terraform in production for four years across Kubernetes clusters and cloud deployments. When HashiCorp switched to the Business Source License in 2023, my team spent two weeks evaluating OpenTofu before making the jump.…]]></description>
<link>https://tsecurity.de/de/3600555/linux-tipps/how-to-migrate-from-terraform-to-opentofu-on-rocky-linux-9-2026-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600555/linux-tipps/how-to-migrate-from-terraform-to-opentofu-on-rocky-linux-9-2026-guide/</guid>
<pubDate>Tue, 16 Jun 2026 05:13:22 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Marcus’s DevOps Brief: I have been running Terraform in production for four years across Kubernetes clusters and cloud deployments. When HashiCorp switched to the Business Source License in 2023, my team spent two weeks evaluating OpenTofu before making the jump.…]]></content:encoded>
</item>
<item>
<title><![CDATA[FBI Issues Urgent Kali365 Security Warning For Teams, Outlook, OneDrive Users]]></title>
<description><![CDATA[alternative_right shares a report from The Hill: The FBI released an urgent security warning to the public about a fast-acting scam targeting Microsoft 365 users on Teams, Outlook and OneDrive. The agency warned that the hacking platform Kali365 seeks out OAuth device codes, allowing scammers to ...]]></description>
<link>https://tsecurity.de/de/3600299/it-security-nachrichten/fbi-issues-urgent-kali365-security-warning-for-teams-outlook-onedrive-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600299/it-security-nachrichten/fbi-issues-urgent-kali365-security-warning-for-teams-outlook-onedrive-users/</guid>
<pubDate>Tue, 16 Jun 2026 00:11:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[alternative_right shares a report from The Hill: The FBI released an urgent security warning to the public about a fast-acting scam targeting Microsoft 365 users on Teams, Outlook and OneDrive. The agency warned that the hacking platform Kali365 seeks out OAuth device codes, allowing scammers to sneak past multi-factor authentication codes, and without the need for a password, to access Microsoft accounts. Scammers will send a phishing email impersonating a trusted document-sharing service with a device code and instructions on how to verify, according to the FBI.
 
"Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities," the FBI stated. The platform is sold to scammers with a $250 per month subscription. The FBI, which first detected Kali365 in April, described the hacking platform as an "emerging Phishing-as-a-Service platform." Hackers with limited skills can access advanced phishing tools through the platform, according to NordPass.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=FBI+Issues+Urgent+Kali365+Security+Warning+For+Teams%2C+Outlook%2C+OneDrive+Users%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F15%2F209242%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F15%2F209242%2Ffbi-issues-urgent-kali365-security-warning-for-teams-outlook-onedrive-users%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/06/15/209242/fbi-issues-urgent-kali365-security-warning-for-teams-outlook-onedrive-users?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta CTO Andrew Bosworth Admits the Company’s AI Reorg Was ‘Atrocious’]]></title>
<description><![CDATA[In an internal memo seen by WIRED, Bosworth promised employees more stability, better communication, and the return of workplace perks as the company seeks to improve morale.]]></description>
<link>https://tsecurity.de/de/3600264/ai-nachrichten/meta-cto-andrew-bosworth-admits-the-companys-ai-reorg-was-atrocious/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600264/ai-nachrichten/meta-cto-andrew-bosworth-admits-the-companys-ai-reorg-was-atrocious/</guid>
<pubDate>Mon, 15 Jun 2026 23:38:01 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In an internal memo seen by WIRED, Bosworth promised employees more stability, better communication, and the return of workplace perks as the company seeks to improve morale.]]></content:encoded>
</item>
<item>
<title><![CDATA[DARPA seeks swappable satellites to help with future star wars]]></title>
<description><![CDATA[Worried that an unexpected strike could take out critical orbital systems, Pentagon researchers want to know how fast the industry thinks it could launch replacements]]></description>
<link>https://tsecurity.de/de/3600261/it-nachrichten/darpa-seeks-swappable-satellites-to-help-with-future-star-wars/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600261/it-nachrichten/darpa-seeks-swappable-satellites-to-help-with-future-star-wars/</guid>
<pubDate>Mon, 15 Jun 2026 23:35:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Worried that an unexpected strike could take out critical orbital systems, Pentagon researchers want to know how fast the industry thinks it could launch replacements]]></content:encoded>
</item>
<item>
<title><![CDATA[Chipmaker Nvidia seeks to raise over $25B in first bond deal since 2021]]></title>
<description><![CDATA[Debt sale set to test investor appetite for further exposure to AI sector amid a deluge of borrowing.]]></description>
<link>https://tsecurity.de/de/3600070/ai-nachrichten/chipmaker-nvidia-seeks-to-raise-over-25b-in-first-bond-deal-since-2021/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600070/ai-nachrichten/chipmaker-nvidia-seeks-to-raise-over-25b-in-first-bond-deal-since-2021/</guid>
<pubDate>Mon, 15 Jun 2026 21:21:29 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Debt sale set to test investor appetite for further exposure to AI sector amid a deluge of borrowing.]]></content:encoded>
</item>
<item>
<title><![CDATA[Das beste Setup: Neues macOS Beta + Windows 11 auf deinem Mac]]></title>
<description><![CDATA[Apple hat auf der WWDC 2026 am 8. Juni eine
The post Das beste Setup: Neues macOS Beta + Windows 11 auf deinem Mac first appeared on IT-LEARNER.]]></description>
<link>https://tsecurity.de/de/3599816/it-nachrichten/das-beste-setup-neues-macos-beta-windows-11-auf-deinem-mac/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599816/it-nachrichten/das-beste-setup-neues-macos-beta-windows-11-auf-deinem-mac/</guid>
<pubDate>Mon, 15 Jun 2026 19:19:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple hat auf der WWDC 2026 am 8. Juni eine</p>
<p>The post <a rel="nofollow" href="https://it-learner.de/neues-macos-beta-windows-11-auf-deinem-mac/">Das beste Setup: Neues macOS Beta + Windows 11 auf deinem Mac</a> first appeared on <a rel="nofollow" href="https://it-learner.de/">IT-LEARNER</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The 11 hardest IT roles to fill in 2026 — and what’s changed]]></title>
<description><![CDATA[These days, hiring a specialist is relatively easy — a SOC analyst, an ML researcher, a cloud architect. Those requisitions close in weeks. What stays open for six to nine months are hybrid roles: engineers fluent in AI who can go deep in code and also understand the business. “Three skills, one ...]]></description>
<link>https://tsecurity.de/de/3598737/it-nachrichten/the-11-hardest-it-roles-to-fill-in-2026-and-whats-changed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598737/it-nachrichten/the-11-hardest-it-roles-to-fill-in-2026-and-whats-changed/</guid>
<pubDate>Mon, 15 Jun 2026 12:17:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>These days, hiring a specialist is relatively easy — a SOC analyst, an ML researcher, a cloud architect. Those requisitions close in weeks. What stays open for six to nine months are hybrid roles: engineers fluent in AI who can go deep in code and also understand the business. “Three skills, one person, small pool,” says <a href="https://www.linkedin.com/in/nealsample/" rel="nofollow">Neal Sample</a>, chief digital and technology officer at Best Buy. “These hybrids are the future of IT — and are hard to find right now.”</p>



<p>Two years after AI leapfrogged cybersecurity as the most difficult IT skill to hire for in CIO.com’s State of the CIO survey, the top of the list hasn’t budged. AI/machine learning and cybersecurity are now tied as the hardest roles to fill, according to the <a href="https://us.resources.cio.com/resources/state-of-the-cio/" rel="nofollow">2026 State of the CIO survey</a>, with data science and analytics close behind. But while the rankings look familiar, the nature of the talent crunch has shifted. The hunt for LLM engineers and prompt specialists has given way to demand for people who can operationalize AI at scale, govern its risks, and wield it effectively without blindly trusting it.</p>



<p>Meanwhile, risk management has climbed into the top five for the first time, while business/IT automation is holding steady near the top. And pressure has eased on roles that dominated just a few years ago: cloud architecture has dropped, and <a href="https://www.cio.com/article/3951133/remember-when-developers-reigned-supreme-the-market-for-software-coding-goes-soft.html">application development has fallen off</a> the list entirely as AI tools reshape what developers actually do.</p>



<p>“The most challenging roles are anything that needs to be bundled with AI,” says <a href="https://www.linkedin.com/in/nielnickolaisen/" rel="nofollow">Niel Nickolaisen</a>, IT advisor and field CTO at Valcom Technologies. Security analysts who can use AI to improve cyber posture while bad actors sharpen their attacks. Software engineers skilled at using AI platforms to design, build, and deploy. “There are simply not yet enough of these people available,” Nickolaisen says.</p>



<p><strong>Hardest-to-fill IT roles: 2026 vs. 2024</strong></p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td>Skill</td><td>2026 rank</td><td>2024 rank</td><td>Change</td></tr><tr><td>AI/machine learning</td><td>#1 (tie)</td><td>#1</td><td>Steady</td></tr><tr><td>Cybersecurity</td><td>#1 (tie)</td><td>#2</td><td>Rising</td></tr><tr><td>Data science/analytics</td><td>#3</td><td>#3</td><td>Steady</td></tr><tr><td>Business/IT automation</td><td>#4</td><td>#4 (tie)</td><td>Steady</td></tr><tr><td>Risk management</td><td>#5</td><td>#8 (tie)</td><td>Rising</td></tr><tr><td>Software engineering</td><td>#6 (tie)</td><td>#6 (tie)</td><td>Steady</td></tr><tr><td>DevOps/DevSecOps</td><td>#6 (tie)</td><td>#11 (tie)</td><td>Rising</td></tr><tr><td>Enterprise architecture</td><td>#8 (tie)</td><td>#10 (tie)</td><td>Rising</td></tr><tr><td>Cloud services/integration</td><td>#8 (tie)</td><td>#12 (tie)</td><td>Rising</td></tr><tr><td>Cloud architecture</td><td>#8 (tie)</td><td>#6 (tie)</td><td>Falling</td></tr><tr><td>Design thinking/UX</td><td>#8 (tie)</td><td>#15 (tie)</td><td>Rising</td></tr></tbody></table> </div></figure>



<p><em> Source: Foundry/CIO.com State of the CIO Survey, 2024 and 2026</em></p>



<h2 class="wp-block-heading">AI hiring grows up</h2>



<p>IT leaders seeking LLM expertise can take heart in the fact that the frenzy around LLM engineers has eased. “Prompt engineering as a standalone job title was a short-lived fad,” Best Buy’s Sample says. “Today, it’s a baseline skill.”</p>



<p>But what most organizations are looking for now is different: AI product engineers who can stand up agents, build testing frameworks, manage the cost-latency-quality triangle, and deploy AI at scale. They’re also trying to fill <a href="https://www.cio.com/article/4137022/new-it-roles-emerge-to-tackle-ai-evaluation.html">governance</a> and <a href="https://www.csoonline.com/article/4029862/how-ai-red-teams-find-hidden-flaws-before-attackers-do.html">red-team</a> roles that didn’t exist on anyone’s org chart three years ago.</p>



<p>“The center of gravity moved from people who build models to people who wield them,” Sample says. “That’s a very different resume.”</p>



<p>Gen AI and LLM tools have become intuitive enough that the skills organizations need have evolved toward more agentic AI and less prompt engineering. “We need people who understand workflows, process simplification, and can work with an agent platform to automate work and tasks,” says Nickolaisen of Valcom Technologies. “I expect this will change over the next year or two as the agent platforms get more intuitive. We can then focus our reskilling on how to make agents more autonomous.”</p>



<p>The challenge is that AI is evolving so rapidly — and being invested in by everyone from cloud providers to the startup ecosystem — that experience at one company may not translate to another, and what someone learned six months ago may already be outdated.</p>



<p>“Best to look for people with a broad understanding and ability to consume market shifts constantly happening,” says <a href="https://www.linkedin.com/in/scotthicar/" rel="nofollow">Scott Hicar</a>, a fractional technology leader focused on the private equity market.</p>



<h2 class="wp-block-heading">Cybersecurity: A skills crisis, not a headcount crisis</h2>



<p>Cybersecurity’s rise to share the top spot with AI reflects more than just demand. It also signals a fundamental shift in the challenges organizations face.</p>



<p>Six in 10 organizations now say skills gaps outweigh staffing shortages as their primary workforce challenge, according to the 2026 <a href="https://www.sans.org/white-papers/2026-cybersecurity-workforce-research-report" rel="nofollow">SANS/GIAC Cybersecurity Workforce Report</a>, a 20-point shift from just a year ago. And the consequences are measurable: 27% of cybersecurity leaders surveyed report breaches directly tied to capability gaps, while 61% say that team stress has increased over the past two years.</p>



<p>The skills scarcity isn’t at the entry level; it’s at the senior architect tier. “People who can make a good security trade-off under real constraints, rather than read a dashboard, are hard to find,” Best Buy’s Sample says. “Those people are naming their price.”</p>



<p>The strain on security teams is compounding. Attack surfaces have expanded with every SaaS addition, API, and agent deployed. Cyber adversaries are using the same AI tools as defenders. Security teams are burning out.</p>



<p>Nickolaisen frames it in operational terms: “Cyber with AI is the biggest need because it’s the most near-term threat. If the bad guys can use vibe programming to build an attack in less than an hour and revise it in minutes, I need to be able to respond and modify my response in near real-time.”</p>



<p>The SANS research found that 74% of organizations say AI is already impacting the size of their cybersecurity teams and the roles within them. SOC and security analysts are the roles most likely to be cut as AI reshapes security teams, and these are <a href="https://www.csoonline.com/article/4058190/ai-is-altering-entry-level-cyber-hiring-and-the-nature-of-the-skills-gap.html">precisely the entry-level positions</a> where the next generation of cybersecurity leaders traditionally learned their craft. At the same time, new roles are emerging, including AI/ML security specialists, AI security engineers, and AI governance analysts.</p>



<h2 class="wp-block-heading">The rise of ‘second-order’ AI skills</h2>



<p>Automation and risk management skills have both climbed into the State of the CIO’s top five hardest-to-fill roles for the first time — and they’re rising for the same reason.</p>



<p>“AI blew out the surface area,” says Sample of Best Buy. “Every agent you deploy is a new automation and a new risk, and most governance, risk, and compliance (GRC) and ops functions weren’t designed for that pace.”</p>



<p>With automation, the need isn’t for more RPA developers; that work has become a commodity. Organizations need people who can <a href="https://www.cio.com/article/4157466/cios-reimagine-business-processes-to-reap-ai-benefits.html">look at a process and decide what to automate</a>, what to retire, and what to redesign. “That’s three jobs welded together,” Sample says. “Business analyst, process engineer, and technologist. Anyone who does all three well is rare — and expensive.”</p>



<p>The shift from chatbots to agents is driving much of this demand for automation talent. “The first wave of agents won’t invent new tasks; they’ll replace how existing work gets done,” says <a href="https://www.linkedin.com/in/ameyakanitkar/" rel="nofollow">Ameya Kanitkar</a>, co-founder and CTO at AI measurement platform Larridin. “Enterprises are rearchitecting critical business workflows around fully or semi-autonomous agentic flows, and the demand for people who can build and operate these is massive.” The catch, he says, is that it requires an uncommon combination: understanding how systems work and how the business runs.</p>



<p>Risk management presents a similar challenge. GRC functions built for SOX and PCI compliance aren’t necessarily optimized for model risk, prompt injection, or third-party AI exposure. “We’re hiring for a discipline that’s maybe five years old, against a job description that’s twenty years old,” Sample says. “That gap is the problem.”</p>



<p>One capability that’s grown more critical is <a href="https://www.csoonline.com/article/4002765/third-party-risk-management-is-broken-but-not-beyond-repair.html">third-party risk management</a>. “With AI being embedded in most of what we purchase and use, [the question becomes] do I need both more people and a better-governed process to assess the AI that comes from third parties?” says Nickolaisen of Valcom Technologies.</p>



<p><a href="https://www.linkedin.com/in/jamesstanger/" rel="nofollow">Dr. James Stanger</a>, chief technology evangelist at CompTIA, notes that risk management requires a different mindset than many technical workers bring to the table. “You’ve got to know your technical stuff, but you have to understand the business use of the technical stuff — otherwise you’re addressing technology, not risk,” he says.</p>



<h2 class="wp-block-heading">The midlevel squeeze</h2>



<p>AI coding tools and low-code platforms haven’t reduced the demand for software engineers, but they’ve changed its shape. A strong engineer with good AI tooling now produces roughly what three engineers did just a few years ago. “The squeeze is on the middle tier: the people whose day job was wiring APIs together,” Sample says.</p>



<p>Engineering hiring is bifurcating, says Larridin’s Kanitkar: strong demand for experienced leaders who bring judgment and ownership, and for junior talent that’s AI-native from day one. “The squeeze is in the middle,” he says. “People coasting on midlevel execution are finding themselves on the wrong side of the job market.”</p>



<p>AI tools are pushing engineers to think more like architects. “At one time, the industry was looking for IT ‘plumbers’ who could code,” CompTIA’s Stanger says. “Now the industry is demanding people who can think architecturally and in terms of risk and privacy. We don’t need keyboard code punchers; we need proactive designers who use AI to model potential performance issues.”</p>



<p>For DevOps specifically, a consolidation is under way. “Platform engineering is the growth role,” Sample says. “The generic DevOps engineer title is being absorbed into platform or site reliability engineering (SRE), and I don’t think it survives the next few years as a distinct function.”</p>



<h2 class="wp-block-heading">Cloud has stabilized</h2>



<p>Cloud roles have become easier to fill. Already visible in 2024, the trend has only continued.<strong></strong></p>



<p>Most organizations have reached a cloud steady-state, says Valcom Technologies’ Nickolaisen. “Unless something big changes, we have our public, private, and on-prem workloads,” he says. “The skills of my system administration teams are adequate to support that.”</p>



<p>Training programs have caught up with cloud, Stanger notes — though he adds it’s hard to say exactly why the pressure has eased.</p>



<p>“Cloud has matured into a real profession,” Sample adds, “and more people have done it at scale for many years now.”</p>



<p>Some cloud specialties remain hard to fill: FinOps, regulated-industry migrations, and reverse migrations. And certain workloads are coming back on-prem. “Especially AI inference, where the unit economics in cloud can be brutal at scale,” Sample says. “That’s shifting the skill mix again, and nobody’s resume says, ‘I can move workloads off the cloud intelligently.’”</p>



<h2 class="wp-block-heading">What’s working to close the gap</h2>



<p>If there’s one point of agreement among IT leaders, it’s this: Upskilling and internal mobility are more effective than external hiring in terms of speed, cost, and retention.</p>



<p>“Our most productive AI engineers in 2025 were not hired as AI engineers,” says Best Buy’s Sample. “They were strong software engineers, upskilled with good internal training and real projects.”</p>



<p>Outside expertise offers less advantage than it used to. AI has moved so fast that contractors aren’t necessarily ahead of internal teams, according to Nickolaisen. “Once my teams are over the initial hump and embrace AI, their skills develop quickly,” he says.</p>



<p>The key is trust. “Assure the teams that we will not use the resulting productivity to get rid of people, and it’s amazing what can be done to accelerate the delivery of value,” says Nickolaisen.</p>



<p>One change that dramatically expanded Best Buy’s talent pool was to stop treating AI hiring as a separate pipeline. “We hire engineers, then we introduce them to our take on AI,” Sample says. “That one reframe opened a pool at least 10 times larger and gave us better output.”</p>



<p>Stanger advocates cross-skilling, apprenticeship-based mentoring, and pathway-based learning — tactics that focus on building capabilities rather than checking off credential boxes.</p>



<p>“Instead of the tired, old, pedigree-based lens that asks, ‘Where is your four-year degree from,’ the most progressive hiring institutions are now asking, ‘What are your skillsets, and where can you take us with them?’” says Stanger.</p>



<p>Chasing the latest job titles carries risk. “The prompt engineer hiring wave of 2023 — those roles aged out in eighteen months, and the people who took them are reskilling now,” Sample says. “Hiring a job title rather than a capability has a short shelf life. That lesson is already repeating with agentic AI in some places. It won’t age better the second time.”</p>



<h2 class="wp-block-heading">Soft market, hard problem</h2>



<p>The tech hiring market is sluggish, driven by uncertainty about AI-driven job displacement, economic conditions, and what Nickolaisen characterizes as “pretty much everything in our lives.” But for the skills that matter most, the competition remains fierce.</p>



<p>“The next couple of years are critical,” Kanitkar says. “This is when the separation happens.” The frontier moves every day, which means the gap between IT organizations that master the shift and those that resist it will only widen.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Open-source CI/CD abuse detector guards against stolen credential attacks]]></title>
<description><![CDATA[CI/CD Abuse Detector is an open-source project that uses a large language model to flag suspicious changes to continuous integration and continuous deployment pipelines, workflows, and automation configurations. The repository contains drop-in templates for GitHub Actions, GitLab CI, and Azure De...]]></description>
<link>https://tsecurity.de/de/3598139/it-security-nachrichten/open-source-cicd-abuse-detector-guards-against-stolen-credential-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598139/it-security-nachrichten/open-source-cicd-abuse-detector-guards-against-stolen-credential-attacks/</guid>
<pubDate>Mon, 15 Jun 2026 07:52:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CI/CD Abuse Detector is an open-source project that uses a large language model to flag suspicious changes to continuous integration and continuous deployment pipelines, workflows, and automation configurations. The repository contains drop-in templates for GitHub Actions, GitLab CI, and Azure DevOps. The project targets a common attack chain in software supply chain compromises. Stolen developer credentials are used to push modifications to workflow files, which then harvest secrets stored in the CI environment. The detector … <a href="https://www.helpnetsecurity.com/2026/06/15/ci-cd-abuse-detector-open-source/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/15/ci-cd-abuse-detector-open-source/">Open-source CI/CD abuse detector guards against stolen credential attacks</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MCP-Server für Datenbanken]]></title>
<description><![CDATA[Datenbanken in KI-Workflows einzubinden, ist kein Problem – den richtigen MCP-Server vorausgesetzt.DC Studio | shutterstock.com



Das Model Context Protocol (MCP) hat sich zur Standard-Schnittstelle zwischen LLM-gestützten Tools und lokalen Systemen, internen und externen APIs sowie Datenquellen...]]></description>
<link>https://tsecurity.de/de/3597947/it-security-nachrichten/mcp-server-fuer-datenbanken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597947/it-security-nachrichten/mcp-server-fuer-datenbanken/</guid>
<pubDate>Mon, 15 Jun 2026 06:07:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/DC-Studio_shutterstock_2628162685_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="AI Dev 16z9" class="wp-image-4183528" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Datenbanken in KI-Workflows einzubinden, ist kein Problem – den richtigen MCP-Server vorausgesetzt.</figcaption></figure><p class="imageCredit">DC Studio | shutterstock.com</p></div>



<p>Das Model Context Protocol (<a href="https://www.computerwoche.de/article/4031227/was-ist-model-context-protocol.html" target="_blank">MCP</a>) hat sich zur Standard-Schnittstelle zwischen LLM-gestützten Tools und lokalen Systemen, internen und externen APIs sowie Datenquellen entwickelt. Offizielle MCP-Server stehen inzwischen nicht nur für <a href="https://www.computerwoche.de/article/4133146/5-mcp-server-fur-mehr-cloud-automation.html" target="_blank">große Cloud-Plattformen</a> und <a href="https://www.computerwoche.de/article/4103988/10-mcp-server-fur-devops.html" target="_blank">DevOps-Tools</a> zur Verfügung, sondern werden auch von den meisten wichtigen Datenbankplattformen unterstützt.</p>



<p>Einen MCP-Server für Datenbanken zu nutzen, kann Anwender unter anderem dazu befähigen,</p>



<ul class="wp-block-list">
<li>Abfragen durchzuführen, Daten zu erstellen und zu aktualisieren sowie administrative Tasks zu erledigen, ohne manuell SQL schreiben zu müssen.</li>



<li>mit LLMs neuen Code zu schreiben oder Automatisierungen zu erstellen, die auf das jeweilige Datenbankschema abgestimmt sind.</li>



<li>das Debugging über schnellere Abfragen optimieren, um Datenprobleme oder Fehlkonfigurationen aufzudecken.</li>
</ul>



<p>In diesem Beitrag stellen wir ihnen offizielle MCP-Server von führenden Datenbank-Plattformanbietern vor. Diese Server können von jedem MCP-kompatiblen Tool, jeder IDE und jedem Agenten genutzt werden. Das erfordert oft nur einen kleinen JSON-Eintrag in der MCP-Konfigurationsdatei.</p>



<h2 class="wp-block-heading">Amazon Aurora MCP-Server</h2>



<p><a href="https://www.computerwoche.de/article/4144155/mysql-weiter-unter-oracle-fuchtel.html" target="_blank">MySQL</a> und <a href="https://www.computerwoche.de/article/3508938/so-geht-postgresql.html" target="_blank">PostgreSQL</a> sind die weltweit am häufigsten verwendeten Open-Source-Datenbanken. In beiden Fällen existiert jedoch kein einheitlicher MCP-Server. Dafür gibt es diese bei verschiedenen Anbietern. Einer davon ist Amazon Web Services (AWS).</p>



<p>Das Unternehmen bietet für seinen gemanagten relationalen Datenbank-Service Aurora einen offiziellen MCP-Server an. Dieser ist sowohl mit MySQL als auch mit PostgreSQL kompatibel. Laut der <a href="https://github.com/awslabs/mcp/tree/main/src/mysql-mcp-server" target="_blank" rel="noreferrer noopener">Dokumentation auf GitHub</a> kann der <a href="https://awslabs.github.io/mcp/servers/mysql-mcp-server" target="_blank" rel="noreferrer noopener">Amazon Aurora MySQL MCP-Server</a> dazu genutzt werden, natürlichsprachliche Befehle in MySQL-kompatible SQL-Abfragen umzuwandeln. Diese können anschließend auf Aurora-MySQL-Datenbanken ausgeführt werden. In ähnlicher Weise bietet der <a href="https://github.com/awslabs/mcp/tree/main/src/postgres-mcp-server" target="_blank" rel="noreferrer noopener">Aurora Postgres MCP-Server</a> MCP-Tools, um mit PostgreSQL-Datenbanken zu arbeiten. Für verteilte Postgres-Datenbanken übernimmt der <a href="https://github.com/awslabs/mcp/tree/main/src/aurora-dsql-mcp-server" target="_blank" rel="noreferrer noopener">Aurora DSQL MCP-Server</a> dieselbe Funktion.</p>



<p>AWS hat darüber hinaus ein <a href="https://github.com/awslabs/mcp" target="_blank" rel="noreferrer noopener">wachsendes Portfolio mit offiziellen MCP-Servern</a> für seine gesamte Produktpalette aufgebaut – darunter auch andere Amazon-Datenbankplattformen wie:</p>



<ul class="wp-block-list">
<li><a href="https://awslabs.github.io/mcp/servers/dynamodb-mcp-server" target="_blank" rel="noreferrer noopener">DynamoDB</a>,</li>



<li><a href="https://awslabs.github.io/mcp/servers/elasticache-mcp-server" target="_blank" rel="noreferrer noopener">ElastiCache</a> und</li>



<li><a href="https://awslabs.github.io/mcp/servers/redshift-mcp-server" target="_blank" rel="noreferrer noopener">Redshift</a>.</li>
</ul>



<p><strong>Zu empfehlen für:</strong> AWS-agnostische Anwender, die ihre LLM-Interaktionen mit Daten unterfüttern wollen.</p>



<h2 class="wp-block-heading">BigQuery MCP-Server</h2>



<p>BigQuery ist Googles Cloud-basierte Datenanalyseplattform und eine beliebte Datenquelle für KI-Anwendungen. BigQuery-Nutzer mit konfiguriertem API-Zugriff können den <a href="https://docs.cloud.google.com/bigquery/docs/use-bigquery-mcp" target="_blank" rel="noreferrer noopener">BigQuery MCP Server</a> nutzen, um über MCP-kompatible KI-Clients mit der Plattform zu interagieren. Mithilfe dieses Remote-MCP-Servers können Entwickler:</p>



<ul class="wp-block-list">
<li>Abfragen zu Datenquellen generieren und ausführen oder</li>



<li>Metadaten zu Datensätzen, Tabellen und Schemata abrufen.</li>
</ul>



<p>All das ist mit einem einfachen Prompt in natürlicher Sprache realisierbar, beispielsweise: „Liste alle Datensätze im Projekt <code>PROJECT_ID</code> auf.“ Die Ergebnisse lassen sich nach Region, Datensatz-ID, Spaltennamen und weiteren Kriterien filtern. Als Teil von Googles vollständig gemanagtem, remote gehostetem MCP-Portfolio kann der BigQuery MCP Server verteilten Teams das Leben in Bezug auf Security, Wartung und Benutzerfreundlichkeit leichter machen. Allerdings unterliegen die BigQuery-MCP-Tools einigen Beschränkungen hinsichtlich des Umfangs der Abfrageergebnisse, der Verarbeitungszeit und anderen Faktoren.</p>



<p><strong>Zu empfehlen für:</strong> Anwender, die bereits auf BigQuery setzen und zusätzliche, agentische Kontrollmaßnahmen wünschen.</p>



<h2 class="wp-block-heading">Elastic Agent Builder</h2>



<p>Eine weitere wichtige Datenbankkategorie umfasst Plattformen, die für Keyword- und semantische Suchen konzipiert sind. In diesem Bereich wird häufig Elasticsearch eingesetzt. Anstelle eines einzelnen MCP-Servers bietetdas Unternehmen inzwischen den <a href="https://www.elastic.co/docs/explore-analyze/ai-features/elastic-agent-builder" target="_blank" rel="noreferrer noopener">Elastic Agent Builder</a> an. Dabei handelt es sich um ein umfassenderes Framework, das auf agentenbasierte Workflows ausgerichtet ist.</p>



<p>Mit dem Elastic Agent Builder können Anwender mit KI-Agenten chatten, um Kontext aus den Elasticsearch-Daten abzurufen und diesen auf verschiedene Umgebungen auszuweiten. Der Agent Builder selbst enthält einen <a href="https://www.elastic.co/docs/explore-analyze/ai-features/agent-builder/mcp-server" target="_blank" rel="noreferrer noopener">MCP-Server-Endpunkt</a> für die Programmability und um Agenten anderen Clients zugänglich zu machen. Hierbei handelt es sich ausdrücklich<strong> nicht</strong> um eine direkte MCP-Schnittstelle zu den reinen Elasticsearch-APIs. Stattdessen stellt das Interface Skills der Agentenplattform bereit.</p>



<p>Ein möglicher Nachteil ist dabei, dass dadurch eine zusätzliche Ebene zwischen IDE (beziehungsweise Agenten) und den Daten, nach denen gesucht wird, eingezogen wird. Einen Agenten einzurichten, erfordert eine höhere Abonnement-Stufe und im Vergleich zu anderen MCP-Servern sind zusätzliche Konfigurationsschritte erforderlich.</p>



<p><strong>Zu empfehlen für:</strong> Anwender, die Wert auf eine erweiterbare gemeinsame Ebene für die Interaktion sowohl mit Elasticsearch als auch mit externen MCP-Servern legen und gleichzeitig Verantwortlichkeiten wie Berechtigungen zentralisieren möchten.</p>



<h2 class="wp-block-heading">Neo4j MCP-Server</h2>



<p>Graph-Datenbanken sind inzwischen ebenfalls ein wichtiger NoSQL-Datenbanktyp. Dieser ist darauf spezialisiert, mithilfe von Nodes und Edges Abfragen in stark vernetzten Datenstrukturen zu beschleunigen. Eine populäre Option in diesem Bereich ist Neo4j. Der zugehörige <a href="https://neo4j.com/developer/genai-ecosystem/model-context-protocol-mcp/">offizielle MCP-Server</a> funktioniert mit jeder Art von Neo4j-Deployment (Desktop, Sandbox, selbstverwaltet und gemanagt) und ermöglicht es LLM-basierten Clients unter anderem:</p>



<ul class="wp-block-list">
<li>Graph-Schemata abzurufen,</li>



<li>Lese- und Schreibanweisungen auszuführen, oder</li>



<li>Graph-Algorithmen auszuführen.</li>
</ul>



<p>Darüber hinaus sind weitere Neo4j-MCP-Server für spezielle Anwendungsbereiche <a href="https://github.com/neo4j-contrib/mcp-neo4j" target="_blank" rel="noreferrer noopener">verfügbar</a>.</p>



<p><strong>Zu empfehlen für:</strong> Neo4j-Poweruser, die mit ihren Graph-Datenbanken auf chatbasierte Weise experimentieren möchten.</p>



<h2 class="wp-block-heading">MCP Toolbox for Databases</h2>



<p>Bei <a href="https://github.com/googleapis/mcp-toolbox" target="_blank" rel="noreferrer noopener">MCP Toolbox for Databases</a> handelt es sich um einen bemerkenswerten MCP-Server von Google, der als populäre „Sammellösung“ für verschiedene Datenbanktypen dient. Denn dieser Server verbindet LLMs nicht mit einer einzelnen verwalteten Datenbank, sondern vereinheitlicht den LLM-Zugriff auf mehrere Systeme. Die Open-Source-Utility wird mit <a href="https://mcp-toolbox.dev/documentation/configuration/prebuilt-configs/" target="_blank" rel="noreferrer noopener">vorkonfigurierten Einstellungen</a> für knapp 30 verschiedene Datenbanken ausgeliefert – darunter:</p>



<ul class="wp-block-list">
<li>PostgreSQL,</li>



<li>MySQL,</li>



<li>SQL Server,</li>



<li>Oracle Database,</li>



<li>MongoDB,</li>



<li>Redis,</li>



<li>Neo4j,</li>



<li>Snowflake, sowie</li>



<li>die Datenbanken in Google Cloud.</li>
</ul>



<p>Sobald die Datenquellen in einer <code>tools.yaml</code>-Datei definiert sind, können mit der MCP Toolbox strukturierte Abfragen oder semantische Suchen in Datenbanken durchgeführt werden – direkt über eine IDE oder einen Agentic Client und in natürlicher Sprache. Dabei werden Befehle in Aktionen wie <code>list_tables</code> und <code>execute_sql</code> übersetzt.</p>



<p><strong>Zu empfehlen für: </strong>Anwender, die verschiedene Datenbanken in Google Cloud (oder anderswo) nutzen und einen „All-in-One“-MCP-Server brauchen.</p>



<h2 class="wp-block-heading">MongoDB MCP-Server</h2>



<p><a href="https://www.computerwoche.de/article/2796089/was-die-nosql-datenbank-kann.html" target="_blank">MongoDB</a> ist eine populäre, dokumentenorientierte NoSQL-Datenbank. Die verantwortlichen Entwickler haben ebenfalls einen <a href="https://github.com/mongodb-js/mongodb-mcp-server" target="_blank" rel="noreferrer noopener">offiziellen MCP-Server</a> veröffentlicht. Dieser ist sowohl mit der quelloffenen Datenbank als auch mit der gehosteten Cloud-Datenbankplattform MongoDB Atlas kompatibel. Um mit MongoDB-Instanzen zu interagieren, stellt der MCP-Server eine <a href="https://github.com/mongodb-js/mongodb-mcp-server#tool-list" target="_blank" rel="noreferrer noopener">Reihe von Tools</a> bereit. Damit ist es etwa möglich:</p>



<ul class="wp-block-list">
<li>die Datenbank abzufragen,</li>



<li>Informationen zu Sammlungen abzurufen,</li>



<li>Indizes zu erstellen und zu entfernen, oder</li>



<li>Statistiken zur Datenbanknutzung zu erfassen.</li>
</ul>



<p>Für MongoDB-Atlas-Prozesse stehen zudem weitere Tools zur Verfügung, beispielsweise um Benutzer zu erstellen und zu clustern.  </p>



<p>Die Tools des MongoDB MCP-Servers sind standardmäßig schreibgeschützt, können aber für Schreibzugriff umkonfiguriert werden. Diese können lokal genutzt werden, unterstützen aber auch den Streamable-HTTP-Transport für Remote-Server (was allerdings mit größeren <a href="https://www.computerwoche.de/article/4093704/tools-um-mcp-server-abzusichern.html" target="_blank">Sicherheitsbedenken</a> verbunden ist).</p>



<p><strong>Zu empfehlen für:</strong> Alle, die MongoDB nutzen und ihre KI-fähige IDE oder CLI mit mehr Automatisierungsfunktionen ausstatten möchten.</p>



<h2 class="wp-block-heading">Pinecone MCP-Server</h2>



<p>Geht es um native <a href="https://www.computerwoche.de/article/2829270/warum-vektorisierung-die-basis-fuer-genai-ist.html" target="_blank">Vektordatenbanken</a>, ist Pinecone eine performante und weit verbreitete Option – inklusive einer gut durchdachten <a href="https://docs.pinecone.io/reference/api/introduction" target="_blank" rel="noreferrer noopener">API</a> und umfassenden SDKs. Der <a href="https://docs.pinecone.io/guides/operations/mcp-server" target="_blank" rel="noreferrer noopener">Pinecone MCP-Server</a> erweitert diese Möglichkeiten und befähigt Benutzer etwa dazu, die Dokumentation abzufragen und Funktionen über KI-Agenten und KI-fähige IDEs auszuführen. Dabei zeichnet sich der Pinecone MCP-Server durch einfache Konfiguration und Installation aus. Derzeit besteht der Pinecone MCP-Server aus neun MCP-Tools. Diese decken diverse schreibgeschützte Aktionen ab, etwa:</p>



<ul class="wp-block-list">
<li>Knowledge Gathering über die offizielle Pinecone-Dokumentation,</li>



<li>die Abfrage von Vektordatensätzen, Index-Metadaten, Konfigurationen sowie Statistiken, und</li>



<li>Datensätze und Indizes zu aktualisieren, beziehungsweise neu zu erstellen.</li>
</ul>



<p><strong>Zu empfehlen für:</strong> Pinecone-Nutzer, die neue LLM-gestützte Workflows ausprobieren möchten, um Indizes mit Embeddings zu erstellen oder Ergebnisse mithilfe von natürlichsprachlichen Befehlen  überprüfen möchten.</p>



<h2 class="wp-block-heading">Redis MCP-Server</h2>



<p>Als schnelle In-Memory-Datenbank wird Redis vornehmlich für Caching, Echtzeitanalysen und andere Anwendungsfälle eingesetzt, bei denen es auf die Latenz ankommt. Die Macher von Redis stellen ebenfalls einen <a href="https://redis.io/docs/latest/integrate/redis-mcp/" target="_blank" rel="noreferrer noopener">offiziellen MCP-Server</a> zur Verfügung, der Lese-, Abfrage- und Schreibfunktionen realisiert. Entwickler können den Redis MCP-Server über einen LLM-Client nutzen, um Redis-Daten auf Prompt-Basis:</p>



<ul class="wp-block-list">
<li>abzufragen,</li>



<li>zu analysieren oder</li>



<li>einzubetten.</li>
</ul>



<p>Die <a href="https://redis.io/docs/latest/integrate/redis-mcp/">Dokumentation</a> enthält auch einige Beispiel-Prompts für gängige Anwendungsfälle.</p>



<p>Im Gegensatz zu anderen MCP-Servern, die nur einen Teil der Plattformfunktionen abbilden, bietet Redis MCP vollen Support. Laut dem zugehörigen <a href="https://github.com/redis/mcp-redis" target="_blank" rel="noreferrer noopener">GitHub-Repository</a> stellt es so auch kein Problem dar, mit Redis-Konstrukten wie Hashes, Lists, Sets und Streams zu arbeiten. Ein möglicher Nachteil dieser Option: Der Redis MCP-Server bietet bislang keinen Support für Streamable-HTTP-Transport. Bis es soweit ist, ist dieser MCP-Server auf eine lokale Bereitstellung beschränkt.</p>



<p><strong>Zu empfehlen für:</strong> Alle, die einen lokalen MCP-Server für die Arbeit mit Redis-Daten suchen.</p>



<h2 class="wp-block-heading">Snowflake MCP-Server</h2>



<p>Snowflake ist eine in der Cloud gehostete, KI-fähige Datenplattform, die im Enterprise-Umfeld häufig für Data Warehousing, Datenanalysen und Data Engineering eingesetzt wird. Im Vergleich zu anderen Plattformen zeichnet sich Snowflake dabei dadurch aus, dass es vollumfänglich gemanagt wird und strukturierte sowie unstrukturierte Datentypen kombiniert. Der <a href="https://www.snowflake.com/en/developers/guides/getting-started-with-snowflake-mcp-server/" target="_blank" rel="noreferrer noopener">Snowflake MCP Server</a>, der über <a href="https://github.com/Snowflake-Labs/mcp" target="_blank" rel="noreferrer noopener">GitHub</a> verfügbar ist, lässt sich für diverse Standardoperationen der Snowflake-Plattform einsetzen. Dazu gehören etwa:</p>



<ul class="wp-block-list">
<li>„Fuzzy“-Suchen über Snowflakes Cortex Search in allen Datensätzen, sowie</li>



<li>semantische Abfragen strukturierter Daten mithilfe von Cortex Analyst.</li>
</ul>



<p>Zu den weiteren Funktionen gehören Objektmanagement-Prozesse – also Datensätze zu erstellen, zu aktualisieren oder zu löschen. Der MCP-Server kann darüber hinaus weitere agentenbasierte Funktionen realisieren, etwa SQL-Anweisungen für Backend-Datenbanken zu generieren und auszuführen. Der Snowflake MCP-Server ist dabei sowohl gut durchdacht als auch umfassend dokumentiert.</p>



<p><strong>Zu empfehlen für:</strong> Anwender, die bereits mit Snowflake arbeiten.</p>



<h2 class="wp-block-heading">Supabase MCP-Server</h2>



<p>PostgreSQL ist eines der beliebtesten und bewährtesten objektrelationalen, SQL-basierten Datenbanksysteme. Seiner aktiven <a href="https://leaddev.com/technical-direction/postgresql-database-quietly-ate-world" target="_blank" rel="noreferrer noopener">Open-Source-Community</a> sei Dank wurde PostgreSQL über Jahrzehnte hinweg weiterentwickelt. Aufgrund des quelloffenen Charakters gibt es jedoch keinen „offiziellen“ MCP-Server für die Plattform. Anthropic hatte ursprünglich zwar eine Referenzimplementierung entwickelt, diese ist jedoch <a href="https://github.com/modelcontextprotocol/servers-archived/tree/main/src/postgres" target="_blank" rel="noreferrer noopener">mittlerweile archiviert</a>.</p>



<p>Stattdessen bieten auf PostgreSQL aufbauende Datenbankplattformen <a href="https://dbhub.ai/blog/state-of-postgres-mcp-servers-2025" target="_blank" rel="noreferrer noopener">verschiedene Varianten</a> von MCP-Servern an. Diese unterscheiden sich hinsichtlich ihrer Herstellerneutralität und Spezifität. Eine bemerkenswerte Option ist der <a href="https://github.com/supabase-community/supabase-mcp#database" target="_blank" rel="noreferrer noopener">MCP-Server von Supabase</a>, einer Cloud-basierten „Backend-as-a-Service“- und Postgres-Entwicklungsplattform. Der Supabase MCP Server verbindet KI-Agenten mit Supabase-Projekten und ermöglicht es Entwicklern, Befehle in natürlicher Sprache zu erteilen, um:</p>



<ul class="wp-block-list">
<li>Tabellen zu verwalten,</li>



<li>Daten abzufragen,</li>



<li>Protokolle abzurufen, und</li>



<li>Konfigurationsinformationen einzusehen.</li>
</ul>



<p>Allerdings gibt es noch kein finales Release des MCP-Servers von Supabase, weswegen einige Funktionen noch experimentell sind.</p>



<p><strong>Zu empfehlen für:</strong> Entwickler, die Supabase nutzen und nach einem MCP-Server suchen, um KI-Assistenten mit Postgres-Datenbanken zu verbinden – auf experimenteller Basis.</p>



<h2 class="wp-block-heading">Weitere MCP-Serveroptionen für Datenbanken</h2>



<p>Neben den offiziellen MCP-Servern mit Anbieter-Support stehen auch zahlreiche MCP-Server für weitere Datenbankplattformen und -typen zur Verfügung. Zum Beispiel:</p>



<ul class="wp-block-list">
<li><a href="https://github.com/bytebase/dbhub" target="_blank" rel="noreferrer noopener">DBHub</a>, ein MCP-Server, der den LLM-Zugriff über verschiedene Datenbanktypen hinweg bündelt und mit MySQL, PostgreSQL, SQL Server, MariaDB und SQLite kompatibel ist.</li>



<li>Der <a href="https://github.com/benborla/mcp-server-mysql">MCP Server for MySQL</a>, der vom deutschen Full-Stack-Entwickler <a href="https://benborla.dev/">Ben Borla</a> entwickelt und für Claude Code optimiert wurde.</li>



<li>Die Supabase-, respektive Postgres-Alternativen <a href="https://github.com/pgEdge/pgedge-postgres-mcp/" target="_blank" rel="noreferrer noopener">pgEdge Postgres MCP</a>, <a href="https://neon.com/docs/ai/neon-mcp-server" target="_blank" rel="noreferrer noopener">Neon MCP Server</a> und <a href="https://github.com/crystaldba/postgres-mcp" target="_blank" rel="noreferrer noopener">Postgres MCP Pro</a>.</li>



<li>Die auf Vektordatenbanken ausgelegten MCP-Server von <a href="https://docs.weaviate.io/weaviate/mcp/docs-mcp-server" target="_blank" rel="noreferrer noopener">Weaviate</a> und <a href="https://milvus.io/docs/milvus_and_mcp.md" target="_blank" rel="noreferrer noopener">Milvus</a>.</li>
</ul>



<p>(fm)</p>



<p><strong>Dieser Artikel ist </strong><a href="https://www.infoworld.com/article/4181843/10-mcp-servers-to-connect-llms-with-databases.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anzeige: IT-Jobs in Cybersecurity, Architektur, DevOps und Entwicklung]]></title>
<description><![CDATA[Cyber Defence, DevOps, IT-Architektur und Network Security: Diese sechs IT-Jobs bieten anspruchsvolle Aufgaben in starken Branchen. (Golem Karrierewelt, Unternehmenssoftware)]]></description>
<link>https://tsecurity.de/de/3596533/it-nachrichten/anzeige-it-jobs-in-cybersecurity-architektur-devops-und-entwicklung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596533/it-nachrichten/anzeige-it-jobs-in-cybersecurity-architektur-devops-und-entwicklung/</guid>
<pubDate>Sun, 14 Jun 2026 07:02:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cyber Defence, DevOps, IT-Architektur und Network Security: Diese sechs IT-Jobs bieten anspruchsvolle Aufgaben in starken Branchen. (<a href="https://www.golem.de/specials/golemakademie/">Golem Karrierewelt</a>, <a href="https://www.golem.de/specials/unternehmenssoftware/">Unternehmenssoftware</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=209697&amp;page=1&amp;ts=1781413202" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Kimi K2.7-Code cuts thinking tokens 30% — but practitioners say the benchmarks don't check out]]></title>
<description><![CDATA[Moonshot AI released Kimi K2.7-Code this week, an open-source update to its K2 coding model family, claiming leaner reasoning and double-digit performance gains.K2.7-Code is built on the same trillion-parameter mixture-of-experts architecture as its predecessor K2.6, and drops in via an OpenAI-co...]]></description>
<link>https://tsecurity.de/de/3594650/it-nachrichten/kimi-k27-code-cuts-thinking-tokens-30-but-practitioners-say-the-benchmarks-dont-check-out/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594650/it-nachrichten/kimi-k27-code-cuts-thinking-tokens-30-but-practitioners-say-the-benchmarks-dont-check-out/</guid>
<pubDate>Sat, 13 Jun 2026 00:25:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Moonshot AI released Kimi K2.7-Code this week, an open-source update to its <a href="https://venturebeat.com/ai/moonshots-kimi-k2-thinking-emerges-as-leading-open-source-ai-outperforming">K2 coding model </a>family, claiming leaner reasoning and double-digit performance gains.</p><p>K2.7-Code is built on the same trillion-parameter mixture-of-experts architecture as its p<a href="https://venturebeat.com/ai/kimi-k2-6-runs-agents-for-days-and-exposes-the-limits-of-enterprise-orchestration">redecessor K2.6</a>, and drops in via an OpenAI-compatible API — which matters for teams already running K2.6 in production gateways.</p><p>When K2.6 launched in April, it topped OpenRouter's weekly LLM leaderboard — a ranking based on actual API routing decisions by developers, not self-reported benchmark scores.</p><p>Moonshot AI says K2.7-Code addresses what it calls "overthinking," reducing thinking-token usage by 30% compared to K2.6 — a number that would directly affect inference costs for teams running agentic workflows. Whether that efficiency gain holds on independent benchmarks is a question practitioners have already started raising publicly.</p><h2>What Kimi K2.7-Code is</h2><p>K2.7-Code is released under a Modified MIT license, with weights available on HuggingFace. The model is deployable via vLLM or SGLang. It runs exclusively in thinking mode and does not support temperature adjustment — Moonshot AI has fixed it at 1.0, meaning teams cannot tune output determinism the way they might with other models.</p><p>The core change from K2.6 is how the model generates low-level code. Where K2.6 produced implementations by wrapping existing libraries and routing through established frameworks, K2.7-Code authors implementations directly. Moonshot AI says this produces more reliable generalization across Rust, Go and Python, and across task types including frontend development, DevOps and performance optimization.</p><p>On benchmark performance, Moonshot AI claims gains of 21.8% on Kimi Code Bench v2, 11% on Program Bench and 31.5% on MLS Bench Lite. All three are proprietary benchmarks run by Moonshot AI. The model has not been submitted to DeepSWE, an independent coding benchmark that produces a 70-point spread across models — compared to SWE-Bench Pro's 30-point spread — making it a more discriminating signal for teams configuring model routing systems.</p><div></div><h2>More honest, weaker for it</h2><p>The picture from outside Moonshot's own benchmarks is more complicated.</p><p>Researcher Elliot Arledge ran K2.7-Code against K2.6 and Claude Fable 5 on KernelBench-Hard, a public benchmark focused on GPU kernel optimization, and published his full run logs at kernelbench.com. </p><p>"K2.7 is more honest but not more capable," <a href="https://x.com/elliotarledge/status/2065443474560946615">Arledge wrote on X</a>. </p><p>On five of six problems, K2.7-Code produced real authored Triton kernels where K2.6 had used library wrappers. Two of those kernels failed on the model's own bugs. The MoE kernel result regressed from K2.6's score of 0.222 to 0.157. </p><p>"Fable, for reference, tops every cell it doesn't honestly fail," Arledge wrote.</p><p>Sugumaran Balasubramaniyan, a developer who built a model-task-router for the Hermes Agent platform using DeepSWE as his reference signal, responded publicly to the K2.7-Code release and challenged Moonshot AI directly on the benchmark choices.</p><p> "Respectfully, every model 'improves' double digits on its own test suite," <a href="https://x.com/sugumaran___/status/2065416166911205579">Balasubramaniyan wrote on X</a>. </p><p>He noted that K2.6 scored 24% on DeepSWE, tied with GPT-5.4-mini, and asked whether Moonshot AI would submit K2.7-Code to the same benchmark. </p><p>Balasubramaniyan said it took 13 review rounds to get the benchmark data right for his router and that he would route coding tasks to K2.7-Code if the independent numbers hold up.</p><div></div><h2>What this means for enterprises</h2><p>The token efficiency gain is immediately usable. Teams running K2.6 in production can swap in K2.7-Code via the OpenAI-compatible API and expect lower inference costs on agentic workflows without an architecture change. The 30% thinking-token reduction is Moonshot's own number, but the integration path is low-risk enough to test against your own workloads before committing.</p><p>The practical question is whether those efficiency gains hold on a team's own task distribution. Running K2.7-Code against your own workloads before adjusting gateway weights is the low-risk path to finding out.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mistral AI seeks 3 billion euros to fund its European AI push]]></title>
<description><![CDATA[French AI startup Mistral AI is negotiating a new funding round of around 3 billion euros at a valuation of approximately 20 billion euros.
The article Mistral AI seeks 3 billion euros to fund its European AI push appeared first on The Decoder.]]></description>
<link>https://tsecurity.de/de/3593665/ai-nachrichten/mistral-ai-seeks-3-billion-euros-to-fund-its-european-ai-push/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593665/ai-nachrichten/mistral-ai-seeks-3-billion-euros-to-fund-its-european-ai-push/</guid>
<pubDate>Fri, 12 Jun 2026 16:05:18 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="2560" height="1429" src="https://the-decoder.com/wp-content/uploads/2026/06/mistral-logo-wall-nano-banana-pro-scaled.jpg" class="attachment-full size-full wp-post-image" alt="Stylized Mistral logos in yellow and orange on a wall symbolize the branding of the AI platform Nano Banana Pro." decoding="async" fetchpriority="high"></p>
<p>        French AI startup Mistral AI is negotiating a new funding round of around 3 billion euros at a valuation of approximately 20 billion euros.</p>
<p>The article <a href="https://the-decoder.com/mistral-ai-seeks-3-billion-euros-to-fund-its-european-ai-push/">Mistral AI seeks 3 billion euros to fund its European AI push</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,74ms -->